Duties:
- Ability to actively lead and manage project update briefings, working sessions and stakeholder meetings
- Strong analytical/assessment capability (e.g., conducting gap analyses, risk assessments)
- Experience with systems engineering discipline
- Ability to actively lead and manage project update briefings, working sessions and stakeholder meetings
- Strong analytical/assessment capability (e.g., conducting gap analyses, risk assessments).
Must have demonstrated knowledge and experience in:
- Designing, developing, implementing, executing, and improving third-party cyber risk management strategy and practices (public and/or private sector)
- Adapting and implementing industry cybersecurity frameworks and standards (e.g., ISO 27001, NIST CSF, NIST 800-53, NIST 800-171, CIS 18, Zero Trust Principles, FedRAMP)
- Assessing supply chain risk based on recognized audit reports (e.g., SOC 2 Type II) and/or questionnaire responses
- Managing and instructing diverse teams with varying levels of subject matter expertise
- Managing competing priorities to ensure timely completion of work
- Communicating with cross-functional leadership and other stakeholders (especially supply chain management) on third-party risk management strategy, risk management activities, and risks
- Learning on the job to expand knowledge for self and team members
- Working with third party risk assessment platforms (e.g., Process Unity GRX)
- Working with Risk Management platforms (e.g., Diligent RSAM)
- Technical Writing
- Contract Review and Negotiations
Nice to have:
- Public and Private Sector Experience
- Proximity (<50 miles) to Gatehouse (Falls Church, VA) or Aerial (Morrisville, NC) for in-person activities
- Familiarity with CyberGRX (now Process Unity GRX) and Diligent RSAM
EXPERIENCE LEVEL:
10+ years of experience in the security aspects of multiple platforms, operating systems, software, communications, and network protocols.
EDUCATION:
Must possess a Bachelors Degree or Masters Degree, PhD or JD in Computer Science, Information Technology or Information Security (Masters Degree preferred).
CERTIFICATIONS: (One or more required)
CISSP, CCSK/CCSP, PMP and/or CISA certifications CRISC - Certified in Risk and Information Systems Control
CISM - Certified Information Security Manager