Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Policy and Compliance Lead

Koniag Services, Inc.

Job Overview Koniag Data Solutions, LLC, a Koniag Government Services company, is seeking a Security Policy and Compliance Lead to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust. We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more. Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Security Policy and Compliance Lead to support the U.S. Small Business Administration (SBA). The ideal candidate is a seasoned cybersecurity professional with deep expertise in federal security policy development, compliance program management, and the application of federal cybersecurity frameworks and regulations within complex federal government environments. This individual will serve as the primary subject matter expert (SME) for security policy and compliance activities at the SBA, providing strategic guidance, technical leadership, and hands‑on program management to ensure the agency’s cybersecurity policies, procedures, and practices align with applicable federal laws, regulations, executive orders, and industry best practices. The Security Policy and Compliance Lead will serve as the senior expert responsible for leading and managing SBA’s security policy and compliance programs, ensuring the agency’s cybersecurity posture aligns with federal security requirements, regulatory obligations, and organizational risk tolerance. Principal Responsibilities Serve as the primary subject matter expert (SME) and program lead for SBA’s security policy and compliance programs, providing strategic direction, technical guidance, and hands‑on leadership to ensure the agency’s cybersecurity policies, procedures, and practices meet all applicable federal security requirements and regulatory obligations. Lead the development, review, maintenance, and continuous improvement of SBA’s cybersecurity policy framework, including agency‑wide security policies, standards, procedures, guidelines, and baselines, ensuring alignment with NIST, FISMA, OMB, and CISA requirements and directives. Oversee and manage SBA’s compliance program, ensuring the agency’s IT systems, security controls, and operational practices comply with applicable federal cybersecurity laws, regulations, executive orders, and OMB mandates, including FISMA, OMB Circular A-130, and relevant CISA Binding Operational Directives (BODs) and Emergency Directives (EDs). Lead and support the NIST Risk Management Framework (RMF) process across SBA’s system portfolio, providing expert guidance on security categorization, control selection, implementation, assessment, authorization, and continuous monitoring activities. Develop, maintain, and continuously improve SBA’s continuous monitoring program, including the development of monitoring strategies, assessment schedules, and reporting mechanisms to track the ongoing security posture of SBA’s information systems and report compliance status to agency leadership. Oversee the preparation and submission of SBA’s annual FISMA reporting requirements, coordinating with system owners, security control assessors, and agency leadership to compile accurate and comprehensive FISMA metrics and performance data. Collaborate with SBA IT teams, system owners, program offices, and the Office of Inspector General (OIG) to address audit findings, compliance gaps, and POA&M (Plan of Action and Milestones) items, developing and tracking corrective action plans to ensure timely resolution. Lead the development and maintenance of SBA’s Plan of Action and Milestones (POA&M) program, overseeing the identification, tracking, prioritization, and remediation of security weaknesses and compliance deficiencies across SBA’s system portfolio. Provide expert guidance and support for third‑party security assessments, audits, and evaluations, including those conducted by the OIG, GAO, and other oversight bodies, coordinating SBA’s response to audit findings and recommendations. Develop and maintain a comprehensive security compliance roadmap and reporting framework, providing SBA leadership with regular visibility into the agency’s compliance posture, outstanding risks, and remediation progress. Monitor and analyze changes to federal cybersecurity laws, regulations, executive orders, OMB guidance, and CISA directives, assessing their impact on SBA’s security policy and compliance programs and leading the timely implementation of required program updates and changes. Collaborate with the Cybersecurity Architect, SOC, privacy, and other cybersecurity program teams to ensure security policies and compliance requirements are integrated into technical operations, system design, and security architecture activities. Develop and deliver security policy and compliance awareness training and briefings to SBA personnel, system owners, and leadership, fostering a culture of security compliance and shared accountability across the agency. Support the development and maintenance of SBA’s cybersecurity strategy and roadmap, providing expert input on policy and compliance considerations to inform agency‑wide security investment and improvement decisions. Serve as a liaison with external stakeholders, including OMB, CISA, DHS, and other federal agencies, on security policy and compliance matters, representing SBA’s interests and ensuring alignment with governmentwide cybersecurity policy initiatives and mandates. Education and Experience Bachelor’s degree in Cybersecurity, Information Technology, Information Assurance, Computer Science, or a related field from an accredited college or university. 8+ years of progressive experience in cybersecurity policy, compliance, information assurance, or a related field, with at least 3 years in a lead or senior role managing federal security policy and compliance programs. Demonstrated experience managing federal cybersecurity compliance programs, including FISMA reporting, RMF implementation, and POA&M management, within a federal government agency or supporting a federal government customer. In‑depth knowledge of federal cybersecurity laws, regulations, and guidance, including FISMA, OMB Circular A-130, NIST SP 800‑53, NIST RMF, and applicable CISA BODs and EDs. One or more of the following certifications: Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) GIAC Security Essentials (GSEC) CompTIA Security+ (with demonstrated senior‑level experience in policy and compliance roles) Certified Authorization Professional (CAP) / ISC2 Certified in Governance, Risk and Compliance (CGRC) Master’s degree in Cybersecurity, Information Assurance, Public Administration, or a related field. 10+ years of experience in federal cybersecurity policy and compliance program management, with demonstrated experience supporting a federal civilian agency of similar size and complexity to the SBA. Required Skills and Competencies Exceptional communication skills in English – both written and oral – with the ability to clearly communicate complex security policy, compliance, and regulatory requirements to diverse audiences, including technical staff, program managers, system owners, and senior agency leadership. Deep expertise in federal cybersecurity frameworks, laws, and regulations, including FISMA, OMB Circular A-130, NIST SP 800‑53, NIST RMF, NIST CSF, and applicable CISA BODs, EDs, and guidance documents. Comprehensive knowledge of the NIST Risk Management Framework (RMF) process, including security categorization (FIPS 199), control selection and tailoring (NIST SP 800‑53), security assessment (NIST SP 800‑53A), authorization, and continuous monitoring (NIST SP 800‑137). Strong experience developing, reviewing, and maintaining federal cybersecurity policy documentation, including agency security policies, standards, procedures, guidelines, system security plans (SSPs), and security assessment reports (SARs). Demonstrated experience leading and managing federal FISMA compliance programs, including the preparation and submission of annual FISMA reports, performance metrics, and supporting documentation. Experience developing and managing POA&M programs, including the identification, tracking, prioritization, and remediation of security weaknesses and compliance deficiencies across complex federal system portfolios. Proficiency in developing and managing continuous monitoring programs, including the development of monitoring strategies, assessment schedules, and compliance reporting mechanisms aligned with NIST SP 800‑137 and CISA CDM program requirements. Experience supporting third‑party security audits, assessments, and evaluations, including those conducted by the OIG, GAO, and independent assessors, and coordinating agency responses to audit findings and recommendations. Strong knowledge of federal IT governance frameworks and their relationship to cybersecurity policy and compliance, including OMB IT governance requirements, Federal Enterprise Architecture (FEA), and FITARA. Ability to develop and deliver effective security policy and compliance awareness training and briefings to diverse federal agency audiences, including technical staff, program managers, and senior leadership. Strong analytical and problem‑solving skills, with the ability to assess complex compliance challenges, identify root causes, and develop practical, risk‑informed remediation strategies. Ability to obtain and maintain a Public Trust Clearance. Desired Skills and Competencies Prior experience supporting SBA or other federal civilian agency security policy and compliance programs, with demonstrated knowledge of SBA’s mission, IT environment, and cybersecurity compliance obligations. Experience with GRC (Governance, Risk, and Compliance) platforms and tools, such as Archer, ServiceNow GRC, CSAM, or similar, for managing security compliance, POA&M tracking, and RMF documentation within a federal environment. Familiarity with cloud security compliance requirements, including FedRAMP authorization processes, FedRAMP continuous monitoring requirements, and the security compliance implications of cloud service adoption within federal agencies. Knowledge of supply chain risk management (SCRM) frameworks and their integration into federal agency cybersecurity policy and compliance programs, including NIST SP 800‑161 and applicable OMB guidance. Experience supporting federal agency responses to CISA Binding Operational Directives (BODs) and Emergency Directives (EDs), including the development and tracking of agency implementation plans and compliance reporting. Familiarity with the CDM (Continuous Diagnostics and Mitigation) program, its tools and data requirements, and the integration of CDM capabilities into agency continuous monitoring and compliance programs. Experience developing and managing cybersecurity policy and compliance programs that address emerging technology areas, including artificial intelligence, cloud computing, and zero‑trust architecture implementation. Knowledge of federal records management requirements and their intersection with cybersecurity policy and compliance obligations, including NARA guidance and federal records schedules. Experience supporting federal agency interactions with oversight bodies, including the OIG, GAO, and congressional oversight committees, on cybersecurity policy and compliance matters. Familiarity with privacy law and its intersection with cybersecurity policy and compliance, including the Privacy Act of 1974, OMB privacy guidance, and NIST privacy controls. Certified in Risk and Information Systems Control (CRISC) certification. Experience developing enterprise cybersecurity compliance dashboards, scorecards, and executive reporting mechanisms to provide agency leadership with real‑time visibility into compliance posture and risk levels. Equal Employment Opportunity Policy The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment. Equal Opportunity Employer/Veterans/Disabled.Shareholder Preference in accordance with Public Law 88-352 #J-18808-Ljbffr Koniag Services, Inc.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Policy and Compliance Lead in Washington DC vacancy
  •  ...cutting-edge AI innovation and national security initiatives. AI Governance Lead The AI Governance Lead will design...  ...ensure alignment with federal AI policy, ethical AI standards, and risk...  ...deploy AI responsibly, safely, and in compliance with emerging federal guidance. Key... 
    Policy

