Cyber Policy Analyst / Technical Writer

Assurit Consulting Group

Washington (District of Columbia)

Hybrid

USD 120,000 - 150,000

Full time

14 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical coverage
Dental coverage
Paid time off

Job summary

Assurit Consulting Group seeks an experienced Cyber Policy Analyst / Technical Writer to own the cybersecurity policy program for a federal civilian agency. You will write, review and manage security, privacy and records-management policies and procedures, serving as the policy advisor for the program.

You will translate requirements from FISMA, NIST SP 800 series, OMB memos and agency directives into clear, enforceable policy, while coordinating with ISSOs, auditors and privacy staff and

Qualifications

  • Bachelor's degree in computer science or an IT-related field is required.
  • 2+10 years of writing, reviewing, researching and editing security and technical documents and presentations.
  • 10+ years of related information security experience.
  • CISSP or equivalent certification (CISSP, CISM, CISA or CGRC).
  • Hands-on information security policy and procedure development under FISMA and the NIST SP 800 series.
  • Knowledge of RMF, POA&M management and security assessments or audits.
  • U.S. citizen; able to pass a High Risk background investigation.
  • On-site work in Washington, DC during core hours (8:00 AM–4:00 PM).

Responsibilities

  • Develop, review and manage security documents to meet customer standards.
  • Advise the cybersecurity program on policy matters.
  • Maintain cybersecurity, privacy and records-management policies, SOPs and related documents.
  • Review every policy, procedure and SOP annually against government guidance, updating as needed.
  • Identify policy gaps, propose fixes and implement approved changes.
  • Write policy and documentation for new requirements (e.g., EO, OMB memos, NIST revisions).
  • Build a cybersecurity core services catalog.
  • Review and maintain the customer’s security control catalog and Minimum Security Parameters.
  • Establish and run a version-controlled cybersecurity document repository.
  • Perform annual gap analyses of policy and governance maturity.
  • Translate FISMA, NIST SP 800 series, OMB A-130 guidance into clear policy.
  • Collaborate with ISSOs, assessors, privacy and audit staff to align policy with RMF and incident response processes.
  • Prepare briefings and presentations on policy changes for the CISO and system owners.

Skills

Security policy writing
Technical writing
Information security
Policy development
Editing security documents

Education

Bachelor's degree in computer science or IT-related field

Job description

Assurit is currently seeking an experienced Cyber Policy Analyst / Technical Writer to support one of our clients.
About the Role:

You will own the cybersecurity policy program for a federal civilian agency. You will write, review and manage security, privacy and records-management policies and procedures. You will also be the program’s advisor on policy questions. The customer’s environment includes FISMA systems, ranging from cloud platforms to operational technology environments.

Location: On site, Washington, DC

Key Responsibilities:
  • Develop, review and manage security documents so that they are high quality and meet customer standards.
  • Advise the cybersecurity program on policy matters.
  • Maintain cybersecurity, privacy and records-management policies, SOPs and related documents, following federal correspondence, style and branding standards.
  • Review every policy, procedure and SOP each year against government-wide and customer guidance on IT security, privacy and records management, and update them.
  • Find gaps in existing policies, procedures and guides, recommend fixes, and carry out the approved fixes.
  • Write new policy and documentation as new requirements come up, such as executive orders, OMB memos, NIST revisions and agency directives.
  • Build a cybersecurity core services catalog.
  • Review, update and maintain the customer’s security control catalog and Minimum Security Parameters.
  • Build and run a cybersecurity document repository with version control and publishing.
  • Run an annual gap analysis of the policy and governance program and report on its maturity.
  • Turn requirements from FISMA, the NIST SP 800 series, OMB A-130 and agency directives into clear, enforceable policy.
  • Work with ISSOs, assessors, privacy and audit staff so that policy matches how the RMF, continuous monitoring, POA&M and incident response processes actually run.
  • Prepare briefings and presentations on policy changes for the CISO and system owners.
Required Qualifications:
  • Bachelor’s degree in computer science or an IT-related field
  • 10+ years writing, reviewing, researching and editing security and technical documents and presentations
  • 10+ years of related information security experience
  • CISSP or an equivalent certification. Equivalent means it covers a similar level of information security domains, or a similar depth of knowledge or experience. Assurit accepts CISSP, CISM, CISA or CGRC.
  • Hands-on information security policy and procedure development under FISMA and the NIST SP 800 series
  • Working knowledge of RMF, POA&M management and security assessments or audits
  • U.S. citizen, able to pass a High Risk background investigation
  • Able to work on site in Washington, DC during core hours, 8:00 AM-4:00 PM
Preferred Qualifications:
  • Experience writing policy for a federal civilian agency or other regulated organization
  • Has built or maintained a NIST 800-53 Rev 5 control catalog or an organization-defined parameter baseline
  • Experience with the policy and compliance modules in ServiceNow GRC/IRM
  • Has written policy covering OT, SCADA or industrial control systems
  • Plain-language writing and editing; federal correspondence style
  • Experience writing Zero Trust or cloud security policy
  • Active Tier 5 or Top Secret investigation

Assurit is an award winning, certified small business headquartered in Fairfax, VA. We offer a highly competitive compensation and benefits package inclusive of medical and dental coverage, as well as paid time off.

Founded in 2013, Assurit has become a trusted provider of cybersecurity expertise to customers across federal, state and local governments, as well as the commercial sector. We are an employee-centric organization that focuses on the growth and development of our greatest asset – our people. We believe that if our Team is trained and educated, we will always be able to deliver our promise of customer success. If you enjoy work environments focused on continuous learning and growth, Assurit will be a great fit for you.

Assurit is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Capabilities Technical Program Manager
Cyber Capabilities Technical Program Manager

Assurit • Fairfax (VA)

Hybrid
USD 150,000 - 210,000
Senior Cyber Policy Architect & Technical Writer
Senior Cyber Policy Architect & Technical Writer

Assurit Consulting Group • Washington

Hybrid
USD 120,000 - 150,000
Medical coverage
Dental coverage
Paid time off
Cyber Policy Analyst / Technical Writer
Cyber Policy Analyst / Technical Writer

Hirebridge LLC • Washington

On-site
USD 120,000 - 180,000
Senior RMF Security Analyst
Senior RMF Security Analyst

AssurIT • Beltsville (MD)

On-site
USD 110,000 - 160,000
Medical coverage
Dental coverage
Paid time off
Cyber Capabilities Technical Program Manager Assurit
Cyber Capabilities Technical Program Manager Assurit

AssurIT • Linthicum (MD)

On-site
USD 120,000 - 160,000
Medical coverage
Dental coverage
Paid time off
Sr. Systems Engineer / Integrator
Sr. Systems Engineer / Integrator

Assurit • Fairfax (VA)

Hybrid
USD 130,000 - 180,000
Medical and dental coverage
Paid time off
Senior RMF Security Analyst
Senior RMF Security Analyst

Assurit • Fairfax (VA)

Hybrid
USD 110,000 - 140,000
Medical and dental coverage
Paid time off
Competitive compensation
Human Risk Manager / Cybersecurity Awareness Professional SME
Human Risk Manager / Cybersecurity Awareness Professional SME

Assurit Consulting Group • Washington

On-site
USD 110,000 - 180,000
IT Audit Remediation Analyst Assurit
IT Audit Remediation Analyst Assurit

AssurIT • Washington

On-site
USD 100,000 - 140,000
Competitive compensation and benefits
Cyber Tools Senior Test & Evaluation Engineer
Cyber Tools Senior Test & Evaluation Engineer

Assurit • Fairfax (VA)

Hybrid
USD 120,000 - 180,000