LanceSoft Inc logo

Cybersecurity Governance, Risk, and Incident Readiness Lead

LanceSoft Inc
  • Columbus, OH
  • Quick Apply
16 days ago

Job Description

This job is with Encode, Inc a fully owned subsidiary of Lancesoft

 
Position summary: The Cybersecurity Governance, Risk, and Incident Readiness Lead will be responsible for CRAA’s cybersecurity governance, maturity, policy improvement, incident-readiness, exercise, and training workstreams.
The role will lead the annual NIST CSF-aligned maturity assessment, review and improve cybersecurity policies and procedures, enhance incident-response and recovery plans, design and facilitate tabletop exercises, deliver quarterly incident-response training, support the airport-wide exercise, and translate findings into practical remediation roadmaps.
CRAA clarified that formal CMMC certification is not required. The recurring maturity requirement is one annual assessment aligned with the NIST Cybersecurity Framework and CRAA’s CMMI-style maturity approach.
Key responsibilities
  • Cybersecurity governance
  • Coordinate governance activities with CRAA’s cybersecurity and information-technology teams.
  • Align advisory work to CRAA’s cybersecurity strategy, roadmap, risk priorities, operating environment, and applicable requirements.
  • Support the Govern, Identify, Protect, Detect, Respond, and Recover functions.
  • Provide consultative support concerning asset management, data governance, risk management, access control, training, data security, recovery, monitoring, response, mitigation, and improvement.
  • Support CRAA’s enterprise Risk Governance forum and existing remediation-tracking processes.
  • Maintain traceability among findings, risks, recommendations, responsible owners, actions, and status.
  • Facilitate prioritization based on severity, business impact, effort, dependencies, and residual risk.
  • Annual cybersecurity maturity assessment
  • Plan and lead one annual NIST CSF-aligned cybersecurity maturity assessment.
  • Define the assessment scope, participants, evidence requests, interviews, rating criteria, and schedule.
  • Review policies, processes, procedures, governance records, technical evidence, and operating practices.
  • Facilitate workshops with CRAA cybersecurity and technology personnel.
  • Assess current maturity using CRAA’s requested CMMI-style approach.
  • Document current-state maturity, target-state objectives, material gaps, strengths, dependencies, and recommended improvements.
  • Develop a prioritized roadmap with approximate levels of effort.
  • Present findings to technical personnel and executive leadership.
  • Track progress against prior-year recommendations.
  • Avoid representing the assessment as a formal CMMC certification or CMMI organizational appraisal.
  • Policy, standard, and procedure support
  • Establish a structured process for reviewing CRAA’s existing cybersecurity documentation.
  • Support review and improvement of approximately 100 policies, standards, procedures, plans, and operational documents, subject to CRAA prioritization.
  • Identify obsolete, conflicting, incomplete, or missing requirements.
  • Recommend practical revisions aligned with CRAA’s technology, risk, and operating environment.
  • Draft new documentation where emerging technology or operations create a material need.
  • Coordinate review with document owners, technical stakeholders, leadership, and other CRAA personnel.
  • Maintain version control, approval history, ownership, review dates, and document relationships.
  • Ensure that policy language is implementable and does not create unsupported operational commitments.
  • Incident-response planning
  • Review and enhance CRAA’s existing Incident Response Plan.
  • Define or improve roles, responsibilities, severity criteria, communications, escalation, evidence handling, containment decisions, recovery coordination, and post-incident review.
  • Align the plan with the co-managed SOC operating model.
  • Document the relationship among the MSSP, CRAA internal responders, cybersecurity leadership, cyber-insurance responders, legal stakeholders, and other participants.
  • Support ransomware-readiness and recovery-planning activities.
  • Ensure incident procedures reflect CRAA’s restrictions on AI, data handling, external ticketing, and third-party access.
  • Incorporate lessons from actual events, exercises, post-mortems, and control assessments.
  • Disaster recovery and business continuity support
  • Review cybersecurity aspects of CRAA’s disaster-recovery and business-continuity plans.
  • Help identify dependencies among incident response, system recovery, communications, crisis management, and continuity functions.
  • Recommend improvements to existing plans rather than assuming they must be developed from the ground up.
  • Support testing and evaluation of cybersecurity-related recovery processes.
  • Coordinate with CRAA stakeholders responsible for technology recovery and continuity.
  • Document gaps, dependencies, recovery risks, and recommended actions.
  • Tabletop exercises
  • Design and facilitate at least two IT-focused tabletop exercises annually.
  • Coordinate exercise objectives, scope, participants, scenario, injects, decision points, facilitation guides, and evaluation criteria.
  • Develop relevant scenarios reflecting CRAA’s identified risks and emerging threats.
  • Test the Technology Department’s ability to detect, communicate, escalate, respond, recover, and coordinate.
  • Observe actions and decisions without creating artificial expectations that differ from approved plans.
  • Facilitate structured hot-wash discussions.
  • Produce after-action reports identifying strengths, gaps, lessons learned, and prioritized recommendations.
  • Track improvement actions into subsequent exercises and program plans.
  • Airport-wide IR/DR/BC exercise
  • Support the broader airport incident-response, disaster-recovery, and business-continuity exercise once during the three-year term.
  • Assist CRAA with technology and cyber-related scenario design.
  • Observe and evaluate technology and cybersecurity response activities.
  • Assess coordination between technology and broader airport stakeholders.
  • Provide feedback on incident-response and recovery performance.
  • Document improvement opportunities and recommended plan updates.
  • Recognize that CRAA’s clarifications describe both an observational role and support for scenario design and evaluation.
  • Quarterly training
  • Develop and deliver four one-hour incident-response training sessions annually.
  • Tailor content to emerging incident-response risks and CRAA’s operating environment.
  • Address best practices, successful response examples, lessons from failed responses, and strategies for avoiding similar failures.
  • Deliver sessions virtually to approximately 25 to 40 participants.
  • Adapt content for the Technology Department while allowing stakeholder or executive participation when CRAA requests it.
  • Develop supporting materials, attendance records, learning objectives, and evaluation methods.
  • Incorporate lessons from incidents, exercises, maturity assessments, and evolving threat patterns.
  • Executive and technical reporting
  • Prepare maturity reports, policy recommendations, exercise reports, training summaries, and incident-readiness roadmaps.
  • Identify findings by risk and severity.
  • Provide approximate levels of effort for recommended changes.
  • Identify residual risk following proposed improvements.
  • Develop executive-level presentations that clearly explain business impact, priorities, and decisions.
  • Coordinate reporting with the Engagement Manager.
  • Ensure that recommendations are practical, cost-conscious, and tailored to CRAA.
  • Required capabilities: The proposed individual should demonstrate:
  • Leadership of cybersecurity governance, risk, compliance, and maturity programs.
  • Experience conducting NIST CSF-aligned maturity assessments.
  • Experience reviewing and developing cybersecurity policies, standards, procedures, and plans.
  • Experience enhancing incident-response, disaster-recovery, and business-continuity documentation.
  • Experience designing and facilitating tabletop exercises.
  • Experience developing and delivering cybersecurity training.
  • Strong executive writing, workshop facilitation, presentation, and stakeholder-management skills.
  • Ability to translate technical findings into prioritized risks and actionable roadmaps.
  • Preferred qualifications: Include only where held:
  • Bachelor’s or advanced degree in cybersecurity, information systems, risk management, business continuity, emergency management, or a related discipline.
  • CISSP, CISM, CRISC, CGEIT, CBCP, CBCI, GCIH, ISO 27001, NIST-related, or comparable credentials.
  • Experience with public-sector, aviation, transportation, critical-infrastructure, or regulated clients.
  • Experience presenting cybersecurity findings to executive leadership.
  • Key performance indicators: Potential measures include:
  • Annual assessment completion
  • Roadmap acceptance and action closure
  • Policy-review completion rate
  • Document approval timeliness
  • Exercise completion
  • After-action report timeliness
  • Exercise-action closure
  • Training completion and attendance
  • Stakeholder feedback
  • Recurring maturity improvement
  • Residual-risk reduction

