1

Cybersecurity Policy Jobs in Virginia (NOW HIRING)

Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...

Cybersecurity Engineer

Mclean, VA · On-site

$140K - $200K/yr

Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...

Cybersecurity Engineer

Mclean, VA · On-site

$140K - $200K/yr

Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...

It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...

It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...

Policy Analyst Mid

Fort Belvoir, VA · On-site

$124K - $148K/yr

Support the organization's Cybersecurity Strategy. * Analyze internal documents and external issuances (e.g., IC/DoW policy, Executive Orders) to identify policy impacts, conflicts, or gaps. Required ...

next page

Showing results 1-20

Cybersecurity Policy information

See Virginia salary details

$56.5K

$131.8K

$184.4K

How much do cybersecurity policy jobs pay per year?

As of Jul 31, 2026, the average yearly pay for cybersecurity policy in Virginia is $131,822.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,000.00 and $148,700.00 per year, depending on experience, location, and employer.

What are the typical daily responsibilities for someone working in Cybersecurity Policy?

Professionals in Cybersecurity Policy typically spend their days developing, reviewing, and updating security policies and procedures to keep pace with emerging threats and regulatory requirements. They collaborate closely with IT, legal, and business teams to ensure comprehensive risk management and compliance throughout the organization. Regular activities also include conducting policy audits, preparing compliance documentation, and providing internal training or guidance on policy-related matters. This role requires balancing technical knowledge with organizational priorities, making it both dynamic and impactful.

What is a Cybersecurity Policy job?

A Cybersecurity Policy job involves developing, implementing, and maintaining security policies to protect an organization's digital assets and data. Professionals in this role ensure compliance with regulations, assess security risks, and create guidelines for safe computing practices. They often collaborate with IT, legal, and executive teams to address security threats and policy updates. This role requires knowledge of cybersecurity frameworks, risk management, and regulatory standards like NIST, ISO 27001, or GDPR.

What are the key skills and qualifications needed to thrive in the Cybersecurity Policy position, and why are they important?

Thriving in a Cybersecurity Policy role requires a strong grasp of information security principles, risk assessment frameworks, and relevant legal and regulatory standards, often backed by a degree in cybersecurity, information technology, or a related field. Familiarity with common cybersecurity tools (such as GRC platforms), industry certifications like CISSP or CISA, and experience with compliance management systems is highly valued. Excellent analytical thinking, written communication, and stakeholder collaboration skills help bridge technical requirements with organizational objectives. These skills ensure that policies are both practical and compliant, effectively reducing cyber risks in a constantly evolving threat landscape.

What are the most commonly searched types of Cybersecurity Policy jobs in Virginia? The most popular types of Cybersecurity Policy jobs in Virginia are:
What are popular job titles related to Cybersecurity Policy jobs in Virginia? For Cybersecurity Policy jobs in Virginia, the most frequently searched job titles are:
What cities in Virginia are hiring for Cybersecurity Policy jobs? Cities in Virginia with the most Cybersecurity Policy job openings:
Infographic showing various Cybersecurity Policy job openings in Virginia as of July 2026, with employment types broken down into 84% Full Time, 6% Part Time, and 10% Contract. Highlights an 94% In-person, and 6% Hybrid job distribution, with an average salary of $131,822 per year, or $63.4 per hour.

Cybersecurity Governance & Policy Specialist ? Level II

RIVIDIUM

Quantico, VA • On-site

Full-time

Posted yesterday

New


Job description

RiVidium Inc. is seeking an experienced Cybersecurity Governance & Policy Specialist ? Level II to serve the team for all Cybersecurity and Intelligence Enterprise Information Technology Services (CIEITS) program activities.

The Cybersecurity Governance & Policy Specialist ? Level II supports the development, implementation, and maintenance of cybersecurity governance, policy, and compliance activities for the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE). Working under the direction of the Senior Security Governance and Policy Analyst, this position assists with researching emerging cybersecurity requirements, analyzing Federal and Intelligence Community (IC) guidance, and ensuring DHS IE cybersecurity policies remain aligned with current Federal laws, Executive Orders, DHS directives, and IC cybersecurity standards.

The ideal candidate possesses strong analytical, research, technical writing, and organizational skills, with experience supporting cybersecurity governance initiatives within classified Federal or Intelligence Community environments. This role collaborates closely with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), cybersecurity leadership, and Government stakeholders to promote policy compliance and effective cybersecurity governance across the enterprise.

Key Responsibilities

  • Support the Senior Cybersecurity Governance and Policy Analyst in reviewing, analyzing, and implementing changes to Federal, DHS, and Intelligence Community cybersecurity policies, directives, standards, and guidance.
  • Research newly issued Executive Orders (EOs), National Security Memoranda (NSMs), Office of Management and Budget (OMB) guidance, DHS directives, and IC cybersecurity policies; prepare summaries and recommendations for leadership review.
  • Draft stakeholder notifications regarding cybersecurity policy changes, updates, and rescissions for review and distribution by the Chief Information Security Officer (CISO).
  • Assist in developing Policy Addenda, implementation guidance, and policy rescission documentation for Cybersecurity Division leadership.
  • Maintain the cybersecurity governance compliance tracker and update policy implementation status on a weekly basis.
  • Maintain SharePoint sites and centralized repositories containing cybersecurity policies, governance documentation, meeting records, and reference materials.
  • Support the preparation of executive briefings, decision papers, white papers, presentation materials, and governance reports for senior leadership.
  • Assist with Intelligence Community Oversight Program (ICOP) briefings and governance working group presentations.
  • Monitor DHS Component compliance with cybersecurity policy requirements and assist in compiling compliance status reports and metrics.
  • Support Government data calls, taskers, audits, inspections, and special reporting requirements.
  • Coordinate governance meetings, working groups, and stakeholder communications; document meeting minutes and track action items.
  • Maintain centralized records of governance decisions, policy changes, waivers, and compliance documentation.
  • Assist with quality assurance reviews of governance documents to ensure consistency with Federal and Intelligence Community requirements.
  • Collaborate with cybersecurity teams to promote policy awareness and governance best practices throughout the enterprise.

Minimum Qualifications

  • Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.
  • Minimum 5 years of experience supporting cybersecurity governance, policy analysis, information assurance, or cybersecurity compliance within the Federal Government or Intelligence Community.
  • Working knowledge of:
    • NIST SP 800-53
    • NIST Risk Management Framework (RMF)
    • CNSSI 1253
    • DHS Sensitive Systems Policy Directive 4300C
    • Intelligence Community cybersecurity directives and governance requirements
  • Experience researching cybersecurity regulations and translating technical guidance into policy recommendations and implementation documentation.
  • Experience preparing executive correspondence, policy memoranda, briefing materials, reports, and technical documentation.
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Political Science, Public Administration, Information Assurance, or a related discipline.
  • Excellent analytical, organizational, technical writing, verbal communication, and presentation skills.
  • Proficiency with Microsoft Office 365, including Word, Excel, PowerPoint, Outlook, and Teams.

Preferred Qualifications

  • Current Certified Information Systems Security Professional (CISSP), CompTIA Security+, or Certified Authorization Professional (CAP) certification.
  • Experience supporting DHS Intelligence & Analysis (I&A) or other Intelligence Community cybersecurity organizations.
  • Experience administering or maintaining SharePoint sites and collaboration platforms.
  • Familiarity with Governance, Risk, and Compliance (GRC) platforms such as RSA Archer.
  • Experience supporting cybersecurity audits, inspections, policy compliance assessments, and governance reviews.
  • Knowledge of Executive Orders, National Security Memoranda (NSMs), OMB Circulars, FISMA, and other Federal cybersecurity mandates.

Required Certifications

One or more of the following certifications are preferred and may be required based on contract needs:

  • CompTIA Security+
  • Certified Information Systems Security Professional (CISSP)
  • Certified Authorization Professional (CAP)

Clearance Requirement

Active Top Secret/Sensitive Compartmented Information (TS/SCI) Clearance Required