Cybersecurity Policy Analyst
$95k - $107kGunnison, CO
Job Type
Full-time
Work location : Hybrid, 1-2 days per week on-site in Bethesda, MD. The Policy Analyst will lead Security Policy and Standards Support for ZTA Operationalization, under the NIH Governance, Risk & Compliance (GRC) Zero Trust Architecture (ZTA) Support Services task order for the NIH Office of the Chief Information Officer (OCIO). Working in the Risk & Policy Pod, candidate will turn federal and HHS Zero Trust mandates into a single, enforceable NIH policy framework. Candidate will also support communications and governance.
- Build the Single Policy Framework: NIH ZTA policy, then standards by pillar, then implementation guides by workload family, then procedures, with an enterprise risk management (ERM) risk-appetite statement at the top.
- Trace every policy statement up to its federal or HHS source (EO 14028, OMB M-22-09, HHS IS2P, HHS ZTA Strategy) and down to the Overlay control, architecture pattern, and governance checkpoint that enforce it.
- Inventory NIH security policies, IS2P-derived standards, and procedures. Benchmark them against NIST SP 800-53 Rev 5, 800-207, 800-63-4, the CISA ZTMM, and current threats (MITRE ATT&CK). Produce a gap register with draft language and an adoption path.
- Develop policy anchors, each made up of the policy statement, the technical setting that enforces it, the evidence that proves it, and the owner. Start with identity (conditional access), devices, networks, and data (classification labels driving DLP).
- Write ZTA Policy Briefs and role-based monthly enterprise communications with the NIH ISAO Communications Team. All content must conform to Section 508.
- Align policy with AI governance (NIST AI RMF, OMB AI memoranda, HHS AI strategy) and with data-management requirements (NIH Data Management and Sharing Policy, Privacy Act, HIPAA where applicable).
- US Citizenship required
- 8+ years in federal cybersecurity policy, governance, or compliance.
- Working knowledge of HHS IS2P, FISMA, NIST frameworks, and OMB M-22-09.
- Experience applying ERM principles to security policy.
- Excellent technical writing and policy-drafting skills.
- Bachelor's degree
- Security+ or CAP/CGRC certification.
- HHS or NIH policy development and approval experience.
- CISSP, CISM, or CGRC certification.
- Zero Trust policy experience; privacy knowledge (Privacy Act, HIPAA, research data).
Gunnison Consulting Group's total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include:
- 3 weeks of Personal Leave your first year
- 11 paid Holidays each year
- 5 days of Flexible Time Off each year for approved training or certifications (self-study is ineligible)
- 401(k) company match at 50% up to 10% of your salary
- Medical, Dental and Vision Insurance
- Life and Disability Insurance
- Public Transportation Subsidies
- Certifications and Training Allowance - Up to $5,000/year!
- Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation.
- Quality is our top priority.
- Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer.
- There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow.
- We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding.
- We hire for careers at Gunnison, not to fill a position.
Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time.
In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects . By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could , the company has thrived for over 25 years. Salary Description
$95,000 - $107,000/year
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity Policy Analyst in Bethesda, MD vacancy
$120k - $130k
...Cybersecurity Policy Analyst Quantum Sky is searching for a Cybersecurity Policy Analyst supports federal government cybersecurity programs by developing, analyzing, implementing, and maintaining cybersecurity policies, standards, procedures, and guidance. The position...SuggestedContract workFor contractors- Cornerstone Defense LLC is seeking a Security Cooperation Analyst to support the Office of the Deputy Assistant Secretary of War for Cyber Operations Policy (DASW COP). The role advances cyberspace security cooperation programs and provides policy, analytical, and technical...SuggestedWork at office
$50k - $70k
Cybersecurity Policy Analyst The Company CenseoConsulting Group is atop Washington D.C. basedmanagement consulting firm dedicated to helping public sector and non-profit clients build operational excellence, deliver better outcomes, and lower cost. We take a personalized...SuggestedFull timeWork at officeRemote workFlexible hours$76k - $106k
...THOR Solutions is seeking a Cybersecurity Policy / IA Program Analyst to support a DHS information technology support services program focused on cybersecurity governance, assessment and authorization (A&A), and information assurance program support in Washington,...SuggestedFull timeTemporary workWork at officeWorldwideFlexible hours- ...Responsibilities Amentum is seeking a Policy Analyst role in Bethesda, MD to support our customer onsite. Responsibilities include: Support Government Leads in the development of counterintelligence(CI)policy and strategy, and promote and communicate shared vision, mission...SuggestedHourly payContract workLocal area
- ...Job Description Job Description Job Title: Mid-Level Cybersecurity Incident Response Analyst Location: Bethesda, Maryland Type: Direct Hire Compensation: 120k Work Model: Hybrid Hours: 40.0 Security Clearance: Public Trust Responsibilities Monitor...Local area
$90k - $130k
...generate progress: Harness your expertise to solve challenges and celebrate success! Job Summary JCS Solutions is seeking a Cybersecurity Analyst and help protect critical federal systems. In this hands-on role, you'll support vulnerability management, threat monitoring...Full timeContract workTemporary workLocal area- TIAG is hiring a Cyber Security Analyst to support USUHS in Bethesda, MD. The role focuses on modernizing RMF ATO packages for Google Cloud, Google Workspace, and ServiceNow GCC-High to IL-4. You will craft narratives, manage POAMs, and ensure accurate control mappings...
$80k - $90k
...Salary/year, Travel Percentage: None, TIAG is hiring Cyber Security Analyst to support our team at the Uniform Services University of... ...information to individual Control Objectives within the ServiceNow GRC Policy and Compliance module. Evaluate Cloud Service Provider FedRAMP...Full timeFor contractorsFor subcontractorLocal area$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by utilizing enterprise-level vulnerability scanning and assessment tools to identify internally and externally facing vulnerabilities...Full timeContract workPart timeWork at officeLocal areaRemote work- DescriptionActioNet has an immediate opportunity for a Cyber Security Analyst requiring a Public Trust clearance located in Silver... ...of IA / INFOSEC concepts and requirements: Firewall Policy, Ports & Protocols, Cybersecurity, CybersafeFamiliarity with Tenable and BigFix,...Immediate start2 days per week1 day per week
- ...supporting our US federal government client. Basic Minimum Qualifications: Knowledge of DOC, NOAA, and NWS IT security policies and implementation standards or those of similar sized organizations AND comprehensive understanding of NIST guidance to include,...Temporary workRemote work
$110k - $130k
...than 70 countries across all 7 continents. The Senior Cybersecurity Risk Analyst is a US remote, senior individual contributor position within... ...program based on industry best practices, regulations, policies, standards, and guidelines. GR&C surfaces and advises on...Hourly payContract workTemporary workLocal areaRemote work$120k - $160k
...Description SAIC is looking for a Senior Cybersecurity Analyst supports Security Operations functions while helping establish and mature the organization's offensive security capability in support of a critical U.S. Government agency. This position is responsible...Remote work$110k - $160k
...Cybersecurity SOC Analyst II Washington, District of Columbia, United States CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed...Contract workWork experience placementCasual workRelocation package- ...Senior Cybersecurity Analyst (Artificial Intelligence) We are seeking up to two Cybersecurity Analysts with experience implementing artificial intelligence (AI) for computer network defense including intrusion detection, prevention and incident response activities....Local area
- ...Senior Cybersecurity Analyst OCH Technologies is seeking a Senior Cybersecurity Analyst to execute independent risk assessments and vulnerability assessments at FAA facilities. Candidate should be based at one of three FAA hub locations (Oklahoma City, Atlantic City...Temporary workFor contractorsLocal area
$100k - $130k
...Alexandria, Virginia Secret Hybrid schedule Information Technology Overview GovCIO is currently hiring a Journeyman Cybersecurity Analyst to support Information Assurance (IA) and Information System Security Officer (ISSO) activities for the U.S. Coast Guard (...Full timeCurrently hiringFlexible hours$130k - $160k
...Amentum is seeking a Cybersecurity Analyst to join our team and support our McLean, VA customer. We are looking for team members who are... ...implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The...Hourly payCivilian ContractorContract workFor contractorsWork at officeLocal area- ...This is a full-time contract position for a Senior Cybersecurity Analyst based in Arlington, Virginia. You will assist with designing, implementing... ...risk exposure. Develop and maintain security standards, policies, and procedures aligned with regulatory frameworks and...Full timeContract work
- ...fluenceenergy.com. Job Description: Role Overview The Senior Cybersecurity Analyst is a hands-on, senior individual contributor within Fluence... ..., and to validate the effectiveness of user and security policies. Incident Response, Root Cause Analysis and Reporting...For contractorsWork at officeVisa sponsorshipWork visaShift work
- ...GENERAL SUMMARY: The Veterans Benefits Policy Analyst position is located in Washington, D.C. The incumbent is responsible for collecting information and analyzing issues related to veterans’ benefits and compensation. ESSENTIAL FUNCTIONS: # Conduct research and...
- ...efficiency), and are aligned at the intersections of assets, processes, policies and people delivering value. ProSidian clients represent a... ...Consulting at DescriptionProSidian Seeks a Policy Evaluation Analyst | Evaluation Support [DOEOP058063] - DPLH Est.: 665.6 Hrs. ST |...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- DescriptionSAIC is hiring a National Policy Integration Analyst. The position will support the Organizational and Management Policy Directorate within the Office of the Director of Administration and Management/Office of Secretary of Defense (OSD). The role will provide...Work at office
$110.18k - $183.63k
...thinking organization, apply now.We are currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington, Virginia (US-VA), United... ...threats, and ensure adherence to federal directives and policies.Job Duties: Vulnerability Assessment & Risk EvaluationConduct...Full timeTemporary workWork at officeRemote workFlexible hours- ...implement preventive measures to strengthen the program's long-term defense posture. Provide expert guidance on cybersecurity directives and risk management policies; review POA&Ms for technical clarity and sound judgment to ensure acceptable remediation timeframes for...Work at office
$105k - $200k
...Cybersecurity Analyst Technomics is a growing employee-owned, decision analytics company that specializes in cost and economic analysis to... ...of clients across the Federal government, from senior level policy makers to program managers, to choose smartly, buy effectively...Work at office$150k - $170k
...Methods is a proven provider of mission-focused technology, cybersecurity, and program management solutions supporting critical Federal... .... Who We’re Looking For (Position Overview:) The Senior Policy Analyst provides policy research, analysis, and development support...Contract work- ...their talents supporting customers with difficult and important mission sets. About the Role Redhorse Corporation is seeking a Policy Analyst to support the Under Secretary of Defense for Intelligence and Security (OUSD(I&S)) Policy Office at the Pentagon. The Policy Office...Contract workWork at office
$71.81k - $102.59k
...cyberspace and anticipate emerging threats. Our capabilities in cybersecurity, network architecture, reverse engineering, software and... ...Mission Technologies is seeking a Senior Telecommunications Policy Analyst to support the Department of War (DoW) Chief Information Officer...Work experience placementWork at officeWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Policy Analyst. Be the first to apply!
Related searches
- education policy Bethesda, MD
- policy intern Bethesda, MD
- environmental policy Bethesda, MD
- intern human rights policy Bethesda, MD
- education policy research Bethesda, MD
- health policy Bethesda, MD
- privacy policy Bethesda, MD
- trade policy jobs Bethesda, MD
- public policy intern Bethesda, MD
- public policy Bethesda, MD




