Founded in 1999 in the beautiful Smoky Mountains of East Tennessee, Cadre5 provides innovative technical solutions to our customers locally and nationally. Our Cadre5 Lab Partners division has partnered with the Information Technology Services Directorate at Oak Ridge National Laboratory (ORNL) to recruit a qualified Cybersecurity Analyst to support the Cybersecurity Division’s Governance team for unclassified operations. The successful candidate should have a basic understanding of all aspects of cybersecurity. The candidate will collaborate with other teams across the lab, to include Information Technology, Physical Security, Classification Office, Cybersecurity, Lab Enterprise Risk, Lab Internal Audit, and others as appropriate.
ORNL delivers scientific discoveries and technical breakthroughs needed to realize solutions in energy and national security and provides economic benefit to the nation. This premier research institution located near Knoxville in Oak Ridge, TN, addresses national needs through impactful research and world-leading research centers.
This is a full-time, permanent position that require on-site work.
- Working with highly talented team members
- 3 weeks’ vacation
- Excellent medical insurance, up to 100% paid by employer and contributions to HSA Plans
- Identify, review, and provide analysis of applicable laws, regulations, orders, and contracts in order to develop policies, procedures, and control structures that meet requirements and alignment with business objectives.
- Ensure systems are documented in accordance with DOE and ORNL security policies and procedures as outlined in applicable System Security Plans (SSPs).
- Ensure compliance with industry standards, regulations, and internal security policies.
- Develop and maintain security documentation, including policies, procedures, and guidelines.
- Provide guidance on policies and controls to support appropriate levels of risk, facilitate risk tolerance discussions and decisions, and recommend controls based on industry standards and practices.
- Participate in internal/external compliance audits, reviews, self-assessments, assessments, and data calls.
- Evaluate and recommend new security solutions to enhance the organization's security posture.
- Other duties as assigned for support within the program.
- Bachelor’s degree with 2-4 years of relevant experience (ex. cybersecurity assessments, risk management, cybersecurity policy, and compliance, etc.). An equivalent combination of education and experience may be considered.
- Ability to obtain and maintain a DOE Q security clearance or equivalent is required.
- Strong analytical and organizational skills as well as problem solving capabilities to understand Cybersecurity risk and exposure (legal, regulatory violations, etc.) to ORNL.
- Demonstrated experience implementing compliance frameworks (NIST, etc)
- Excellent interpersonal, verbal, written, and presentation communication skills.
- Thorough understanding of industry standards and regulations including NIST 800-53, NIST Risk Management Framework, and NIST Cybersecurity Framework (CSF).
- Working knowledge of privacy regulations and impacts.
- Ability to work independently, meet deadlines, and uphold high ethical standards.
- The ability to obtain and maintain a Department of Energy "Q" clearance is required. This requires US Citizenship.
- Active DOE Q or TS security clearance or equivalent.
- Master’s degree in information assurance or related field with 1-3years of relevant experience working in an information security, information technology or information risk management related field.
- Cybersecurity certifications (CISSP, CISA, CISM, CRISC, CCSP, SSCP) and Incident Response Certification
- Privacy management, cybersecurity, evaluating security controls, identifying control gaps, and mitigating measures along with a strong understanding of business practices and technology concepts.
- Highly motivated individual with an enthusiasm for governance, risk and compliance who can communicate benefits and drive success.
- Demonstrated background in governance, risk, and compliance.
- Experience in obtaining Authority to Operate (ATO) for DOE government systems.
Benefits
Cadre5 offers excellent pay and benefits, to include full medical, dental, and vision coverage coupled with 401K match, 15 days PTO, and 10 holidays.
Cadre5 is an equal opportunity employer. All qualified applicants, including individuals with disabilities and protected veterans, are encouraged to apply. Cadre5 is an E-Verify Employer.