Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Policy and Compliance Lead

Koniag Services, Inc.

Job Overview Koniag Data Solutions, LLC, a Koniag Government Services company, is seeking a Security Policy and Compliance Lead to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust. We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more. Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Security Policy and Compliance Lead to support the U.S. Small Business Administration (SBA). The ideal candidate is a seasoned cybersecurity professional with deep expertise in federal security policy development, compliance program management, and the application of federal cybersecurity frameworks and regulations within complex federal government environments. This individual will serve as the primary subject matter expert (SME) for security policy and compliance activities at the SBA, providing strategic guidance, technical leadership, and hands‑on program management to ensure the agency’s cybersecurity policies, procedures, and practices align with applicable federal laws, regulations, executive orders, and industry best practices. The Security Policy and Compliance Lead will serve as the senior expert responsible for leading and managing SBA’s security policy and compliance programs, ensuring the agency’s cybersecurity posture aligns with federal security requirements, regulatory obligations, and organizational risk tolerance. Principal Responsibilities Serve as the primary subject matter expert (SME) and program lead for SBA’s security policy and compliance programs, providing strategic direction, technical guidance, and hands‑on leadership to ensure the agency’s cybersecurity policies, procedures, and practices meet all applicable federal security requirements and regulatory obligations. Lead the development, review, maintenance, and continuous improvement of SBA’s cybersecurity policy framework, including agency‑wide security policies, standards, procedures, guidelines, and baselines, ensuring alignment with NIST, FISMA, OMB, and CISA requirements and directives. Oversee and manage SBA’s compliance program, ensuring the agency’s IT systems, security controls, and operational practices comply with applicable federal cybersecurity laws, regulations, executive orders, and OMB mandates, including FISMA, OMB Circular A-130, and relevant CISA Binding Operational Directives (BODs) and Emergency Directives (EDs). Lead and support the NIST Risk Management Framework (RMF) process across SBA’s system portfolio, providing expert guidance on security categorization, control selection, implementation, assessment, authorization, and continuous monitoring activities. Develop, maintain, and continuously improve SBA’s continuous monitoring program, including the development of monitoring strategies, assessment schedules, and reporting mechanisms to track the ongoing security posture of SBA’s information systems and report compliance status to agency leadership. Oversee the preparation and submission of SBA’s annual FISMA reporting requirements, coordinating with system owners, security control assessors, and agency leadership to compile accurate and comprehensive FISMA metrics and performance data. Collaborate with SBA IT teams, system owners, program offices, and the Office of Inspector General (OIG) to address audit findings, compliance gaps, and POA&M (Plan of Action and Milestones) items, developing and tracking corrective action plans to ensure timely resolution. Lead the development and maintenance of SBA’s Plan of Action and Milestones (POA&M) program, overseeing the identification, tracking, prioritization, and remediation of security weaknesses and compliance deficiencies across SBA’s system portfolio. Provide expert guidance and support for third‑party security assessments, audits, and evaluations, including those conducted by the OIG, GAO, and other oversight bodies, coordinating SBA’s response to audit findings and recommendations. Develop and maintain a comprehensive security compliance roadmap and reporting framework, providing SBA leadership with regular visibility into the agency’s compliance posture, outstanding risks, and remediation progress. Monitor and analyze changes to federal cybersecurity laws, regulations, executive orders, OMB guidance, and CISA directives, assessing their impact on SBA’s security policy and compliance programs and leading the timely implementation of required program updates and changes. Collaborate with the Cybersecurity Architect, SOC, privacy, and other cybersecurity program teams to ensure security policies and compliance requirements are integrated into technical operations, system design, and security architecture activities. Develop and deliver security policy and compliance awareness training and briefings to SBA personnel, system owners, and leadership, fostering a culture of security compliance and shared accountability across the agency. Support the development and maintenance of SBA’s cybersecurity strategy and roadmap, providing expert input on policy and compliance considerations to inform agency‑wide security investment and improvement decisions. Serve as a liaison with external stakeholders, including OMB, CISA, DHS, and other federal agencies, on security policy and compliance matters, representing SBA’s interests and ensuring alignment with governmentwide cybersecurity policy initiatives and mandates. Education and Experience Bachelor’s degree in Cybersecurity, Information Technology, Information Assurance, Computer Science, or a related field from an accredited college or university. 8+ years of progressive experience in cybersecurity policy, compliance, information assurance, or a related field, with at least 3 years in a lead or senior role managing federal security policy and compliance programs. Demonstrated experience managing federal cybersecurity compliance programs, including FISMA reporting, RMF implementation, and POA&M management, within a federal government agency or supporting a federal government customer. In‑depth knowledge of federal cybersecurity laws, regulations, and guidance, including FISMA, OMB Circular A-130, NIST SP 800‑53, NIST RMF, and applicable CISA BODs and EDs. One or more of the following certifications: Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) GIAC Security Essentials (GSEC) CompTIA Security+ (with demonstrated senior‑level experience in policy and compliance roles) Certified Authorization Professional (CAP) / ISC2 Certified in Governance, Risk and Compliance (CGRC) Master’s degree in Cybersecurity, Information Assurance, Public Administration, or a related field. 10+ years of experience in federal cybersecurity policy and compliance program management, with demonstrated experience supporting a federal civilian agency of similar size and complexity to the SBA. Required Skills and Competencies Exceptional communication skills in English – both written and oral – with the ability to clearly communicate complex security policy, compliance, and regulatory requirements to diverse audiences, including technical staff, program managers, system owners, and senior agency leadership. Deep expertise in federal cybersecurity frameworks, laws, and regulations, including FISMA, OMB Circular A-130, NIST SP 800‑53, NIST RMF, NIST CSF, and applicable CISA BODs, EDs, and guidance documents. Comprehensive knowledge of the NIST Risk Management Framework (RMF) process, including security categorization (FIPS 199), control selection and tailoring (NIST SP 800‑53), security assessment (NIST SP 800‑53A), authorization, and continuous monitoring (NIST SP 800‑137). Strong experience developing, reviewing, and maintaining federal cybersecurity policy documentation, including agency security policies, standards, procedures, guidelines, system security plans (SSPs), and security assessment reports (SARs). Demonstrated experience leading and managing federal FISMA compliance programs, including the preparation and submission of annual FISMA reports, performance metrics, and supporting documentation. Experience developing and managing POA&M programs, including the identification, tracking, prioritization, and remediation of security weaknesses and compliance deficiencies across complex federal system portfolios. Proficiency in developing and managing continuous monitoring programs, including the development of monitoring strategies, assessment schedules, and compliance reporting mechanisms aligned with NIST SP 800‑137 and CISA CDM program requirements. Experience supporting third‑party security audits, assessments, and evaluations, including those conducted by the OIG, GAO, and independent assessors, and coordinating agency responses to audit findings and recommendations. Strong knowledge of federal IT governance frameworks and their relationship to cybersecurity policy and compliance, including OMB IT governance requirements, Federal Enterprise Architecture (FEA), and FITARA. Ability to develop and deliver effective security policy and compliance awareness training and briefings to diverse federal agency audiences, including technical staff, program managers, and senior leadership. Strong analytical and problem‑solving skills, with the ability to assess complex compliance challenges, identify root causes, and develop practical, risk‑informed remediation strategies. Ability to obtain and maintain a Public Trust Clearance. Desired Skills and Competencies Prior experience supporting SBA or other federal civilian agency security policy and compliance programs, with demonstrated knowledge of SBA’s mission, IT environment, and cybersecurity compliance obligations. Experience with GRC (Governance, Risk, and Compliance) platforms and tools, such as Archer, ServiceNow GRC, CSAM, or similar, for managing security compliance, POA&M tracking, and RMF documentation within a federal environment. Familiarity with cloud security compliance requirements, including FedRAMP authorization processes, FedRAMP continuous monitoring requirements, and the security compliance implications of cloud service adoption within federal agencies. Knowledge of supply chain risk management (SCRM) frameworks and their integration into federal agency cybersecurity policy and compliance programs, including NIST SP 800‑161 and applicable OMB guidance. Experience supporting federal agency responses to CISA Binding Operational Directives (BODs) and Emergency Directives (EDs), including the development and tracking of agency implementation plans and compliance reporting. Familiarity with the CDM (Continuous Diagnostics and Mitigation) program, its tools and data requirements, and the integration of CDM capabilities into agency continuous monitoring and compliance programs. Experience developing and managing cybersecurity policy and compliance programs that address emerging technology areas, including artificial intelligence, cloud computing, and zero‑trust architecture implementation. Knowledge of federal records management requirements and their intersection with cybersecurity policy and compliance obligations, including NARA guidance and federal records schedules. Experience supporting federal agency interactions with oversight bodies, including the OIG, GAO, and congressional oversight committees, on cybersecurity policy and compliance matters. Familiarity with privacy law and its intersection with cybersecurity policy and compliance, including the Privacy Act of 1974, OMB privacy guidance, and NIST privacy controls. Certified in Risk and Information Systems Control (CRISC) certification. Experience developing enterprise cybersecurity compliance dashboards, scorecards, and executive reporting mechanisms to provide agency leadership with real‑time visibility into compliance posture and risk levels. Equal Employment Opportunity Policy The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment. Equal Opportunity Employer/Veterans/Disabled.Shareholder Preference in accordance with Public Law 88-352 #J-18808-Ljbffr Koniag Services, Inc.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Security Policy and Compliance Lead in Washington DC vacancy
  •  ...Description Job Description Description: XSI is seeking a Lead Cyber Security Analysis SME to anchor the cybersecurity engineering...  ...a senior, hands-on engineering leadership role — not a policy, compliance, or SOC-monitoring position. You will lead technical... 
    Policy
    Work at office

    Xtreme Solutions Corporate

    Washington DC
    a month ago
  •  ...in Arlington, Virginia is seeking a FOIA Specialist responsible for processing Freedom of Information Act requests and ensuring compliance with federal regulations. The role involves analyzing various records, coordinating responses with agency staff, and maintaining... 
    Policy

    System High Corporation

    Arlington, VA
    1 day ago
  • Jobtailor seeks a seasoned DoD Security Administrator to manage and implement security policies across JIAMDO and partner organizations. You will ensure SCI...  ...administration experience and a track record of leading compliance efforts in complex environments. #J-18808-... 
    Policy

    Jobtailor

    Arlington, VA
    4 days ago
  •  ...Arlington, VA seeks a Subcontractor & Procurement Specialist to lead end-to-end procure-to-pay for vendors and subcontractors, negotiate contracts under FAR/DFARS, and ensure compliance with security policies. The role reports to Contracts, interacting with CFO and CEO,... 
    Policy
    Full time
    For subcontractor
    Work at office

    Apogee Research, LLC

    Arlington, VA
    1 day ago
  •  ...Join Improbable U.S. Defense & National Security and you will help users leverage our...  ....    Your Mission The Security & Compliance Lead/Facility Security Officer (“FSO”) manages...  ...government regulations and Company security policies and procedures to maintain the Company’... 
    Policy
    For contractors
    Flexible hours

    Improbable LLC

    Arlington, VA
    more than 2 months ago
  •  ...services and solutions in: National Security Programs Professional, Administrative...  ...: Contingent Position Title: System Compliance Lead Location:Washington, DC Clearance...  ...and are in accordance with DHS and TSA policies: Research major obstacles related to... 
    Policy
    Full time
    For contractors

    gTANGIBLE Corporation

    Washington DC
    more than 2 months ago
  • $140k - $170k

    Cypress Creek Energy in Washington, DC is seeking an Information Security Manager to lead security operations and compliance. The successful candidate will manage tools like Microsoft Defender and Zscaler, enhancing security posture and ensuring compliance with NIST standards... 
    Policy

    Cypress Creek Energy

    Washington DC
    1 day ago
  • $39k - $77k

    Security Management Lead (SML) - Junior Work Location: Washington, DC Employment Type: Full‑Time, Junior‑Level Department: Administrative...  ...Lead security program activities, enforce security policies, and coordinate compliance across mission operations. Collaborate with cross‑... 
    Policy
    Full time
    Flexible hours

    Contact Government Services, LLC

    Washington DC
    5 days ago
  • A leading technology firm seeks a Security Policy and Compliance Lead in Washington, DC. Ideal candidates will possess 5+ years in developing security documentation and implementing NIST standards, alongside a CISSP certification. The position focuses on enhancing skills... 
    Policy

    Njvc LLC

    Washington DC
    1 day ago
  • $72.4k

     ...work in international trade compliance? Are you passionate about ensuring...  ...nation on critical national security space and national health...  ...International Trade Program Lead with expertise in International...  ...of compensation per internal policy and/or contractual designation... 
    Policy
    Contract work
    Temporary work
    Work experience placement
    Interim role
    Relocation package
    Flexible hours

    Johns Hopkins Applied Physics Lab

    Laurel, MD
    1 day ago
  •  ...Assurance Devices. This role ensures compliance with DoD security and accreditation requirements, supports...  ...:The COMSEC Engineer - Functional Lead performs COMSEC engineering for the F‑...  ...which the company has facilities. This policy applies to all terms and conditions of... 
    Policy
    For contractors
    Work experience placement
    Local area
    Relocation

    Armada Ltd

    Arlington, VA
    12 days ago
  • Armada LTD is seeking a full-time Security Manager located in Falls Church, VA. The role involves providing policy support and technical guidance for security, managing compliance programs, and ensuring effective background checks. The ideal candidate should possess a Bachelor... 
    Policy
    Full time

    Armada LTD

    Falls Church, VA
    3 days ago
  •  ...Focus, and Proactive Safety & Security’ are what every employee needs...  ....    JOB SUMMARY:   The Lead Enterprise Fraud Risk Analyst is...  ...using data analysis to assess compliance with applicable laws, regulations, and internal policies Identify opportunities to enhance... 
    Policy
    Hourly pay
    Permanent employment
    Temporary work
    Work experience placement
    Interim role
    Local area
    Relocation
    Flexible hours

    Amtrak

    Washington DC
    16 days ago
  • DescriptionSAIC is seeking a Policy and Proposal Lead to support multiple customers within the Department of Navy (DON), including the office of...  ...the Deputy Undersecretary of the Navy for Intelligence and Security (DUSN I&S) and Naval Criminal Investigative Service (NCIS).... 
    Policy
    Work at office
    Remote work

    Science Applications International Corporation

    Arlington, VA
    1 day ago
  • $83k - $167k

     ...On-Site /On-siteSecurity Management Lead (SML) - SME Work Location: Washington...  ...Support CGS is seeking a skilled Security Management Lead (SML) - SME to support...  ...program activities, enforce security policies, and coordinate compliance across mission operations.... 
    Policy
    Full time

    CONTACT GOVERNMENT SERVICES

    Washington DC
    16 hours ago
  •  ...Group is seeking a Call Order Lead to own delivery, staffing,...  ...fill them, track your team's security and clearance processing through...  ...labor charging, and contract compliance.ClearanceApplicants selected...  ...planning, program management, policy development, operational... 
    Policy
    Contract work
    Work at office
    Local area
    Immediate start
    Flexible hours

    Red Gate

    Arlington, VA
    16 hours ago
  •  ...technical solutions to complex national security issues. With over 50 years of business expertise...  ...and reporting activities. You will lead and assist in analyzing and managing all...  ...), as well as applicable DoD Acquisition policy guidance. You will also be expected to provide... 
    Policy
    Full time
    Contract work
    Work experience placement
    Work at office
    Flexible hours

    MCR

    Washington DC
    3 days ago
  • $153k - $225k

     ...Mechanical and Fire Protection Lead with the potential to work...  ...mechanical engineers' work for code compliance and constructability.Estimate...  ...Code of Conduct and related policies and proceduresProven track...  ...a US Government issued security clearance or CAC.WSP Benefits... 
    Policy
    For contractors
    Local area
    Flexible hours

    WSP Group

    Arlington, VA
    1 day ago
  •  ...technical solutions to complex national security issues. With over 50 years of business expertise...  ...technical, operational, programmatic, policy and business analysis to NAVSEA Team...  ...Ship Control System Integration Team (SIT) Lead will support the Team Submarine SSN(X) Future... 
    Policy
    Full time
    Contract work
    Work at office
    Flexible hours

