IT Security Analyst IV
Job Description
Join a mission-driven team as a cybersecurity subject matter expert supporting Arctic research and remote operations. This full-time remote role with Battelle (Ohio) combines strong compliance work, technical leadership, and the flexibility to work a balanced schedule.
In this position, you will help drive the implementation, assessment, documentation, and continual improvement of cybersecurity and compliance programs for federal information systems, cloud environments, research platforms, and geographically distributed Arctic operations.
Key Responsibilities
- Lead implementation, assessment, monitoring, and sustainment of cybersecurity controls to maintain compliance with FISMA, NIST 800-53, and federal Risk Management Framework (RMF) requirements
- Coordinate cybersecurity assessments, audits, and authorization activities with internal stakeholders, external assessors, federal agencies, and corporate cybersecurity teams
- Lead cybersecurity projects and initiatives, ensuring objectives are met within scope, schedule, and budget constraints
- Perform security assessments, control reviews, vulnerability assessments, and risk analyses to evaluate control effectiveness and identify improvement opportunities
- Develop and maintain security documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), policies, procedures, standards, and related compliance artifacts
- Drive continuous monitoring activities such as vulnerability management, remediation tracking, configuration compliance validation, and security metrics collection and reporting
- Collaborate with infrastructure, cloud, networking, and application teams to design and implement secure solutions that meet business and federal compliance requirements
- Evaluate emerging technologies, cloud services, applications, and operational initiatives to identify cybersecurity risks and recommend mitigations
- Support incident response activities including security investigations, root cause analysis, corrective action planning, and implementation of security improvements
- Advise system owners, project teams, program leadership, and stakeholders on cybersecurity strategy, risk management, compliance requirements, and security best practices
- Provide mentorship, guidance, and technical leadership to junior cybersecurity and IT staff
- Support cybersecurity activities across dispersed facilities, remote field sites, cloud platforms, and Arctic communications infrastructure
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related field, plus eight (8) years of relevant experience; or an equivalent combination of education and experience
- Demonstrated experience supporting federal cybersecurity compliance programs, including implementation and assessment of NIST 800-53 security controls
- Experience with FISMA, RMF, continuous monitoring, vulnerability management, and security assessments
- Experience developing and maintaining cybersecurity documentation, policies, procedures, risk assessments, and compliance artifacts
- Strong understanding of cybersecurity principles, including identity and access management, cloud security, infrastructure security, and enterprise security architecture
- Experience leading cybersecurity projects and coordinating across technical and non-technical teams
- Ability to communicate cybersecurity risks and recommendations effectively to technical staff, management, and external stakeholders
- Prior experience in information security, cybersecurity operations, governance, risk management, or compliance functions
- Must be a U.S. citizen
Preferred Qualifications
- CISSP
- Additional certifications such as CISM, CRISC, CGRC (formerly CAP), Security+, GIAC, or equivalent
- Experience supporting federal civilian agencies, government contractors, or research organizations subject to FISMA
- Experience in roles such as ISSO, Security Control Assessor, cybersecurity program lead, compliance lead, or similar senior positions
- Experience with Microsoft Azure, Microsoft 365, Entra ID, Defender, vulnerability management platforms, and cloud security technologies
- Knowledge of cybersecurity considerations for remote operations, scientific research environments, and geographically distributed infrastructure
- Experience leading teams, mentoring staff, and coordinating cross-functional cybersecurity initiatives
Benefits & Work Style
- Comprehensive and competitive benefits package
- Compressed schedule: every other Friday off
- Enhanced flexibility: hybrid arrangement (60% in-office, 40% remote), with Monday and Tuesday as common in-office days
- Paid time off
- Medical, dental, and vision coverage, plus wellness incentives and benefits; optional supplemental benefits
- Coverage for partners, gender-affirming care and health support, and family formation support
- 401(k) retirement savings plan (for most employees, 5 percent whether or not you contribute, with match on top of that)
- Tuition assistance
Tools & Technologies
FISMA, NIST 800-53, Risk Management Framework (RMF), Microsoft Azure, Microsoft 365, Entra ID, Defender, CISSP, CISM, CRISC, CGRC (formerly CAP), Security+, GIAC, SSPs, POA&Ms
Vaccinations & Safety Protocols
Battelle may require employees, based on job duties, work location, and/or client requirements, to follow safety protocols and be vaccinated against certain viruses, bacteria, and diseases as a condition of employment and continued employment, including providing documentation of full vaccination.
If applicable, reasonable accommodations may be provided based on a qualified disability or medical condition under the Americans with Disabilities Act or the Rehabilitation Act, or for a sincerely held religious belief under Title VII of the Civil Rights Act of 1964 (and related state laws).
Compensation: USD 160,000 - 180,000 per year.