Cybersecurity Analyst Job at ITR, Oak Ridge, TN

VlFCYVlrYi8wa1JKVzBqNEkzYUg1ajZaMlE9PQ==
  • ITR
  • Oak Ridge, TN

Job Description

Job Description

Job Description

Overview:

Cybersecurity Analyst

Candidates must be able to obtain a federal security clearance so US citizenship is required. Candidates will also be expected to work onsite.

East Tennessee company is currently seeking qualified applicants to serve as a Cybersecurity Analyst to support the Cybersecurity Division’s Governance team for unclassified operations. The successful candidate should have a basic understanding of all aspects of cybersecurity. The candidate will collaborate with other teams across the lab, to include Information Technology, Physical Security, Classification Office, Cybersecurity, Lab Enterprise Risk, Lab Internal Audit, and others as appropriate.

Purpose:

Assist the Information Systems Security Manager (ISSM) and the Chief Information Security Officer (CISO) in the implementation of cyber security requirements and procedures across the clients IT network. This role aligns with the Cybersecurity Division's mission to safeguard critical infrastructure, protect sensitive information, and drive research and innovation. By promoting collaboration, leveraging technology, and adhering to best practices, we ensure the resilience and integrity of our digital landscape while empowering stakeholders with secure solutions.

Duties and Responsibilities:

A Cybersecurity Analyst in the Cybersecurity Division’s Governance Group is responsible for assisting in the development, review, and updating of cybersecurity policies and procedures, ensuring compliance with industry standards and regulations. They conduct regular audits, risk assessments, and participate in incident response activities, documenting findings and recommending corrective actions. They support the delivery of cybersecurity training and awareness programs, maintain accurate records of cybersecurity activities, and help prepare reports for senior management. Additionally, they help conduct security assessments and ensure data protection measures are effective. They participate in Governance group meetings, stay updated on relevant laws and standards, and contribute to continuous improvement initiatives to enhance ORNL’s cybersecurity posture.

Primary Responsibilities:

  • Identify, review, and provide analysis of applicable laws, regulations, orders, and contracts in order to develop policies, procedures, and control structures that meet requirements and alignment with business objectives.
  • Ensure systems are documented in accordance with DOE and ORNL security policies and procedures as outlined in applicable System Security Plans (SSPs).
  • Ensure compliance with industry standards, regulations, and internal security policies.
  • Develop and maintain security documentation, including policies, procedures, and guidelines.
  • Provide guidance on policies and controls to support appropriate levels of risk, facilitate risk tolerance discussions and decisions, and recommend controls based on industry standards and practices.
  • Participate in internal/external compliance audits, reviews, self-assessments, assessments, and data calls.
  • Evaluate and recommend new security solutions to enhance the organization's security posture.
  • Other duties as assigned for support within the program.

Basic Qualifications:

  • Bachelor’s degree with 2-4 years of relevant experience (ex. cybersecurity assessments, risk management, cybersecurity policy, and compliance, etc.). An equivalent combination of education and experience may be considered.
  • Ability to obtain and maintain a DOE Q security clearance or equivalent is required.
  • Strong analytical and organizational skills as well as problem solving capabilities to understand Cybersecurity risk and exposure (legal, regulatory violations, etc.) to ORNL.
  • Demonstrated experience implementing compliance frameworks (NIST, etc)
  • Excellent interpersonal, verbal, written, and presentation communication skills.
  • Thorough understanding of industry standards and regulations including NIST 800-53, NIST Risk Management Framework, and NIST Cybersecurity Framework (CSF).
  • Working knowledge of privacy regulations and impacts.
  • Ability to work independently, meet deadlines, and uphold high ethical standards.

Preferred Qualifications:

  • Active DOE Q or TS security clearance or equivalent.
  • Master’s degree in information assurance or related field with 1-3years of relevant experience working in an information security, information technology or information risk management related field.
  • Cybersecurity certifications (CISSP, CISA, CISM, CRISC, CCSP, SSCP) and Incident Response Certification
  • Privacy management, cybersecurity, evaluating security controls, identifying control gaps, and mitigating measures along with a strong understanding of business practices and technology concepts.
  • Highly motivated individual with an enthusiasm for governance, risk and compliance who can communicate benefits and drive success.
  • Demonstrated background in governance, risk, and compliance.
  • Experience in obtaining Authority to Operate (ATO) for DOE government systems.

Special Requirement:

This position requires the ability to obtain and maintain a clearance from the Department of Energy and is subject to Workplace Substance Abuse (WSAP) testing designated position requirements. WSAP positions require passing a pre-placement drug test and participation in an ongoing random drug testing program.

Job Tags

Work at office,

Similar Jobs

Workoo Technologies

Data Entry Clerk Job at Workoo Technologies

 ...you for checking us out. Work From Home/ Remote. We are looking for people that are motivated...  ..., as well as online virtual gift cards codes. Opportunities to earn rewards....  ...entry clerk and also remote client service experience are not required, they are highly beneficial... 

PTR Global

IT UX Product Designer Job at PTR Global

 ...Position: IT UX Product Designer Location: Boston, Massachusetts Duration: Contract Job ID: 169410 Pay term:- W2 role Job Overview: We are seeking a talented IT UX Product Designer to join our UX Product Design team, focusing on enhancing customer... 

HealthTrust Workforce Solutions Per Diem

Per Diem / PRN Sterile Processing Technician - $23 per hour Job at HealthTrust Workforce Solutions Per Diem

 ...HealthTrust Workforce Solutions Per Diem is seeking a per diem / prn Sterile Processing Technician for a per diem / prn job in Independence, Missouri. Job Description & Requirements Specialty: Sterile Processing Technician Discipline: Allied Health Professional... 

Noor Staffing Group

Part-time Intercept Field Interviewer Job at Noor Staffing Group

On behalf of our client, Noor is seeking outgoing and motivated Intercept Field Interviewers to conduct face-to-face interviews with respondents at designated locations for a long-term, ongoing assignment. Interviewers must be persuasive, energetic, friendly, and self-...

ServiceMaster Comm. Srvcs. of Myrtle Beach

Cleaner/Janitor/Office Cleaning/Commercial Cleaning Job at ServiceMaster Comm. Srvcs. of Myrtle Beach

 ...Job Description Looking to boost your income with part-time weekend work? We're hiring a dependable team member for 810 hours per...  ...Saturdays and Sundays. Responsibilities Emptying trash Clean and supply restrooms Sweep, mop floors, and vacuum carpets...