    AMA CONSULTING

    Lanham, MD
    1 day ago
  •  ...Duties and Responsibilities: Lead all Food Lion To-Go operations,...  ...Food Lion procedures Ensures compliance with local, state and federal...  ...Adheres to all company guidelines, policies and standard practices Maintains security standards Successfully complete... 
    Policy
    Work experience placement
    Local area
    Immediate start

    Food Lion

    Laurel, MD
    3 days ago
  •  ...in Arlington, Virginia is seeking a FOIA Specialist responsible for processing Freedom of Information Act requests and ensuring compliance with federal regulations. The role involves analyzing various records, coordinating responses with agency staff, and maintaining... 
    Policy

    System High Corporation

    Arlington, VA
    13 hours ago
  • Koniag Data Solutions, LLC, a Koniag Government Services company, seeks a Security Policy and Compliance Lead to support SBA in Washington, DC. This senior role requires expertise in federal policy development, RMF, FISMA, and audit readiness to align agency security with... 
    Policy

    Koniag Services, Inc.

    Washington DC
    2 days ago
  • $110k - $190k

     ...within regulated environments. Responsibilities include monitoring data movement, developing policies, and collaborating with multiple departments to ensure security compliance. We offer health benefits, retirement options, and competitive salaries ranging from $110,000... 
    Policy

    CHAOS Industries

    Washington DC
    13 hours ago
  •  ...government contractor is seeking a highly skilled Lead Incident Responder to manage critical security documentation and ensure compliance with government standards. This role...  ...Control Assessments, and managing security policy oversight for a variety of systems. The ideal... 
    Policy
    For contractors

    DirectViz Solutions, LLC

    Washington DC
    4 days ago
  • Unison is seeking a Security Governance Manager to lead our governance program across FedRAMP, IL4/IL5, and...  ...Reporting to the CISO, you will own policy, evidence, and certification activities...  ..., balance business enablement with compliance, and translate complex requirements... 
    Policy
    Remote job

    Unison Software, Inc.

