1

Cybersecurity Policy Jobs in Virginia (NOW HIRING)

Cybersecurity Engineer

Mclean, VA · On-site

$120 - $180/hr

Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...

Cybersecurity Engineer

Mclean, VA · On-site

$140K - $200K/yr

Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...

Cybersecurity Engineer

Mclean, VA · On-site

$140K - $200K/yr

Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...

Cybersecurity Engineer

Mclean, VA · On-site

$140K - $200K/yr

Support the overall DoD implementation of its authorization process, including cybersecurity policy and procedures. * Authorize information systems or serve as a SME for systems undergoing ...

Cybersecurity Engineer

Mclean, VA · On-site

$69.40 - $158/hr

Apply expertise in DoD strategic policy to allow an organization to apply cybersecurity requirements to the development and delivery of cyber resilient systems. Apply a thorough grasp of DoD ...

It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...

It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security ...

Policy Analyst Mid

Fort Belvoir, VA · On-site

$124K - $148K/yr

Support the organization's Cybersecurity Strategy. * Analyze internal documents and external issuances (e.g., IC/DoW policy, Executive Orders) to identify policy impacts, conflicts, or gaps. Required ...

next page

Showing results 1-20

Cybersecurity Policy information

See Virginia salary details

$56.5K

$131.8K

$184.4K

How much do cybersecurity policy jobs pay per year?

As of Aug 7, 2026, the average yearly pay for cybersecurity policy in Virginia is $131,822.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,000.00 and $148,700.00 per year, depending on experience, location, and employer.

What do cybersecurity policies do?

Cybersecurity policies define the rules and procedures that organizations follow to protect their information systems and data. They establish security standards, guide employee behavior, and help ensure compliance with regulations, supporting cybersecurity professionals in maintaining a secure environment. These policies are essential for risk management and incident response planning.

How to get into cybersecurity policy?

To enter cybersecurity policy, develop a strong understanding of cybersecurity principles, laws, and regulations, often through a degree in cybersecurity, computer science, or public policy. Gaining experience with policy analysis, cybersecurity frameworks, and relevant certifications like CISSP or CIPP can enhance your qualifications. Internships or entry-level roles in government agencies, think tanks, or private firms also provide valuable experience in this field.

What does a cybersecurity policy professional do?

Professionals in Cybersecurity Policy typically spend their days developing, reviewing, and updating security policies and procedures to keep pace with emerging threats and regulatory requirements. They collaborate closely with IT, legal, and business teams to ensure comprehensive risk management and compliance throughout the organization. Regular activities also include conducting policy audits, preparing compliance documentation, and providing internal training or guidance on policy-related matters. This role requires balancing technical knowledge with organizational priorities, making it both dynamic and impactful.

What is a cybersecurity policy?

A Cybersecurity Policy job involves developing, implementing, and maintaining security policies to protect an organization's digital assets and data. Professionals in this role ensure compliance with regulations, assess security risks, and create guidelines for safe computing practices. They often collaborate with IT, legal, and executive teams to address security threats and policy updates. This role requires knowledge of cybersecurity frameworks, risk management, and regulatory standards like NIST, ISO 27001, or GDPR.

What are the key skills and qualifications needed to thrive in cybersecurity policy?

Thriving in a Cybersecurity Policy role requires a strong grasp of information security principles, risk assessment frameworks, and relevant legal and regulatory standards, often backed by a degree in cybersecurity, information technology, or a related field. Familiarity with common cybersecurity tools (such as GRC platforms), industry certifications like CISSP or CISA, and experience with compliance management systems is highly valued. Excellent analytical thinking, written communication, and stakeholder collaboration skills help bridge technical requirements with organizational objectives. These skills ensure that policies are both practical and compliant, effectively reducing cyber risks in a constantly evolving threat landscape.

What are the most commonly searched types of Cybersecurity Policy jobs in Virginia? The most popular types of Cybersecurity Policy jobs in Virginia are:
What are popular job titles related to Cybersecurity Policy jobs in Virginia? For Cybersecurity Policy jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Policy jobs in Virginia look for? The top searched job categories for Cybersecurity Policy jobs in Virginia are:
What cities in Virginia are hiring for Cybersecurity Policy jobs? Cities in Virginia with the most Cybersecurity Policy job openings:
Infographic showing various Cybersecurity Policy job openings in Virginia as of July 2026, with employment types broken down into 84% Full Time, 6% Part Time, and 10% Contract. Highlights an 94% In-person, and 6% Hybrid job distribution, with an average salary of $131,822 per year, or $63.4 per hour.

Cybersecurity Policy & Governance Specialist

Cyber Synergy Consulting Group

Falls Church, VA • On-site

Full-time

Posted yesterday

New


Job description

Cybersecurity Policy & Governance Specialist (Task 5 - Policy & Governance, Federal Cybersecurity Contract)
Location: Hybrid (Washington, D.C. Metro Area)
Employment Type: Full-Time
Clearance: Public Trust (or eligibility to obtain)
We are seeking an experienced Cybersecurity Policy & Governance Specialist to support Task 5 - Policy and Governance on a federal cybersecurity services contract. This role owns the development, review, and approval of cybersecurity policies, standards, procedures, and SOPs supporting enterprise cybersecurity operations.
The ideal candidate has hands-on experience authoring federal cybersecurity policy and governance documentation, is comfortable independently researching complex regulatory requirements, and is proactive by nature, someone who tracks documents through review, follows up with stakeholders without being asked, and keeps multiple concurrent efforts moving to closure.
Key Responsibilities
* Author, refine, and maintain cybersecurity policies, standards, procedures, SOPs, and governance documentation from initial draft through final approval.
* Research and analyze federal cybersecurity laws, regulations, executive orders, NIST publications, and agency guidance to develop well-supported policy recommendations.
* Translate complex technical and regulatory requirements into clear, actionable guidance for technical and non-technical audiences.
* Proactively identify, contact, and follow up with SMEs, ISSOs, system owners, and technical stakeholders to keep documents moving through review.
* Track outstanding reviews and inputs and escalate unresponsive stakeholders or review delays before they impact schedule.
* Build and maintain a Gantt chart or sprint-based schedule to plan, track, and brief on documentation milestones.
* Prepare and deliver weekly status reports and monthly KPI/metrics reporting to program leadership, with on-demand reporting as requested.
* Support Risk Management Framework (RMF), Ongoing Authorization (OA), High Value Asset (HVA), and Continuous Monitoring documentation.
* Support cybersecurity assessments, audits, and compliance activities, including documentation tied to open audit findings.
* Coordinate document reviews, adjudicate stakeholder feedback, and maintain document repositories and version control.
* Support the Policy & Governance Change Control Board (CCB), including preparation of meeting minutes and maintenance of change control logs.
Required Qualifications
* 5+ years of experience supporting federal government cybersecurity programs.
* Demonstrated experience developing cybersecurity policies, standards, procedures, SOPs, or governance documentation , and driving them through to final approval, not just drafting.
* Strong knowledge of NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), FISMA, and OMB guidance.
* Demonstrated track record of proactively managing stakeholders - following up on and escalating reviews rather than waiting for responses.
* Advanced proficiency with Microsoft 365 (Teams, SharePoint Online, Word, Excel, PowerPoint, Outlook).
* Ability to build and maintain a Gantt chart or sprint-based schedule to plan and track documentation milestones.
* Exceptional written and verbal communication skills; ability to work directly with government leadership and cross-functional technical teams.
* Eligibility to obtain and maintain a Public Trust clearance.
* Working knowledge of Section 508 accessibility requirements as applied to policy and governance documentation.
Preferred Qualifications
* Experience supporting federal civilian cybersecurity programs (HHS, DHS, DOJ, or similar).
* Experience supporting Authorization to Operate (ATO) or Ongoing Authorization (OA) activities.
* Experience supporting High Value Asset (HVA) programs or enterprise policy/governance offices.
* Experience supporting cybersecurity audits or assessments, including closing longstanding findings.
* Familiarity with Microsoft Lists, Power Automate, Power Apps, Planner, or Visio.
* Certifications such as CISSP, CISM, Security+, CAP, or PMP.
Work Schedule & Expectations
* Core hours: standard business hours, Monday through Friday, EST.
* Hybrid schedule; onsite presence required periodically, particularly during onboarding, knowledge transfer, and key program working sessions.
* Remote work permitted with reliable connectivity.
* Writing samples (policies, standards, or SOPs - sanitized as needed) will be requested as part of the interview process.