IT Professional III Information Systems Security ...
The National Renewable Energy Laboratory (NREL) - Golden, CO
Apply NowJob Description
Posting Title IT Professional III Information Systems Security Officer Location CO - Golden Position Type Regular Hours Per Week 40 Working at NLR NLR is located at the foothills of the Rocky Mountains in Golden, Colorado is the nation's primary laboratory for energy systems research and development. Join the National Laboratory of the Rockies (NLR), where world-class scientists, engineers, and experts are accelerating energy innovation through breakthrough research and systems integration. From our mission to our collaborative culture, NLR stands out in the research community for its commitment to an affordable and secure energy future. Spanning foundational science to applied systems engineering and analysis, we focus on solving complex challenges to deliver advanced, secure, reliable, and cost-effective energy solutions. Our work helps strengthen U.S. industries, support job creation, and promote national economic growth. At NLR, you'll find a mission-driven environment supported by state-of-the-art facilities, multidisciplinary research teams, and strong collaborations with industry, academia, and other national laboratories. We offer robust professional development opportunities, and a competitive benefits package designed to support your career and well-being. Job Description Perform security and privacy risk and impact analysis for system additions (ex. new hardware, software, or services), significant changes to systems, and network- and system-level requests for control changes and exceptions. Support cybersecurity policy and procedure development, risk awareness, and control implementation training initiatives by creating and delivering online and in-person content. Support continuous assessment and monitoring of NLR's security and privacy posture by observing and reporting trends in risks assessed or observed among NLR'S information systems. Provide NLR colleagues with technical direction and coaching to remedy security and privacy control weaknesses. Analyze, prioritize, and report on the results of control weakness remediation. Champion cybersecurity and privacy best practices to technical and non-technical audiences. Participate in projects that improve the effectiveness and efficiency of NLR's cybersecurity program, including but not limited to workflow improvements, management tool enhancements, program or NLR strategic initiatives, and user awareness training. Basic Qualifications Relevant Bachelor's Degree and 5 or more years of experience or equivalent relevant education/experience. Or, relevant Master's Degree and 3 or more years of experience or equivalent relevant education/experience. Or, relevant PhD or equivalent relevant education/experience. Complete understanding and wide application of principles, concepts and techniques in specific field. General knowledge of related IS disciplines. Strong leadership and project management skills. Skilled in analytical techniques, practices and problem solving. Advanced programming, design and analysis abilities with various computer software programs and information systems. Must meet educational requirements prior to employment start date. Additional Required Qualifications At least 5 years of experience working specifically in a risk assessment, auditing, and/or security planning and control implementation role. Subject matter expertise in one or a combination of the following areas: the system development and engineering lifecycle; network security principles including an understanding of firewalls and security segmentation; endpoint and application security principles including understanding of access controls, vulnerability management; encryption best practices; and cloud and vendor security management principles. One or more professional security certifications, such as GIAC (SANS) certifications, CRISC, CISA, CISSP, Security+. Awareness of or training in FAIR Analysis fundamentals. Interest or experience in improving processes through procedural analysis and/or automation. Familiarity with federal information security frameworks including but not limited to NIST frameworks and FISMA requirements. Awareness of legal and ethical issues related to cybersecurity including but not limited to privacy and regulatory or legal compliance requirements. Comfortable in a fast-paced, and rapidly changing environment. Experience with operational planning. Preferred Qualifications • Ability to perform research, read documentation, and independently learn new skills. • Ability to work both alone and as part of a collaborative team. • Demonstrated skills in critical thinking and problem solving. • Excellent communication skills, including active listening, ability to prepare and deliver presentations, and clear written correspondence and documentation. • Completed SkillBridge or other internship program with DOE Laboratory Experience. • Master Degree. Candidates who possess or can obtain and maintain a DOE (L or Q) security clearance and SCI access are preferred. SCI access may require a polygraph examination. NOTE: To obtain a clearance, an individual must be at least 18 years of age; U.S. citizenship is required except in very limited circumstances. See DOE Order 472.2 for additional information. Job Application Submission Window The anticipated closing window for application submission is up to 30 days and may be extended as needed. Annual Salary Range (based on full-time 40 hours per week) Job Profile: IT Professional III / Annual Salary Range: $83,600 - $150,500 NLR takes into consideration a candidate's education, training, and experience, expected quality and quantity of work, required travel (if any), external market and internal value, including seniority and merit systems, and internal pay alignment when determining the salary level for potential new employees. In compliance with the Colorado Equal Pay for Equal Work Act, a potential new employee's salary history will not be used in compensation decisions. Benefits Summary Benefits include medical, dental, and vision insurance; short- and long-term disability insurance; pension benefits; 403(b) Employee Savings Plan with employer match; life and accidental death and dismemberment (AD&D) insurance; personal time off (PTO) and sick leave; paid holidays; and tuition reimbursement. NLR employees may be eligible for, but are not guaranteed, performance-, merit-, and achievement- based awards that include a monetary component. Some positions may be eligible for relocation expense reimbursement. Limited-term positions are not eligible for long-term disability or tuition reimbursement. Based on eligibility rules Badging Requirement NLR is subject to Department of Energy (DOE) access restrictions. All employees must also be able to obtain and maintain a federal Personal Identity Verification (PIV) card as required by Homeland Security Presidential Directive 12 (HSPD-12), which includes a favorable background investigation. Drug Free Workplace NLR is committed to maintaining a drug-free workplace in accordance with the federal Drug-Free Workplace Act and complies with federal laws prohibiting the possession and use of illegal drugs. Under federal law, marijuana remains an illegal drug. If you are offered employment at NLR, you must pass a pre-employment drug test prior to commencing employment. Unless prohibited by state or local law, the pre-employment drug test will include marijuana. If you test positive on the pre-employment drug test, your offer of employment may be withdrawn. Submission Guidelines Please note that in order to be considered an applicant for any position at NLR you must submit an application form for each position for which you believe you are qualified. Applications are not kept on file for future positions. Please include a cover letter and resume with each position application. Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard basis of age (40 and over), color, disability, gender identity, genetic information, marital status, domestic partner status, military or veteran status, national origin/ancestry, race, religion, creed, sex (including pregnancy, childbirth, breastfeeding), sexual orientation, and any other applicable status protected by federal, state, or local laws. Reasonable Accommodations E-Verify For information about right to work, click here for English or here for Spanish. E-Verify is a registered trademark of the U.S. Department of Homeland Security. This business uses E-Verify in its hiring practices to achieve a lawful workforce.
Created: 2026-03-12