Cyber Risk and Vulnerability Lead (Remote)

Akima, LLC

• $155K — $165K *
US-AnywhereRemote in Washington, DC
Energy & Utilities
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in an IT-related field and eight years of IT experience.
  • Minimum four years of experience in risk and vulnerability assessments.
  • Experience in cybersecurity operations or related technical security functions.
  • Ability to apply cybersecurity policies effectively across IT services.
  • Demonstrated capacity to collaborate with leadership to develop security solutions.
  • Skills in validating cybersecurity tools and assessing enterprise security status.
  • Leadership experience in enterprise-wide risk and vulnerability initiatives.
  • Strong written and verbal communication skills for presenting security strategies.

Responsibilities

  • Ensure implementation of cybersecurity policies across IT services.
  • Collaborate to develop security solutions for information assurance.
  • Assess and validate new cybersecurity tools with cybersecurity personnel.
  • Lead enterprise-wide risk and vulnerability management efforts.
  • Provide subject matter expertise on cyber risks and vulnerabilities.
  • Conduct cybersecurity analysis and provide guidance on NIST and FISMA systems.
  • Communicate complex risks effectively to executive leadership.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • Life insurance and a 401(k) plan.
  • Access to a range of voluntary benefits.
  • Paid Time Off (PTO) for regular employees.
Full Job Description

The Office of the Chief Information Officer (OCIO) advances the Department of Energy’s (DOE) mission by establishing enterprise-wide policy, standards, and services that ensure secure, reliable, and innovative information technology (IT) delivery across the Department. The OCIO is committed to strengthening DOE’s cybersecurity posture, improving IT service performance, and ensuring the protection of the Department’s systems, networks, and data while maintaining responsible stewardship of taxpayer resources.  To join our team of outstanding professionals, apply today!

 

Cyber Risk and Vulnerability Lead is a subject matter expert who supports this mission by leading cybersecurity measures, assessing security controls, evaluating system risks, and leading efforts to respond to cybersecurity data calls, research, and analysis. This role combinesdeep experience and understanding of cybersecurity functions and oversight and compliance responsibilities, ensuring DOE systemsremaincompliant, secure, and resilient.

Responsibilities
  • Ensures the appropriate implementation of cybersecurity policies, principles, and practices across information technology and cybersecurity services.
  • Collaborates with IT and cybersecurity line management to develop security solutions that maintain information assurance across the enterprise.
  • Collaborates with cybersecurity personnel to assess and validate new cybersecurity tools and processes. Evaluates the enterprises overall status against established benchmarks.
  • Leads the enterprise-wide risk and vulnerability management efforts for key areas, typically overseeing a small team of senior technical professionals.
  • Serves as a subject matter expert in cyber risk and vulnerabilities, with in-depth knowledge of cybersecurity, risk management, vulnerabilities, and best practices for strengthening and enhancing the enterprise security posture.
  • Applies principles, methods, and expertise in cyber risk and vulnerability management across relevant technical and engineering disciplines to develop sound, secure solutions for applications and systems.
  • Conducts briefings to Federal Leadership and possesses and applies subject matter expertise across key tasks and high-impact assignments.
  • Serves as a security and technical expert across multiple project assignments.

Cyber Risk and Vulnerability Lead Duties:

  • Perform cybersecurity, risk, and vulnerability analysis and guidance of NIST and FISMA systems, including subsystems within respective system boundaries.
  • Effectively communicate findings, articulate the potential cybersecurity implications of identified risks, vulnerabilities, and weaknesses, and work through recommended resolutions.
  • When determining and assessing risks, evaluate the likelihood that a threat will exploit a vulnerability, as well as the potential impact on operations or data.
  • Provide oversight and leadership by advising IT and engineering teams on prioritizing fixes according to real-world implications, business risk, and business impacts.
  • To meet compliance objectives, ensure enterprise applications and systems adhere to all applicable legal, governmental, and industry security requirements.
  • Establish and maintain strong relationships across teams of cybersecurity professionals, including Information System Security Officers (ISSOs), System Owners (SOs), and Technical Points of Contact (TPOCs).
  • Provide leadership and guidance in responding to cybersecurity and system vulnerability data requests for internal and external audits and reporting, as needed.
  • Provide leadership in communicating complex technical risks clearly and concisely to management, executive leaders, and other federal officials.
  • Act as the primary liaison and point of contact among operational security teams, third-party system owners, contractors, government, and federal executive leadership.
Qualifications
  • Bachelor's Degree in an information technology-related field and eight (8) years of work experience in Information Technology.
  • At least four (4) years of experience performing risk and vulnerability assessments on progressively more complex systems and projects.
  • Experience in cybersecurity operations, security control assessments, or other related technical security functions.
  • Ability to ensure the appropriate application of cybersecurity policies, principles, and practices across information technology and cybersecurity services.
  • Demonstrated experience collaborating with IT and cybersecurity leadership to develop security solutions that maintain information assurance across the enterprise.
  • Experience collaborating with cybersecurity personnel to validate new cybersecurity tools and processes, as well as assessing the enterprises overall status against established benchmarks.
  • Ability to provide senior-level consulting services to the client as needed to maintain a secure environment.
  • Ability to lead the enterprise-wide Risk and Vulnerability effort for significant organizational components, typically overseeing a small team of senior staff.
  • Ability to work independently with cybersecurity, assessment, external, and government teams to address cybersecurity and vulnerability issues, remove obstacles and barriers, and achieve successful outcomes.
  • Demonstrates strong written and verbal communication skills in preparing, presenting, and defending security strategies, vulnerability assessments, and remediation plans and outcomes.
  • Ability to complete a DOE background investigation and obtain federal government clearance for access to federal systems.
  • Ability to obtain DOE L clearance.
  • Any clearance requirements for this position are established by the government contract.
Benefits InformationRegular - The company offers a comprehensive benefits program, including medical, dental, vision, life insurance, 401(k) and a range of other voluntary benefits. Paid Time Off (PTO) is offered to regular full-time and part-time employees. Pay Range$155,000 - $165,000 Job ID2026-26053 Work TypeRemote

Similar Jobs

More Jobs at Akima, LLC

More Energy & Utilities Jobs

Find similar Cyber Risk and Vulnerability Lead (Remote) jobs: