Job Description
Job DescriptionBenefits:
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Profit sharing
- Training & development
- Tuition assistance
- Vision insurance
SarelaTech is seeking a Cybersecurity Policy Analyst to support the Defense Logistics Agency (DLA) Enterprise Cyber Security Service Provider (CSSP). The selected candidate will provide technical expertise in the development, review, implementation, and maintenance of cybersecurity policies, procedures, and governance supporting enterprise cyber defense and Incident Response operations.
Working closely with government stakeholders, cybersecurity engineers, compliance personnel, and incident response teams, the Cybersecurity Policy Analyst will ensure cybersecurity policies, operational procedures, and documentation remain aligned with Department of Defense (DoD), Defense Logistics Agency (DLA), Risk Management Framework (RMF), and Cyber Defense requirements. This position also supports CSSP assessments, compliance reporting, cybersecurity exercises, audit readiness, and the development and delivery of cybersecurity training.
Primary Responsibilities
- Develop, review, maintain, and update cybersecurity policies, Standard Operating Procedures (SOPs), Tactics, Techniques, and Procedures (TTPs), and operational guidance supporting DLA Enterprise Cyber Security Service Provider (CSSP) operations and Incident Response activities.
- Ensure cybersecurity policies and documentation comply with DoD, DLA, NIST, RMF, and applicable cybersecurity directives, standards, and regulatory requirements.
- Support CSSP assessments, inspections, audits, and compliance activities by preparing documentation, tracking metrics, compiling required artifacts, and coordinating with government stakeholders.
- Assist DLA programs with the development and maintenance of Risk Management Framework (RMF) documentation and cybersecurity compliance packages.
- Plan, coordinate, and support cybersecurity tabletop exercises; develop After Action Reports (AARs), lessons learned, and process improvement recommendations.
- Develop and deliver cybersecurity training, presentations, and briefings on Incident Response policies, procedures, and compliance requirements for government personnel.
- Prepare technical documentation, executive briefings, compliance reports, meeting minutes, and status updates to support cybersecurity governance and operational readiness.
- Collaborate with cybersecurity operations, incident response teams, engineers, and government leadership to implement policy updates and improve enterprise cybersecurity processes.
Required Qualifications
- Top Secret security clearance with SCI eligibility
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or related technical discipline.
- Seven (7) or more years of experience supporting cybersecurity policy, governance, compliance, security operations, or Incident Response programs within a DoD or Federal environment.
- Experience developing and maintaining cybersecurity policies, SOPs, TTPs, technical documentation, or operational procedures.
- Knowledge of DoD cybersecurity policies, Risk Management Framework (RMF), NIST guidance, and cybersecurity compliance requirements.
- Experience supporting cybersecurity compliance activities, inspections, audits, or assessment programs.
- Strong technical writing, documentation, analytical, and presentation skills.
- Ability to communicate effectively with technical teams, cybersecurity leadership, and government stakeholders.
Desired Qualifications
- Experience supporting the Defense Logistics Agency (DLA), DISA, or other DoD organizations.
- Experience supporting Cyber Security Service Provider (CSSP) operations or assessments.
- Knowledge of NIST SP 800-53, NIST SP 800-61, DoDI 8500.01, DoDI 8510.01 (RMF), DISA STIGs, and related cybersecurity standards.
- Experience preparing RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and other authorization artifacts.
- Experience planning or supporting cybersecurity exercises and developing After Action Reports (AARs).
- Experience developing and delivering cybersecurity training, briefings, or awareness materials.
- Professional cybersecurity certifications such as Security+, CySA+, CASP+, CISSP, CISM, GSLC, or equivalent.
Preferred Skills
- Cybersecurity policy and governance
- Incident Response policy and procedures
- Risk Management Framework (RMF)
- Cybersecurity compliance and audit support
- CSSP operations and assessment support
- SOP and TTP development
- Technical writing and documentation
- Executive briefings and reporting
- NIST and DoD cybersecurity standards
- Microsoft Office Suite (Word, Excel, PowerPoint, Visio)
- SharePoint and collaboration platforms
