1

Cybersecurity Policy Jobs in Baltimore, MD (NOW HIRING)

Maintain in-depth knowledge and understanding of the DOD cybersecurity policies and the Risk Management Framework * With no guidance, conduct cybersecurity engineering research and analysis, provide ...

Maintain in-depth knowledge and understanding of the DOD cybersecurity policies and the Risk Management Framework * With no guidance, conduct cybersecurity engineering research and analysis, provide ...

Maintain in-depth knowledge and understanding of the DOD cybersecurity policies and the Risk Management Framework * With no guidance, conduct cybersecurity engineering research and analysis, provide ...

Maintain thorough knowledge and understanding of the DOD cybersecurity policies and the Risk Management Framework * Initiate actions to conduct cybersecurity engineering research and analysis and ...

next page

Showing results 1-20

Cybersecurity Policy information

See Baltimore, MD salary details

$56.6K

$132.1K

$184.8K

How much do cybersecurity policy jobs pay per year?

As of Sep 5, 2026, the average yearly pay for cybersecurity policy in Baltimore, MD is $132,116.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,300.00 and $149,000.00 per year, depending on experience, location, and employer.

What is a cybersecurity policy?

A Cybersecurity Policy job involves developing, implementing, and maintaining security policies to protect an organization's digital assets and data. Professionals in this role ensure compliance with regulations, assess security risks, and create guidelines for safe computing practices. They often collaborate with IT, legal, and executive teams to address security threats and policy updates. This role requires knowledge of cybersecurity frameworks, risk management, and regulatory standards like NIST, ISO 27001, or GDPR.

What does a cybersecurity policy professional do?

Professionals in Cybersecurity Policy typically spend their days developing, reviewing, and updating security policies and procedures to keep pace with emerging threats and regulatory requirements. They collaborate closely with IT, legal, and business teams to ensure comprehensive risk management and compliance throughout the organization. Regular activities also include conducting policy audits, preparing compliance documentation, and providing internal training or guidance on policy-related matters. This role requires balancing technical knowledge with organizational priorities, making it both dynamic and impactful.

What are the key skills and qualifications needed to thrive in cybersecurity policy?

Thriving in a Cybersecurity Policy role requires a strong grasp of information security principles, risk assessment frameworks, and relevant legal and regulatory standards, often backed by a degree in cybersecurity, information technology, or a related field. Familiarity with common cybersecurity tools (such as GRC platforms), industry certifications like CISSP or CISA, and experience with compliance management systems is highly valued. Excellent analytical thinking, written communication, and stakeholder collaboration skills help bridge technical requirements with organizational objectives. These skills ensure that policies are both practical and compliant, effectively reducing cyber risks in a constantly evolving threat landscape.

What are the most commonly searched types of Cybersecurity Policy jobs in Baltimore, MD?

The most popular types of Cybersecurity Policy jobs in Baltimore, MD are:

What are popular job titles related to Cybersecurity Policy jobs in Baltimore, MD?

For Cybersecurity Policy jobs in Baltimore, MD, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Policy jobs in Baltimore, MD look for?

The top searched job categories for Cybersecurity Policy jobs in Baltimore, MD are:

What cities near Baltimore, MD are hiring for Cybersecurity Policy jobs?

Cities near Baltimore, MD with the most Cybersecurity Policy job openings:

Infographic showing various Cybersecurity Policy job openings in Baltimore, MD as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 16% Part Time, and 2% Contract. Highlights an 95% Physical, 2% Hybrid, and 3% Remote job distribution, with an average salary of $132,116 per year, or $63.5 per hour.

