Job Requirements
Brooklyn Heights, NY
DoE Q or L Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Description
***This position is contingent upon award ***
Responsibilities:
Location: Hybrid - 3 days onsite Brooklyn, NY, 2 days remote
Requirements
Applicant must be a U.S. citizen residing in the U.S.
This position requires obtaining a clearance through the Department of Education. Applicants must be willing to undergo a background check as part of the hiring process.
Education: Bachelor's degree from an accredited university or 5-7 years of relevant experience.
Experience: 3+ years in GRC, third-party risk management, federal compliance (NIST 800-53, 800-37)
Certifications: (candidates MUST HAVE obtained at least one)
Technical Skills:
Benefits
***This position is contingent upon award ***
Responsibilities:
- Drive enterprise cybersecurity risk management by quantifying risks, assessing control effectiveness, and ensuring alignment with NIST 800-53, FISMA, and DOE policies
- Lead enterprise-wide risk assessments, audits, and user awareness programs
- Maintain and manage the enterprise Risk Register and POA&M lifecycle
- Monitor/report critical cyber risks; use dashboards and metrics to inform leadership
- Design security awareness programs and phishing simulations
- Collaborate with engineers and analysts to define compliance guardrails and prioritize remediation activities
- Generate automated risk metrics, heat maps, and executive-level security reports
Location: Hybrid - 3 days onsite Brooklyn, NY, 2 days remote
Requirements
Applicant must be a U.S. citizen residing in the U.S.
This position requires obtaining a clearance through the Department of Education. Applicants must be willing to undergo a background check as part of the hiring process.
Education: Bachelor's degree from an accredited university or 5-7 years of relevant experience.
Experience: 3+ years in GRC, third-party risk management, federal compliance (NIST 800-53, 800-37)
Certifications: (candidates MUST HAVE obtained at least one)
- CISA (Certified Information Systems Auditor)
- CRISC
- CGEIT
- CISSP
- CompTIA Security+
- CCSK (Certificate of Cloud Security Knowledge)
- CAP/ISC2 CGRC
Technical Skills:
- GRC platforms (Archer/ServiceNow)
- TPRM tools (OneTrust/Prevalent)
- Awareness platforms (KnowBe4/Proofpoint)
- MS Power BI
- Advanced Excel
- JIRA
Benefits
- Health Care Plan (Medical, Dental & Vision)
- Retirement Plan (401k, IRA)
- Life Insurance (Basic, Voluntary & AD&D)
- Paid Time Off (Vacation, Sick & Public Holidays)
- Training & Development
group id: 91128970