Cybersecurity Policy Analyst

Cb
  • Columbus, Ohio
    21 days ago

    Job Description

    Responsive recruiter
    Replies within 24 hours
    Benefits:
    • 401(k)
    • 401(k) matching
    • Dental insurance
    • Health insurance
    • Paid time off
    • Profit sharing
    • Training & development
    • Tuition assistance
    • Vision insurance
    SarelaTech is seeking a Cybersecurity Policy Analyst to support the Defense Logistics Agency (DLA) Enterprise Cyber Security Service Provider (CSSP). The selected candidate will provide technical expertise in the development, review, implementation, and maintenance of cybersecurity policies, procedures, and governance supporting enterprise cyber defense and Incident Response operations.

    Working closely with government stakeholders, cybersecurity engineers, compliance personnel, and incident response teams, the Cybersecurity Policy Analyst will ensure cybersecurity policies, operational procedures, and documentation remain aligned with Department of Defense (DoD), Defense Logistics Agency (DLA), Risk Management Framework (RMF), and Cyber Defense requirements. This position also supports CSSP assessments, compliance reporting, cybersecurity exercises, audit readiness, and the development and delivery of cybersecurity training.

    Primary Responsibilities
    • Develop, review, maintain, and update cybersecurity policies, Standard Operating Procedures (SOPs), Tactics, Techniques, and Procedures (TTPs), and operational guidance supporting DLA Enterprise Cyber Security Service Provider (CSSP) operations and Incident Response activities.
    • Ensure cybersecurity policies and documentation comply with DoD, DLA, NIST, RMF, and applicable cybersecurity directives, standards, and regulatory requirements.
    • Support CSSP assessments, inspections, audits, and compliance activities by preparing documentation, tracking metrics, compiling required artifacts, and coordinating with government stakeholders.
    • Assist DLA programs with the development and maintenance of Risk Management Framework (RMF) documentation and cybersecurity compliance packages.
    • Plan, coordinate, and support cybersecurity tabletop exercises; develop After Action Reports (AARs), lessons learned, and process improvement recommendations.
    • Develop and deliver cybersecurity training, presentations, and briefings on Incident Response policies, procedures, and compliance requirements for government personnel.
    • Prepare technical documentation, executive briefings, compliance reports, meeting minutes, and status updates to support cybersecurity governance and operational readiness.
    • Collaborate with cybersecurity operations, incident response teams, engineers, and government leadership to implement policy updates and improve enterprise cybersecurity processes.
    Required Qualifications

    • Top Secret security clearance with SCI eligibility
    • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or related technical discipline.
    • Seven (7) or more years of experience supporting cybersecurity policy, governance, compliance, security operations, or Incident Response programs within a DoD or Federal environment.
    • Experience developing and maintaining cybersecurity policies, SOPs, TTPs, technical documentation, or operational procedures.
    • Knowledge of DoD cybersecurity policies, Risk Management Framework (RMF), NIST guidance, and cybersecurity compliance requirements.
    • Experience supporting cybersecurity compliance activities, inspections, audits, or assessment programs.
    • Strong technical writing, documentation, analytical, and presentation skills.
    • Ability to communicate effectively with technical teams, cybersecurity leadership, and government stakeholders.
    Desired Qualifications

    • Experience supporting the Defense Logistics Agency (DLA), DISA, or other DoD organizations.
    • Experience supporting Cyber Security Service Provider (CSSP) operations or assessments.
    • Knowledge of NIST SP 800-53, NIST SP 800-61, DoDI 8500.01, DoDI 8510.01 (RMF), DISA STIGs, and related cybersecurity standards.
    • Experience preparing RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and other authorization artifacts.
    • Experience planning or supporting cybersecurity exercises and developing After Action Reports (AARs).
    • Experience developing and delivering cybersecurity training, briefings, or awareness materials.
    • Professional cybersecurity certifications such as Security+, CySA+, CASP+, CISSP, CISM, GSLC, or equivalent.
    Preferred Skills

    • Cybersecurity policy and governance
    • Incident Response policy and procedures
    • Risk Management Framework (RMF)
    • Cybersecurity compliance and audit support
    • CSSP operations and assessment support
    • SOP and TTP development
    • Technical writing and documentation
    • Executive briefings and reporting
    • NIST and DoD cybersecurity standards
    • Microsoft Office Suite (Word, Excel, PowerPoint, Visio)
    • SharePoint and collaboration platforms




    Numbers & Facts

    LocationColumbus, Ohio
    Websitehttps://www.sarelatech.com

    Skills

    • Analysis Skillsunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Communication Skillsunmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Defense Information Systems Agency (DISA)unmatched
    • Dental Insuranceunmatched
    • Documentationunmatched
    • Enterprise Protectionunmatched
    • GSLC - GIAC Security Leadership Certificateunmatched
    • Governmentunmatched
    • Government Requirementsunmatched
    • Health Insuranceunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Logisticsunmatched
    • Meeting Minutesunmatched
    • Metricsunmatched
    • Microsoft Excelunmatched
    • Microsoft Officeunmatched
    • Microsoft PowerPointunmatched
    • Microsoft SharePointunmatched
    • Microsoft Visiounmatched
    • Microsoft Wordunmatched
    • Military/DoD Standardsunmatched
    • Operational Auditunmatched
    • Operational Supportunmatched
    • Operations Processesunmatched
    • Policy Analysisunmatched
    • Policy Implementationunmatched
    • Presentation/Verbal Skillsunmatched
    • Process Improvementunmatched
    • Protective Servicesunmatched
    • Regulatory Complianceunmatched
    • Regulatory Requirementsunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Analysisunmatched
    • Staff Requirementsunmatched
    • Standard Operating Procedures (SOP)unmatched
    • Technical Writingunmatched
    • Training/Teachingunmatched
    • Tuition Feesunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Department of Defense (DoD)unmatched
    • Vision Planunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder