Cybersecurity Policy & Governance Specialist (Task 5 - Policy & Governance, Federal Cybersecurity Contract) Location: Hybrid (Washington, D.C. Metro Area) Employment Type: Full-Time Clearance: Public ...
Cybersecurity Policy & Governance Specialist (Task 5 - Policy & Governance, Federal Cybersecurity Contract) Location: Hybrid (Washington, D.C. Metro Area) Employment Type: Full-Time Clearance: Public ...
Cybersecurity Subject Matter Expert Lead (59834)
Fort Myer, VA · On-site +1
Medical
Dental
Vision
Retirement
BMA is seeking a Cybersecurity Subject Matter Expert - Lead to support the DLA JETS Cybersecurity Policy and Oversight Support Services (CPOSS) program. This is a fully remote position and contingent ...
Cybersecurity Subject Matter Expert Lead (59834)
Fort Myer, VA · On-site +1
Medical
Dental
Vision
Retirement
BMA is seeking a Cybersecurity Subject Matter Expert - Lead to support the DLA JETS Cybersecurity Policy and Oversight Support Services (CPOSS) program. This is a fully remote position and contingent ...
Cybersecurity Policy and Compliance Certified Professional with Security Clearance
Fort Belvoir, VA · On-site
Cybersecurity Policy and Compliance Certified Professional Client: U.S. Army Location: Fort Belvoir, VA Clearance: Top Secret • Responsible for providing support of A&A, Access Only, and other ...
New
Cybersecurity Policy and Compliance Certified Professional with Security Clearance
Fort Belvoir, VA · On-site
Cybersecurity Policy and Compliance Certified Professional Client: U.S. Army Location: Fort Belvoir, VA Clearance: Top Secret • Responsible for providing support of A&A, Access Only, and other ...
New
CYBERSECURITY ASSESSMENT
Fort Belvoir, VA · On-site
... policies and procedures. Performs a DOD cybersecurity process while either authorizing an information system or serving as a SME for an information system undergoing authorization.Possesses an ...
Quick apply
CYBERSECURITY ASSESSMENT
Fort Belvoir, VA · On-site
... policies and procedures. Performs a DOD cybersecurity process while either authorizing an information system or serving as a SME for an information system undergoing authorization.Possesses an ...
Cybersecurity Engineer
Mclean, VA · On-site
$120 - $180/hr
Medical
Dental
Vision
Life
Retirement
PTO
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Cybersecurity Engineer
Mclean, VA · On-site
$120 - $180/hr
Medical
Dental
Vision
Life
Retirement
PTO
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
They are seeking a Cybersecurity Engineer to prepare and implement cybersecurity policies, assess vulnerabilities, and ensure compliance with security measures. Responsibilities : • Preparing ...
They are seeking a Cybersecurity Engineer to prepare and implement cybersecurity policies, assess vulnerabilities, and ensure compliance with security measures. Responsibilities : • Preparing ...
Cybersecurity Engineer
Mclean, VA · On-site
$140K - $200K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Cybersecurity Engineer
Mclean, VA · On-site
$140K - $200K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Cybersecurity Engineer
Mclean, VA · On-site
$140K - $200K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Cybersecurity Engineer
Mclean, VA · On-site
$140K - $200K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Cybersecurity Engineer
Mclean, VA · On-site
$140K - $200K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Quick apply
Cybersecurity Engineer
Mclean, VA · On-site
$140K - $200K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Cybersecurity Engineer
Mclean, VA · On-site
$69.40 - $158/hr
Medical
Life
Retirement
PTO
Apply expertise in DoD strategic policy to allow an organization to apply cybersecurity requirements to the development and delivery of cyber resilient systems. Apply a thorough grasp of DoD ...
Cybersecurity Engineer
Mclean, VA · On-site
$69.40 - $158/hr
Medical
Life
Retirement
PTO
Apply expertise in DoD strategic policy to allow an organization to apply cybersecurity requirements to the development and delivery of cyber resilient systems. Apply a thorough grasp of DoD ...
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$106K - $137K/yr
Mayvin is seeking a Senior Cybersecurity Analyst to serve as a subject-matter expert in Cybersecurity Policy, Planning, and Risk Management Framework (RMF) implementation. This role is responsible ...
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$106K - $137K/yr
Mayvin is seeking a Senior Cybersecurity Analyst to serve as a subject-matter expert in Cybersecurity Policy, Planning, and Risk Management Framework (RMF) implementation. This role is responsible ...
The role involves preparing, implementing, and ensuring compliance with cybersecurity policies, as well as assessing vulnerabilities and proposing remediation strategies. Responsibilities : • ...
The role involves preparing, implementing, and ensuring compliance with cybersecurity policies, as well as assessing vulnerabilities and proposing remediation strategies. Responsibilities : • ...
Cybersecurity Analyst
Mclean, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...
Cybersecurity Analyst
Mclean, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...
Cybersecurity Analyst
Mclean, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...
Cybersecurity Analyst
Mclean, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$106K - $137K/yr
Duties Include • Review cybersecurity policies, procedures, and directives to ensure compliance with DoN, DoD, and federal regulations (e.g., DoD 8500-series, NIST SP 800-series, Clinger Cohen Act ...
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$106K - $137K/yr
Duties Include • Review cybersecurity policies, procedures, and directives to ensure compliance with DoN, DoD, and federal regulations (e.g., DoD 8500-series, NIST SP 800-series, Clinger Cohen Act ...
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$107K - $138K/yr
Duties Include • Review cybersecurity policies, procedures, and directives to ensure compliance with DoN, DoD, and federal regulations (e.g., DoD 8500-series, NIST SP 800-series, Clinger Cohen Act ...
Senior Cybersecurity Analyst with Security Clearance
Alexandria, VA · On-site
$107K - $138K/yr
Duties Include • Review cybersecurity policies, procedures, and directives to ensure compliance with DoN, DoD, and federal regulations (e.g., DoD 8500-series, NIST SP 800-series, Clinger Cohen Act ...
Control Validation Security Specialist Senior (59833)
Fort Myer, VA · On-site +1
Medical
Dental
Vision
Retirement
BMA is seeking a Control Validation Security Specialist - Senior to support the DLA JETS Cybersecurity Policy and Oversight Support Services (CPOSS) program. This is a fully remote position and ...
Control Validation Security Specialist Senior (59833)
Fort Myer, VA · On-site +1
Medical
Dental
Vision
Retirement
BMA is seeking a Control Validation Security Specialist - Senior to support the DLA JETS Cybersecurity Policy and Oversight Support Services (CPOSS) program. This is a fully remote position and ...
Policy Analyst Mid
Fort Belvoir, VA · On-site
$124K - $148K/yr
Medical
Dental
Vision
Retirement
Support the organization's Cybersecurity Strategy. * Analyze internal documents and external issuances (e.g., IC/DoW policy, Executive Orders) to identify policy impacts, conflicts, or gaps. Required ...
Quick apply
Policy Analyst Mid
Fort Belvoir, VA · On-site
$124K - $148K/yr
Medical
Dental
Vision
Retirement
Support the organization's Cybersecurity Strategy. * Analyze internal documents and external issuances (e.g., IC/DoW policy, Executive Orders) to identify policy impacts, conflicts, or gaps. Required ...
Cybersecurity Engineer with Security Clearance
Fairfax, VA · On-site
$140K - $200K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Cybersecurity Engineer with Security Clearance
Fairfax, VA · On-site
$140K - $200K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...
Lead the development, review, and coordination of corporate, IT service, and cybersecurity/information assurance policies to ensure enterprise-wide alignment. * Direct the creation of SME self ...
Lead the development, review, and coordination of corporate, IT service, and cybersecurity/information assurance policies to ensure enterprise-wide alignment. * Direct the creation of SME self ...
Cybersecurity Policy information
See Virginia salary details
$56.5K - $68.1K
1% of jobs
$68.1K - $79.8K
4% of jobs
$79.8K - $91.4K
5% of jobs
$91.4K - $103K
9% of jobs
$109.4K is the 25th percentile. Wages below this are outliers.
$103K - $114.6K
11% of jobs
$114.6K - $126.3K
10% of jobs
The median wage is $130.7K / yr.
$126.3K - $137.9K
28% of jobs
$144.6K is the 75th percentile. Wages above this are outliers.
$137.9K - $149.5K
14% of jobs
$149.5K - $161.2K
11% of jobs
$161.2K - $172.8K
4% of jobs
$172.8K - $184.4K
4% of jobs
$56.5K
$131.8K
$184.4K
How much do cybersecurity policy jobs pay per year?
What do cybersecurity policies do?
How to get into cybersecurity policy?
What does a cybersecurity policy professional do?
Professionals in Cybersecurity Policy typically spend their days developing, reviewing, and updating security policies and procedures to keep pace with emerging threats and regulatory requirements. They collaborate closely with IT, legal, and business teams to ensure comprehensive risk management and compliance throughout the organization. Regular activities also include conducting policy audits, preparing compliance documentation, and providing internal training or guidance on policy-related matters. This role requires balancing technical knowledge with organizational priorities, making it both dynamic and impactful.
What is a cybersecurity policy?
A Cybersecurity Policy job involves developing, implementing, and maintaining security policies to protect an organization's digital assets and data. Professionals in this role ensure compliance with regulations, assess security risks, and create guidelines for safe computing practices. They often collaborate with IT, legal, and executive teams to address security threats and policy updates. This role requires knowledge of cybersecurity frameworks, risk management, and regulatory standards like NIST, ISO 27001, or GDPR.
What are the key skills and qualifications needed to thrive in cybersecurity policy?
Thriving in a Cybersecurity Policy role requires a strong grasp of information security principles, risk assessment frameworks, and relevant legal and regulatory standards, often backed by a degree in cybersecurity, information technology, or a related field. Familiarity with common cybersecurity tools (such as GRC platforms), industry certifications like CISSP or CISA, and experience with compliance management systems is highly valued. Excellent analytical thinking, written communication, and stakeholder collaboration skills help bridge technical requirements with organizational objectives. These skills ensure that policies are both practical and compliant, effectively reducing cyber risks in a constantly evolving threat landscape.
What are the most commonly searched types of Cybersecurity Policy jobs in Virginia?
The most popular types of Cybersecurity Policy jobs in Virginia are:
What are popular job titles related to Cybersecurity Policy jobs in Virginia?
For Cybersecurity Policy jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Policy jobs in Virginia look for?
The top searched job categories for Cybersecurity Policy jobs in Virginia are:
What cities in Virginia are hiring for Cybersecurity Policy jobs?
Cities in Virginia with the most Cybersecurity Policy job openings:

Cybersecurity Policy & Governance Specialist
Falls Church, VA • On-site
Full-time
Posted 7 days ago
Job description
Location: Hybrid (Washington, D.C. Metro Area)
Employment Type: Full-Time
Clearance: Public Trust (or eligibility to obtain)
We are seeking an experienced Cybersecurity Policy & Governance Specialist to support Task 5 - Policy and Governance on a federal cybersecurity services contract. This role owns the development, review, and approval of cybersecurity policies, standards, procedures, and SOPs supporting enterprise cybersecurity operations.
The ideal candidate has hands-on experience authoring federal cybersecurity policy and governance documentation, is comfortable independently researching complex regulatory requirements, and is proactive by nature, someone who tracks documents through review, follows up with stakeholders without being asked, and keeps multiple concurrent efforts moving to closure.
Key Responsibilities
* Author, refine, and maintain cybersecurity policies, standards, procedures, SOPs, and governance documentation from initial draft through final approval.
* Research and analyze federal cybersecurity laws, regulations, executive orders, NIST publications, and agency guidance to develop well-supported policy recommendations.
* Translate complex technical and regulatory requirements into clear, actionable guidance for technical and non-technical audiences.
* Proactively identify, contact, and follow up with SMEs, ISSOs, system owners, and technical stakeholders to keep documents moving through review.
* Track outstanding reviews and inputs and escalate unresponsive stakeholders or review delays before they impact schedule.
* Build and maintain a Gantt chart or sprint-based schedule to plan, track, and brief on documentation milestones.
* Prepare and deliver weekly status reports and monthly KPI/metrics reporting to program leadership, with on-demand reporting as requested.
* Support Risk Management Framework (RMF), Ongoing Authorization (OA), High Value Asset (HVA), and Continuous Monitoring documentation.
* Support cybersecurity assessments, audits, and compliance activities, including documentation tied to open audit findings.
* Coordinate document reviews, adjudicate stakeholder feedback, and maintain document repositories and version control.
* Support the Policy & Governance Change Control Board (CCB), including preparation of meeting minutes and maintenance of change control logs.
Required Qualifications
* 5+ years of experience supporting federal government cybersecurity programs.
* Demonstrated experience developing cybersecurity policies, standards, procedures, SOPs, or governance documentation , and driving them through to final approval, not just drafting.
* Strong knowledge of NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), FISMA, and OMB guidance.
* Demonstrated track record of proactively managing stakeholders - following up on and escalating reviews rather than waiting for responses.
* Advanced proficiency with Microsoft 365 (Teams, SharePoint Online, Word, Excel, PowerPoint, Outlook).
* Ability to build and maintain a Gantt chart or sprint-based schedule to plan and track documentation milestones.
* Exceptional written and verbal communication skills; ability to work directly with government leadership and cross-functional technical teams.
* Eligibility to obtain and maintain a Public Trust clearance.
* Working knowledge of Section 508 accessibility requirements as applied to policy and governance documentation.
Preferred Qualifications
* Experience supporting federal civilian cybersecurity programs (HHS, DHS, DOJ, or similar).
* Experience supporting Authorization to Operate (ATO) or Ongoing Authorization (OA) activities.
* Experience supporting High Value Asset (HVA) programs or enterprise policy/governance offices.
* Experience supporting cybersecurity audits or assessments, including closing longstanding findings.
* Familiarity with Microsoft Lists, Power Automate, Power Apps, Planner, or Visio.
* Certifications such as CISSP, CISM, Security+, CAP, or PMP.
Work Schedule & Expectations
* Core hours: standard business hours, Monday through Friday, EST.
* Hybrid schedule; onsite presence required periodically, particularly during onboarding, knowledge transfer, and key program working sessions.
* Remote work permitted with reliable connectivity.
* Writing samples (policies, standards, or SOPs - sanitized as needed) will be requested as part of the interview process.