Skip to main content

This job has expired

Program Lead, Cybersecurity (Risk Management & Vulnerability Management)

Employer
Washington Metropolitan Area Transit Authority
Location
Washington D.C
Closing date
Jun 10, 2023

Job Details

***This posting has two openings one focuses on Risk Management and the other one on Vulnerability Management.

Department Marketing Stement:

The Washington Metropolitan Area Transit Authority (Metro) is building a state-of-the-art cybersecurity program to better protect the critical transit infrastructure supporting our nation's capital. This position will serve as the program lead, Cybersecurity Risk Management responsible for risk management and mitigation across WMATA program areas based on industry best practices to include NIST CSF/RMF and 800-53 Rev. 5. The program lead will conduct and manage risk assessments for WMATA systems to include those that store, process, and transmit Payment Card Industry (PCI), NIST 800-53 Rev. 5 (FISMA), health and wellness (HIPPA), and privacy (PII, PHI, GDPR) data. They will be responsible for the overall planning, coordination and execution of the risk management program with an emphasis on vulnerability remediation status reporting and coordination across the enterprise. The program lead will also partner with WMATA ISSOs/ISSMs to facilitate, manage, track and report on risk reduction activities via the WMATA GRC tool in support of the enterprise risk management program.

General Hybrid Work Statement:

This opportunity is a hybrid opportunity allowing for flexibility between virtual and in-person work subject to the Authority's telework policy.

Minimum Qualifications

Education
  • A Bachelor's degree from an accredited college or university

Experience
  • Six (6) years of experience as a cybersecurity officer/engineer, information systems security officer, or specialized expertise in cyber policy, intelligence, analytics, budget, audit, metrics, or training such that it meets the specific role posted

Preferred Education
  • A Bachelor's Degree in Computer Science, Cybersecurity or a related technical field


ADDITIONAL CRITERIA FOR PROGRESSION
  • Note: Progression is not automatic nor guaranteed and is dependent on successfully completing the specified workload requirements
  • Candidates for promotion meet the minimum qualifications and work experience of the next career ladder series job before consideration for advancement

Medical Group

Satisfactorily complete the medical examination for this position, if required. The incumbent must be able to perform the essential functions of this position either with or without reasonable accommodations.

Summary

The Cybersecurity Officer Lead is responsible for ensuring that the Washington Metropolitan Area Transit Authority (WMATA) cybersecurity program is conducted based on the cybersecurity strategy and that it aligns well with industry best practices such as the National Institute of Standards and Technology (NIST) framework. The officer ensures that the skills necessary for an effective cybersecurity program are defined and that there is adequate funding to hire the right people to provide those skills. The officer designs an effective security awareness program to educate and change the cybersecurity culture of the WMATA staff, as well as develop security policies for compliance with internal and external audits. The officer is responsible for making sure that the selection and implementation of cybersecurity controls are built into the initial stages of any system/software acquisition and system/application vulnerability scans will be conducted to ensure controls implementation for all systems and applications.

Essential Functions
  • Oversees and contributes to the development of cybersecurity career enhancing workforce plans, strategies, and guidance to enable the development and retention of the best professionals possible. Creates training and education requirements to address changes to cybersecurity policy, emerging threats, certification requirements and industry best practices through partnerships with universities, certification companies, state/federal partners and other innovative strategies that deliver relevant content. Creates a strong culture of cybersecurity within the IT organization and drives behavioral changes for all business units within WMATA. Ensures that timely, mission-focused, and tailored cybersecurity training and developmental opportunities are provided to cybersecurity personnel.
  • Oversees and contributes to the creation of governance standards based on NIST and other frameworks (policies, processes, workplans, templates, etc.) by which the WMATA Cybersecurity program is managed and measured against. Develops and maintains cybersecurity plans, strategy, and policy to support and align with organizational cybersecurity initiatives and regulatory compliance. Ensures that WMATA's cybersecurity program has a governance model based on best practice.
  • Oversees and contributes to performance assessments of threats and vulnerabilities for systems and networks within the network environment; determines deviations from acceptable configurations, enterprise or local policy; assesses the level of risk; and develops and/or recommends appropriate mitigation countermeasures in operational and nonoperational situations. Measures the effectiveness of defense-in-depth architecture against known vulnerabilities. Ensures that system and network threats and vulnerabilities are identified and remediated in a timely manner.
  • Oversees and contributes to performance evaluations of the IT security program and its individual components to determine compliance with published standards. Tracks finding and reports of remediation progress. Supports policy compliance, governance and incident response programs. Prepares audit reports that identify technical and procedural findings and provides recommended remediation strategies/solutions. Coordinates external audit requirements. Ensures that systems, processes and people follow published policy and alerts personnel to potential risk areas.
  • Oversees and compiles and reviews budgets for the Cybersecurity program using actual performance, previous budget figures, estimated revenue, expense reports, and other data sources to control funds and provide for proper financial administration. Uses an understanding of system security to develop budgetary requirements. Works with the cybersecurity personnel to ensure they effectively plan send monitor their budgets. Tracks contracting costs and needs, managing statement of work efforts. Ensures that the cybersecurity program manages costs effectively, projects future budget needs, improves services received and meet schedule demands for service delivery.
  • Oversees, prepares and presents governance and compliance management reports, key performance metrics, scorecards, and briefings, as required, to cybersecurity and IT leadership. Works with leadership to use continuous monitoring scoring and grading metrics to make information security investment decisions to address persistent issues. Works with organization risk analyst to ensure risk metrics are defined realistically to support continuous monitoring. Ensures the enterprise has a cybersecurity scorecard that presents a clear view of the health of the organization, including but not limited to system-level health (categorized by business units and rolled up), operational defensive effectiveness (detection, response, remediation of threats), employee training/effectiveness (phishing, social engineering).
  • Oversees the cybersecurity components of the governance, risk and compliance (GRC) tool. Configures and populates the tool to enable security professionals to document a wide-array of controls. Creates and maintains inherited controls at the direction of the Authorizing Official. Supports audit and metric requirements by developing exports and reports. Ensures that all system security controls are tracked and managed effectively.
  • Executes a risk-based, repeatable/consistent system security strategy based on the NIST Risk Management Framework/Cybersecurity Framework which includes: control selection and inheritance, drafting and reviewing system authorization documentation, documenting/remediating vulnerabilities, populating a Governance Risk and Compliance (GRC) tool, partnering with developers/owners to ensure security is a part of the complete system development life cycle, and continuous monitoring. Ensures that WMATA has a consistent process around system authorization and monitoring.
  • As a part of the system security life cycle, provides program oversight and leadership for the evaluation of the effectiveness of procurement function in addressing information security requirements and supply chain risks through procurement activities and recommends improvements. Develops and documents supply chain risks for critical system elements, as appropriate. Ensures that WMATA systems and technology are procured with security considered from the start.
  • Oversees, evaluates, and supports the documentation, validation, assessment, and authorization processes necessary to assure that existing and new information technology (IT) systems meet the organization's cybersecurity and risk requirements. Ensures appropriate treatment of risk, compliance, and assurance from internal and external perspectives. Ensures that WMATA has a properly managed risk management framework.
  • Oversees and performs privacy impact assessments of an application's security design for the appropriate security controls, which protect the confidentiality and integrity of Personally Identifiable Information (PII) and assess the security effectiveness of the security controls. Ensure PII is properly protected in all WMATA systems and applications.
  • Oversees and contributes to the implementation of the security controls specified in a security plan or other system documentation and develops a strategy for monitoring control effectiveness; coordinates the system-level strategy with the organization and mission/business process monitoring strategy. Ensures that WMATA has a properly managed risk management framework.
  • Advises security leadership (e.g., Chief Information Security Officer [CISO], Director, etc.) on risk levels and security posture of managed systems, and on the cost/benefit analysis of information programs/projects, policies, processes, systems and elements.
  • Consults with customers to gather and evaluate functional requirements, determine security controls that mitigate risks, adhere to policy and facilitate customer needs, and translates these requirements into technical solutions. Provides guidance to customers about applicability of security controls to meet business needs. Supports the development phases of the systems development life cycle.

