Cybersecurity Policy & Governance Specialist

Cyber Synergy Consulting Group

Washington (District of Columbia)

Hybrid

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cyber Synergy Consulting Group is seeking a Cybersecurity Policy & Governance Specialist to support Task 5 on a federal contract. Hybrid in Washington, D.C. Metro Area. Requires 5+ years in federal cybersecurity policy, strong governance writing, and RMF/CSF knowledge.

Public Trust eligibility and 508 accessibility familiarity are required. Excellent stakeholder engagement and reporting skills are needed. The role encompasses developing, reviewing, and approving policies, procedures, and

Qualifications

  • 5+ years of experience in federal cybersecurity programs.
  • Experience developing cybersecurity policies, standards, SOPs, or governance docs.
  • Knowledge of RMF, CSF, FISMA, and OMB guidance.
  • Strong stakeholder management and follow-up skills.
  • Advanced proficiency with Microsoft 365 (Teams, SharePoint Online, Word, Excel, PowerPoint, Outlook).
  • Ability to manage schedules and milestones for documentation.
  • Excellent written and verbal communication; ability to work with government leadership.

Responsibilities

  • Author and maintain cybersecurity policies, standards, SOPs, and governance docs from draft to final approval.
  • Research federal laws, regulations, NIST guidance to develop policy recommendations.
  • Translate complex requirements into actionable guidance for technical and non-technical audiences.
  • Coordinate with SMEs, ISSOs, owners, and stakeholders to move documents through review.
  • Track reviews, escalate delays, and keep schedule on track.
  • Create and maintain project schedules and provide status updates to program leadership.
  • Support RMF, OA, HVA, and Continuous Monitoring documentation.
  • Assist with audits, assessments, and open findings.

Job description

Cybersecurity Policy & Governance Specialist (Task 5 - Policy & Governance, Federal Cybersecurity Contract)

Location: Hybrid (Washington, D.C. Metro Area)

Employment Type: Full-Time

Clearance: Public Trust (or eligibility to obtain)

We are seeking an experienced Cybersecurity Policy & Governance Specialist to support Task 5 - Policy and Governance on a federal cybersecurity services contract. This role owns the development, review, and approval of cybersecurity policies, standards, procedures, and SOPs supporting enterprise cybersecurity operations.

The ideal candidate has hands-on experience authoring federal cybersecurity policy and governance documentation, is comfortable independently researching complex regulatory requirements, and is proactive by nature, someone who tracks documents through review, follows up with stakeholders without being asked, and keeps multiple concurrent efforts moving to closure.

Key Responsibilities
  • Author, refine, and maintain cybersecurity policies, standards, procedures, SOPs, and governance documentation from initial draft through final approval.
  • Research and analyze federal cybersecurity laws, regulations, executive orders, NIST publications, and agency guidance to develop well-supported policy recommendations.
  • Translate complex technical and regulatory requirements into clear, actionable guidance for technical and non-technical audiences.
  • Proactively identify, contact, and follow up with SMEs, ISSOs, system owners, and technical stakeholders to keep documents moving through review.
  • Track outstanding reviews and inputs and escalates unresponsive stakeholders or review delays before they impact schedule.
  • Build and maintain a Gantt chart or sprint-based schedule to plan, track, and brief on documentation milestones.
  • Prepare and deliver weekly status reports and monthly KPI/metrics reporting to program leadership, with on-demand reporting as requested.
  • Support Risk Management Framework (RMF), Ongoing Authorization (OA), High Value Asset (HVA), and Continuous Monitoring documentation.
  • Support cybersecurity assessments, audits, and compliance activities, including documentation tied to open audit findings.
  • Coordinate document reviews, adjudicate stakeholder feedback, and maintain document repositories and version control.
  • Support the Policy & Governance Change Control Board (CCB), including preparation of meeting minutes and maintenance of change control logs.
Required Qualifications
  • 5+ years of experience supporting federal government cybersecurity programs.
  • Demonstrated experience developing cybersecurity policies, standards, procedures, SOPs, or governance documentation , and driving them through to final approval, not just drafting.
  • Strong knowledge of NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), FISMA, and OMB guidance.
  • Demonstrated track record of proactively managing stakeholders - following up on and escalating reviews rather than waiting for responses.
  • Advanced proficiency with Microsoft 365 (Teams, SharePoint Online, Word, Excel, PowerPoint, Outlook).
  • Ability to build and maintain a Gantt chart or sprint-based schedule to plan and track documentation milestones.
  • Exceptional written and verbal communication skills; ability to work directly with government leadership and cross-functional technical teams.
  • Eligibility to obtain and maintain a Public Trust clearance.
  • Working knowledge of Section 508 accessibility requirements as applied to policy and governance documentation.
Preferred Qualifications
  • Experience supporting federal civilian cybersecurity programs (HHS, DHS, DOJ, or similar).
  • Experience supporting Authorization to Operate (ATO) or Ongoing Authorization (OA) activities.
  • Experience supporting High Value Asset (HVA) programs or enterprise policy/governance offices.
  • Experience supporting cybersecurity audits or assessments, including closing longstanding findings.
  • Familiarity with Microsoft Lists, Power Automate, Power Apps, Planner, or Visio.
  • Certifications such as CISSP, CISM, Security+, CAP, or PMP.
Work Schedule & Expectations
  • Core hours: standard business hours, Monday through Friday, EST.
  • Hybrid schedule; onsite presence required periodically, particularly during onboarding, knowledge transfer, and key program working sessions.
  • Remote work permitted with reliable connectivity.
  • Writing samples (policies, standards, or SOPs - sanitized as needed) will be requested as part of the interview process.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Federal Cybersecurity Policy & Governance Lead
Federal Cybersecurity Policy & Governance Lead

Cyber Synergy Consulting Group • Washington

Hybrid
USD 110,000 - 140,000
Senior Cybersecurity Program Manager (No C2C)
Senior Cybersecurity Program Manager (No C2C)

Spanidea • San Jose (CA)

On-site
USD 180,000 - 240,000
Cybersecurity Governance & Policy Specialist — Level II
Cybersecurity Governance & Policy Specialist — Level II

Rividium Inc • Washington

On-site
USD 120,000 - 150,000
Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Agecareers • Columbus (OH)

On-site
USD 90,000 - 104,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5
Cybersecurity Governance & Policy Specialist - Level II
Cybersecurity Governance & Policy Specialist - Level II

Rividium • Washington

On-site
USD 120,000 - 160,000
Cybersecurity Governance & Policy Specialist Level II with Security Clearance
Cybersecurity Governance & Policy Specialist Level II with Security Clearance

Rividium Inc • Washington

On-site
USD 95,000 - 130,000
Cybersecurity Program Analyst
Cybersecurity Program Analyst

Jobtailor • Washington

On-site
USD 100,000 - 150,000
Senior Enterprise Cybersecurity Policy Writer
Senior Enterprise Cybersecurity Policy Writer

Darkwolfsolutions • Ogden (UT)

On-site
USD 120,000 - 170,000
Senior Cybersecurity Project Manager
Senior Cybersecurity Project Manager

Def-Logix, Inc. • Washington

On-site
USD 150,000 - 190,000
Cybersecurity Program Manager GRC
Cybersecurity Program Manager GRC

Saigepartners • San Jose (CA), Northern (KY)

Hybrid
USD 117,000 - 131,000