×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity Governance, Risk, and Incident Readiness Lead

Job in Columbus, Franklin County, Ohio, 43215, USA
Listing for: LanceSoft
Full Time position
Listed on 2026-08-31
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below

Cybersecurity Governance, Risk, and Incident Readiness Lead

The Cybersecurity Governance, Risk, and Incident Readiness Lead will be responsible for CRAA's cybersecurity governance, maturity, policy improvement, incident-readiness, exercise, and training work streams. The role will lead the annual NIST CSF-aligned maturity assessment, review and improve cybersecurity policies and procedures, enhance incident-response and recovery plans, design and facilitate tabletop exercises, deliver quarterly incident-response training, support the airport-wide exercise, and translate findings into practical remediation roadmaps.

CRAA clarified that formal CMMC certification is not required. The recurring maturity requirement is one annual assessment aligned with the NIST Cybersecurity Framework and CRAA's CMMI-style maturity approach.

Key Responsibilities
  • Coordinate governance activities with CRAA's cybersecurity and information-technology teams.
  • Align advisory work to CRAA's cybersecurity strategy, roadmap, risk priorities, operating environment, and applicable requirements.
  • Support the Govern, Identify, Protect, Detect, Respond, and Recover functions.
  • Provide consultative support concerning asset management, data governance, risk management, access control, training, data security, recovery, monitoring, response, mitigation, and improvement.
  • Support CRAA's enterprise Risk Governance forum and existing remediation-tracking processes.
  • Maintain traceability among findings, risks, recommendations, responsible owners, actions, and status.
  • Facilitate prioritization based on severity, business impact, effort, dependencies, and residual risk.
  • Plan and lead one annual NIST CSF-aligned cybersecurity maturity assessment.
  • Define the assessment scope, participants, evidence requests, interviews, rating criteria, and schedule.
  • Review policies, processes, procedures, governance records, technical evidence, and operating practices.
  • Facilitate workshops with CRAA cybersecurity and technology personnel.
  • Assess current maturity using CRAA's requested CMMI-style approach.
  • Document current-state maturity, target-state objectives, material gaps, strengths, dependencies, and recommended improvements.
  • Develop a prioritized roadmap with approximate levels of effort.
  • Present findings to technical personnel and executive leadership.
  • Track progress against prior-year recommendations.
  • Avoid representing the assessment as a formal CMMC certification or CMMI organizational appraisal.
  • Establish a structured process for reviewing CRAA's existing cybersecurity documentation.
  • Support review and improvement of approximately 100 policies, standards, procedures, plans, and operational documents, subject to CRAA prioritization.
  • Identify obsolete, conflicting, incomplete, or missing requirements.
  • Recommend practical revisions aligned with CRAA's technology, risk, and operating environment.
  • Draft new documentation where emerging technology or operations create a material need.
  • Coordinate review with document owners, technical stakeholders, leadership, and other CRAA personnel.
  • Maintain version control, approval history, ownership, review dates, and document relationships.
  • Ensure that policy language is implementable and does not create unsupported operational commitments.
  • Review and enhance CRAA's existing Incident Response Plan.
  • Define or improve roles, responsibilities, severity criteria, communications, escalation, evidence handling, containment decisions, recovery coordination, and post-incident review.
  • Align the plan with the co-managed SOC operating model.
  • Document the relationship among the MSSP, CRAA internal responders, cybersecurity leadership, cyber-insurance responders, legal stakeholders, and other participants.
  • Support ransomware-readiness and recovery-planning activities.
  • Ensure incident procedures reflect CRAA's restrictions on AI, data handling, external ticketing, and third-party access.
  • Incorporate lessons from actual events, exercises, post-mortems, and control assessments.
  • Review cybersecurity aspects of CRAA's disaster-recovery and business-continuity plans.
  • Help identify dependencies among incident response, system recovery, communications, crisis…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary