Senior Cybersecurity Policy Analyst
Job Description
eTelligent Group LLC is hiring a Senior Cybersecurity Policy Analyst to help operationalize Zero Trust Architecture (ZTA) policy under NIH governance, risk, and compliance. In this hybrid role based in Bethesda, MD, you will translate federal and HHS Zero Trust mandates into a single, enforceable NIH policy framework that supports NIH OCIO ZTA operationalization.
You will work within the Risk & Policy Pod, leading Task 5 security policy and standards support while also supporting communications (Task 6) and governance (Task 7). This is a mission-focused position for someone who can connect policy statements to controls, architecture patterns, governance checkpoints, and the evidence needed to prove compliance.
Responsibilities
- Build the Single Policy Framework (Subtask 5.1): develop NIH ZTA policy, then standards by pillar, implementation guides by workload family, and procedures, with an enterprise risk management (ERM) risk-appetite statement at the top.
- Establish full policy traceability: trace each policy statement up to its federal or HHS source (including EO 14028, OMB M-22-09, HHS IS2P, and HHS ZTA Strategy) and down to the Overlay control, architecture pattern, and governance checkpoint that enforce it.
- Inventory and benchmark existing requirements: inventory NIH security policies, IS2P-derived standards, and procedures; benchmark against NIST SP 800-53 Rev 5, NIST SP 800-207, NIST SP 800-63-4, CISA ZTMM, and current threats using MITRE ATT&CK. Deliver a gap register with draft language and an adoption path (Subtask 5.2).
- Develop policy anchors (Subtask 5.3): create anchors that include the policy statement, the technical setting that enforces it, the evidence that proves it, and the owner. Initial focus areas include identity (conditional access), devices, networks, and data (including classification labels driving DLP).
- Publish and communicate: write ZTA Policy Briefs and support role-based monthly enterprise communications with the NIH ISAO Communications Team, ensuring all content conforms to Section 508.
- Align with AI governance and data requirements: incorporate NIST AI RMF, OMB AI memoranda, and HHS AI strategy as well as data-management and privacy obligations including the NIH Data Management and Sharing Policy, Privacy Act, and HIPAA where applicable.
Required Qualifications
- Bachelor's degree and 8+ years of experience in federal cybersecurity policy, governance, or compliance.
- Working knowledge of HHS IS2P, FISMA, NIST frameworks, and OMB M-22-09.
- Experience applying ERM principles to security policy.
- Excellent technical writing and policy-drafting skills.
- Ability to obtain an NIH suitability determination and PIV credential; fluent in English.
Preferred Qualifications
- HHS or NIH policy development and approval experience.
- CISSP, CISM, or CGRC.
- Zero Trust policy experience; privacy knowledge including the Privacy Act, HIPAA, and research data.
- Current NIH or U.S. Department of Health and Human Services (HHS) experience.
Work Location and Schedule
- Hybrid with presence at NIH, Bethesda, MD.
- On site for stakeholder workshops, typically 1β2 days/week during the first 120 days, then as scheduled.
Citizenship, Clearance, and Credentialing
- U.S. Citizenship required.
- All staff must obtain NIH suitability and a PIV credential and be fluent in English.
- Risk or vulnerability testing requires a current T2 (BI) or higher investigation.
Salary
$110,000β$120,000 per year.
Tools and Frameworks
Microsoft 365/SharePoint, Confluence, OCIO ZTA Wiki, Jira, Microsoft Accessibility Checker, Adobe Acrobat, and requirements and standards including Section 508, EO 14028, OMB M-22-09, HHS IS2P, HHS ZTA Strategy, NIST SP 800-53 Rev 5, NIST SP 800-207, NIST SP 800-63-4, CISA ZTMM, MITRE ATT&CK, NIST AI RMF, and the NIH Data Management and Sharing Policy, including Privacy Act and HIPAA.