Cybersecurity Officer Lead

3 weeks ago


Virginia Beach, United States Washington Metropolitan Area Transit Authority Full time
Job Description

Below covers everything you need to know about what this opportunity entails, as well as what is expected from applicants.

Department Marketing Statement:

The Washington Metropolitan Area Transit Authority (Metro) is building a state-of-the-art cybersecurity program to better protect the critical transit infrastructure supporting our nation¿s capital. This position will serve as the program lead, Cybersecurity Risk Management responsible for risk management and mitigation across WMATA program areas based on industry best practices to include NIST CSF/RMF and 800-53 Rev. 5. The program lead will conduct and manage risk assessments for WMATA systems to include those that store, process, and transmit Payment Card Industry (PCI), NIST 800-53 Rev. 5 (FISMA), health and wellness (HIPPA), and privacy (PII, PHI, GDPR) data. This key position involves overseeing the identification, assessment, and mitigation of security vulnerabilities within Metro' systems, networks and applications. The idea candidate will possess a strong background in cybersecurity with expertise in one of leading vulnerability scanning tools, threat analysis, and risk management strategies. The program lead responsibilities include conducting regular vulnerability assessments, coordinating with ISSOs/ISSMs to identified risks, and developing reports to inform management on risk reduction activities via the WMATA GRC tool in support of the enterprise risk management program.

General Hybrid Work Statement:

This opportunity is a hybrid opportunity allowing for flexibility between virtual and in-person work subject to the Authority¿s telework policy.

Minimum Qualifications

Education

A Bachelor¿s degree from an accredited college or university

Experience

Six (6) years of experience as a cybersecurity officer/engineer, information systems security officer, or specialized expertise in cyber policy, intelligence, analytics, budget, audit, metrics, or training such that it meets the specific role posted

Preferred Education

A Bachelor¿s Degree in Computer Science, Cybersecurity or a related technical field

ADDITIONAL CRITERIA FOR PROGRESSION

Note: Progression is not automatic nor guaranteed and is dependent on successfully completing the specified workload requirements
Candidates for promotion meet the minimum qualifications and work experience of the next career ladder series job before consideration for advancement

Medical Group

Satisfactorily complete the medical examination for this position, if required. The incumbent must be able to perform the essential functions of this position either with or without reasonable accommodations.

Summary

The Cybersecurity Officer Lead is responsible for ensuring that the Washington Metropolitan Area Transit Authority (WMATA) cybersecurity program is conducted based on the cybersecurity strategy and that it aligns well with industry best practices such as the National Institute of Standards and Technology (NIST) framework. The officer ensures that the skills necessary for an effective cybersecurity program are defined and that there is adequate funding to hire the right people to provide those skills. The officer designs an effective security awareness program to educate and change the cybersecurity culture of the WMATA staff, as well as develop security policies for compliance with internal and external audits. The officer is responsible for making sure that the selection and implementation of cybersecurity controls are built into the initial stages of any system/software acquisition and system/application vulnerability scans will be conducted to ensure controls implementation for all systems and applications.

Essential Functions

Oversees and contributes to the development of cybersecurity career enhancing workforce plans, strategies, and guidance to enable the development and retention of the best professionals possible. Creates training and education requirements to address changes to cybersecurity policy, emerging threats, certification requirements and industry best practices through partnerships with universities, certification companies, state/federal partners and other innovative strategies that deliver relevant content. Creates a strong culture of cybersecurity within the IT organization and drives behavioral changes for all business units within WMATA. Ensures that timely, mission-focused, and tailored cybersecurity training and developmental opportunities are provided to cybersecurity personnel.
Oversees and contributes to the creation of governance standards based on NIST and other frameworks (policies, processes, workplans, templates, etc.) by which the WMATA Cybersecurity program is managed and measured against. Develops and maintains cybersecurity plans, strategy, and policy to support and align with organizational cybersecurity initiatives and regulatory compliance. Ensures that WMATA's cybersecurity program has a governance model based on best practice.
Oversees and contributes to performance assessments of threats and vulnerabilities for systems and networks within the network environment; determines deviations from acceptable configurations, enterprise or local policy; assesses the level of risk; and develops and/or recommends appropriate mitigation countermeasures in operational and nonoperational situations. Measures the effectiveness of defense-in-depth architecture against known vulnerabilities. Ensures that system and network threats and vulnerabilities are identified and remediated in a timely manner.
Oversees and contributes to performance evaluations of the IT security program and its individual components to determine compliance with published standards. Tracks finding and reports of remediation progress. Supports policy compliance, governance and incident response programs. Prepares audit reports that identify technical and procedural findings and provides recommended remediation strategies/solutions. Coordinates external audit requirements. Ensures that systems, processes and people follow published policy and alerts personnel to potential risk areas.
Oversees and compiles and reviews budgets for the Cybersecurity program using actual performance, previous budget figures, estimated revenue, expense reports, and other data sources to control funds and provide for proper financial administration. Uses an understanding of system security to develop budgetary requirements. Works with the cybersecurity personnel to ensure they effectively plan send monitor their budgets. Tracks contracting costs and needs, managing statement of work efforts. Ensures that the cybersecurity program manages costs effectively, projects future budget needs, improves services received and meet schedule demands for service delivery.
Oversees, prepares and presents governance and compliance management reports, key performance metrics, scorecards, and briefings, as required, to cybersecurity and IT leadership. Works with leadership to use continuous monitoring scoring and grading metrics to make information security investment decisions to address persistent issues. Works with organization risk analyst to ensure risk metrics are defined realistically to support continuous monitoring. Ensures the enterprise has a cybersecurity scorecard that presents a clear view of the health of the organization, including but not limited to system-level health (categorized by business units and rolled up), operational defensive effectiveness (detection, response, remediation of threats), employee training/effectiveness (phishing, social engineering).
Oversees the cybersecurity components of the governance, risk and compliance (GRC) tool. Configures and populates the tool to enable security professionals to document a wide-array of controls. Creates and maintains inherited controls at the direction of the Authorizing Official. Supports audit and metric requirements by developing exports and reports. Ensures that all system security controls are tracked and managed effectively.
Executes a risk-based, repeatable/consistent system security strategy based on the NIST Risk Management Framework/Cybersecurity Framework which includes: control selection and inheritance, drafting and reviewing system authorization documentation, documenting/remediating vulnerabilities, populating a Governance Risk and Compliance (GRC) tool, partnering with developers/owners to ensure security is a part of the complete system development life cycle, and continuous monitoring. Ensures that WMATA has a consistent process around system authorization and monitoring.
As a part of the system security life cycle, provides program oversight and leadership for the evaluation of the effectiveness of procurement function in addressing information security requirements and supply chain risks through procurement activities and recommends improvements. Develops and documents supply chain risks for critical system elements, as appropriate. Ensures that WMATA systems and technology are procured with security considered from the start.
Oversees, evaluates, and supports the documentation, validation, assessment, and authorization processes necessary to assure that existing and new information technology (IT) systems meet the organization's cybersecurity and risk requirements. Ensures appropriate treatment of risk, compliance, and assurance from internal and external perspectives. Ensures that WMATA has a properly managed risk management framework.
Oversees and performs privacy impact assessments of an application's security design for the appropriate security controls, which protect the confidentiality and integrity of Personally Identifiable Information (PII) and assess the security effectiveness of the security controls. Ensure PII is properly protected in all WMATA systems and applications.
Oversees and contributes to the implementation of the security controls specified in a security plan or other system documentation and develops a strategy for monitoring control effectiveness; coordinates the system-level strategy with the organization and mission/business process monitoring strategy. Ensures that WMATA has a properly managed risk management framework.
Advises security leadership (e.g., Chief Information Security Officer [CISO], Director, etc.) on risk levels and security posture of managed systems, and on the cost/benefit analysis of information programs/projects, policies, processes, systems and elements.
Consults with customers to gather and evaluate functional requirements, determine security controls that mitigate risks, adhere to policy and facilitate customer needs, and translates these requirements into technical solutions. Provides guidance to customers about applicability of security controls to meet business needs. Supports the development phases of the systems development life cycle.

