Cyber Policy Analyst / Technical Writer

Hirebridge LLC

Washington (District of Columbia)

On-site

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Hirebridge LLC in Washington, DC is seeking a Cyber Policy Analyst / Technical Writer to own the cybersecurity policy program for a federal civilian agency. You will write, review and manage security, privacy and records-management policies and procedures, and advise on policy questions.

The role spans FISMA systems from cloud platforms to OT environments. On-site work is required in core hours 8:00 AM–4:00 PM.

Qualifications

  • Bachelor’s degree in computer science or IT-related field.
  • 10+ years writing, reviewing, researching and editing security and technical documents and presentations.
  • 10+ years of related information security experience.
  • CISSP or an equivalent certification (CISM, CISA or CGRC accepted).
  • Hands-on information security policy development under FISMA and NIST SP 800 series.
  • Working knowledge of RMF, POA&M management and security assessments or audits.
  • U.S. citizen, able to pass a High Risk background investigation.
  • Able to work on site in Washington, DC during core hours, 8:00 AM-4:00 PM.

Responsibilities

  • Develop, review and manage security documents to high quality standards.
  • Advise the cybersecurity program on policy matters.
  • Maintain cybersecurity, privacy and records-management policies, SOPs and related documents.
  • Review policies annually against government guidance and update as needed.
  • Identify gaps and implement approved fixes.
  • Write new policy and documentation for new requirements (EOs, NIST updates, agency directives).
  • Build a cybersecurity core services catalog.
  • Maintain the customer’s security control catalog and parameters.
  • Create a version-controlled cybersecurity document repository.
  • Conduct an annual gap analysis and report on maturity.
  • Translate RMF, POA&M, and incident response processes into clear policy.
  • Prepare briefings on policy changes for the CISO and system owners.

Skills

Policy writing
Technical writing
Information security
Federal policy knowledge

Education

Bachelor’s degree in computer science or IT-related field

Tools

ServiceNow GRC/IRM
RMF tooling

Job description

Cyber Policy Analyst / Technical Writer
Location: On site, Washington, DC

About the Role

You will own the cybersecurity policy program for a federal civilian agency. You will write, review and manage security, privacy and records-management policies and procedures. You will also be the program’s advisor on policy questions. The customer’s environment includes FISMA systems, ranging from cloud platforms to operational technology environments.

What You’ll Do

  • Develop, review and manage security documents so that they are high quality and meet customer standards.
  • Advise the cybersecurity program on policy matters.
  • Maintain cybersecurity, privacy and records-management policies, SOPs and related documents, following federal correspondence, style and branding standards.
  • Review every policy, procedure and SOP each year against government-wide and customer guidance on IT security, privacy and records management, and update them.
  • Find gaps in existing policies, procedures and guides, recommend fixes, and carry out the approved fixes.
  • Write new policy and documentation as new requirements come up, such as executive orders, OMB memos, NIST revisions and agency directives.
  • Build a cybersecurity core services catalog.
  • Review, update and maintain the customer’s security control catalog and Minimum Security Parameters.
  • Build and run a cybersecurity document repository with version control and publishing.
  • Run an annual gap analysis of the policy and governance program and report on its maturity.
  • Turn requirements from FISMA, the NIST SP 800 series, OMB A-130 and agency directives into clear, enforceable policy.
  • Work with ISSOs, assessors, privacy and audit staff so that policy matches how the RMF, continuous monitoring, POA&M and incident response processes actually run.
  • Prepare briefings and presentations on policy changes for the CISO and system owners.

Required Qualifications

  • Bachelor’s degree in computer science or an IT-related field
  • 10+ years writing, reviewing, researching and editing security and technical documents and presentations
  • 10+ years of related information security experience
  • CISSP or an equivalent certification. Equivalent means it covers a similar level of information security domains, or a similar depth of knowledge or experience. Assurit accepts CISSP, CISM, CISA or CGRC.
  • Hands-on information security policy and procedure development under FISMA and the NIST SP 800 series
  • Working knowledge of RMF, POA&M management and security assessments or audits
  • U.S. citizen, able to pass a High Risk background investigation
  • Able to work on site in Washington, DC during core hours, 8:00 AM-4:00 PM

Desired Qualifications

  • Experience writing policy for a federal civilian agency or other regulated organization
  • Has built or maintained a NIST 800-53 Rev 5 control catalog or an organization-defined parameter baseline
  • Experience with the policy and compliance modules in ServiceNow GRC/IRM
  • Has written policy covering OT, SCADA or industrial control systems
  • Plain-language writing and editing; federal correspondence style
  • Experience writing Zero Trust or cloud security policy
  • Active Tier 5 or Top Secret investigation
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Policy Architect & Technical Writer
Senior Cyber Policy Architect & Technical Writer

Assurit Consulting Group • Washington

Hybrid
USD 120,000 - 150,000
Medical coverage
Dental coverage
Paid time off
Cyber Policy Analyst / Technical Writer
Cyber Policy Analyst / Technical Writer

Assurit Consulting Group • Washington

Hybrid
USD 120,000 - 150,000
Medical coverage
Dental coverage
Paid time off
Cybersecurity Specialist
Cybersecurity Specialist

Kaizen Lab Inc. • Charlotte (NC)

On-site
USD 120,000 - 180,000
Security Governance and Policy Analyst
Security Governance and Policy Analyst

ANALYGENCE • Washington

On-site
USD 110,000 - 170,000
Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Cybersecurity Jobs • Maryland

On-site
USD 88,000 - 155,000
Medical
Dental
Vision
+5
IT - Information Security/Privacy Analyst II
IT - Information Security/Privacy Analyst II

PlanIT Group, LLC • Reston (VA)

Hybrid
USD 110,000 - 150,000
Senior Enterprise Cybersecurity Policy Writer
Senior Enterprise Cybersecurity Policy Writer

Dark Wolf • Ogden (UT)

On-site
USD 120,000 - 170,000
On-site at Hill AFB
Competitive base salary
CyberSecurity Analyst
CyberSecurity Analyst

Pitech Solutions, Inc. • Washington, Northern (KY)

On-site
USD 130,000 - 185,000
Cyber Policy Leader & Technical Writer - Onsite DC
Cyber Policy Leader & Technical Writer - Onsite DC

Hirebridge LLC • Washington

On-site
USD 120,000 - 180,000
Information Security Analyst
Information Security Analyst

CALIBRE Systems Inc • Washington

On-site
USD 80,000 - 90,000