
Job Information
North Wind Solutions Cyber Security Analyst III - Governance, Risk, and Compliance (GRC) 03734 NWSOL in Richland, Washington
Location: Richland, Washington or Remote Title: Cyber Security Analyst III - Governance, Risk, and Compliance (GRC) Schedule (FT/PT): Regular Full Time Travel Required: No Clearance: Ability to Obtain North Wind Solutions is a Government contracting small business with operations at military and civilian installations across the United States. The company's focus is facilities operation and maintenance, waste management and radiological services, security control and force protection, and environmental services. POSITION PURPOSE: Support cybersecurity governance, risk, and compliance (GRC) activities for the cybersecurity program at the U.S. Department of Energy Hanford Site in Richland, Washington. ESSENTIAL DUTIES AND RESPONSIBILITIES: Responsible for specific projects or specific service areas within the cybersecurity GRC work scope; creates and presents metrics, reports, and presentations to update senior management on status of specific projects or service areas. Develops and maintains strategies, standards, plans, policies, procedures, and other documentation in support of Department of Energy (DOE) and National Institute of Standards and Technology (NIST) requirements for federal information systems. Performs and supports risk management activities including impact assessments and risk assessments. Performs and supports assurance activities including security assessments and issues management. Performs and supports training activities including phishing campaigns and development and maintenance of training modules and documentation. Performs and supports vulnerability management activities including vulnerability analysis and coordinating remediation efforts. Supports cybersecurity audits, assessments, data calls, investigations, incidents, and other duties as required. Bachelor's Degree in cybersecurity, computer science, or a related field and 5 or more years of experience, or an equivalent combination of education, training, and experience. QUALIFICATIONS REQUIRED: Education and Experience: Bachelor's Degree in cybersecurity, computer science, or a related field and 5 or more years of experience, or an equivalent combination of education, training, and experience. Skills and Abilities: Knowledge of cybersecurity compliance frameworks, such as National Institute of Standards and Technology (NIST), Center for Internet Security Critical Security Controls (CIS), International Standards Organizations (ISO) 27001 and 27002, or similar. Ability to set and manage priorities judiciously. Excellent written and verbal communication skills and interpersonal skills. SPECIAL REQUIREMENTS: Must pass pre-employment background check Must pass pre-employment drug screening Applicants are required to have REAL ID ACT compliant documentation at time of hire and nothing on record that would prohibit you from gaining access to Department of Energy sites Must be able to obtain and maintain at least a DOE "L" clearance PHYSICAL DEMANDS: This position is primarily sedentary in nature. The work involves sitting most of the time but may involve walking or standing for brief periods of time. The work may involve exerting up to 10 pounds of force occasionally or a negligible amount of force frequently to lift, carry, push, pull, or otherwise move objects, including the human body. WORKING ENVIRONMENT: Works mainly in a typical office environment. The noise level in the work environment is usually quiet. REASONABLE ACCOMMODATION STATEMENT: North Wind offers a competitive pay and benefits package to include health, life, and disability insurance benefits, 401(k) with company match, generous paid leave and tuition reimbursement for eligible employees. As a company, we are committed to employee wellness, professional development, and work-life balance. We value safety, reliabili