Jobs
>
Salem

    Cybersecurity Services - Salem, United States - NR Consulting

    Default job background
    Description

    Job Title:
    Cybersecurity Services (CSS) State and Local Cybersecurity Grant Program (SLCGP) Manager



    Work Location:
    Salem, OR

    Duration:12+ Months Contract (Possible Extension)


    Position Summary:

    Administrative Tasks and Approach to Work

    Contractor shall create a Project Plan and Schedule that outlines the tasks, milestones, timeframes, responsibilities, decision points and methodology to complete the outlined scope and assure completion of all tasks within the expected timeframe.

    This plan and schedule will serve as the basis against which the Contractor's performance will be measured.
    Contractor shall complete the appropriate Deliverables. Contractor shall participate in daily and weekly planning and review meetings.
    Contractor shall follow EIS and SLCGP Project standards including the naming conventions.


    Primary Tasks:


    Task 1: Project Management and Reporting.
    Contractor shall provide all aspects of project management for its Services provided.


    This specifically includes:
    Participate in Project Kick-off session.

    The purpose of the kickoff meeting is to confirm mutual understanding of the overall SLCGP Project, the scope of this engagement, and clarification of expectations.

    Following execution of this WOC, Authorized Purchaser will schedule an initial kick-off session, and Contractor's team will attend and participate in this review of the Project scope and expectations.

    Following the meeting, Contractor shall provide written synopsis of the kick-off meeting.

    Contractor shall engage Authorized Purchaser's SLCGP Project Team and create a Project Plan and Schedule that outlines the Tasks, Milestones, timeframes, responsibilities, decision points and methodology to complete the outlined scope and assure completion of all Services within the expected timeframe.

    Contractor shall provide written status reports, SLCGP Project Team-requested updates to the Project Plan and Schedule and meet with CSS Project Manager/Sponsor weekly or otherwise as requested by Authorized Purchaser.


    Task 1 Deliverables:


    Deliverable 1.

    A:
    Kickoff Meeting Synopsis.

    Contractor shall deliver a written summary of the kick-off session.
    This Deliverable must include at least an agenda, summary of action items, responsibilities, meeting minutes, and timelines.

    This Deliverable must be written to a level of detail that will convey mutual understanding of the scope and expectations of the engagement.


    Deliverable 1.

    B:
    Project Plan and Schedule.

    Contractor shall develop and deliver a Project Plan and Schedule no later than 10 business days following the Acceptance of Deliverable 1.A.

    This Deliverable must reflect at least the following items:
    Vision of how Contractor and SLCGP Project Team will function together to accomplish the Statement of Work tasks.
    Each of Contractor's deliverables.
    Contractor's understanding of the responsibilities, tasks, and deliverables required of Contractor.
    Contractor's expected need for SLCGP Project Team involvement in each task.

    Written explanation of the plan and schedule, describing the process and time frame Contractor expects to successfully accomplish and complete the requirements, milestones and Deliverables of the Statement of Work and WOC.

    Mitigation plan for any risks and issues identified.


    The Project Plan will include at a minimum, the following:
    Project Plan narrative that describes the overall goal and visions of the SLCGP Project.
    Roles and responsibilities.
    Plan for change control management.
    Plan for issues and risks tracking/management.
    Status report format.
    Format for all Deliverables.
    Deliverable tracking framework.
    Status Report and meeting cadence.


    The Project Schedule will:

    Identify the steps necessary to complete each Task and Deliverable within the awarded Contractor's Statement of Work and WOC.
    Contain milestones to be met.
    Identify State resources (e.g., CSS, agency representation and specific skill set or viewpoint to represent).
    Contain a sequential timeframe of completion for Deliverables.


    Deliverables 1.

    C:
    Weekly and Monthly Status Reports.

    Contractor shall deliver Weekly and Monthly Status Reports which contain details of progress, current status, and provide updated documentation of Task inputs, Task objectives, and Deliverables.

    Each report must document progress made towards project goals and include at least the following:
    Tasks completed by Contractor.
    Description of activities with percentage complete.
    Description of overall Task and Deliverable percentage complete.
    Description of planned activities not completed.
    Description of project issues, risks or concerns that occurred or were worked during the reporting period.
    Project goals planned for the next week/month.
    Updates to previously Accepted Deliverables, as requested by Authorized Purchaser.


    Task 2:
    Document Current SLCGP Program

    Contractor shall facilitate the review of and document the current SLCGP Program.

    Documentation to be developed under this Task includes at least:

    Developing stakeholder libraries.
    Preparing SLCGP Planning and Advisory Committee artifacts.
    Develop content for updates to the Cybersecurity Services Catalog.
    Develop content for updates to the State Cybersecurity Plan.
    Assist with memorandums of understanding (MOUs) with local governments.


    Task 2 Deliverables

    Deliverable 2.A. Grant Program Timeline Update. Contractor shall deliver an update to the Grant Program Timeline. The current Grant Program Timeline is available in the SLCGP Project Basecamp repository and includes key milestones, deadlines, and Deliverables, which ensures timely and effective implementation of cybersecurity initiatives.

    Deliverable 2.B. Reserved.

    Deliverable 2.C. SLCGP Planning Committee Presentations. Contractor shall develop presentations for the SLCGP Planning Committee every other week .

    Deliverable 2.D. SLCGP Advisory Committee Presentations.
    Contractor shall develop and prepare presentations for the SLCGP Advisory Committee, monthly or as needed

    Deliverable 2.E. SLCGP Planning Committee Monthly Status Reports.

    Contractor shall prepare Monthly Status Reports for the SLCGP Planning Committee Chair, who is the State Chief Information Security Officer.


    Deliverable 2.F. Cybersecurity Plan Update. Contractor shall develop a plan that describes how the SLCGP Cybersecurity Plan will be updated quarterly and the delivery method for accessing or distributing the updated Cybersecurity Plan.

    Deliverable 2.G. SLCGP Cybersecurity Services Library. Contractor shall update and maintain a library of stakeholder adoption of services or programs within the State repository identified by CSS. Contractor shall create a Library of stakeholder recommended services to be adopted provided by CISA, MS-ISAC, and the State of Oregon. Contractor shall develop a plan to update catalog of cybersecurity services that can be consumed by participant local jurisdictions and state entities that includes description of the service and rationale of why it is a priority for Oregon.


    Task 3:
    Document Current Security Use Cases

    Contractor shall assist with the development of use cases for the purposes of defining specific scenarios or situations where the grant program can be used to address cybersecurity risks and improve the security posture of eligible State local governments, rural areas, and special districts.

    Use cases help to identify the types of projects and initiatives that can be funded through the grant program and provide a framework for evaluating proposals and awarding grants.


    Services under this Task include at least:

    Participate in discussions, facilitated by Authorized Purchaser, or as otherwise authorized, with entities for which use cases are being documented by the Contractor.

    Coordinate the review and completion of Nationwide Cybersecurity Review (NCSR) questionnaires.

    Serve as the point of contact for local governments, rural areas, and special districts on the NCSR Use Case documentation process.

    Ensure responses to questions and program information provided to states, local governments, rural areas, and special districts is consistent and authorized by Authorized Purchaser.

    Analyze identified use cases and funding and determine the processes and procedures for the SLCGP Program to award grants to local governments, rural areas, and special districts.



    Task 3 Deliverables

    Deliverable 3.A. Use Case Analysis.

    Contractor shall deliver a plan and findings summary for identifying and analyzing the following use cases provided by the SLCGP Program as well as any other use cases identified:

    Cybersecurity assessments and risk management.
    Cybersecurity training and awareness.
    Incident response and recovery.
    Upgrading and securing critical infrastructure.
    Enhancing information sharing and collaboration.
    Enhancing identity and access management.


    Deliverable 3.B. Grant Proposals Evaluation Framework. Contractor shall develop a framework for evaluating proposals and for the SLCGP Program to award grants to local governments, rural areas, and special districts

    Task 4:
    Document SLCGP Operations.

    Contractor shall collect and analyze data from the Oregon SLCGP Planning Committee and SLCGP community engagement events and document SLCGP operations for all levels of Oregon government (e.g., State, local governments, rural areas, and special districts).