The essential duties listed are not intended to limit specific duties and responsibilities of any particular position. Nor is it intended to limit in any way the right of managers and supervisors to assign, direct and control the work of employees under their supervision.

Evaluation Criteria

Consideration will be given to applicants whose resumes demonstrate the required education and experience. Applicants should include all relevant education and work experience.

Evaluation criteria may include one or more of the following:

Skills and/or behavioral assessment
Personal interview
Verification of education and experience (including certifications and licenses)
Criminal Background Check (a criminal conviction is not an automatic bar to employment)
Medical examination including a drug and alcohol screening (for safety sensitive positions)
Review of a current motor vehicle report

Closing

WMATA is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other status protected by applicable federal law.

This posting is an announcement of a vacant position under recruitment. It is not intended to replace the official job description. Job descriptions are available upon confirmation of an interview.

  • Virginia Beach, Virginia, United States Medline Full time

    At Medline, we are committed to fostering a collaborative environment that encourages personal and professional growth. Our dedication to our workforce has been unwavering since our inception. We believe that our employees are the cornerstone of our success, and we are eager to welcome individuals who are enthusiastic about pioneering innovative...


  • Virginia Beach, Virginia, United States Claxton Logistics Services, LLC Full time

    Job OverviewPosition Title: Cybersecurity Compliance AnalystCompany: Claxton Logistics Services, LLCLocation: Various locationsRole Summary:The Cybersecurity Compliance Analyst plays a crucial role in upholding and ensuring adherence to cybersecurity standards within a governmental or defense context. This position involves the systematic entry and upkeep of...


  • Virginia, Minnesota, United States Nightwing Full time

    Position Overview:As a key member of Nightwing, the Information Systems Security Officer (ISSO) will play a vital role in supporting a U.S. Government initiative focused on the design, development, and maintenance of a secure network operations environment. This position is essential for integrating advanced cybersecurity capabilities to counteract evolving...


  • Virginia Beach, Virginia, United States Washington Metroplitan Area Transit Authority Full time

    Job OverviewThe Washington Metropolitan Area Transit Authority (WMATA) is committed to establishing a cutting-edge cybersecurity framework aimed at safeguarding the vital transit infrastructure that supports our nation's capital. The Senior Cybersecurity Metrics Specialist plays a crucial role in the comprehensive assessment and performance evaluation of...


  • Sterling, Virginia, United States Ampsight Full time

    About the RoleAmpsight is seeking a highly skilled Lead Cybersecurity Analyst to join our Cyber Threat Intelligence team. This role involves identifying, analyzing, and mitigating sophisticated cyber threats.Key ResponsibilitiesConduct proactive threat hunting activities to identify and mitigate potential cyber threats.Utilize advanced threat detection...


  • Virginia Beach, Virginia, United States Sentara Healthcare Full time

    Job OverviewJoin a distinguished healthcare organization that prioritizes our People, Quality, Patient Safety, Service, and Integrity. Become part of a team dedicated to enhancing health every day and striving to be the preferred healthcare provider in the communities we serve.Sentara is seeking a Senior Cybersecurity Operations Leader.This is a Full-Time...


  • Mastic Beach, United States MyCareersFuture Full time

    Roles & Responsibilities Lead the team to conduct more thorough security assessments that span across cloud, infrastructure, system, web and mobile applications, etc. and discover deeper rooted vulnerabilities. Reverse engineering of binaries, exploitation of vulnerabilities, and familiarity with various Operating System kernel exploit and exploit...


  • Myrtle Beach, South Carolina, United States Archetype SC LLC Full time

    Lead Cybersecurity Advisor Position Address incidents and inquiries from various ticketing platforms for a range of products. Offer assistance to end users, encompassing both technical and non-technical support. Significant expertise with diverse security technologies, including web security, endpoint protection, and cloud security solutions. Employ...


  • West Palm Beach, Florida, United States TEKsystems Full time

    Position Overview: TEKsystems is looking to enhance its IT Compliance Team by bringing on board a dedicated IT Compliance Analyst. This role is integral to our IT Security Division, ensuring that our systems adhere to necessary compliance standards. The selected candidate will work in a hybrid environment, splitting their time between in-office and...


