Cybersecurity Governance & Policy Specialist ? Level II

Rividium

Washington (District of Columbia)

On-site

USD 90,000 - 130,000

Full time

15 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

RiVidium Inc. in Washington, DC, seeks a Cybersecurity Governance & Policy Specialist – Level II to develop and maintain cybersecurity policies, standards, and governance in a federal environment.

The role requires translating regulations into actionable guidance and collaborating with cybersecurity, compliance, risk, IT, and program teams. The ideal candidate has strong governance and compliance knowledge, excellent technical writing, and the ability to communicate complex requirements to

Qualifications

  • Bachelor’s degree in cybersecurity, information systems, information technology, computer science, political science, or a related field.
  • Experience in cybersecurity governance, policy, compliance, information assurance, or risk management.
  • Knowledge of cybersecurity policies, standards, frameworks, and regulatory requirements.

Responsibilities

  • Develop, review, update, and maintain cybersecurity policies, standards, procedures, guidelines, and governance documentation.
  • Analyze federal cybersecurity requirements and determine their impact on organizational policies and security practices.
  • Translate cybersecurity regulations, standards, and frameworks into actionable organizational requirements.
  • Support the implementation and enforcement of cybersecurity governance processes.
  • Conduct policy and compliance reviews to identify gaps, inconsistencies, and areas requiring improvement.
  • Assist with developing cybersecurity governance frameworks and operating procedures.
  • Support RMF, security authorization, continuous monitoring, and compliance activities.
  • Prepare executive briefings, presentations, reports, and governance materials.

Skills

Cybersecurity Governance
Policy Development
GRC
Regulatory Compliance
RMF
NIST SP 800-53
NIST SP 800-37
FISMA
Risk Management
Policy Writing
Security Audits
Technical Writing
Stakeholder Communication
A&A
Security Controls
RMF A&A
Security Metrics
RSA Archer
ServiceNow GRC
eMASS

Education

Bachelor's degree in Cybersecurity / Information Systems / IT / CS / Political Science

Tools

RSA Archer
ServiceNow GRC
eMASS

Job description

Cybersecurity Governance & Policy Specialist � Level II

Full-Time/Part-Time Full-Time

Description

RiVidium Inc. is seeking an experienced Cybersecurity Governance & Policy Specialist - Level II to support the development, implementation, and maintenance of cybersecurity policies, standards, procedures, and governance processes within a federal environment.

The Cybersecurity Governance & Policy Specialist will help ensure cybersecurity practices align with federal requirements, organizational policies, industry standards, and risk management objectives. This role will work closely with cybersecurity, compliance, risk management, IT, and program teams to translate regulatory and security requirements into practical policies and procedures.

The ideal candidate will have a strong understanding of cybersecurity governance and compliance, excellent technical writing skills, and the ability to interpret complex security requirements and communicate them clearly to technical and non-technical stakeholders.

Key Responsibilities
  • Develop, review, update, and maintain cybersecurity policies, standards, procedures, guidelines, and governance documentation.
  • Analyze federal cybersecurity requirements and determine their impact on organizational policies and security practices.
  • Translate cybersecurity regulations, standards, and frameworks into actionable organizational requirements.
  • Support the implementation and enforcement of cybersecurity governance processes.
  • Conduct policy and compliance reviews to identify gaps, inconsistencies, and areas requiring improvement.
  • Assist with developing cybersecurity governance frameworks and operating procedures.
  • Support the alignment of cybersecurity policies with NIST, FISMA, and other applicable federal requirements.
  • Research emerging cybersecurity threats, regulations, standards, and industry best practices.
  • Perform gap assessments against applicable cybersecurity policies, standards, and regulatory requirements.
  • Develop recommendations for addressing identified policy, governance, and compliance gaps.
  • Collaborate with cybersecurity engineers, ISSOs, ISSMs, system owners, security assessors, and program leadership.
  • Support Risk Management Framework (RMF), security authorization, continuous monitoring, and compliance activities.
  • Assist with the development and maintenance of cybersecurity governance metrics and reporting.
  • Support cybersecurity risk management and compliance assessments.
  • Review security documentation for consistency with established policies and requirements.
  • Assist with policy exception, waiver, and risk acceptance processes.
  • Support internal and external cybersecurity audits, assessments, and inspections.
  • Prepare executive briefings, presentations, reports, and other governance materials.
  • Maintain documentation repositories and ensure cybersecurity policies remain current and properly version controlled.
  • Provide guidance to stakeholders on cybersecurity policy interpretation and implementation.
  • Participate in cybersecurity working groups, governance boards, and customer meetings.
  • Support continuous improvement of cybersecurity governance processes and organizational security posture.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Computer Science, Political Science, or a related field.
  • Demonstrated experience in cybersecurity governance, policy, compliance, information assurance, risk management, or a related discipline.
  • Working knowledge of cybersecurity policies, standards, frameworks, and regulatory requirements.
  • Experience developing, reviewing, or implementing cybersecurity policies and procedures.
  • Ability to interpret complex cybersecurity requirements and translate them into practical organizational guidance.
  • Knowledge of cybersecurity risk management and compliance principles.
  • Familiarity with the NIST Risk Management Framework (RMF).
  • Understanding of federal cybersecurity requirements and information security best practices.
  • Strong technical writing, editing, research, and documentation skills.
  • Strong analytical and problem-solving abilities.
  • Excellent verbal and written communication skills.
  • Ability to work effectively with technical teams, management, and government stakeholders.
Preferred Certification
  • CompTIA Security+

