Demo

Security Policy and Compliance Lead

Innosoft Corporation
Washington, DC Full Time
POSTED ON 9/24/2025
AVAILABLE BEFORE 11/23/2025

SECURITY POLICY AND COMPLIANCE LEAD

Project

SBA Enterprise Cybersecurity Services

Client

U.S. Small Business Administration (SBA)

Agency

SBA Office of the Chief Information Officer

Location

Washington DC 20416

Contract Duration

FTE Position

Interview Type

Virtual

Tentative Start Date

October 15 2025

Project Overview

The U.S. Small Business Administration (SBA) provides critical value-added services to the small business community. To protect mission-critical systems, applications, and sensitive data, the SBA Office of the Chief Information Officer (OCIO) Information Security Division (ISD) is strengthening its enterprise cybersecurity posture. The SBA IT ecosystem is centered on a 20,000-node MPLS infrastructure, two primary data centers, seventy regional field offices, and a mix of on-premises and cloud-hosted environments, including Microsoft O365/M365/D365, Amazon Web Services (AWS), Salesforce, and over forty SaaS products.

The ISD seeks innovative and adaptable cybersecurity professionals with expertise in cybersecurity policy and compliance, risk management, continuous monitoring, and governance frameworks. The Security Policy and Compliance Lead will be instrumental in ensuring compliance with NIST standards, FISMA, and SBA-specific information assurance requirements across the enterprise

Duties/Responsibilities

The Security Policy and Compliance Lead will:

  • Develop, review, and maintain required Authorization & Accreditation (A&A) documentation, including System Security Plans (SSP), Contingency Plans (CP), Security Assessment Reports (SAR), and associated deliverables.
  • Oversee and manage Plans of Action and Milestones (POA&Ms) to track, remediate, and close identified security risks and weaknesses.
  • Lead all continuous monitoring functions, ensuring security controls are tested, validated, and reported per SBA and federal standards.
  • Conduct risk assessments leveraging NIST Risk Management Framework (RMF) to identify, assess, and mitigate cybersecurity and information assurance risks.
  • Support SBA in the implementation of NIST SP 800-53A security controls across enterprise systems and verify compliance for FISMA reporting.
  • Correlate and analyze information from data structures, data mining, and business intelligence tools to produce risk dashboards, compliance visualizations, and executive-level reporting.
  • Collaborate with SBA stakeholders, including the Chief Information Security Officer (CISO), ISSOs, and privacy/compliance staff, to integrate cybersecurity into system lifecycle activities


RequirementsEducation

Required: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or closely related discipline.

Preferred: Master’s degree in a related field with specialization in cybersecurity, risk management, or information assurance

Required Experience
  • At least 8 years of Information Technology experience and minimum 5 years of direct experience developing and maintaining A&A documentation (SSP, CP, SAR) and managing POA&Ms.
  • Demonstrated ability to perform continuous monitoring and compliance reporting within the last three years.
  • Strong experience applying risk management frameworks (NIST RMF, SP 800-37) to federal systems.
  • At least 5 years implementing NIST 800-53A security controls for federal agencies.
  • At least 1 year of experience in data structures, data mining, business intelligence, including correlating data from multiple disparate sources to develop compliance dashboards and reports.
  • CISSP Certification required.


Benefits
Standard Employee Benefits.

50% Health Insurance Paid by Innosoft, Paid Vacation, 401K Match, STD LTD and AD&D paid by Innosoft. See attached Innosoft Benefits Guide.


If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security Policy and Compliance Lead?

Sign up to receive alerts about other jobs on the Security Policy and Compliance Lead career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$123,246 - $161,441
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Innosoft Corporation

Innosoft Corporation
Hired Organization Address Annapolis, MD Full Time
Job Details SENIOR COMPUTER PROGRAMMER Project Help Desk, Application and System Support Client State of Maryland Agency...
Innosoft Corporation
Hired Organization Address Annapolis, MD Full Time
Job Details SENIOR NETWORK ENGINEER Project Help Desk, Application and System Support Client State of Maryland Agency Re...
Innosoft Corporation
Hired Organization Address Annapolis, MD Full Time
Job Details HELP DESK SPECIALIST Project Help Desk, Application and System Support Client State of Maryland Agency Regis...

Not the job you're looking for? Here are some other Security Policy and Compliance Lead jobs in the Washington, DC area that may be a better fit.

Security Policy and Compliance Lead

etelligentgroup, Washington, DC

Security Policy and Compliance Lead

eTelligent Group, Washington, DC

AI Assistant is available now!

Feel free to start your new journey!