    Washington DC
    4 days ago
  •  ...Systems, LLC in Washington, DC is seeking an Assessment Lead responsible for managing security assessments and preparing compliance reports. Ideal candidates should possess knowledge of Government Security Policies (NIST / FISMA) and have a solid technical background.... 
    Policy

    Technology Information Systems, LLC

    Washington DC
    3 days ago
  • Koniag Data Solutions, LLC seeks an experienced Security Policy and Compliance Lead to support SBA. You will guide policy development, RMF implementation, and compliance programs across federal requirements, ensuring alignment with FISMA, NIST standards, and OMB directives... 
    Policy

    Koniag Government Services

    Washington DC
    1 day ago
  • Cape Fox Shared Services is seeking a Site Security Manager (SSM) to oversee security protocols for...  ...conducting security inspections, and ensuring compliance with regulations. Candidates should have experience with DoD policies and be able to coordinate closely with... 
    Policy

    Cape Fox Shared Services

    Washington DC
    13 hours ago
  • Barbaricum is looking for an Information System Security Officer (ISSO) in Washington, DC to join their cybersecurity...  ...ATOs for government software, providing expert policy interpretation, and ensuring compliance with security requirements. Candidates should have experience... 
    Policy

    Barbaricum

    Washington DC
    13 hours ago
  • Global Resource Solutions is seeking a Program Security Representative II to provide security support for Special...  ...experience. Responsibilities include conducting compliance reviews and ensuring adherence to security policies. Ideal candidates should possess excellent... 
    Policy

    Global Resource solution

    Washington DC
    1 day ago
  • Leidos Inc is seeking a Senior Industrial Security Representative (ISR)/Contractor Program...  ...information and managing security policies and procedures. The ISR/CPSO will work alongside...  ...like clearance prescreening and compliance with federal regulations. The ideal candidate... 
    Policy
    For contractors

    Leidos Inc

    Alexandria, VA
    2 days ago
  • $140k - $170k

    Cypress Creek Energy in Washington, DC is seeking an Information Security Manager to lead security operations and compliance. The successful candidate will manage tools like Microsoft Defender and Zscaler, enhancing security posture and ensuring compliance with NIST standards... 
    Policy

    Cypress Creek Energy

    Washington DC
    13 hours ago
  •  ...Piper Solutions seeks an ISSO Lead to support federal missions...  ...operations, engineering, and compliance. This on-site role in Washington...  ...systems meet strict federal security requirements. You will...  ...monitoring, while developing policies and training materials for stakeholders... 
    Policy

    Zachary Piper Solutions

    Washington DC
    2 days ago
  • Cybersecurity Lead - Joint Base Anacostia-Bolling, Washington, D.C. - Active TS...  ...the senior authority on all aspects of security architecture, compliance, and risk management. This role...  ...comprehensive cybersecurity strategies, policies, and architectures. Oversee RMF compliance... 
    Policy
    Full time

    Synertex LLC

    Washington DC
    13 hours ago
  •  ...cybersecurity and IT advisory firm specializing in security operations, architecture, governance,...  ...is seeking an Information Security Compliance Lead for a high‑stakes, client‑facing...  ...Conduct and document risk assessments, policy reviews, and audit evidence gathering for... 
    Policy
    Immediate start

    Dragonfli Group

    Washington DC
    3 days ago
  • $150k - $170k

     ...Solutions is seeking an ISSO Lead to support a company focused...  ...operations, engineering, and compliance for federal missions. This position...  ...systems meet strict federal security requirements. This role...  ...initiatives Develop cybersecurity policies, training materials, and... 
    Policy

    Zachary Piper Solutions

    Washington DC
    2 days ago
  • XSI is seeking a Lead Cyber Security Analysis SME to anchor the cybersecurity engineering team supporting the Congressional Budget Office...  ...a senior, hands‑on engineering leadership role — not a policy, compliance, or SOC‑monitoring position. You will lead technical... 
    Policy
    Work at office

    Xtreme Solutions Inc

    Washington DC
    3 hours ago
  • $155.34k

     ..., US Salary: $155,337.00 Annually Lead Provider Intake Medical at Department...  ...efficiently, accurately, and in compliance with applicable policies, procedures and regulations of Unity...  ...individuals while maintaining safety and security standards. MAJOR DUTIES/ESSENTIAL... 
    Policy
    Full time
    Immediate start

    Unity Health Care.