    Documentation must reflect the NCSR template for this work. Contractor shall complete at least the following as part of this Task

    Document "as is" processes of the standardized approach of the NCSR process across State local governments, rural areas, and special districts, with narratives that are satisfactory to the Authorized Purchaser.

    Identify gaps between current Security use cases, NCSR template activities (Accepted Task 3 Deliverables), and identified future state.
    Provide Implementation and Maintenance & Operations Plans that detail the execution from Current State to Future State.
    Update Accepted Deliverables during the course of performance as requested by Authorized Purchaser.


    Task 4 Deliverables


    Deliverable 4.

    A:
    SLCGP Current State.

    Contractor shall document and deliver the SLCGP Project's current capabilities of utilizing, at least, the following NCSR tools and processes:

    Self-Assessment Questionnaire (SAQ) - The SAQ is a set of questions designed to evaluate the cybersecurity posture of states, local governments, rural areas, and special districts.

    The NCSR template includes a standardized set of questions that must be answered by states, local governments, rural areas, and special districts, covering topics such as governance, risk management, access control, and incident response.

    Security Control Assessment (SCA) - The SCA is a comprehensive evaluation of the cybersecurity controls and practices of the states, local governments, rural areas, and special districts.

    The NCSR template includes guidance and requirements for conducting an SCA, including the scope, methodology, and reporting requirements.

    Tabletop Exercise (TTX) - The TTX is a simulated cybersecurity incident designed to test the incident response and coordination capabilities of the states, local governments, rural areas, and special districts.

    The NCSR template includes guidance and requirements for conducting a TTX, including the scenario, objectives, and reporting requirements.

    Improvement Plan - Based on the results of the SAQ, SCA, and TTX, the states, local governments, rural areas, and special districts must develop and submit an improvement plan that outlines the steps they will take to address identified cybersecurity risks and gaps.


    Deliverable 4

    B:
    GAP Analysis. Contractor shall develop and deliver a GAP Analysis that identifies gaps between the Current State and identified Future State.


    Deliverable 4

    C:
    SLCGP Future State.

    Contractor shall develop and deliver the following plans for the SLCGP Project based off of the Current State and GAP Analysis deliverables:

    SLCGP Implementation Plan.
    SLCGP Maintenance & Operations Plan.
    Implement multi-factor authentication.
    Implement enhanced logging.
    Data encryption for data at rest and in transit.
    End use of unsupported/end of life software and hardware that are accessible from the Internet.
    Prohibit use of known/fixed/default passwords and credentials.
    Ensure the ability to reconstitute systems (backups).
    Migration to the .gov internet domain.


    Task 5:
    SLCGP Cybersecurity Plan. Contractor shall assist, in coordination with the EIS SLCGP Team, maintaining the Oregon Cybersecurity Plan. This plan has been submitted to CISA/FEMA by Authorized Purchaser for review and is anticipated to be completed by September 30, 2023.


    Task 5 Deliverables

    Deliverable 5.A. Program Objectives. Contractor shall, based on the federally-approved Cybersecurity Plan, deliver clearly defined and documented objectives for the cybersecurity grant program, outlining the overarching goals and outcomes to be achieved through the program.

    Deliverable 5.B. Program Scope and Eligibility. Contractor shall, based on the federally-approved Oregon Cybersecurity Plan, deliver detailed documentation of the scope and coverage of the grant program, including the types of cybersecurity projects or initiatives that are eligible for funding, and the criteria and requirements for local government entities to qualify for a grant.

    Deliverable 5.C. Resource Allocation Plan. Contractor shall develop and deliver documentation of the process for resource allocation of State and local government information systems and networks.

    Deliverable 5.D. Risk Assessment and Mitigation Plan. Contractor shall develop and deliver documentation of the process for conducting risk assessments of state and local government information systems and networks, identifying potential vulnerabilities, threats, and risks, and outlining the strategies and actions for mitigating these risks.

    Deliverable 5.E. Governance and Policy Documentation. Contractor shall develop governance structures and processes for overseeing the grant program, including roles and responsibilities of program managers, stakeholders, and participants, and documentation of policies, procedures, guidelines, and best practices for managing cybersecurity initiatives at the state and local government levels.

    Deliverable 5.F. Capacity Building and Training Plan. Contractor shall develop documentation of strategies and actions for building the cybersecurity capacity and capabilities of state and local government personnel, such as providing training on cybersecurity best practices, organizing awareness campaigns, and supporting professional development initiatives.

    Deliverable 5.G. Incident Response and Recovery Plan. Contractor shall develop detailed documentation of the plans and procedures for detecting, responding to, and recovering from cybersecurity incidents, including the roles and responsibilities of state and local government entities, law enforcement agencies, and other stakeholders, and outlining the coordination mechanisms and communication protocols for incident response efforts.

    Deliverable 5.H. Information Sharing and Collaboration Plan. Contractor shall develop documentation of strategies and actions for facilitating information sharing and collaboration among state and local government entities, and fostering partnerships with relevant stakeholders, such as federal agencies, industry associations, and cybersecurity experts, to leverage collective expertise and resources in addressing cybersecurity challenges.

    Deliverable 5.I. Compliance and Reporting Plan. Contractor shall develop documentation of the processes for monitoring and ensuring compliance with relevant laws, regulations, and industry standards related to cybersecurity, and defining the reporting requirements for state and local government entities to provide regular updates on their cybersecurity performance and progress.

    Deliverable 5.J. Evaluation and Continuous Improvement Plan. Contractor shall develop documentation of the process for conducting regular evaluations of the effectiveness of the grant program and its cybersecurity initiatives, and using feedback and lessons learned to continuously improve cybersecurity practices and outcomes.

    Deliverable 5.K. Program Timeline and Milestones. Contractor shall develop a timeline of the grant program, including key milestones, deadlines, and deliverables, to ensure timely and effective implementation of cybersecurity initiatives.

    Deliverable 5.L. Budget and Resources Documentation. Contractor shall develop documentation of the budget and resources allocated to the grant program, including funding sources, funding levels, and resource requirements for implementing cybersecurity initiatives.

    Deliverable 5.M. SLCGP Cybersecurity Plan. Contractor shall develop Documentation of a strategic roadmap for managing cybersecurity risks at the state and local government levels, providing a coordinated and systematic approach to enhance cybersecurity capabilities, protect critical information assets, and safeguard the public interest. It will be regularly reviewed, updated, and aligned with the evolving cybersecurity landscape and requirements of state and local governments.


  • State of Oregon Salem, United States

    Job Description: · LOCATION: Salem, OR · In-state remote work is available for this position with supervisor approval. · See definition and requirements of remote work for the Oregon Secretary of State's Office: · SALARY: · Information Systems Specialist 8 (C1488) · $7,478 - $1 ...


  • Taleo Be Salem, United States

    Typical pay range: $ $66.85 per hour ($101,129-$139,048 annually). · The role is eligible to work remotely in a State approved by St. Charles (please see list). · This full-time exempt position comes with a comprehensive benefits plan that includes medical, dental, vision, a 403 ...


  • Zurich Insurance Group Salem, United States

    ** IT Service Delivery Consultant** · 79981 · **Job Summary** · Utilizes technical and operational expertise to support and provide recommendations to deliver effective IT services that will meet the day to day needs of the business. · **Job Qualifications** · Required: · Bachel ...

  • DMI

    Business Analyst

    11 hours ago


    DMI Salem, United States

    About DMI · DMI is a leading global provider of digital services working at the intersection of public and private sectors. With broad capabilities across IT managed services, cybersecurity, cloud migration and application development, DMI provides on-site and remote support to c ...

  • DMI (Digital Management, Inc.)

    Business Analyst

    11 hours ago


    DMI (Digital Management, Inc.) Salem, United States

    · Business Analyst · Job ID · Category · Architect · Location · US-OR-Salem · About DMI · DMI is a leading global provider of digital services working at the intersection of public and private sectors. With broad capabilities across IT managed services, cybersecurity, cloud mi ...