Additional cybersecurity, governance, risk, or compliance certifications are desirable.

Preferred Qualifications
  • Experience supporting federal civilian or Department of Defense (DoD) cybersecurity programs.
  • Knowledge of NIST SP 800-53, NIST SP 800-37, and FISMA.
  • Experience developing policies aligned with federal cybersecurity requirements.
  • Experience with RMF, Assessment & Authorization (A&A), and security control requirements.
  • Familiarity with cybersecurity governance frameworks and industry standards.
  • Experience conducting cybersecurity policy and compliance gap assessments.
  • Experience supporting cybersecurity audits and regulatory assessments.
  • Familiarity with GRC platforms such as RSA Archer, ServiceNow GRC, or eMASS.
  • Experience with cybersecurity risk assessments and risk acceptance processes.
  • Knowledge of cloud security governance and compliance.
  • Experience developing cybersecurity awareness, policy, and training materials.
  • Familiarity with security control implementation and assessment processes.
  • Certifications such as CISM, CISSP, CAP, CRISC, or CGRC are a plus.
Technical Skills
  • Cybersecurity Governance
  • Cybersecurity Policy Development
  • Security Standards and Procedures
  • Governance, Risk & Compliance (GRC)
  • Cybersecurity Risk Management
  • Regulatory Compliance
  • NIST Frameworks
  • NIST SP 800-53
  • NIST SP 800-37
  • FISMA
  • Risk Management Framework (RMF)
  • Assessment & Authorization (A&A)
  • Security Controls
  • Continuous Monitoring
  • Compliance Assessments
  • Gap Analysis
  • Risk Assessments
  • Policy Exception Management
  • Risk Acceptance
  • Security Documentation
  • Technical Writing
  • Cybersecurity Metrics and Reporting
  • RSA Archer
  • ServiceNow GRC
  • eMASS

RiVidium Inc is seeking a 'Cybersecurity Governance & Policy Specialist - Level II' to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify qualified candidates for a potential future opportunity and does not represent a currently available position. Compensation has not yet been determined and will be established based on contract requirements, candidate qualifications, experience, and applicable market conditions.

About the Organization

Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology.

EOE Statement

We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at hr@rividium.com.

This position is currently accepting applications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Governance & Policy Specialist — Level II
Cybersecurity Governance & Policy Specialist — Level II

Rividium Inc • Washington

On-site
USD 120,000 - 150,000
Senior Cybersecurity Governance & Policy Specialist — Level III
Senior Cybersecurity Governance & Policy Specialist — Level III

Rividium Inc • Washington

On-site
USD 180,000 - 240,000
Cybersecurity Program Manager ? Level III
Cybersecurity Program Manager ? Level III

Rividium • Washington

On-site
USD 140,000 - 200,000
IT Security Operations Specialist
IT Security Operations Specialist

Rividium • Washington

On-site
USD 100,000 - 150,000
Information Systems Security Manager - Intermediate
Information Systems Security Manager - Intermediate

Rividium Inc • Springfield (VA)

On-site
USD 140,000 - 220,000
Cybersecurity Policy & Governance Specialist II
Cybersecurity Policy & Governance Specialist II

Rividium Inc • Washington

On-site
USD 120,000 - 150,000
Cybersecurity Policy & Governance Specialist II
Cybersecurity Policy & Governance Specialist II

Rividium • Washington

On-site
USD 90,000 - 130,000
Security Control Assessor - Intermediate
Security Control Assessor - Intermediate

Rividium • Springfield (VA)

On-site
USD 135,000 - 140,000
Security Control Assessor - Intermediate with Security Clearance
Security Control Assessor - Intermediate with Security Clearance

Rividium Inc • Springfield (VA)

On-site
USD 135,000 - 140,000
Senior Cybersecurity Engineer / (SME) — Level III
Senior Cybersecurity Engineer / (SME) — Level III

Rividium Inc • Washington

On-site
USD 150,000 - 210,000