Demo

Cybersecurity Policy & Governance Specialist

Cyber Synergy
Washington, DC Full Time
POSTED ON 8/11/2026
AVAILABLE BEFORE 12/9/2026
  • Posted 06-Aug-2026 (EST)
  • Washington, DC, USA
  • Full Time
  • Medical, Dental, Vision, PTO, Holidays, 401k

Cybersecurity Policy & Governance Specialist (Task 5 – Policy & Governance, Federal Cybersecurity Contract)

Location: Hybrid (Washington, D.C. Metro Area)

Employment Type: Full-Time

Clearance: Public Trust (or eligibility to obtain)


We are seeking an experienced Cybersecurity Policy & Governance Specialist to support Task 5 – Policy and Governance on a federal cybersecurity services contract. This role owns the development, review, and approval of cybersecurity policies, standards, procedures, and SOPs supporting enterprise cybersecurity operations.


The ideal candidate has hands-on experience authoring federal cybersecurity policy and governance documentation, is comfortable independently researching complex regulatory requirements, and is proactive by nature, someone who tracks documents through review, follows up with stakeholders without being asked, and keeps multiple concurrent efforts moving to closure.


Key Responsibilities


  • Author, refine, and maintain cybersecurity policies, standards, procedures, SOPs, and governance documentation from initial draft through final approval.
  • Research and analyze federal cybersecurity laws, regulations, executive orders, NIST publications, and agency guidance to develop well-supported policy recommendations.
  • Translate complex technical and regulatory requirements into clear, actionable guidance for technical and non-technical audiences.
  • Proactively identify, contact, and follow up with SMEs, ISSOs, system owners, and technical stakeholders to keep documents moving through review.
  • Track outstanding reviews and inputs and escalate unresponsive stakeholders or review delays before they impact schedule.
  • Build and maintain a Gantt chart or sprint-based schedule to plan, track, and brief on documentation milestones.
  • Prepare and deliver weekly status reports and monthly KPI/metrics reporting to program leadership, with on-demand reporting as requested.
  • Support Risk Management Framework (RMF), Ongoing Authorization (OA), High Value Asset (HVA), and Continuous Monitoring documentation.
  • Support cybersecurity assessments, audits, and compliance activities, including documentation tied to open audit findings.
  • Coordinate document reviews, adjudicate stakeholder feedback, and maintain document repositories and version control.
  • Support the Policy & Governance Change Control Board (CCB), including preparation of meeting minutes and maintenance of change control logs.

Required Qualifications


  • 5 years of experience supporting federal government cybersecurity programs.
  • Demonstrated experience developing cybersecurity policies, standards, procedures, SOPs, or governance documentation , and driving them through to final approval, not just drafting.
  • Strong knowledge of NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), FISMA, and OMB guidance.
  • Demonstrated track record of proactively managing stakeholders - following up on and escalating reviews rather than waiting for responses.
  • Advanced proficiency with Microsoft 365 (Teams, SharePoint Online, Word, Excel, PowerPoint, Outlook).
  • Ability to build and maintain a Gantt chart or sprint-based schedule to plan and track documentation milestones.
  • Exceptional written and verbal communication skills; ability to work directly with government leadership and cross-functional technical teams.
  • Eligibility to obtain and maintain a Public Trust clearance.
  • Working knowledge of Section 508 accessibility requirements as applied to policy and governance documentation.

Preferred Qualifications


  • Experience supporting federal civilian cybersecurity programs (HHS, DHS, DOJ, or similar).
  • Experience supporting Authorization to Operate (ATO) or Ongoing Authorization (OA) activities.
  • Experience supporting High Value Asset (HVA) programs or enterprise policy/governance offices.
  • Experience supporting cybersecurity audits or assessments, including closing longstanding findings.
  • Familiarity with Microsoft Lists, Power Automate, Power Apps, Planner, or Visio.
  • Certifications such as CISSP, CISM, Security , CAP, or PMP.

Work Schedule & Expectations


  • Core hours: standard business hours, Monday through Friday, EST.
  • Hybrid schedule; onsite presence required periodically, particularly during onboarding, knowledge transfer, and key program working sessions.
  • Remote work permitted with reliable connectivity.
  • Writing samples (policies, standards, or SOPs - sanitized as needed) will be requested as part of the interview process.

Salary : $89,179 - $131,487

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cybersecurity Policy & Governance Specialist?

Sign up to receive alerts about other jobs on the Cybersecurity Policy & Governance Specialist career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Not the job you're looking for? Here are some other Cybersecurity Policy & Governance Specialist jobs in the Washington, DC area that may be a better fit.

  • Cyber Synergy Consulting Group Washington, DC
  • Job Description. Job Description. Cybersecurity Policy & Governance Specialist (Task 5 – Policy & Governance, Federal Cybersecurity Contract)Location: Hybr... more
  • 24 Days Ago

  • RIVIDIUM Quantico, VA
  • RiVidium Inc. is seeking an experienced Cybersecurity Governance & Policy Specialist ? Level II to serve the team for all Cybersecurity and Intelligence En... more
  • 1 Month Ago

AI Assistant is available now!

Feel free to start your new journey!