What are the responsibilities and job description for the Senior Security Governance and Policy Analyst position at Tharros Defense, Inc?
Tharros is seeking a Senior Security Governance and Policy Analyst to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region.
This role will support cybersecurity governance, policy, compliance, and executive communications across a complex mission environment. The ideal candidate can translate Federal, DHS, and Intelligence Community cybersecurity policy into practical implementation plans and help senior cybersecurity leaders drive consistent governance across cloud, on-premise, classified, and unclassified environments.
This role will support cybersecurity governance, policy, compliance, and executive communications across a complex mission environment. The ideal candidate can translate Federal, DHS, and Intelligence Community cybersecurity policy into practical implementation plans and help senior cybersecurity leaders drive consistent governance across cloud, on-premise, classified, and unclassified environments.
Responsibilities:
- Serve as a senior cybersecurity governance and policy advisor supporting cybersecurity leadership.
- Analyze cybersecurity requirements derived from policies, directives, standards, and guidance.
- Develop and update cybersecurity policies, standards, governance documentation, and implementation recommendations.
- Support governance activities related to RMF, FISMA, CNSSI standards, NIST 800-53, security control catalogs, supply chain risk management, AI/ML security considerations, and cybersecurity compliance.
- Review changes to Federal, DHS, Intelligence Community, and other applicable cybersecurity policies and recommend practical implementation approaches.
- Support updates to security policy manuals, supply chain risk management policy, security control catalogs, and related governance artifacts.
- Coordinate with governance, risk, and compliance stakeholders to support accurate control mapping and policy implementation.
- Research new or updated cybersecurity Executive Orders, Intelligence Community policies, national security guidance, and related requirements.
- Support cybersecurity audit response activities, including inspection, compliance, and oversight-related efforts.
- Prepare executive summaries, reports, talking points, briefings, stakeholder communications, and senior-leader presentation materials.
- Support cybersecurity governance working groups, taskers, data calls, trackers, repositories, and policy reference updates.
- Help identify opportunities to improve governance processes, streamline policy implementation, and increase consistency across cybersecurity compliance activities.