Senior Cybersecurity Policy Analyst

Posted 3 Days Ago
Be an Early Applicant
Hiring Remotely in Bethesda, MD, USA
In-Office or Remote
110K-120K Annually
Senior level
Information Technology • Professional Services
The Role
Lead NIH Zero Trust security policy and standards support by translating federal and HHS mandates into an enforceable policy framework. Develop policy hierarchies, trace requirements to controls and governance checkpoints, benchmark policies against NIST and CISA standards, produce gap registers, and create policy anchors with enforcement evidence and ownership. Draft accessible policy briefs and communications, while aligning security policy with AI governance, privacy, HIPAA, and data-management requirements.
Summary Generated by Built In

Company Overview:

Over the past 15 years, eTel has delivered essential solutions for the federal government by securing and managing data, providing scalable identity access, modernizing legacy systems, and building high-performance platforms. By integrating new technologies and ensuring reliable operations we help agencies stay prepared for future challenges As a premier technology solutions and services company to the US federal government, eTel possesses longstanding relationships across the federal civilian marketplace. Other customers include the broader Treasury Department, Commerce Department, and State Department.


eTel offers integrated CMMI Level 3 processes, tools, and techniques with innovative, cost-efficient, and secure solutions to address complex challenges. eTel also holds ISO 9001:2015, ISO/IEC 27001:2013, and ISO/IEC 20000-1:2018 certifications, and offers dedicated subject matter experts (SMEs) and thought leaders that possess a deep understanding of customers’ environments and challenges.

Work Location and On-Site/Telework Requirements: Hybrid – NIH, Bethesda, MD. On site for stakeholder workshops (typically 1–2 days/week during the first 120 days, then as scheduled).

Citizenship: U.S. Citizenship required

Clearance: All staff must obtain NIH suitability and a PIV credential and be fluent in English. Anyone doing risk or vulnerability testing needs a current T2 (BI) or higher investigation.

Salary Range: $110,000-$120,000 yearly salary

 

Overview:

You will lead Task 5, Security Policy and Standards Support for ZTA Operationalization, under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). Working in the Risk & Policy Pod, you will turn federal and HHS Zero Trust mandates into a single, enforceable NIH policy framework. You will also support Task 6 communications and Task 7 governance.

 

Responsibilities:

  • Build the Single Policy Framework (Subtask 5.1): NIH ZTA policy, then standards by pillar, then implementation guides by workload family, then procedures, with an enterprise risk management (ERM) risk-appetite statement at the top.
  • Trace every policy statement up to its federal or HHS source (EO 14028, OMB M-22-09, HHS IS2P, HHS ZTA Strategy) and down to the Overlay control, architecture pattern, and governance checkpoint that enforce it.
  • Inventory NIH security policies, IS2P-derived standards, and procedures. Benchmark them against NIST SP 800-53 Rev 5, 800-207, 800-63-4, the CISA ZTMM, and current threats (MITRE ATT&CK). Produce a gap register with draft language and an adoption path (Subtask 5.2).
  • Develop policy anchors (Subtask 5.3), each made up of the policy statement, the technical setting that enforces it, the evidence that proves it, and the owner. Start with identity (conditional access), devices, networks, and data (classification labels driving DLP).
  • Write ZTA Policy Briefs and role-based monthly enterprise communications with the NIH ISAO Communications Team. All content must conform to Section 508.
  • Align policy with AI governance (NIST AI RMF, OMB AI memoranda, HHS AI strategy) and with data-management requirements (NIH Data Management and Sharing Policy, Privacy Act, HIPAA where applicable).

Tools & Technology Environment: Microsoft 365/SharePoint, Confluence and the OCIO ZTA Wiki, Jira; Microsoft Accessibility Checker and Adobe Acrobat for Section 508 checks.


Required Qualifications:

  • Bachelor's degree plus 8+ years in federal cybersecurity policy, governance, or compliance.
  • Working knowledge of HHS IS2P, FISMA, NIST frameworks, and OMB M-22-09.
  • Experience applying ERM principles to security policy.
  • Excellent technical writing and policy-drafting skills.
  • Ability to obtain an NIH suitability determination and PIV credential; fluent in English.

Preferred Qualifications:

  • HHS or NIH policy development and approval experience.
  • CISSP, CISM, or CGRC.
  • Zero Trust policy experience; privacy knowledge (Privacy Act, HIPAA, research data).
  • Current National Institutes of Health (NIH) or U.S. Department of Health and Human Services (HHS) experience is highly preferred.

Commitment to Diversity -
eTelligent Group provides equal employment opportunities (EEO) to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, nations origin, age, disability, genetic information, marital status, amnesty, status as a covered veteran, and any other characteristic provided in accordance with applicable, federal, state and local laws.

Skills Required

  • Bachelor's degree
  • 8+ years of experience in federal cybersecurity policy, governance, or compliance
  • Working knowledge of HHS IS2P, FISMA, NIST frameworks, and OMB M-22-09
  • Experience applying enterprise risk management principles to security policy
  • Excellent technical writing and policy-drafting skills
  • Ability to obtain an NIH suitability determination and PIV credential
  • Fluency in English
  • HHS or NIH policy development and approval experience
  • CISSP, CISM, or CGRC certification
  • Zero Trust policy experience
  • Privacy knowledge, including the Privacy Act, HIPAA, and research data
  • Current NIH or HHS experience
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Leesburg, VA
33 Employees
Year Founded: 2005

What We Do

eTelligent Group is a proven team of talented IT professionals providing reliable solutions for business & information technology (IT) management and services. We solve complex program and IT problems by implementing proven strategies & innovative solutions. We deliver IT services, agile and DevOps development, big data services, IT program management, and cyber security services. Working as a trusted partner of the Federal Government, we hold ourselves to the highest industry standards such as (CMMI Level 3 and PMBOK). We are proud of our outstanding past performance implementing client solutions that increase both reliability and security for our clients. We deliver professional services by applying our proven process methodologies to exceed performance standards. We partner with leading COTS solution providers such as webMethods, MuleSoft, and RedHat to provide Middleware, API-led integrations, and SOA-based solutions. We deliver cutting edge technical solutions, while meeting the core business needs of each client.

Similar Jobs

Wipfli Logo Wipfli

Consultant

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
88K-118K Annually

Wipfli Logo Wipfli

Senior Manager/Director, Tax - Insurance

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
142K-192K Annually

Shield AI Logo Shield AI

Staff Engineer

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Remote
USA
200K-300K Annually

Shield AI Logo Shield AI

Staff Deep Learning Engineer, State Estimation (R5785)

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Remote
USA
200K-300K Annually

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account