Cybersecurity Risk & Compliance Specialist
Job in
Idaho Falls, Bonneville County, Idaho, 83401, USA
Listed on 2026-07-22
Listing for:
Idaho National Laboratory
Full Time
position Listed on 2026-07-22
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Role Summary
As a Cybersecurity Risk and Compliance Specialist in the Computer Engineering department at Idaho National Laboratory, you will shape the future of national energy supply by performing mechanical design and analysis of advanced nuclear reactors and associated systems. You will collaborate with world‑class scientists and engineers to develop designs that enable advanced nuclear reactor projects through multiple INL program sponsors. This position is located at our Materials and Fuels Complex, which hosts the core of the U.S. nuclear research and development capabilities.
Responsibilities- Develop and evaluate compliance with programs and processes to mitigate cybersecurity risk and ensure protection of company and allied assets and information.
- Research and interpret current and pending governmental laws and regulations, industry standards and customer and vendor contracts to communicate compliance requirements.
- Conduct information security risk assessments, security compliance audits and cybersecurity audits.
- Document, investigate, and report cybersecurity compliance issues and incidents.
- Work with business leaders to ensure information security risk findings are reviewed and solutions are implemented.
- Coordinate the cybersecurity audit program and act as the audit liaison to facilitate successful coordination with external auditors and the Lab.
- Represent the Cybersecurity risk management program to INL senior leadership, DOE‑, DOE‑NE oversight, and internal and external auditors.
- Coordinate with accountable subject matter experts to develop and obtain management approval of corrective action plans to address audit findings.
- Track and communicate audit finding remediation milestones and due dates, and provide status updates to DOE.
- Maintain external audit findings in DOE’s Enterprise Cybersecurity Enterprise Governance (ECGS) system.
- Serve as an advisor on all matters involving security of assigned information systems.
- Develop policy, programs, and guidelines for implementation and promote awareness of cyber policy and strategy among management.
- Assess policy needs and collaborate with stakeholders to develop policies to govern cyber activities.
- Review, conduct, or participate in assessments and audits of cyber programs and projects.
- Perform other duties as assigned.
- Establish and maintain an appropriate IT/OT cyber risk management methodology and work with management to document those items and risk.
- Develop indicators and metrics for material technology risks, obligations, and controls.
- Collaborate with stakeholders across the organization to reduce the likelihood and potential impacts to risks that could be realized.
- Utilize the integrated risk management platform to monitor and report on the effectiveness of risk management controls and processes and make recommendations for improvement as needed.
- Coordinate the cybersecurity audit program.
- Act as the audit liaison to facilitate successful coordination with external auditors and the Lab.
- Coordinate audit meetings, assessment activities, and requests.
- Represent the Cybersecurity risk management program to INL senior leadership, DOE‑, DOE‑NE oversight, and internal and external auditors.
- Coordinate with accountable subject matter experts to ensure development and appropriate management approval of corrective action plans to address audit findings.
- Submit corrective actions to the CISO and unclassified ISSM.
- Track and communicate audit finding remediation milestones and due dates.
- Ensure accountable subject matter experts and management are aware of commitments to remediate findings and the status of ongoing remediations.
- Maintain external audit findings in DOE’s Enterprise Cybersecurity Enterprise Governance (ECGS) system.
- Serve as an advisor on all matters, technical and otherwise, involving security of assigned information systems.
- Develop policy, programs, and guidelines for implementation.
- Maintain communication channels with stakeholders.
- Promote awareness of cyber policy and strategy as appropriate among management and ensure sound principles are reflected in the organization’s mission, vision, and goals.
- Assess policy needs and collaborate…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×