Cyber Policy Process -SME

Full Time
Crownsville, MD
$70 - $75 an hour
Posted
Job description

Title: Cyber Policy/Process SME

Location: Crownsville, MD

Duration: Long Term Contract

Client: State of MD, DoIT

*Only Locals Preferred

*Candidates chosen for an interview will meet the Education, General Experience and Specialized Experience requirements.

Job Description:

Background: The Office of Security Management (OSM) is responsible for the establishment of Security Policies, Security Guidance, Security Awareness, and is a source of IT security information for State agencies. OSM is also critical in supporting the Maryland Department of Emergency Management Cyber Preparedness Unit during emergency response efforts.

This Cyber Policy/Process SME will support the State CISO and the Office of Security Management (OSM) in the creation, updating, maintenance, regular review, and implementation of cyber-related policies. The individual will develop and maintain cybersecurity plans, strategies, and policies to support and align with organizational cybersecurity initiatives and regulatory compliance.

Duties and Responsibilities

♦Develop cybersecurity policy, programs, and guidelines for implementation

♦Create, update, maintain, including regular editing and review state cybersecurity policy, providing guidance to management, staff, and end users

♦Maintain and update the State Security Manual and guidance documents as needed

♦Review existing and proposed policies with stakeholders

♦Ensure that cyber policies and process comply with legal and organizational requirements

♦Interpret and apply applicable laws, statutes, and regulatory documents and integrate into policy

♦Assess policy needs and collaborate with stakeholders to develop policies to govern cyber activities

♦Support efforts to design/integrate a cyber strategy that outlines the vision, mission, and goals that align with the organization’s strategic plan

♦Draft, staff, and support the publishing of cyber policy

♦Provide cyber policy guidance to management, staff, and users

♦Facilitate work sessions and meetings for new and updated policies

♦Proactively work to improve the existing policies, manuals, and overall cyber governance Program

*Education and Certifications:

♦A Bachelor's Degree from an accredited college or university with a major in Computer Science, Information Systems, Engineering, Business, or other related scientific or technical discipline.

♦A Master’s degree in the field highly preferred

♦Certified Information Systems Security Professional (CISSP)

♦ITIL certification

*General Experience:

♦At least twelve (12) years of experience in the IT Field.

♦Strong verbal and written English-language communication skills.

*Specialized Experience:

♦Strong understanding of:

o National Institute of Standards and Technology (NIST) SP 800-53 (including a mapping of Rev.4 to Rev.5)

o Internal Revenue Service (IRS) Publication 1075 Cybersecurity Guidelines

o NIST Cybersecurity Framework

o Center for Internet Security (CIS) Top 20 - Critical Security Controls

o Information Technology Infrastructure Library (ITIL) Concepts

o Relevant Cybersecurity and IT laws and regulations

♦At least 12 years of relevant industry experience.

♦Experience writing policy, standards, guidance, and guidelines.

♦Demonstrative experience in developing policy, plans, and strategy in compliance with laws, regulations, policies, and standards in support of organizational cyber activities.

♦Demonstrated understanding of risk management processes (such as methods for assessing and mitigating cyber risk).

♦Firm grasp of, including but not limited to, technical document conventions, structure and format.

Preferred Experience Qualifications:

♦Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy at the state level.

♦Prior experience implementing a cyber security program at the local, state, or federal level.

♦Knowledge of cyber threats and vulnerabilities.

♦Knowledge of operational impacts of unmitigated or non-addressed cybersecurity risk cybersecurity lapses.

Job Types: Full-time, Contract

Pay: $70.00 - $75.00 per hour

Schedule:

  • 8 hour shift

Ability to commute/relocate:

  • Crownsville, MD: Reliably commute or planning to relocate before starting work (Required)

Experience:

  • Develop cybersecurity policy, programs, and guidelines: 10 years (Required)
  • cyber policies and process comply with legal: 10 years (Required)

License/Certification:

  • Certified Information Systems Security Professional (CISSP) (Required)
  • ITIL Certification (Required)

Work Location: In person

johnandkristie.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, johnandkristie.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, johnandkristie.com is the ideal place to find your next job.

Intrested in this job?

Related Jobs

All Related Listed jobs