United States Department of Homeland Security - Washington, DC

posted 5 months ago

Full-time - Mid Level
Washington, DC
Administration of Economic Programs

About the position

The Department of Homeland Security (DHS) is actively seeking professionals to fill various leadership roles within Cybersecurity Risk Management and Compliance. This includes positions such as Cybersecurity Risk Management Lead, Cybersecurity Governance Team Lead, Senior Risk and Compliance Program Manager, Cybersecurity Risk Consultant, and Risk Assessment and Compliance Manager. All roles are part of the DHS Cybersecurity Service, which employs a multi-phase assessment process to qualify applicants. This process is designed to identify individuals who have successfully completed the necessary evaluations for their respective capability and career track/level. Given the rapidly evolving landscape of cybersecurity, the DHS Cybersecurity Service utilizes 'Talent Pools' to maintain a pool of qualified candidates for ongoing consideration for relevant job openings. By applying to this job announcement, candidates are opting to be part of the DHS-CS Talent Pool, remaining eligible for consideration for up to one year from the date of completion. The DHS Cybersecurity Service offers a variety of opportunities across the Department, including specialized programs at the DHS Office of Strategy, Policy, and Plans (PLCY), the Cybersecurity and Infrastructure Security Agency (CISA), the DHS Office of the Chief Information Officer (OCIO), and the Federal Emergency Management Agency (FEMA). Depending on the specific career level and role, employees in the Leadership Career Track with a focus on Risk Management and Compliance will apply their expertise to perform a range of critical tasks. These tasks include overseeing the evaluation, documentation, validation, assessment, and authorization processes necessary to ensure that both existing and new information technology systems comply with the Department's cybersecurity and risk requirements. This role is pivotal in providing decision-makers with the knowledge needed to make informed risk decisions. In addition to technical responsibilities, the position involves considering risk assumptions and organizational tolerance for risk to inform strategic decision-making. Employees will lead teams or programs to assess adverse impacts or consequences to DHS, tailoring communications for various leadership levels and target audiences to present strategic recommendations. They will assist DHS leadership in making policy decisions that guide subsequent risk management processes and engage with stakeholders across multiple organizations to implement and assess necessary security and privacy controls. Furthermore, the role includes ensuring appropriate treatment of risk, compliance, and assurance from both internal and external perspectives, and reporting on the security state of systems to relevant stakeholders. Employees will also be responsible for maintaining situational awareness regarding the security and privacy posture of systems and collaborating with internal and external experts in risk management and compliance.

Responsibilities

  • Oversee and lead the evaluation, documentation, validation, assessment, and authorization processes for information technology systems to meet cybersecurity and risk requirements.
  • Consider risk assumptions and organizational tolerance for risk to inform strategic decision-making.
  • Lead teams in determining adverse impacts or consequences to DHS and customize communications for different leadership levels to present strategic recommendations.
  • Assist DHS leadership in making strategy or policy decisions regarding the adverse impact or consequences to the organization.
  • Engage with stakeholders to identify, select, tailor, implement, document, and assess necessary security and privacy controls.
  • Ensure appropriate treatment of risk, compliance, and assurance from internal and external perspectives, reporting on the security state of systems.
  • Prepare and organize collaborative efforts for monitoring and maintaining situational awareness about the security and privacy posture of systems.
  • Collaborate with internal and external stakeholders and experts in risk management and compliance.
  • Authorize system operation based on risk determinations to organizational operations and assets.
  • Lead teams in cybersecurity risk assessment and compliance to determine levels of risk and policy impact on strategy.

Requirements

  • 5-15 years of cybersecurity work experience.
  • 0-5 years of cybersecurity leadership experience.
  • Expertise in overseeing, evaluating, and supporting documentation, validation, assessment, and authorization processes for information technology systems.
  • Understanding and utilization of the National Institute of Standards and Technology (NIST) series of documents.

Nice-to-haves

  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Knowledge of federal cybersecurity requirements such as FISMA and relevant Executive Orders.
  • Exposure to tools/technologies for hardware/software asset management, identity management, secure cloud services, and cyber threat intelligence.

Benefits

  • Competitive salary based on experience and expertise.
  • Opportunities for career advancement within the DHS Cybersecurity Service.
  • Access to specialized training and certifications in cybersecurity.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service