Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Policy and Compliance Lead

cFocus Software Incorporated

Security Policy and Compliance Lead Position Title: Security Policy and Compliance Lead Program: SBA Enterprise Cybersecurity Services (ECS) Position Overview The Security Policy and Compliance Lead shall serve as the senior cybersecurity policy, compliance, and Risk Management Framework (RMF) lead supporting the U.S. Small Business Administration (SBA) Enterprise Cybersecurity Services (ECS) program. Key Responsibilities Active Certified Information Systems Security Professional (CISSP) certification Lead and oversee enterprise cybersecurity policy and compliance support activities across SBA systems, applications, and programs. Manage and support the SBA Risk Management Framework (RMF) lifecycle, including system authorization, assessment, continuous monitoring, and ongoing authorization activities. Develop, review, revise, maintain, and update cybersecurity and privacy documentation including SSPs, CMPs, ISCPs, ISCP Test Reports, ERAs, POA&Ms, policies, procedures, and architecture diagrams. Ensure documentation aligns with SBA implementation procedures, NIST SP 800-series guidance, FISMA requirements, OMB mandates, FedRAMP, and Zero Trust principles. Lead controls assessment and evaluation activities in accordance with NIST SP 800-53 and NIST SP 800-53A methodologies. Coordinate and support Information System Continuous Monitoring (ISCM) activities, Ongoing Authorization (OA) testing, and enterprise cybersecurity metrics reporting. Provide ISSO oversight and coordination support for assigned systems, ensuring systems maintain compliance with authorization requirements and agency security standards. Support FISMA reporting activities including collection, validation, analysis, and submission of enterprise cybersecurity metrics and CyberScope reporting. Coordinate audit support activities for Inspector General (IG), GAO, FISMA, FedRAMP, and internal cybersecurity audits. Support development and maintenance of cybersecurity dashboards, risk registers, visualizations, and automated compliance reporting capabilities. Facilitate High Value Asset (HVA) assessment activities and ensure alignment with CISA and OMB requirements. Support FedRAMP Continuous Monitoring (CONMON) activities and facilitate monthly stakeholder meetings. Support enterprise vulnerability management coordination, remediation tracking, and compliance reporting. Develop and deliver cybersecurity awareness and compliance training content in support of agency requirements. Coordinate enterprise risk management (ERM) integration activities utilizing FAIR methodology and cybersecurity risk quantification. Ensure all deliverables are peer reviewed, Section 508 compliant, and submitted in accordance with SBA-defined timelines and quality standards. Serve as a trusted advisor to SBA leadership, ISSOs, system owners, and program stakeholders regarding cybersecurity governance, policy, and compliance matters. Required Qualifications Bachelor’s degree in Cybersecurity, Information Assurance, Information Technology, Computer Science, Engineering, or related field. Master’s degree preferred. Minimum of ten (10) years of experience supporting federal cybersecurity policy, compliance, RMF, and FISMA programs. At least five years of experience developing the required documents for the A&A package (e.g., SSP, CP, and SAR), including oversight and development of POA&M's, and performing all continuous monitoring functions with the most recent experience occurring in the last three years. Experience in applying risk management techniques to develop and complete risk assessments based on NIST standards to ensure system design and implementation sufficiently addresses or mitigates IA risk. At least five years of experience implementing NIST 800-53A security controls for Federal agencies. At least one year of experience in data structures, data mining, business intelligence, with the ability to correlate data across multiple disparate sources, linking common data elements, and constructing informative visualizations. Minimum of five (5) years of experience serving in an ISSM, ISSO, cybersecurity compliance lead, or equivalent leadership role. Demonstrated expertise in NIST RMF processes, NIST SP 800-53 Rev. 5, NIST SP 800-53A, FISMA, OMB Circular A-130, and federal cybersecurity governance. Experience developing and maintaining cybersecurity documentation including SSPs, POA&M's, SARs, ISCPs, CMPs, and related accreditation artifacts. Experience supporting continuous monitoring, ongoing authorization (OA), audit readiness, and security controls assessments. Strong understanding of federal cybersecurity compliance frameworks including FedRAMP, CISA HVA requirements, and Zero Trust Architecture. Experience supporting enterprise governance, risk, and compliance (GRC) platforms and automated reporting solutions. Excellent written and verbal communication skills with experience supporting executive briefings, audits, and stakeholder coordination. Relevant cybersecurity certifications such as CISSP, CISM, CAP, GSLC, or equivalent required. Project Management Professional (PMP) certification preferred. Ability to obtain and maintain a Moderate Risk background investigation and eligibility for higher-level clearances if required. Desired Experience Experience supporting SBA, DHS, CISA, or other civilian federal agencies. Experience supporting FedRAMP cloud environments including AWS, Azure, Microsoft 365, Salesforce, and SaaS platforms. Experience developing enterprise cybersecurity dashboards, metrics, automation, and data visualizations. Experience supporting enterprise risk management (ERM) integration and FAIR-based risk quantification. #J-18808-Ljbffr

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Security Policy and Compliance Lead in Washington DC vacancy
  •  ...cFocus Software Incorporated is seeking a Security Policy and Compliance Lead for the SBA Enterprise Cybersecurity Services program in Washington, DC. This senior role requires managing cybersecurity policy, compliance, and the Risk Management Framework lifecycle. The... 
    Policy

    cFocus Software Incorporated

    Washington DC
    3 days ago
  •  ...Oman is seeking an Assistant Director in Information Security to enhance compliance with security policies and reduce risks across global assets. You will work...  ...compliance management by developing strategies and leading security initiatives. Candidates should have a relevant... 
    Policy
    Flexible hours

    Ernst & Young Oman

    Washington DC
    4 days ago
  •  ...government contractor is seeking a highly skilled Lead Incident Responder to manage critical security documentation and ensure compliance with government standards. This role...  ...Control Assessments, and managing security policy oversight for a variety of systems. The ideal... 
    Policy
    For contractors

    DirectViz Solutions

    Washington DC
    3 days ago
  •  ...cybersecurity and IT advisory firm specializing in security operations, architecture, governance,...  ...is seeking an Information Security Compliance Lead for a high‑stakes, client‑facing...  ...Conduct and document risk assessments, policy reviews, and audit evidence gathering for... 
    Policy
    Immediate start

    Dragonfli Group LLC

    Washington DC
    3 days ago
  •  ...supervision of the Medical Director, the Lead Provider Intake Medical for...  ...performed efficiently, accurately, and in compliance with applicable policies, procedures and regulations of Unity...  ...while maintaining safety and security standards. MAJOR DUTIES/ESSENTIAL... 
    Policy
    Immediate start

    Unity Health Care

    Washington DC
    15 hours ago
  •  ...A leading technology firm seeks a Security Policy and Compliance Lead in Washington, DC. Ideal candidates will possess 5+ years in developing security documentation and implementing NIST standards, alongside a CISSP certification. The position focuses on enhancing skills... 
    Policy

    NJVC

    Washington DC
    4 days ago
  •  ...Security Policy and Compliance Lead Washington, DC Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer’s core culture? If so, Chenega... 
    Policy

    NJVC

    Washington DC
    3 days ago
  • $170k - $193k

     ..., you’ll design, implement, and sustain secure, automated CI/CD pipelines and infrastructure...  ...DevOps workflows, enabling continuous compliance, monitoring, and resilient system...  ...compensation, subject to the terms and policies of MetroStar, which may include: Performance... 
    Policy
    Full time
    Work experience placement
    Local area
    Flexible hours

    MetroStar Corporation

    Washington DC
    4 days ago
  •  ...Join Improbable U.S. Defense & National Security and you will help users leverage our...  ....    Your Mission The Security & Compliance Lead/Facility Security Officer (“FSO”) manages...  ...government regulations and Company security policies and procedures to maintain the Company’... 
    Policy
    For contractors
    Flexible hours

    Improbable LLC

    Arlington, VA
    4 days ago
  •  ...Salary: Senior Information System Security Officer / RMF Lead Position Overview The Senior ISSO...  ...serves as the senior cybersecurity compliance and authorization lead supporting the...  ...and interpret federal cybersecurity policy, CDC/HHS security requirements, CIPSEA... 
    Policy
    For contractors

    R3 Management Services

    Hyattsville, MD
    5 days ago
  •  ...Overtime Exempt: No Reports To: ARMADA HQ Security Clearance Required: Active TS/SCI w/ CI...  ...Access Programs (CAP). Ensures compliance with physical, personnel, and program security...  ...enforce physical and personnel access control policies. Coordinate visitor security operations... 
    Policy
    Full time
    Contract work
    For contractors
    Local area
    Relocation

    Armada LTD

    Washington DC
    2 days ago
  • $62k - $141k

    Booz Allen Hamilton is seeking a Policy Analyst in Arlington, Virginia, to provide analytical expertise and lead initiatives in Security Cooperation. You will oversee various issues, liaise with military leadership, and develop innovative solutions to complex challenges... 
    Policy
    Full time

    Booz Allen Hamilton

    Arlington, VA
    1 day ago
  • $91.42k - $146.26k

     ...RPMGlobal is seeking a Facility Security Officer (FSO) in Alexandria, Virginia, responsible for enforcing security policies and compliance with government regulations to protect classified information. The role includes managing security programs, ensuring compliance... 
    Policy

    RPMGlobal

    Alexandria, VA
    3 days ago
  •  ...cutting-edge AI innovation and national security initiatives. AI Governance Lead The AI Governance Lead will design...  ...ensure alignment with federal AI policy, ethical AI standards, and risk...  ...deploy AI responsibly, safely, and in compliance with emerging federal guidance. Key... 
    Policy

    AMA CONSULTING

    Lanham, MD
    3 days ago
  •  ...vulnerability assessment operations using the Assured Compliance Assessment Solution (ACAS), Tenable Security Center, and Nessus scanning infrastructure to...  ...appliances. • Develops and maintains custom scan policies, STIG and SRG compliance profiles, authenticated scanning... 
    Policy
    Contract work

    ECS Limited

    Falls Church, VA
    4 days ago
  •  ...solutions based on industry-leading practices. ProSidian provides...  ...solutions for Risk Management | Compliance | Business Process | IT...  ...intersections of assets, processes, policies, and people delivering value....  ...– Identifying, pursuing, and securing growth opportunities through... 
    Policy
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    ProSidian Consulting, LLC

    Alexandria, VA
    9 days ago
  •  ...services and solutions in: ~National Security Programs ~Professional, Administrative...  ...Status:  Contingent Position Title: System Compliance Lead Location:Washington, DC Clearance:...  ...and are in accordance with DHS and TSA policies: ~Research major obstacles related to... 
    Policy
    Full time
    For contractors

    gTANGIBLE Corporation

    Washington DC
    21 days ago
  • $145.92k - $191.05k

     ...[NYSE: IONQ] is the world’s leading quantum company delivering solutions...  ...used for export control and compliance purposes, and the answers...  ...Global Applicant Privacy Policy. I consent to the collection,...  ...regulatory, contractual, and security obligations; (ii) meet requirements... 
    Policy
    Permanent employment
    Contract work
    Temporary work
    For contractors
    For subcontractor
    H1b
    Work at office
    Local area
    Relocation
    Shift work

    IonQ

    College Park, MD
    1 day ago
  •  ...K2 Group, Inc. is seeking a SAP Security Specialist in Camp Springs, MD. The role involves managing the Special Access Program operations, ensuring compliance with security policies, and conducting risk assessments. Applicants should have 5-10 years of experience in SAP... 
    Policy

    K2 Group

    District Heights, MD
    3 days ago
  • ID.me is seeking a GRC Technical Program Manager to oversee security compliance programs for FedRAMP, ISO 27001, and SOC 2. This role demands...  ...alignment and manage the lifecycle of controls and policies. A minimum of 3 years in security or compliance and significant... 
    Policy
    Full time
    Work at office

    jobs.frontdoordefense.com - Jobboard

    Mc Lean, VA
    15 hours ago
  • $83.5k - $86k

     ...A prominent national organization in Washington is seeking a Senior Manager of National Security Policy to oversee several active policy committees. Responsibilities include developing initiatives, managing correspondence, and mentoring junior staff. Ideal candidates will... 
    Policy
    Full time

    US Chamber of Commerce

    Washington DC
    3 days ago
  •  ...seeking a qualified candidate for a position focused on housing security and climate change. This role will involve supporting the Great...  ..., strong facilitation skills, and a background in housing policy or community engagement. A robust benefits package and a hybrid... 
    Policy

    Nashville Public Radio

    Washington DC
    4 days ago
  •  ...Cybersecurity Manager in Arlington, VA, to develop and implement strategic cybersecurity policies. You will lead a team, manage risks, and ensure compliance with relevant security regulations. The ideal candidate will have over 12 years of experience in cybersecurity,... 
    Policy

    Chenega Corporation

    Arlington, VA
    4 days ago
  •  ...International City Management Association Retirement Corporation is seeking a detail-oriented Compliance Officer to ensure compliance with securities laws and internal policies. You will conduct compliance reviews, support regulatory filings, and maintain compliance... 
    Policy
    Flexible hours

    LE_ICMA-RC International City Management Association Retirem...

    Washington DC
    3 days ago
  •  ...A leading industry association in Washington, DC is seeking a Senior Manager, Regulatory Affairs to advocate for the vehicle supplier industry. This hybrid role requires approximately 5 years of regulatory experience, strong public speaking and communication skills, and... 
    Policy

    MEMA. The Vehicle Suppliers Association

    Washington DC
    3 days ago
  •  ...Corporation is seeking an Information System Security Officer (ISSO) in Arlington, VA. The ISSO will provide oversight for network compliance, lead risk management efforts, and ensure...  ...to Federal Information Assurance policies. Candidates should have relevant experience... 
    Policy
    Remote work

    Chenega Corporation

    Arlington, VA
    4 days ago
  •  ...seeking an Information System Security Officer (ISSO) in Arlington, VA, to oversee network compliance and ensure adherence to Federal Information Assurance policies. The ideal candidate will have...  ...Responsibilities include network oversight, leading risk management efforts, and... 
    Policy
    Remote work

    NJVC

    Arlington, VA
    3 days ago
  •  ...CoStar Group, Inc. seeks a Compliance Manager in Arlington, VA to oversee the legal compliance program. The role includes managing compliance risks, designing training, and supporting policy governance. Candidates should have a Bachelor's degree and over 5 years in regulatory... 
    Policy
    Work at office
    Visa sponsorship

    CoStar Group

    Arlington, VA
    3 days ago
  •  ...systems integration services to the US National Security market, has an immediate need for an IT Capabilities Integration Lead for a Department of Defense customer. In this...  ...goals and metrics Devise and establish IT policies and systems to support the implementation of... 
    Policy
    Immediate start

    Tau Six

    Arlington, VA
    3 days ago
  • $62k - $124k

     ...Security Management Lead (SML) Senior Work Location: Washington, DC Employment Type: Full-Time, Senior-Level Department...  ...Lead security program activities, enforce security policies, and coordinate compliance across mission operations. Collaborate with cross... 
    Policy
    Full time
    Flexible hours

    Contact Government Services LLC

    Washington DC
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Policy and Compliance Lead. Be the first to apply!