The essential duties listed are not intended to limit specific duties and responsibilities of any particular position. Nor is it intended to limit in any way the right of managers and supervisors to assign, direct and control the work of employees under their supervision.

Evaluation Criteria

Consideration will be given to applicants whose resumes demonstrate the required education and experience. Applicants should include all relevant education and work experience.

Evaluation criteria may include one or more of the following:
  • Skills and/or behavioral assessment
  • Personal interview
  • Verification of education and experience (including certifications and licenses)
  • Criminal Background Check (a criminal conviction is not an automatic bar to employment)
  • Medical examination including a drug and alcohol screening (for safety sensitive positions)
  • Review of a current motor vehicle report


Closing

WMATA is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other status protected by applicable federal law.

This posting is an announcement of a vacant position under recruitment. It is not intended to replace the official job description. Job descriptions are available upon confirmation of an interview.

Company

The Washington Metropolitan Area Transit Authority operates the second largest rail transit system and the fifth largest bus network in the United States. Safe, clean and reliable, "America's Transit System" transports more than a third of the federal government to work and millions of tourists to the landmarks in the Nation's Capital.

Metro has earned a worldwide reputation for security and architectural beauty. WMATA is clearly the employer of choice for over 10,000 area residents. The Authority was created in 1967 by an interstate compact to plan, develop, build, finance and operate a balanced regional transportation system in the National Capital area. Construction of the Metrorail system began in 1969. Four area bus systems were acquired in 1973. The first phase of Metrorail began operation in 1976. The final leg of the original 103-mile rail network was completed in early 2001. Metrorail now operates 83 stations. One line extension and three new stations are now under construction.

Metrorail and Metrobus serve a population of 3.4 million within a 1,500-square-mile area. The transit zone consists of the District of Columbia, the suburban Maryland counties of Montgomery and Prince George's and the Northern Virginia counties of Arlington, Fairfax and Loudoun and the cities of Alexandria, Fairfax and Falls Church. Overall, about 40 percent of the region's residents commute to work on Metro.

Metro and the federal government are partners in transportation. Half of the 83 Metrorail stations serve federal facilities and 36 percent of the local federal workforce uses Metro. We are committed to being an integral part of the Washington metropolitan area by ensuring the best in safe, reliable, cost-effective and responsive transit services, by promoting regional mobility and by contributing toward the social, economic and environmental well-being of our community. Employees are Metro.; We are committed to providing a working environment that fosters a high standard of performance, recognition for contributions and innovations, mutual respect and a healthy quality of life.

We are committed to developing ourselves through technology, training and education. We recognize our diversity as a source of strength that enables us to attain individual and Authority goals. In addition to competitive salaries, Metro employees enjoy a number of attractive benefits. These benefits include paid time off in the form of vacations, holidays and sick leave; medical, dental, life insurances as well as long term disability. Retirement is planned for through a defined contribution plan and a deferred compensation plan. Alternative work schedules, teleworking and free transportation on Metrorail and Metrobus make for an great benefits package for WMATA employees.Jump to our website to apply online for current openings and save the link for future vacancies as they occur.http://content.wmata.com/jobs/employment_opportunities.cfm

 

 

Company info
Website
Location
600 Fifth St. NW
Washington
DC
20001
US

Get job alerts

Create a job alert and receive personalized job recommendations straight to your inbox.

Create alert