Cybersecurity Governance Manager

OneMain Financial

Baltimore, MD • On-site

$110K - $149K/yr

Full-time

Re-posted 4 days ago


OneMain Financial rating

7.5

Company rating: 7.5 out of 10

Based on 103 frontline employees who took The Breakroom Quiz

116th of 154 rated financial services


Job description

We are seeking aManagerof Cybersecurity Governance to join our dynamic teamreporting to theDirectorof Cybersecurity Governance and Risk.This rolewillleadthedevelopmentof a comprehensive technology and cybersecuritygovernanceframework tailored to ouron-premiseandcloudenvironments. This role is critical in ensuring that our company'stechnology and cybersecuritypractices are compliant with regulatory requirements and industry standards, while alsoeffectivelyidentifyingrisks.

Members of the Cybersecurity Governance team are motivated, detail-oriented, and thrive in a collaborative environment where they will add value to key business partners. This position will require you to be adaptive, willing to drive change and innovation, and work in a fast-paced environment requiring collaboration and the ability to organize and prioritize assignments.

Responsibilities:

  • Establish andmaintainasecurity governance frameworkbased on the National Institute of Standards and Technology (NIST) Cybersecurity Frameworkto ensure effective oversight and accountability.

  • Oversee thetechnology and cybersecurity policy program, which includes policyand controldrafting,facilitatingcross-functional input,and enforcement of policies, procedures, and controls.

  • Maintain the company's technology and cybersecurity riskandcontrolsmatrix in alignment with multiple frameworks, including SOC2,CIS,PCI, NIST CSF,NIST 800-53, and NYDFS Part 500.

  • Leadtheannualenterprisetechnology and cybersecurity riskassessment.

  • Establish an automatedtechnology and cybergovernance risk and compliance (GRC) program to continuouslymonitorand report on technology and cyber risk and control effectiveness.

  • Lead the company's annual NYDFS Part 500 Cybersecurity self-assessment.

  • Oversee andfacilitatethe annual SOC2 audit and any exams and assessments focused on technology and cybersecurity controlsfrom state examiners, regulators, and OneMain partners.

  • Educate,influenceandprovide clear directives for technology projects, either directly or through committees, to ensure the consistent application of policies,standardsand controlsacross all technology projects,systemsand services.

  • Partnerand coordinatewith the enterprise risk management team, internal audit, and otherfunctions withinthe cyber risk team to ensureappropriateoversightand management of cyber risks and controls in-line with OneMain's enterprise riskmanagementframework.

  • Partner with cybersecurity architects, engineers, andtechnologyoperations teams to ensuregovernance programsforaccess privileges,applications, cloud environments, asset management, artificial intelligence, and other technology functionsareimplementedandmaintainedaccording tocybersecuritystandardsand guidelines.

  • Lead a metrics and reporting program to measure the efficiency and effectiveness of the cybersecurity program for senior management providing insights,trendsand recommendations.

Qualifications:

  • Bachelor's Degree with a focus in Cybersecurity, Information Technology disciplines or equivalent experience.

  • Minimum of 5 - 7 yearsofexperience inplanning, designing,implementingand managingtechnology and cybersecurity governanceandcontrolsframeworkin the financial industry or other regulated industry.

  • Minimum 3 - 5 years in a leadership rolewith a strong ability to influence peers,leadersand team members at all levels and across functional lines.

  • In-depth knowledge of cybersecurity frameworks, such as NIST, SOC2,andCIS.

  • In-depth knowledge of cybersecurity laws and regulations, industry standards and best practicesincludingGLBA 501(b),NYDFSand PCI.

  • Excellent verbal and written communication and presentation skillswith the ability to prepare and deliver complex data in a way that is concise/understandable.

  • Strong organizational and program management skills. Ability to effectively respond to shifting priorities and assignments.

  • Sound analytical, problem solving andresearchskills.

  • Proficient incomputerskills in Microsoft Office suite - Word, Excel, and PowerPoint.

  • Familiarity withGRC, metrics, and reporting tools likeArcher,Anecdotes,Power BI, or equivalent software a plus.

  • Self-motivation with proven ability to be adaptable to a dynamic, fast-pacedwork environment with multiple priorities and strict timelines.

OneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.


What OneMain Financial employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom