Security Policy and Compliance Lead
cFocus Software Incorporated
Security Policy and Compliance Lead Position Title: Security Policy and Compliance Lead Program: SBA Enterprise Cybersecurity Services (ECS) Position Overview The Security Policy and Compliance Lead shall serve as the senior cybersecurity policy, compliance, and Risk Management Framework (RMF) lead supporting the U.S. Small Business Administration (SBA) Enterprise Cybersecurity Services (ECS) program. Key Responsibilities Active Certified Information Systems Security Professional (CISSP) certification Lead and oversee enterprise cybersecurity policy and compliance support activities across SBA systems, applications, and programs. Manage and support the SBA Risk Management Framework (RMF) lifecycle, including system authorization, assessment, continuous monitoring, and ongoing authorization activities. Develop, review, revise, maintain, and update cybersecurity and privacy documentation including SSPs, CMPs, ISCPs, ISCP Test Reports, ERAs, POA&Ms, policies, procedures, and architecture diagrams. Ensure documentation aligns with SBA implementation procedures, NIST SP 800-series guidance, FISMA requirements, OMB mandates, FedRAMP, and Zero Trust principles. Lead controls assessment and evaluation activities in accordance with NIST SP 800-53 and NIST SP 800-53A methodologies. Coordinate and support Information System Continuous Monitoring (ISCM) activities, Ongoing Authorization (OA) testing, and enterprise cybersecurity metrics reporting. Provide ISSO oversight and coordination support for assigned systems, ensuring systems maintain compliance with authorization requirements and agency security standards. Support FISMA reporting activities including collection, validation, analysis, and submission of enterprise cybersecurity metrics and CyberScope reporting. Coordinate audit support activities for Inspector General (IG), GAO, FISMA, FedRAMP, and internal cybersecurity audits. Support development and maintenance of cybersecurity dashboards, risk registers, visualizations, and automated compliance reporting capabilities. Facilitate High Value Asset (HVA) assessment activities and ensure alignment with CISA and OMB requirements. Support FedRAMP Continuous Monitoring (CONMON) activities and facilitate monthly stakeholder meetings. Support enterprise vulnerability management coordination, remediation tracking, and compliance reporting. Develop and deliver cybersecurity awareness and compliance training content in support of agency requirements. Coordinate enterprise risk management (ERM) integration activities utilizing FAIR methodology and cybersecurity risk quantification. Ensure all deliverables are peer reviewed, Section 508 compliant, and submitted in accordance with SBA-defined timelines and quality standards. Serve as a trusted advisor to SBA leadership, ISSOs, system owners, and program stakeholders regarding cybersecurity governance, policy, and compliance matters. Required Qualifications Bachelor’s degree in Cybersecurity, Information Assurance, Information Technology, Computer Science, Engineering, or related field. Master’s degree preferred. Minimum of ten (10) years of experience supporting federal cybersecurity policy, compliance, RMF, and FISMA programs. At least five years of experience developing the required documents for the A&A package (e.g., SSP, CP, and SAR), including oversight and development of POA&M's, and performing all continuous monitoring functions with the most recent experience occurring in the last three years. Experience in applying risk management techniques to develop and complete risk assessments based on NIST standards to ensure system design and implementation sufficiently addresses or mitigates IA risk. At least five years of experience implementing NIST 800-53A security controls for Federal agencies. At least one year of experience in data structures, data mining, business intelligence, with the ability to correlate data across multiple disparate sources, linking common data elements, and constructing informative visualizations. Minimum of five (5) years of experience serving in an ISSM, ISSO, cybersecurity compliance lead, or equivalent leadership role. Demonstrated expertise in NIST RMF processes, NIST SP 800-53 Rev. 5, NIST SP 800-53A, FISMA, OMB Circular A-130, and federal cybersecurity governance. Experience developing and maintaining cybersecurity documentation including SSPs, POA&M's, SARs, ISCPs, CMPs, and related accreditation artifacts. Experience supporting continuous monitoring, ongoing authorization (OA), audit readiness, and security controls assessments. Strong understanding of federal cybersecurity compliance frameworks including FedRAMP, CISA HVA requirements, and Zero Trust Architecture. Experience supporting enterprise governance, risk, and compliance (GRC) platforms and automated reporting solutions. Excellent written and verbal communication skills with experience supporting executive briefings, audits, and stakeholder coordination. Relevant cybersecurity certifications such as CISSP, CISM, CAP, GSLC, or equivalent required. Project Management Professional (PMP) certification preferred. Ability to obtain and maintain a Moderate Risk background investigation and eligibility for higher-level clearances if required. Desired Experience Experience supporting SBA, DHS, CISA, or other civilian federal agencies. Experience supporting FedRAMP cloud environments including AWS, Azure, Microsoft 365, Salesforce, and SaaS platforms. Experience developing enterprise cybersecurity dashboards, metrics, automation, and data visualizations. Experience supporting enterprise risk management (ERM) integration and FAIR-based risk quantification. #J-18808-Ljbffr
- ...cFocus Software Incorporated is seeking a Security Policy and Compliance Lead for the SBA Enterprise Cybersecurity Services program in Washington, DC. This senior role requires managing cybersecurity policy, compliance, and the Risk Management Framework lifecycle. The...Policy
- ...Oman is seeking an Assistant Director in Information Security to enhance compliance with security policies and reduce risks across global assets. You will work... ...compliance management by developing strategies and leading security initiatives. Candidates should have a relevant...PolicyFlexible hours
- ...government contractor is seeking a highly skilled Lead Incident Responder to manage critical security documentation and ensure compliance with government standards. This role... ...Control Assessments, and managing security policy oversight for a variety of systems. The ideal...PolicyFor contractors
- ...cybersecurity and IT advisory firm specializing in security operations, architecture, governance,... ...is seeking an Information Security Compliance Lead for a high‑stakes, client‑facing... ...Conduct and document risk assessments, policy reviews, and audit evidence gathering for...PolicyImmediate start
- ...supervision of the Medical Director, the Lead Provider Intake Medical for... ...performed efficiently, accurately, and in compliance with applicable policies, procedures and regulations of Unity... ...while maintaining safety and security standards. MAJOR DUTIES/ESSENTIAL...PolicyImmediate start
- ...A leading technology firm seeks a Security Policy and Compliance Lead in Washington, DC. Ideal candidates will possess 5+ years in developing security documentation and implementing NIST standards, alongside a CISSP certification. The position focuses on enhancing skills...Policy
- ...Security Policy and Compliance Lead Washington, DC Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer’s core culture? If so, Chenega...Policy
$170k - $193k
..., you’ll design, implement, and sustain secure, automated CI/CD pipelines and infrastructure... ...DevOps workflows, enabling continuous compliance, monitoring, and resilient system... ...compensation, subject to the terms and policies of MetroStar, which may include: Performance...PolicyFull timeWork experience placementLocal areaFlexible hours- ...Join Improbable U.S. Defense & National Security and you will help users leverage our... .... Your Mission The Security & Compliance Lead/Facility Security Officer (“FSO”) manages... ...government regulations and Company security policies and procedures to maintain the Company’...PolicyFor contractorsFlexible hours
- ...Salary: Senior Information System Security Officer / RMF Lead Position Overview The Senior ISSO... ...serves as the senior cybersecurity compliance and authorization lead supporting the... ...and interpret federal cybersecurity policy, CDC/HHS security requirements, CIPSEA...PolicyFor contractors
- ...Overtime Exempt: No Reports To: ARMADA HQ Security Clearance Required: Active TS/SCI w/ CI... ...Access Programs (CAP). Ensures compliance with physical, personnel, and program security... ...enforce physical and personnel access control policies. Coordinate visitor security operations...PolicyFull timeContract workFor contractorsLocal areaRelocation
$62k - $141k
Booz Allen Hamilton is seeking a Policy Analyst in Arlington, Virginia, to provide analytical expertise and lead initiatives in Security Cooperation. You will oversee various issues, liaise with military leadership, and develop innovative solutions to complex challenges...PolicyFull time$91.42k - $146.26k
...RPMGlobal is seeking a Facility Security Officer (FSO) in Alexandria, Virginia, responsible for enforcing security policies and compliance with government regulations to protect classified information. The role includes managing security programs, ensuring compliance...Policy- ...cutting-edge AI innovation and national security initiatives. AI Governance Lead The AI Governance Lead will design... ...ensure alignment with federal AI policy, ethical AI standards, and risk... ...deploy AI responsibly, safely, and in compliance with emerging federal guidance. Key...Policy
- ...vulnerability assessment operations using the Assured Compliance Assessment Solution (ACAS), Tenable Security Center, and Nessus scanning infrastructure to... ...appliances. • Develops and maintains custom scan policies, STIG and SRG compliance profiles, authenticated scanning...PolicyContract work
