Cybersecurity Policy & Governance Specialist
Cyber Synergy Consulting Group · Fairfax County, Virginia, United States
IT Services and IT Consulting · 2-10 employees
About the role
The specialist will author, maintain, and manage the lifecycle of cybersecurity policies, standards, and governance documentation for federal programs. They are responsible for coordinating with stakeholders to ensure compliance, tracking milestones, and reporting on program metrics.
What they look for
Requirements
Candidates must have at least 5 years of experience in federal cybersecurity policy development and a strong understanding of NIST frameworks and FISMA. Exceptional communication skills and the ability to obtain a Public Trust clearance are required.
Full description
Cybersecurity Policy & Governance Specialist (Task 5 – Policy & Governance, Federal Cybersecurity Contract)
Location: Hybrid (Washington, D.C. Metro Area)
Employment Type: Full-Time
Clearance: Public Trust (or eligibility to obtain)
We are seeking an experienced Cybersecurity Policy & Governance Specialist to support Task 5 – Policy and Governance on a federal cybersecurity services contract. This role owns the development, review, and approval of cybersecurity policies, standards, procedures, and SOPs supporting enterprise cybersecurity operations.
The ideal candidate has hands-on experience authoring federal cybersecurity policy and governance documentation, is comfortable independently researching complex regulatory requirements, and is proactive by nature, someone who tracks documents through review, follows up with stakeholders without being asked, and keeps multiple concurrent efforts moving to closure.
Key Responsibilities
* Author, refine, and maintain cybersecurity policies, standards, procedures, SOPs, and governance documentation from initial draft through final approval.
* Research and analyze federal cybersecurity laws, regulations, executive orders, NIST publications, and agency guidance to develop well-supported policy recommendations.
* Translate complex technical and regulatory requirements into clear, actionable guidance for technical and non-technical audiences.
* Proactively identify, contact, and follow up with SMEs, ISSOs, system owners, and technical stakeholders to keep documents moving through review.
* Track outstanding reviews and inputs and escalate unresponsive stakeholders or review delays before they impact schedule.
* Build and maintain a Gantt chart or sprint-based schedule to plan, track, and brief on documentation milestones.
* Prepare and deliver weekly status reports and monthly KPI/metrics reporting to program leadership, with on-demand reporting as requested.
* Support Risk Management Framework (RMF), Ongoing Authorization (OA), High Value Asset (HVA), and Continuous Monitoring documentation.
* Support cybersecurity assessments, audits, and compliance activities, including documentation tied to open audit findings.
* Coordinate document reviews, adjudicate stakeholder feedback, and maintain document repositories and version control.
* Support the Policy & Governance Change Control Board (CCB), including preparation of meeting minutes and maintenance of change control logs.
Required Qualifications
* 5+ years of experience supporting federal government cybersecurity programs.
* Demonstrated experience developing cybersecurity policies, standards, procedures, SOPs, or governance documentation , and driving them through to final approval, not just drafting.
* Strong knowledge of NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), FISMA, and OMB guidance.
* Demonstrated track record of proactively managing stakeholders - following up on and escalating reviews rather than waiting for responses.
* Advanced proficiency with Microsoft 365 (Teams, SharePoint Online, Word, Excel, PowerPoint, Outlook).
* Ability to build and maintain a Gantt chart or sprint-based schedule to plan and track documentation milestones.
* Exceptional written and verbal communication skills; ability to work directly with government leadership and cross-functional technical teams.
* Eligibility to obtain and maintain a Public Trust clearance.
* Working knowledge of Section 508 accessibility requirements as applied to policy and governance documentation.
Preferred Qualifications
* Experience supporting federal civilian cybersecurity programs (HHS, DHS, DOJ, or similar).
* Experience supporting Authorization to Operate (ATO) or Ongoing Authorization (OA) activities.
* Experience supporting High Value Asset (HVA) programs or enterprise policy/governance offices.
* Experience supporting cybersecurity audits or assessments, including closing longstanding findings.
* Familiarity with Microsoft Lists, Power Automate, Power Apps, Planner, or Visio.
* Certifications such as CISSP, CISM, Security+, CAP, or PMP.
Work Schedule & Expectations
* Core hours: standard business hours, Monday through Friday, EST.
* Hybrid schedule; onsite presence required periodically, particularly during onboarding, knowledge transfer, and key program working sessions.
* Remote work permitted with reliable connectivity.
* Writing samples (policies, standards, or SOPs - sanitized as needed) will be requested as part of the interview process.