Numbers & Facts

LocationColumbus, OH
IndustryStaffing/Employment Agencies
Company Size2,000 to 2,499 employees
Year Founded2000
Websitehttp://www.lancesoft.com/

About Company

We are a $125 Million, NMSDC-certified Minority & Woman owned Workforce Solutions Company headquartered in the DC metro area with presence across US with global presence - Canada, Mexico, India, UK, Malaysia, Indonasia, Hongkong, Singapore, UAE. We are specialized in providing Workforce Solutions, SOW project delivery, Engineering Solutions, Creative Services. We currently support 100+ Fortune companies globally and across multiple industry segments. We are currently supporting several massive programs across industry segment nationally/globally (Intel, Ally, AMD, QUALCOMM, Morgan Stanley, Kraft/ Mondelez, MNP, Amdocs, Dell, SanDisk, Medtronic, Becton Dickinson, GE, Lockheed Martin, UTC, L-3 Communications, Caterpillar, BMW, Mercedes Benz, National Grid, Dominion, Energy Future Holdings, PSEG, 3M, Fidelity, Aetna, Humana, Johnson & Johnson, Pfizer, Merck etc). 

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender, identity, national origin, disability, or protected veteran status.

Skills

  • Access Controlunmatched
  • Artificial Intelligence (AI)unmatched
  • Asset Managementunmatched
  • Aviation Industryunmatched
  • Best Practicesunmatched
  • Business Continuity Planning (BCP)unmatched
  • Business Supportunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Capability Maturity Model Integration (CMMI)unmatched
  • Communication Skillsunmatched
  • Crisis Managementunmatched
  • Data Recoveryunmatched
  • Disaster Recoveryunmatched
  • Documentationunmatched
  • Emergency Managementunmatched
  • Emerging Technologyunmatched
  • Establish Prioritiesunmatched
  • GCIH - GIAC Certified Incident Handlerunmatched
  • IR (Infrared)unmatched
  • ISO (International Organization for Standardization)unmatched
  • Incident Managementunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Insuranceunmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Legalunmatched
  • Operations Planningunmatched
  • Performance Metricsunmatched
  • Policy Developmentunmatched
  • Policy Implementationunmatched
  • Procedure Developmentunmatched
  • Program Planningunmatched
  • Project Trackingunmatched
  • Ransomwareunmatched
  • Reporting Skillsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Source Code/Configuration Management (SCM)unmatched
  • Strength of Materialsunmatched
  • Technical Operationsunmatched
  • Technical Presentationunmatched
  • Technical Writingunmatched
  • Technology Analysisunmatched
  • Testingunmatched
  • Traceabilityunmatched
  • Training/Teachingunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder