> Markdown version of [/jobs/ext/918718-cyber-security-analyst-cyber-policy](https://www.wearedevelopers.com/jobs/ext/918718-cyber-security-analyst-cyber-policy). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst - Cyber Policy - **Company:** Savannah River National Laboratory - **Location:** Aiken, SC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Management - **Published:** June 5, 2026 - **Apply:** https://diversityjobs.com/career/17150342/Cyber-Security-Analyst-Cyber-Policy-South-Carolina-Aiken ## About the Role * Bachelor's degree in Cybersecurity, Information Management/Assurance, or related field * 6 to 9 years of experience in Cybersecurity and Policy in a federal-contractor position * Excellent and proven writing skills in the cybersecurity field that show the ability to be clear and concise for complex topics. Samples provided may be redacted if needed. * For ability to obtain and maintain a security clearance, US Citizenship is Legally Required. Preferred Qualifications * Expert knowledge of DOE 205.1x and Cyber Security Program Plans * Current or recent experience supporting DOE policies related to cybersecurity * Good interpersonal skills and demonstrated ability to work collaboratively in a team environment * Certifications in Cyber such as CISSP, CISM, CGRC (formerly ISC2 CAP), or CRISC. * Policy-focused certifications (GIAC-GLEG, GSLC or similar) * Strong attention to detail * Ability to learn new technologies, concepts, and processes quickly * Active DOE L clearance ## Description Savannah River National Laboratory (SRNL) is seeking an experienced cyber security policy professional to join the Cyber Assurance, Governance, Risk Management and Compliance team! The selected individual will serve as lead policy writer and subject-matter expert for the DOE-SRNL cybersecurity program. * Serve as principal author for all new and revised SRNL specific cybersecurity policies and procedures * Develop and maintain responses to contracts for DOE Orders and Cyber Security Program Plan * Review and advise as to impact to cybersecurity approved policies for other SRNL procedures with cybersecurity references * Assist ISSOs with creating and maintaining supplemental program documents, policies and procedures for multiple accreditation boundaries based on approved security controls * Perform gap analysis for draft, new, or updated federal mandates (EO 14028, BODS, OMB Memos) and write comprehensive summaries that support efficient decision making where needed * Support audits and assessments with policy evidence artifact/packages * Review cybersecurity training and develop newly identified training, keeping aligned with approved policies * Review and advise ISSOs additional documents such as Risk Assessments, Security Impact Analysis or others as requested. * Work effectively in a team environment and contribute to continuous process improvement efforts. * Participate/assist with compliance assessments/audits and data calls. * Interact with customers and peers in a professional and responsive manner. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [How to Navigate Professional Relationships in the Tech Industry](https://www.wearedevelopers.com/videos/1276-how-to-navigate-professional-relationships-in-the-tech-industry) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [APItoolkit: Using Merkle Trees and LLMs to Detect the UnDetectable in Software Monitoring](https://www.wearedevelopers.com/videos/1639-apitoolkit-using-merkle-trees-and-llms-to-detect-the-undetectable-in-software-monitoring) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)