Cybersecurity Policy & Governance Specialist (Task 5 - Policy & Governance, Federal Cybersecurity Contract) Location: Hybrid (Washington, D.C. Metro Area) Employment Type: Full-Time Clearance: Public ...
Cybersecurity Policy & Governance Specialist (Task 5 - Policy & Governance, Federal Cybersecurity Contract) Location: Hybrid (Washington, D.C. Metro Area) Employment Type: Full-Time Clearance: Public ...
Cybersecurity Policy Analyst - Senior Associate
Arlington, VA · On-site
$75K - $90K/yr
Cybersecurity Policy Analyst - Senior Associate Job Summary: Lafayette Group is seeking a Policy Analyst to support the Cybersecurity Division (CSD) within the Cybersecurity and Infrastructure ...
New
Cybersecurity Policy Analyst - Senior Associate
Arlington, VA · On-site
$75K - $90K/yr
Cybersecurity Policy Analyst - Senior Associate Job Summary: Lafayette Group is seeking a Policy Analyst to support the Cybersecurity Division (CSD) within the Cybersecurity and Infrastructure ...
New
BMA is seeking a Cybersecurity Subject Matter Expert - Lead to support the DLA JETS Cybersecurity Policy and Oversight Support Services (CPOSS) program. This is a fully remote position and contingent ...
BMA is seeking a Cybersecurity Subject Matter Expert - Lead to support the DLA JETS Cybersecurity Policy and Oversight Support Services (CPOSS) program. This is a fully remote position and contingent ...
Cybersecurity Policy and Compliance Certified Professional with Security Clearance
Fort Belvoir, VA · On-site
Cybersecurity Policy and Compliance Certified Professional Client: U.S. Army Location: Fort Belvoir, VA Clearance: Top Secret • Responsible for providing support of A&A, Access Only, and other ...
Cybersecurity Policy and Compliance Certified Professional with Security Clearance
Fort Belvoir, VA · On-site
Cybersecurity Policy and Compliance Certified Professional Client: U.S. Army Location: Fort Belvoir, VA Clearance: Top Secret • Responsible for providing support of A&A, Access Only, and other ...
Policy Analyst - MID
Springfield, VA · On-site
$96K - $118K/yr
The role's breadth is demonstrated through various specializations, including high-level strategic planning and business analysis for executive management; detailed IT and cybersecurity policy ...
New
Policy Analyst - MID
Springfield, VA · On-site
$96K - $118K/yr
The role's breadth is demonstrated through various specializations, including high-level strategic planning and business analysis for executive management; detailed IT and cybersecurity policy ...
New
CYBERSECURITY ASSESSMENT
Fort Belvoir, VA · On-site
... policies and procedures. Performs a DOD cybersecurity process while either authorizing an information system or serving as a SME for an information system undergoing authorization.Possesses an ...
Quick apply
CYBERSECURITY ASSESSMENT
Fort Belvoir, VA · On-site
... policies and procedures. Performs a DOD cybersecurity process while either authorizing an information system or serving as a SME for an information system undergoing authorization.Possesses an ...
Policy Analyst - MID
Springfield, VA · On-site
$96K - $118K/yr
Support the organization's Cybersecurity Strategy. * Analyze internal documents and external issuances (e.g., IC/DoW policy, Executive Orders) to identify policy impacts, conflicts, or gaps. * Other ...
New
Policy Analyst - MID
Springfield, VA · On-site
$96K - $118K/yr
Support the organization's Cybersecurity Strategy. * Analyze internal documents and external issuances (e.g., IC/DoW policy, Executive Orders) to identify policy impacts, conflicts, or gaps. * Other ...
New
Cybersecurity Engineer
Mclean, VA · On-site
$120 - $180/hr
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Cybersecurity Engineer
Mclean, VA · On-site
$120 - $180/hr
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
They are seeking a Cybersecurity Engineer to prepare and implement cybersecurity policies, assess vulnerabilities, and ensure compliance with security measures. Responsibilities : • Preparing ...
They are seeking a Cybersecurity Engineer to prepare and implement cybersecurity policies, assess vulnerabilities, and ensure compliance with security measures. Responsibilities : • Preparing ...
Cybersecurity Engineer
Mclean, VA · On-site
$140K - $200K/yr
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Cybersecurity Engineer
Mclean, VA · On-site
$140K - $200K/yr
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Policy Analyst
Springfield, VA · On-site
$110 - $160/hr
Lead the development, review, and coordination of corporate, IT service, and cybersecurity/information assurance policies to ensure enterprise-wide alignment. * Direct the creation of SME self ...
New
Policy Analyst
Springfield, VA · On-site
$110 - $160/hr
Lead the development, review, and coordination of corporate, IT service, and cybersecurity/information assurance policies to ensure enterprise-wide alignment. * Direct the creation of SME self ...
New
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$106K - $137K/yr
Mayvin is seeking a Senior Cybersecurity Analyst to serve as a subject-matter expert in Cybersecurity Policy, Planning, and Risk Management Framework (RMF) implementation. This role is responsible ...
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$106K - $137K/yr
Mayvin is seeking a Senior Cybersecurity Analyst to serve as a subject-matter expert in Cybersecurity Policy, Planning, and Risk Management Framework (RMF) implementation. This role is responsible ...
Policy Analyst - MID with Security Clearance
Springfield, VA · On-site
$96K - $118K/yr
Support the organization's Cybersecurity Strategy. * Analyze internal documents and external issuances (e.g., IC/DoW policy, Executive Orders) to identify policy impacts, conflicts, or gaps. * Other ...
New
Policy Analyst - MID with Security Clearance
Springfield, VA · On-site
$96K - $118K/yr
Support the organization's Cybersecurity Strategy. * Analyze internal documents and external issuances (e.g., IC/DoW policy, Executive Orders) to identify policy impacts, conflicts, or gaps. * Other ...
New
The role involves preparing, implementing, and ensuring compliance with cybersecurity policies, as well as assessing vulnerabilities and proposing remediation strategies. Responsibilities : • ...
The role involves preparing, implementing, and ensuring compliance with cybersecurity policies, as well as assessing vulnerabilities and proposing remediation strategies. Responsibilities : • ...
It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...
It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...
Cybersecurity Analyst
Mclean, VA · On-site
It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...
Cybersecurity Analyst
Mclean, VA · On-site
It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...
Senior Cyber Policy Analyst (ICAM & Compliance)
Alexandria, VA · On-site
$69.40 - $158/hr
The role focuses on Identity, Credential, and Access Management (ICAM) and requires over 10 years of professional experience, with at least 5 years dedicated to cybersecurity policy. Success in this ...
New
Senior Cyber Policy Analyst (ICAM & Compliance)
Alexandria, VA · On-site
$69.40 - $158/hr
The role focuses on Identity, Credential, and Access Management (ICAM) and requires over 10 years of professional experience, with at least 5 years dedicated to cybersecurity policy. Success in this ...
New
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$106K - $137K/yr
Duties Include • Review cybersecurity policies, procedures, and directives to ensure compliance with DoN, DoD, and federal regulations (e.g., DoD 8500-series, NIST SP 800-series, Clinger Cohen Act ...
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$106K - $137K/yr
Duties Include • Review cybersecurity policies, procedures, and directives to ensure compliance with DoN, DoD, and federal regulations (e.g., DoD 8500-series, NIST SP 800-series, Clinger Cohen Act ...
BMA is seeking a Control Validation Security Specialist - Senior to support the DLA JETS Cybersecurity Policy and Oversight Support Services (CPOSS) program. This is a fully remote position and ...
BMA is seeking a Control Validation Security Specialist - Senior to support the DLA JETS Cybersecurity Policy and Oversight Support Services (CPOSS) program. This is a fully remote position and ...
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$107K - $138K/yr
Duties Include • Review cybersecurity policies, procedures, and directives to ensure compliance with DoN, DoD, and federal regulations (e.g., DoD 8500-series, NIST SP 800-series, Clinger Cohen Act ...
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$107K - $138K/yr
Duties Include • Review cybersecurity policies, procedures, and directives to ensure compliance with DoN, DoD, and federal regulations (e.g., DoD 8500-series, NIST SP 800-series, Clinger Cohen Act ...
Cyber Security Policy information
See Virginia salary details
$56.5K - $68.1K
1% of jobs
$68.1K - $79.8K
4% of jobs
$79.8K - $91.4K
5% of jobs
$91.4K - $103K
9% of jobs
$109.4K is the 25th percentile. Wages below this are outliers.
$103K - $114.6K
11% of jobs
$114.6K - $126.3K
10% of jobs
The median wage is $130.7K / yr.
$126.3K - $137.9K
28% of jobs
$144.6K is the 75th percentile. Wages above this are outliers.
$137.9K - $149.5K
14% of jobs
$149.5K - $161.2K
11% of jobs
$161.2K - $172.8K
4% of jobs
$172.8K - $184.4K
4% of jobs
$56.5K
$131.8K
$184.4K
How much do cyber security policy jobs pay per year?
What is cyber security policy?
What are the key skills and qualifications needed to thrive in cyber security policy?
What are some common challenges faced by professionals working in cyber security policy roles?
What is the difference between Cyber Security Policy vs Cyber Security Analyst?
| Aspect | Cyber Security Policy | Cyber Security Analyst |
|---|---|---|
| Primary Focus | Developing, implementing, and maintaining security policies and procedures | Monitoring, analyzing, and responding to security threats and incidents |
| Required Credentials | Knowledge of security frameworks, policies, and compliance standards | Certifications like CISSP, CEH, or Security+; technical skills |
| Work Environment | Policy development teams, compliance departments, management | Security operations centers, IT teams, incident response teams |
| Industry Usage | Used across organizations to establish security standards | Used to identify and mitigate security threats |
While a Cyber Security Policy focuses on creating and maintaining security guidelines, a Cyber Security Analyst actively monitors and responds to security threats. Both roles are essential for a comprehensive security strategy, with policies providing the framework and analysts ensuring its enforcement and effectiveness.
How to get into cybersecurity policy?
What are popular job titles related to Cyber Security Policy jobs in Virginia?
For Cyber Security Policy jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Cyber Security Policy jobs in Virginia look for?
The top searched job categories for Cyber Security Policy jobs in Virginia are:
What cities in Virginia are hiring for Cyber Security Policy jobs?
Cities in Virginia with the most Cyber Security Policy job openings:

Cybersecurity Policy & Governance Specialist
Falls Church, VA • On-site
Full-time
Posted 15 days ago
Job description
Location: Hybrid (Washington, D.C. Metro Area)
Employment Type: Full-Time
Clearance: Public Trust (or eligibility to obtain)
We are seeking an experienced Cybersecurity Policy & Governance Specialist to support Task 5 - Policy and Governance on a federal cybersecurity services contract. This role owns the development, review, and approval of cybersecurity policies, standards, procedures, and SOPs supporting enterprise cybersecurity operations.
The ideal candidate has hands-on experience authoring federal cybersecurity policy and governance documentation, is comfortable independently researching complex regulatory requirements, and is proactive by nature, someone who tracks documents through review, follows up with stakeholders without being asked, and keeps multiple concurrent efforts moving to closure.
Key Responsibilities
* Author, refine, and maintain cybersecurity policies, standards, procedures, SOPs, and governance documentation from initial draft through final approval.
* Research and analyze federal cybersecurity laws, regulations, executive orders, NIST publications, and agency guidance to develop well-supported policy recommendations.
* Translate complex technical and regulatory requirements into clear, actionable guidance for technical and non-technical audiences.
* Proactively identify, contact, and follow up with SMEs, ISSOs, system owners, and technical stakeholders to keep documents moving through review.
* Track outstanding reviews and inputs and escalate unresponsive stakeholders or review delays before they impact schedule.
* Build and maintain a Gantt chart or sprint-based schedule to plan, track, and brief on documentation milestones.
* Prepare and deliver weekly status reports and monthly KPI/metrics reporting to program leadership, with on-demand reporting as requested.
* Support Risk Management Framework (RMF), Ongoing Authorization (OA), High Value Asset (HVA), and Continuous Monitoring documentation.
* Support cybersecurity assessments, audits, and compliance activities, including documentation tied to open audit findings.
* Coordinate document reviews, adjudicate stakeholder feedback, and maintain document repositories and version control.
* Support the Policy & Governance Change Control Board (CCB), including preparation of meeting minutes and maintenance of change control logs.
Required Qualifications
* 5+ years of experience supporting federal government cybersecurity programs.
* Demonstrated experience developing cybersecurity policies, standards, procedures, SOPs, or governance documentation , and driving them through to final approval, not just drafting.
* Strong knowledge of NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), FISMA, and OMB guidance.
* Demonstrated track record of proactively managing stakeholders - following up on and escalating reviews rather than waiting for responses.
* Advanced proficiency with Microsoft 365 (Teams, SharePoint Online, Word, Excel, PowerPoint, Outlook).
* Ability to build and maintain a Gantt chart or sprint-based schedule to plan and track documentation milestones.
* Exceptional written and verbal communication skills; ability to work directly with government leadership and cross-functional technical teams.
* Eligibility to obtain and maintain a Public Trust clearance.
* Working knowledge of Section 508 accessibility requirements as applied to policy and governance documentation.
Preferred Qualifications
* Experience supporting federal civilian cybersecurity programs (HHS, DHS, DOJ, or similar).
* Experience supporting Authorization to Operate (ATO) or Ongoing Authorization (OA) activities.
* Experience supporting High Value Asset (HVA) programs or enterprise policy/governance offices.
* Experience supporting cybersecurity audits or assessments, including closing longstanding findings.
* Familiarity with Microsoft Lists, Power Automate, Power Apps, Planner, or Visio.
* Certifications such as CISSP, CISM, Security+, CAP, or PMP.
Work Schedule & Expectations
* Core hours: standard business hours, Monday through Friday, EST.
* Hybrid schedule; onsite presence required periodically, particularly during onboarding, knowledge transfer, and key program working sessions.
* Remote work permitted with reliable connectivity.
* Writing samples (policies, standards, or SOPs - sanitized as needed) will be requested as part of the interview process.