    MCR

    Washington DC
    4 days ago
  •  ...Tetra Tech is adding a SME/Team Lead to our Tetra Tech team based...  ...Position Summary:The Defense Security Cooperation Agency (DSCA)...  ...management, monitoring & evaluation, policy and international affairs,...  ...technical quality and policy compliance of deliverables, and... 
    Policy
    Contract work
    For contractors
    Work at office
    Worldwide

    Tetra Tech

    Arlington, VA
    1 day ago
  •  ...growing government contractor providing leading-edge support to federal customers, with a...  ...particular focus on Defense and National Security mission sets. We leverage more than 17 years...  ...under the Military Community and Family Policy (MC&FP) Outreach and Digital Enterprise... 
    Policy
    Contract work
    For contractors
    Work at office

    Barbaricum

    Washington DC
    3 days ago
  •  ...growing government contractor providing leading-edge support to federal customers, with a...  ...particular focus on Defense and National Security mission sets. We leverage more than 17 years...  ...under the Military Community and Family Policy (MC&FP) Outreach and Digital Enterprise... 
    Policy
    Contract work
    For contractors
    Local area

    Barbaricum

    Washington DC
    3 days ago
  • $89k - $105k

     ...Expectations are high, and so are the rewards. The compliance team supporting Robinhood’s credit card...  ...while supporting business goals.As Lead Compliance Analyst, you will play a...  ...maintenance, and implementation of compliance policies, procedures, and training materials.... 
    Policy
    Work at office
    Flexible hours
    Shift work
    3 days per week

    Robinhood Financial

    Washington DC
    1 day ago
  • $156.5k - $191.2k

     .... Connect. Grow. with KBR!KBR’s National Security Solutions team provides high-end engineering...  ...qualified candidate to act as Team Lead for a team supporting the Chief Information...  ...certain job titles or levels, per internal policy or contractual designation. Additional... 
    Policy
    Full time
    Contract work
    Temporary work
    For contractors
    For subcontractor
    Work at office
    Local area
    Relocation package
    Flexible hours

    KBR

    Bethesda, MD
    4 days ago
  •  ...growing government contractor providing leading-edge support to federal customers, with a...  ...particular focus on Defense and National Security mission sets. We leverage more than 17 years...  ...under the Military Community and Family Policy (MC&FP) Outreach and Digital Enterprise... 
    Policy
    Contract work
    For contractors

    Barbaricum

    Washington DC
    3 days ago
  • $94k - $151.8k

     ...Enterprise Strategy & SecurityJob Sub Function: Security & ControlsJob Category:Scientific/...  ...searching for top talent for Cybersecurity Lead, You will be the Business Information...  ...Process Optimization, Report Writing, Security Policies, Technical Credibility, Technologically... 
    Policy
    Full time
    Local area
    Immediate start
    Remote work

    Johnson & Johnson

    Washington DC
    1 day ago
  • $222k - $332k

     ...customers in the intelligence and national security communities. In this position, your work...  ...to hire a Navy/Maritime Division Growth Lead who will work in partnership with D&I operations...  ...job titles or levels, per internal policy or contractual designation. Additional... 
    Policy
    Full time
    Temporary work
    Casual work
    Local area
    Relocation package
    Flexible hours

    KBR

    Arlington, VA
    1 day ago
  •  ...government contractor providing leading-edge support to federal...  ...focus on Defense and National Security mission sets. We leverage more...  ...Military Community and Family Policy (MC&FP) Outreach and Digital...  ...consistency, effectiveness, and compliance with brand standards.Manage... 
    Policy
    Contract work
    For contractors

    Barbaricum

    Washington DC
    3 days ago
  • About DMIDMI is a leading provider of digital services and technology solutions,...  ...Workplace, DMI is committed to delivering secure, efficient, and cost-effective...  ...needed.Develop and enforce security policies, controls, and compliance standards across Oracle Cloud applications... 
    Policy
    Work experience placement

    DMI Mobile Enterprise Solutions

    Washington DC
    5 days ago
  •  ...solutions based on industry-leading practices. ProSidian provides...  ...solutions for Risk Management | Compliance | Business Process | IT...  ...intersections of assets, processes, policies, and people delivering value....  ...- Identifying, pursuing, and securing growth opportunities through... 
    Policy
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Alexandria, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Policy and Compliance Lead. Be the first to apply!