Advisory Support & Program Analyst
Job Description
Advisory Support & Program Analyst
Reports To: Program Manager & Lead SME
Supports: Deliverables 4 and 7; research support for Deliverable 5
Certifications: CISA preferred (or actively pursuing)
Experience: 3–5 years in cybersecurity/IT audit advisory, program reporting, or QA/evaluation analysis
Allocation: Full-time; primary owner of the day-to-day support mailbox and reporting cadence
Consolidates Original Roles
On-Call Advisory SME (mailbox) + Governance, Reporting & Quality Assurance Analyst + Audit Planning & Risk Advisor (research/support functions)
Role Summary
This role is the engagement's steady, day-to-day service layer: staffing the “Ask the CIG Mailbox” within contractual SLAs, maintaining the training/SME activity repository, running course evaluations, and producing the monthly and annual reporting required under Deliverable 7 while also supporting the Program Manager with the risk research that feeds audit planning.
Key Responsibilities
- Monitor and respond to the dedicated advisory mailbox/portal, answering questions on scoping, evidence sufficiency, and control evaluation within 1 business day (Section 4.4) and general technical inquiries within 24 hours (Section 1.0(k)).
- Maintain the centralized, securely accessible repository of attendance, session objectives, materials, and outcomes for all training sessions and SME interactions.
- Administer post-session course evaluations (participant surveys, instructor assessments, learning-outcome analysis) and share results promptly with the OCIG.
- Design, administer, and compile the annual enterprise-wide needs assessment survey and produce the formal report within 30 days of completion.
- Prepare and distribute monthly written progress updates to program managers, project leads, and department heads.
- Support the Program Manager with stakeholder interviews and prior-findings research that feeds the audit planning roadmap.
- Escalate complex or precedent-setting advisory questions to the Program Manager/Lead SME or Audit Program & Training Delivery Specialist.
Required Qualifications
- Minimum 3 years of experience in cybersecurity/IT audit advisory work, program reporting, or training/program evaluation.
- Strong written communication skills and survey design/data analysis skills.
- Working familiarity with NIST CSF terminology and evidence sufficiency concepts.
Preferred Qualifications
- CISA certification (or actively pursuing).
- Experience supporting a government audit or inspector general function.