  • SailPoint Technologies Salem, United States

    As the · leader in Identity Security · , · SailPoint is the leader in identity security for the modern enterprise. Harnessing the power of AI and machine learning, delivering the central control point for risk management for the enterprise. SailPoint continues to grow globally ...


  • State of Oregon Salem, United States

    Initial Posting Date: · 05/08/2024 · Application Deadline: · 05/22/2024 · Agency: · Oregon Health Authority · Salary Range: · $7,149 - $10,826 · Position Type: · Employee · Position Title: · Senior End Point Security Analyst (Information Systems Specialist 8) · Job Descript ...


  • SMS Data Products Group, Inc. Ballston, United States

    Overview: · As a dynamic systems integrator, SMS offers proven solutions in engineering, operations, cybersecurity, and digital transformation. With expertise in modernizing and optimizing legacy infrastructure and systems, ensuring operational efficiency, and designing, implemen ...


  • Baker Charter Schools Salem, United States

    Technology Director · For full consideration please apply via this link: · Position Purpose · The Technology Director plays a critical role in driving the success and sustainability of our statewide asynchronous virtual school in Oregon. We are seeking a dynamic leader who is ...


  • Trellix Salem, United States

    Job Title: · Senior Customer Success Manager · Role Overview: · The Senior Customer Success Manager is responsible for driving customer loyalty, adoption, and implementation of Trellix Solutions. This dynamic and customer centric individual must be comfortable consulting with lar ...


  • Ryder Salem, United States

    _Job Seekers can review the Job Applicant Privacy Policy by clicking HERE. )_ · Summary · The identity and access management (IAM) engineer position is a practitioner role working under the leadership of Information Security management. The IAM engineer helps define, establish, ...


  • Trellix Salem, United States

    Trellix · Senior Customer Success Manager · Salem , · Oregon · Apply Now · The Senior Customer Success Manager is responsible for driving customer loyalty, adoption, and implementation of Trellix Solutions. This dynamic and customer centric individual must be comfortable con ...


  • Mimecast Salem, United States

    We are seeking a skilled and experienced Mimecast Professional Services Consultant to join our team. In this role, your primary responsibilities will include presenting, and implementing Mimecast's Professional Services offerings for our customers. As a PS Consultant, you will be ...


  • Arctic Wolf Networks Salem, United States

    Ready to further your career in the fast-paced, exciting world of cyber security? · Arctic Wolf, with its unicorn valuation, is the leader in security operations in an exciting and fast-growing industry-cybersecurity. We have won countless awards for our excellence in security o ...


  • Cardinal Health Salem, United States

    Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a global, integrated healthcare services and products company connecting patients, providers, payers, pharmacists and manufacturers for integrated care coordination and better patient management. Backed by nearly ...


  • Proofpoint Oregon, United States Full time

    It's fun to work in a company where people truly BELIEVE in what they're doing · We're committed to bringing passion and customer focus to the business. · Corporate Overview · In today's cyber threat landscape, protection starts with people. At Proofpoint, that simple truth fuel ...


  • BECU Salem, United States

    As the nation's largest community credit union, we begin every day focused on delivering superior financial products and services for our 1.3 million members and more than $30 billion in managed assets. Our work has an economic impact as we support our members' financial goals. W ...


  • Proofpoint Salem, United States

    It's fun to work in a company where people truly BELIEVE in what they're doing · We're committed to bringing passion and customer focus to the business. · Corporate Overview · In today's cyber threat landscape, protection starts with people. At Proofpoint, that simple truth fuels ...


  • H2 Performance Consulting Salem, United States

    Job Description · Job Description · H2 Performance Consulting is subject to the Vietnam Era Veteran's Readjustment Assistance Act as a Federal Contractor and is an Equal · Opportunity/Affirmative · Action Employer and strives to build a diverse workforce. All qualified applic ...


  • Bishop Fox Salem, United States

    Bishop Fox is the leading authority in offensive security, providing solutions ranging from continuous penetration testing, red teaming, and attack surface management to product, cloud, and application security assessments. We've worked with more than a quarter of the Fortune 100 ...