  • Virginia Beach, Virginia, United States Palo Alto Networks Full time

    Your CareerThe Cybersecurity Solutions Consultant Leader represents a modern evolution of the conventional Sales Engineer Manager role, focusing on how we guide teams to effectively assist our clients in comprehending their environment, offering solution insights, and ensuring the realization of value from their investment with Palo Alto Networks.As the...


  • Mastic Beach, New York, United States MyCareersFuture Full time

    Job SummaryMyCareersFuture is seeking a highly skilled IT Security Manager to join our team. As a key member of our organization, you will be responsible for analyzing and prioritizing vulnerabilities, providing strategic guidance, and leading the development of incident response procedures.Key ResponsibilitiesAnalyze and prioritize vulnerabilities based on...


  • Herndon, Virginia, United States Peraton Full time

    Job SummaryWe are seeking a highly skilled Cybersecurity Engineer to join our team at Peraton. As a Cybersecurity Engineer, you will play a critical role in supporting the acquisition, integration, support, management, and control of all software, hardware, systems, and network configurations for a USAF Air Combat Command critical mission system.Key...


  • Mastic Beach, New York, United States MyCareersFuture Full time

    About the RoleAs a Senior Cybersecurity Consultant at MyCareersFuture, you will play a critical role in leading the execution of cybersecurity projects from inception to completion. Your expertise in managing Info security and Datacenter projects will be invaluable in ensuring the successful implementation of cybersecurity projects in compliance with...


  • Juno Beach, Florida, United States NextEra Energy , Inc. Full time

    Position Overview:NextEra Energy, Inc. is seeking a distinguished Lead Cybersecurity Architect to join our innovative team.About Us:As a leader in the energy sector, we are committed to delivering sustainable and reliable energy solutions to millions. Our focus on cutting-edge technology and strategic initiatives positions us at the forefront of the...


  • Virginia, Minnesota, United States Avid Technology Professionals Full time

    Key Responsibilities:Leading Systems Engineering initiatives for a sophisticated cybersecurity platform.Facilitating collaboration among teams for the design, integration, and evaluation of cutting-edge cybersecurity solutions, alongside the Design & Development Lead and Chief Engineer.Engaging directly with clients, stakeholders, and end-users to understand...


  • Virginia Beach, United States Haynes Furniture Company Full time

    Position: Chief Information Officer (CIO) – Transformational Leadership at Haynes Furniture and The Dump. Join a Legacy, Lead the Future. This is an on-site position in Virginia Beach, Virginia. Relocation assistance is available for the ideal candidateAre you a visionary technology leader ready to steer a successful, family-owned furniture retailer into...


  • Arlington, Virginia, United States Nodel Full time

    Position Title: Cybersecurity Operations ManagerLocation: Arlington, VASecurity Clearance: Top Secret Security Clearance RequiredNode is dedicated to supporting a U.S. Government client by providing essential assistance for on-site incident management to civilian agencies and critical asset proprietors facing cyber threats. This role involves immediate...


  • Mastic Beach, New York, United States MyCareersFuture Full time

    **Job Summary**MyCareersFuture is seeking a highly skilled and experienced Cybersecurity Manager to lead our Endpoint DLP implementation project. As a key member of our Security Operations Team, you will be responsible for spearheading the project and making recommendations to deliver the implementation within approved budget and timeline with minimal...


  • Arlington, Virginia, United States Peraton Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Visual Designer to join our team at Peraton. As a key member of our Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program, you will play a critical role in providing leading cyber and technology security experience to enable innovative, effective, and secure business...


  • Newport Beach, California, United States Chipotle Full time

    Cybersecurity SpecialistJOIN US IN MAKING A DIFFERENCEAt Chipotle, we believe that fast food can be a force for good. Our mission is to transform the fast-food landscape, initiating meaningful dialogues and actively contributing to the evolution of sustainable farming and food practices. We invite you to be part of our journey as we strive to make quality...