*** | SUPPLEMENTAL LABOR MANAGEMENT OFFICE
ADDITIONAL PROCUREMENT INFORMATION (API)
Title & Level
Business Analyst 3
Work Group Location
Portland, OR
Specialty
INFOSEC Compliance and Business Process
Offsite Work Eligibility*
Routine Telework Eligible
Organization
NNP
Number of Days Onsite
3 days per Month
Hours
Full-Time, up to 40 hours
Additional Information
Assignment is approved for telework based on the approval of Personnel Security Manager.
Overtime
5% anticipated
On-Call
No
Travel
Up to 5% for local meetings and training
FN Status
NOT open to Foreign Nationals
* Current telework, remote work and onsite support is based on BPA's business needs and is subject to change or termination at any time.
** Assignments with the "Remote" Designation must reside in WA, OR, ID or MT. Case-by-case exceptions may apply only when in the best interest of BPA.
OVERVIEW
Assignment
This contract Business Analyst 3 assignment is located within the NNP (Personnel and Information Security, PERSEC) organization and will serve as a hands-on programmatic coordinator and auditor, supporting effective program management and project plan coordination for the INFOSEC (Information Security) program objectives and initiatives. The Business Analyst will play a key role in the development of an agency-wide Information Security and Awareness Program and subsequent implementation.
Organization
The NNP organization enacts, enables and performs work related to Personnel and Information security policy and guidance from Homeland Security Presidential Directive (HSPD) 12, Department of Energy (DOE), North American Electric Reliability Critical Infrastructure Protection (NERC CIP), Office of Personnel Management (OPM), and General Services Administration (GSA). NNP is a small but critical organization for BPA which requires personnel to be cross-trained in order to fully support the work load. NNP is a customer service organization with a unique responsibility to protect and serve our stakeholders. Our team members are independent, proactive thinkers who collaborate well. Our work ranges from detail-oriented, process-driven tasks to stressful, high priority work that requires personnel who can react appropriately and keep a calm head under pressure.
The ideal candidate will:
• Listen thoroughly to understand their stakeholder's needs, remain flexible and is able to make thoughtful decisions quickly and efficiently.
• Be able to carry out assigned tasks with a professional demeanor, as exhibited in excellent written and oral communication skills, listening skills, patience, logical and sound reasoning, and problem-solving approach.
• Have a high level of attention to detail and accuracy and be a logical thinker.
• Have the ability to work well within a highly matrixed organization.
• Have the ability to work under pressure in constantly changing and demanding environments; must demonstrate flexibility and ability to deal with ambiguity.
ASSIGNMENT RESPONSIBILITIES
Note: All official drafts, documents and recommendations, as listed below, must be reviewed, finalized and approved / accepted by appropriate BPA manager or other federal personnel with the authority to do so.
Provide highly skilled project coordination and change management services in support of Information Security initiatives.
Develop recommendations to NNP manager regarding process improvement(s) as they relate to Information Security implementation and operational excellence.
Execute to drive success on project initiatives through development of sound project plans and change management plans in the areas of stakeholder sponsorship, communication, and training and resistance management.
Develop BPA-wide information sharing tools, such as visuals, poster boards, fliers, informational handouts, etc.
Provide guidance to BPA personnel regarding security policies and procedures as needed
Develop and/or maintain BPA-wide reporting and tracking tools using SharePoint
Compile, track, and/or report status/progress data as requested for inclusion in management, program, and/or project reports; this may include providing information for Key Strategic Initiatives (KSIs).
Develop, implement and monitor effectiveness of change plans and strategies through various feedback loops or measurements and continuously improve to gain maximum benefit, mitigate risks and address identified deficiencies
Develop, maintain and improve project management/change management goals and tools to track program progress, objectives, and milestones in support of BPA wide INFOSEC implementation schedule (deliverables, templates, techniques) that are simple, effective, and designed for different audiences.
Document, test, and evaluate BPA adherence to established policies and procedures, providing feedback to applicable parties in the form of assessments/audits.
Support a sustainable infrastructure by providing adequate documentation of activities (strong evidence and compliance experience).
Cross-train other personnel and employees on INFOSEC processes and procedures as needed.
Coordinate with NNP manager on recommended improvements, changes, and course corrections.
Working with BPA manager / team lead or other federal party, follow up and coordinate BPA responses to security incidents.
Develop recommended assessment/adherence plans; obtain approval for recommended actions; execute approved plans and report results to NNP manager.
Provide expertise with business process modeling techniques to recommend new business drivers and roles and responsibilities within a project or program plan; incorporate approved recommendations as assigned.
Research the necessary information to develop training manuals and materials. Develop formats for training courses, providing recommendations on the emphasis to be placed upon each segment; obtain appropriate approvals on recommendations. Based on approved training material recommendations:
Carry out the training project or assignment (delivery) including resolving routine and/or technical problems/issues;
Validate training material aligns appropriately with BPA / INFOSEC policy;
Provide recommendations regarding the best practice training approach to be taken, including the methods and techniques to be employed; obtain BPA manager / team lead approval of recommended approach;
Train the trainers, as appropriate and/or requested.
Develop methods to evaluate trainee progress in business process-related training, as well as for continuing education. Provide developed methods for BPA manager/team lead review and approval; implement approved evaluation methods, with continuing coordination and oversight of the appropriate BPA manager / team lead.
Provide guidance and input into technical reviews of proposed projects, including recommended certification and accreditation process to be utilized.
Provide status update(s) to the BPA manager / team lead in a routine and timely manner, allowing time for review and approval and any necessary corrections that may be needed before established deadline(s).
REQUIREMENTS
Education & Corresponding Experience (required on matrix)
A degree in business administration, management, accounting, computer science or a closely-related field is preferred.
With an applicable Bachelor's Degree, 8 years of experience is required
With an applicable Associate's Degree, 10 years of experience is required
Without an applicable degree, 12 years of experience is required
Experience should include the specific requirements of business analysis and progressively more technical in nature.
Required Technical Skills & Experience (required on matrix)
Experience with the following:
Note: Candidate resume and requirements matrix must clearly explain applicable experience in sufficient detail to validate the following
requirements:
3+ years of experience effectively performing compliance and performance measurement activities in a security environment.
Direct work experience and knowledge of change management methodologies coupled with project planning and execution principles.
Experience should include a minimum of three years in one or more of the following security disciplines: Information/Operations (InfoSec/OpSec), Physical, Personnel, or Industrial.
Previous program support/project coordination experience demonstrating strong ability to interpret requirements and apply judgment to validate policies are compliant with regulations is required
Intermediate to Expert level experience with Microsoft Office Suite Software (MS Word, Excel, Outlook); (MS Office 2010 proficiency required).
Intermediate level experience with MS Project, SharePoint and PowerPoint is required. Experience should be sufficient to:
Define and track projects utilizing MS Project
Provide status and project reporting utilizing SharePoint
Develop and/or maintain BPA-wide reporting and tracking tools utilizing SharePoint
Create comprehensive, informational, and attractive presentations using PowerPoint
Experience in evaluating the adequacy and existence of security controls, preferably related to a security discipline.
Experience researching and maintaining proficiency in tools, techniques, countermeasures, and trends in information security, computer and network vulnerabilities
Ability to meet/monitor/report timelines, milestones, deliverables, and provide timely status updates on assigned tasks utilizing MS Project and other acceptable work processing tools
Experience applying change management techniques independently and, as a team member; plan, execute strategies and recommendations in the environment.
Experience performing analysis of in-place technical and non-technical information security controls protecting information in both electronic and physical form.
Preferred Skills & Experience (optional on matrix)
Training development experience using the Captivate software program.
Knowledge of principles of project management and change management
Experience with identification of sensitive and/or classified information
Additional Requirements (not required on matrix)
Valid U.S. Driver's License is required.
Must be able to obtain a Certificate of Completion in Personnel Security and Information Security training plan (See BPA required training below)
Other Assignment Considerations
May be required to work non-core hours as circumstances warrant. Saturdays and evening hours may be necessary for finishing assessments/audits and other compliance related activities, as needed.
Appendices
The following appendices apply to this assignment and may be downloaded from the Fieldglass Reference Library:
Offsite Work
Training Expectations (Worker is expected to keep current on the latest technologies and skills required for the assignment.)
Training Type
Details
Provided by
OPEx Process Mapping
BPA
OpEx Intro to Quality Management
BPA
OpEx Root Cause Analysis
BPA
OpEx Defining and Achieving the ROI of quality in service
BPA
InfoPath (or its replacement)
BPA
NERC/CIP and Site Access Training (Resolver)
BPA
Business Case 101
BPA
DOE National Training Centers on-line Learning Management System courses needed to obtain a Certificate of Completion in Personnel Security and Information Security program tracks
BPA
NERC CIP User Group Conference
BPA
NERC CIP 101 Training
BPA
Electricity Fundamentals Training - This training is held at BPA and is necessary to provide a knowledge baseline to INFOSEC staff. INFOSEC staff then can provide relevant Information, protection policies and procedures that are aligned with stakeholder's practices.
BPA
Attendance at all conferences, workshops, training, etc. must be pre-approved by SLMO. Requests will be reviewed on a case-by-case basis. Approval is subject to the most current guidance provided to SLMO by BPA or DOE and is subject to change at any time. SLMO reserves the right to negotiate attendance on billable/non-billable hours and reimbursement of travel costs with the supplier. Reimbursable travel costs must adhere to the Federal Travel Regulations and be submitted via an expense sheet in Fieldglass.
CLOSELY ASSOCIATED RESPONSIBILITIES & REQUIRED ASSOCIATED MITIGATION MEASURES
The following is a list of potential inherently governmental risk areas and the measures that SLMO-Compliance has determined must be in place, via processes and procedures, to mitigate the associated risks. The BPA manager's acceptance of the API or CWSD serves as their attestation that all applicable mitigation measures listed below are or will be established and adhered to in their organization.
Area of potential Closely Associated / Inherently Government function
Mitigation Measures
Access to Confidential / Sensitive Information
CFTE must sign NDA (Non-Disclosure Agreements) at beginning of assignments. (Does not apply to Craft assignments)
CFTE must complete annual Information Security and Privacy Awareness training.
CFTE must complete and pass background investigations of an appropriate level.
Acquisition Planning / Source Selection
CFTE are not permitted to serve as "voting" members for acquisition selections.
All purchasing decisions must be made by appropriate federal personnel (Contracting Officers).
All acquisition documents (requirements,
SOW's, evaluation criteria, etc.) must be reviewed, finalized and approved by appropriate BPA federal personnel.
Only Contracting Officers are authorized to obligate BPA funds.
Agency / Org Planning
All drafts, documents, materials and recommendations must be reviewed, finalized and approved by appropriate BPA federal personnel.
Budget / Finance Prep
Only Federal Employees may determine budget priorities & allocations.
BFTE must control and finalize / appro