    Washington DC
    2 days ago
  •  ...provides services and solutions in: National Security Programs Professional, Administrative,...  ...: Contingent Position Title: System Compliance Lead Location: Washington, DC Clearance:...  ...and are in accordance with DHS and TSA policies: Research major obstacles related to... 
    Policy
    Full time
    For contractors

    gTANGIBLE Corporation

    Washington DC
    13 hours ago
  •  ...Join Improbable U.S. Defense & National Security and you will help users leverage our...  ....    Your Mission The Security & Compliance Lead/Facility Security Officer (“FSO”) manages...  ...government regulations and Company security policies and procedures to maintain the Company’... 
    Policy
    For contractors
    Flexible hours

    Improbable LLC

    Arlington, VA
    7 days ago
  • $72.4k

     ...work in international trade compliance? Are you passionate about ensuring...  ...nation on critical national security space and national health...  ...International Trade Program Lead with expertise in International...  ...of compensation per internal policy and/or contractual designation... 
    Policy
    Contract work
    Temporary work
    Work experience placement
    Interim role
    Relocation package
    Flexible hours

    Johns Hopkins Applied Physics Lab

    Laurel, MD
    13 hours ago
  •  ...development Paid time off Job Title: Lead Locksmith Technician Reports To:...  ...is an integral part of FlyLock Security Solutions - Herndon and is key to...  ...on ladders. Ability to drive in compliance with company vehicle policy. Provide a high level of timely &... 
    Policy
    Flexible hours

    FlyLock Security Solutions - Herndon

    Washington DC
    23 days ago
  •  ...transformation for federal agencies requiring agility, security, and impact. Position Lead Business Analyst Location Washington, DC...  ...integrating federal cybersecurity and compliance requirements (DHS sensitive systems policy, NIST800-series, FISMA) into solution... 
    Policy
    Contract work
    Temporary work
    For subcontractor
    Local area
    Shift work

    PBG

    Washington DC
    13 hours ago
  •  ...in Washington, D.C., is seeking a Director, Facility Security Officer to lead security compliance efforts. This role involves overseeing FOCI compliance...  ...a Top Secret clearance, and is proficient in security policies and procedures. Join Collibra to help uphold security... 
    Policy

    Collibra

    Washington DC
    13 hours ago
  •  ...for federal agencies requiring agility, security, and impact. Citizenship U.S. Citizens...  ...ONLY) Position Summary The Engagement Lead serves as the senior on-site leader and...  ...facilitate prioritization, approvals, policy compliance, and portfolio oversight. Establish a... 
    Policy
    Contract work
    Temporary work
    Work at office
    Local area

    PBG

    Arlington, VA
    2 days ago
  • $60.5k - $74.5k

     ...us every time you step onto the floor. Lead a dynamic retail team focused on...  ...for holding teammates accountable for compliance with policies and procedures, including termination...  ...That said, to protect the integrity and security of our hiring process, we ask that candidates... 
    Policy

    DICK'S SPORTING GOODS INC

    Washington DC
    2 days ago
  • $25.5 - $27.5 per hour

     ...pricingand promotions strategies Leading a team by planning department...  ...processes whilemaintaininga compliance culture, including compliance...  ...conduct,following all Target policies and safety procedures, adhere...  ...the execution of physical security processesin order toenhance... 
    Policy
    Hourly pay
    Temporary work
    Work experience placement
    Flexible hours
    Shift work
    Night shift

    Target

    Upper Marlboro, MD
    3 days ago
  • $22 - $23 per hour

     ...of all dispensary operations to ensure compliance with security, inventory, and local and state...  ...within the vault. Actively participate in leading team members to effectively execute programs...  ...comply with the rules, regulations, policies, and procedures of Green Thumb. Must... 
    Policy
    Work at office
    Local area
    Shift work
    Night shift
    Weekend work
    Day shift

    Green Thumb Industries INC

    Bethesda, MD
    13 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Policy and Compliance Lead. Be the first to apply!