1

Manager Cyber Security Governance Jobs (NOW HIRING)

The Deputy Cybersecurity Governance Lead provides deep technical and operational oversight for ... Report directly to the SPMO Manager and support execution of governance, compliance, and ...

The Deputy Cybersecurity Governance Lead provides deep technical and operational oversight for ... Report directly to the SPMO Manager and support execution of governance, compliance, and ...

The Deputy Cybersecurity Governance Lead provides deep technical and operational oversight for ... Report directly to the SPMO Manager and support execution of governance, compliance, and ...

Manager, Cybersecurity

Poughkeepsie, NY · On-site

$105K - $110K/yr

Manager, Cybersecurity Department/School: Cybersecurity, Information Technology Salary/Pay Rate ... Expand the existing Governance, Risk and Compliance program to improve the maturity of the cyber ...

Manager, Cybersecurity Apply now Posting Number: 493995 Type of Position: Full-time Location ... Expand the existing Governance, Risk and Compliance program to improve the maturity of the cyber ...

$106K - $142K/yr

Information Technology also conducts incident response, threat management, vulnerability scanning ... Job Summary The Vice President - Cybersecurity Governance, Risk & Compliance is a senior executive ...

Manager, Cybersecurity

Poughkeepsie, NY · On-site

$105K - $110K/yr

Manager, Cybersecurity Department/School: Cybersecurity, Information Technology Salary/Pay Rate ... Expand the existing Governance, Risk and Compliance program to improve the maturity of the cyber ...

next page

Showing results 1-20

Manager Cyber Security Governance information

See salary details

$57K

$133K

$186K

How much do manager cyber security governance jobs pay per year?

As of Jun 12, 2026, the average yearly pay for manager cyber security governance in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Manager Cyber Security Governance, and why are they important?

To thrive as a Manager Cyber Security Governance, you need a deep understanding of information security frameworks, risk management, and regulatory compliance, typically supported by a degree in cybersecurity or a related field. Familiarity with standards such as ISO 27001, NIST, and tools like GRC (Governance, Risk, and Compliance) platforms, as well as certifications like CISSP or CISM, is highly valued. Exceptional leadership, communication, and analytical skills help you effectively guide teams and communicate complex security concepts to stakeholders. These competencies are vital to ensure robust cybersecurity posture, regulatory compliance, and alignment of security initiatives with organizational goals.

What are some common challenges faced by a Manager of Cyber Security Governance, and how can they be addressed?

A Manager of Cyber Security Governance often encounters challenges like aligning security policies with evolving regulatory requirements, ensuring company-wide compliance, and managing stakeholder expectations. Balancing strict security controls with business agility can also be difficult, especially in fast-paced environments. Success in this role typically involves strong communication skills, ongoing training, and fostering collaboration between IT, legal, and business teams to create a security-aware culture. Regular policy reviews and proactive risk assessments can further help in addressing these challenges effectively.

What does a Manager Cyber Security Governance do?

A Manager Cyber Security Governance oversees the development and implementation of policies, standards, and procedures to ensure an organization’s information security practices meet regulatory and business requirements. They coordinate risk assessments, manage compliance initiatives, and work closely with other departments to align security strategies with organizational goals. This role also involves monitoring for regulatory changes, providing guidance on best practices, and ensuring continuous improvement of the cyber security governance framework.

What is the difference between Manager Cyber Security Governance vs Cyber Security Analyst?

AspectManager Cyber Security GovernanceCyber Security Analyst
CertificationsCISSP, CISM, CISACompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentLeadership, policy development, strategic planningTechnical analysis, monitoring, incident response
Employer & Industry UsageOrganizations with security governance teamsSecurity operations centers, IT departments

The Manager Cyber Security Governance focuses on establishing security policies, compliance, and strategic oversight, while the Cyber Security Analyst handles technical security monitoring, threat detection, and incident response. Both roles require relevant certifications and work within the cybersecurity field, but their responsibilities and focus areas differ significantly.

What cities are hiring for Manager Cyber Security Governance jobs? Cities with the most Manager Cyber Security Governance job openings:
What are the most commonly searched types of Cyber Security Governance jobs? The most popular types of Cyber Security Governance jobs are:
What states have the most Manager Cyber Security Governance jobs? States with the most job openings for Manager Cyber Security Governance jobs include:
Deputy Cybersecurity Governance Lead

Deputy Cybersecurity Governance Lead

Science Applications International Corporation

Washington, DC • Hybrid

$131K/yr

Other

Posted 9 days ago


SAIC rating

7.8

Company rating: 7.8 out of 10

Based on 78 frontline employees who took The Breakroom Quiz

71st of 204 rated it services


Job description

SAIC is seeking a Deputy Cybersecurity Governance Lead to support a critical U.S. government agency in the National Capital Region. This role serves as a senior operational and technical lead supporting the Security Program Management Office (SPMO) Manager and is responsible for overseeing Information System Security Officer (ISSO) operations, authorization activities, and risk management functions across a portfolio of systems.

The Deputy Cybersecurity Governance Lead provides deep technical and operational oversight for teams responsible for system security, assessment and authorization, continuous monitoring, and risk management activities. This is a hands-on player/coach role that combines strong federal cybersecurity expertise with team leadership, operational coordination, and oversight of day-to-day Governance, Risk and Compliance (GRC) activities..

This hybrid role requires a minimum of three on-site days per week in Washington, DC.

Responsibilities:

  • Report directly to the SPMO Manager and support execution of governance, compliance, and operational security activities across the environment.
  • Provide day-to-day operational leadership across GRC workstreams, including Risk Management, Assessment & Authorization, Continuous Monitoring, and Audit Support.
  • Oversee operations and provide leadership and operational oversight for personnel supporting assigned systems and workstreams.
  • Provide technical guidance, mentorship, prioritization support, and quality review for ISSO deliverables and operational activities.
  • Oversee development, review, and quality assurance of Security Authorization packages, including SSPs, SARs, POA&Ms, SIAs, Risk Acceptance requests, and related security artifacts across multiple systems.
  • Coordinate and prepare systems for Security Control Assessments (SCAs), ensuring completeness, accuracy, and audit readiness of all artifacts.
  • Ensure effective implementation, assessment, and monitoring of security controls in accordance with NIST SP 800-53, RMF, and agency security policies.
  • Lead POA&M lifecycle management, including development, tracking, remediation validation, and closure assessments.
  • Oversee Risk Acceptance processes, ensuring proper documentation, justification, and alignment with system risk posture.
  • Manage and enforce continuous monitoring activities, ensuring control effectiveness and ongoing authorization compliance.
  • Coordinate audit support activities, including PBC responses, audit data calls, audit brief development, and remediation tracking activities.
  • Lead development of audit response packages and support FISMA and A-130 reporting requirements.
  • Coordinate with government stakeholders, system owners, engineering teams, and security personnel to resolve compliance and risk issues.
  • Coordinate with external security operations and infrastructure teams regarding remediation status, risk impacts, and compliance tracking activities.
  • Establish and enforce quality standards for GRC deliverables and ensure documentation accurately reflects implemented system controls and configurations.
  • Oversee task tracking, prioritization, reporting, and execution across team activities to ensure contract deliverables and timelines are met.
  • Identify process gaps and implement improvements to increase efficiency, reduce RMF cycle time, and enhance audit readiness.
  • Prepare and deliver executive-level reports, risk briefings, metrics, and status updates to internal and external stakeholders.
  • Oversee development and maintenance of operational dashboards, reporting metrics, and workflow tracking artifacts using tools such as SharePoint and PowerBI.
SAIC is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.

We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.

Requirements:

  • Bachelor's degree and 10+ years of IT security, GRC, RMF, or systems security engineering experience, or Master's degree with 8+ years of experience.
  • Minimum 3+ years of experience leading teams or overseeing operational cybersecurity activities in a federal environment.
  • Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card. 
  • Strong technical background in federal cybersecurity, including hands-on experience with RMF implementation, security controls, system authorization, risk management, and continuous monitoring.
  • Demonstrated experience supporting ATO processes, authorization artifacts (SSP, SAR, POA&M, SIA), Risk Acceptance activities, and assessment events.
  • Strong understanding of NIST RMF, NIST SP 800-53, FISMA, and federal cybersecurity policies and guidance.
  • Experience coordinating across engineering, operations, compliance, and stakeholder teams within complex enterprise environments.
  • Ability to drive accountability, prioritization, and execution across multiple stakeholders and workstreams.
  • Strong understanding of enterprise IT environments, including cloud (AWS, Azure, GCP) and hybrid architectures.
  • Familiarity with enterprise platforms such as Microsoft 365, Azure AD, Cisco, and Oracle.
  • Experience with GRC and SA&A tools such as Archer, eMASS, JCAM/CSAM, or Xacta.
  • Strong documentation, reporting, analytical, leadership, and communication skills, including the ability to convey complex technical issues to non-technical audiences.
  • Experience using SharePoint and PowerBI to support reporting, metrics tracking, workflow management, and executive visibility activities. 
  • Proficient in Microsoft Office (Word, Excel, PowerPoint, SharePoint).

Preferred Qualifications:

  • Prior experience functioning in an ISSM, Deputy ISSM, Lead ISSO, or GRC Lead role within a federal environment.
  • CISSP (strongly preferred), CISM, CAP, CRISC, and/or PMP certification.
  • Experience supporting enterprise-level or multi-system federal portfolios.
  • Familiarity with FedRAMP, cloud compliance requirements, and federal privacy regulations.
  • Familiarity with cloud security, enterprise architectures, and modern federal cybersecurity practices.
  • Ability to operate effectively in a fast-paced, high-visibility environment with competing priorities.

What SAIC employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom