Governance, Compliance, and Training SME

GuidehouseWashington, DC
2d$130,000 - $216,000Onsite

About The Position

Guidehouse is seeking a cybersecurity Governance, Compliance, and Training (GRT) subject matter expert to provide program management and product development support to a client GCT Manager. The GCT SME will be responsible for recommending, developing, and implementing GCT program initiatives. Responsibilities include the following: Supporting the GCT Manager with execution of the Authorizing Official’s Risk Management Framework program Preparing risk assessment reports and system authorization recommendations Facilitating System Owner briefings to the Authorizing Official Developing and updating cybersecurity policies, plans, and procedures Preparing and maintaining cybersecurity governance documentation Communicating cybersecurity policy and procedure updates to stakeholders Implementing new cybersecurity governance processes Providing compliance standard research and gap analyses Advising on the implementation of federal cybersecurity compliance standards Coordinating the technical implementation of cybersecurity controls with technical teams Managing cybersecurity audit preparation and execution projects across the system environment Analyzing and reporting on cybersecurity audit reports and remediation recommendations Validating that implemented cybersecurity controls adequately address system security risk Developing and implementing cybersecurity awareness and training initiatives Managing GCT program projects and providing project coordination support to cybersecurity operations and network operations teams Providing security impact assessments and compliance assessments to the Change Control Board Regularly interfacing with system administrator, engineering, and development teams Recommending GCT program initiatives to continuously improve GCT program effectiveness and integration with the operational system environment Preparing and facilitating briefings to the Chief Information Security Officer and Chief Information Officer

Requirements

  • An ACTIVE and MAINTAINED "TOP SECRET" Federal or DoD security clearance
  • Bachelor's Degree
  • FIVE (5) or more years of experience working in federal cybersecurity or IT
  • Ability to work onsite at client site in Washington D.C. 4-5 days a week

Nice To Haves

  • An ACTIVE and MAINTAINED "TOP SECRET/SCI (TS/SCI)" Federal or DoD security clearance
  • Master’s degree in a cybersecurity discipline
  • Experience supporting customers in a client-facing environment
  • Excellent written and verbal communication, organizational, and time management skills
  • Experience working in cybersecurity or IT, including experience in cybersecurity governance, risk management, and compliance
  • Relevant cybersecurity certification (CISSP, CISM, CGRC, CISA)
  • Experience supporting DoD or Intelligence Community cybersecurity programs
  • Experience in cybersecurity or IT project management, including managing multiple long-term projects simultaneously
  • Experience deliberately improving program maturity
  • Experience evaluating, setting, and modifying program priorities
  • Experience leading cybersecurity compliance projects in a classified federal environment
  • Experience executing cybersecurity compliance external audits
  • Experience supporting the NIST Risk Management Framework for classified federal systems
  • Experience building new cybersecurity programs
  • Experience developing cybersecurity training products and communications
  • Experience working directly with both management and technical teams
  • Demonstrated ability to quickly grasp new technical concepts and integrate new information into existing plans and frameworks
  • Experience leading Cybersecurity Awareness Month campaigns
  • Experience leading technical teams in cybersecurity or IT settings
  • Experience interfacing with physical security and personnel security stakeholders
  • Experience coordinating multidisciplinary cybersecurity initiatives (including cybersecurity operations and cybersecurity engineering)
  • Understanding of Zero Trust architecture
  • Understanding of cybersecurity risk and governance considerations associated with emerging technologies

Responsibilities

  • Supporting the GCT Manager with execution of the Authorizing Official’s Risk Management Framework program
  • Preparing risk assessment reports and system authorization recommendations
  • Facilitating System Owner briefings to the Authorizing Official
  • Developing and updating cybersecurity policies, plans, and procedures
  • Preparing and maintaining cybersecurity governance documentation
  • Communicating cybersecurity policy and procedure updates to stakeholders
  • Implementing new cybersecurity governance processes
  • Providing compliance standard research and gap analyses
  • Advising on the implementation of federal cybersecurity compliance standards
  • Coordinating the technical implementation of cybersecurity controls with technical teams
  • Managing cybersecurity audit preparation and execution projects across the system environment
  • Analyzing and reporting on cybersecurity audit reports and remediation recommendations
  • Validating that implemented cybersecurity controls adequately address system security risk
  • Developing and implementing cybersecurity awareness and training initiatives
  • Managing GCT program projects and providing project coordination support to cybersecurity operations and network operations teams
  • Providing security impact assessments and compliance assessments to the Change Control Board
  • Regularly interfacing with system administrator, engineering, and development teams
  • Recommending GCT program initiatives to continuously improve GCT program effectiveness and integration with the operational system environment
  • Preparing and facilitating briefings to the Chief Information Security Officer and Chief Information Officer

Benefits

  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service