- ...solutions based on industry-leading practices. ProSidian provides... ...solutions for Risk Management | Compliance | Business Process | IT... ...intersections of assets, processes, policies, and people delivering value.... ...– Identifying, pursuing, and securing growth opportunities through...PolicyFull timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- ...services and solutions in: ~National Security Programs ~Professional, Administrative... ...Status: Contingent Position Title: System Compliance Lead Location:Washington, DC Clearance:... ...and are in accordance with DHS and TSA policies: ~Research major obstacles related to...PolicyFull timeFor contractors
$145.92k - $191.05k
...[NYSE: IONQ] is the world’s leading quantum company delivering solutions... ...used for export control and compliance purposes, and the answers... ...Global Applicant Privacy Policy. I consent to the collection,... ...regulatory, contractual, and security obligations; (ii) meet requirements...PolicyPermanent employmentContract workTemporary workFor contractorsFor subcontractorH1bWork at officeLocal areaRelocationShift work- ...K2 Group, Inc. is seeking a SAP Security Specialist in Camp Springs, MD. The role involves managing the Special Access Program operations, ensuring compliance with security policies, and conducting risk assessments. Applicants should have 5-10 years of experience in SAP...Policy
- ID.me is seeking a GRC Technical Program Manager to oversee security compliance programs for FedRAMP, ISO 27001, and SOC 2. This role demands... ...alignment and manage the lifecycle of controls and policies. A minimum of 3 years in security or compliance and significant...PolicyFull timeWork at office
$83.5k - $86k
...A prominent national organization in Washington is seeking a Senior Manager of National Security Policy to oversee several active policy committees. Responsibilities include developing initiatives, managing correspondence, and mentoring junior staff. Ideal candidates will...PolicyFull time- ...seeking a qualified candidate for a position focused on housing security and climate change. This role will involve supporting the Great... ..., strong facilitation skills, and a background in housing policy or community engagement. A robust benefits package and a hybrid...Policy
- ...Cybersecurity Manager in Arlington, VA, to develop and implement strategic cybersecurity policies. You will lead a team, manage risks, and ensure compliance with relevant security regulations. The ideal candidate will have over 12 years of experience in cybersecurity,...Policy
- ...International City Management Association Retirement Corporation is seeking a detail-oriented Compliance Officer to ensure compliance with securities laws and internal policies. You will conduct compliance reviews, support regulatory filings, and maintain compliance...PolicyFlexible hours
- ...A leading industry association in Washington, DC is seeking a Senior Manager, Regulatory Affairs to advocate for the vehicle supplier industry. This hybrid role requires approximately 5 years of regulatory experience, strong public speaking and communication skills, and...Policy
- ...Corporation is seeking an Information System Security Officer (ISSO) in Arlington, VA. The ISSO will provide oversight for network compliance, lead risk management efforts, and ensure... ...to Federal Information Assurance policies. Candidates should have relevant experience...PolicyRemote work
- ...seeking an Information System Security Officer (ISSO) in Arlington, VA, to oversee network compliance and ensure adherence to Federal Information Assurance policies. The ideal candidate will have... ...Responsibilities include network oversight, leading risk management efforts, and...PolicyRemote work
- ...CoStar Group, Inc. seeks a Compliance Manager in Arlington, VA to oversee the legal compliance program. The role includes managing compliance risks, designing training, and supporting policy governance. Candidates should have a Bachelor's degree and over 5 years in regulatory...PolicyWork at officeVisa sponsorship
- ...systems integration services to the US National Security market, has an immediate need for an IT Capabilities Integration Lead for a Department of Defense customer. In this... ...goals and metrics Devise and establish IT policies and systems to support the implementation of...PolicyImmediate start
$62k - $124k
...Security Management Lead (SML) Senior Work Location: Washington, DC Employment Type: Full-Time, Senior-Level Department... ...Lead security program activities, enforce security policies, and coordinate compliance across mission operations. Collaborate with cross...PolicyFull timeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Policy and Compliance Lead. Be the first to apply!
- education policy research Washington DC
- policy specialist Washington DC
- policy assistant Washington DC
- policy associate Washington DC
- environmental policy Washington DC
- privacy policy Washington DC
- public policy Washington DC
- vice president public policy Washington DC
- policy think tank Washington DC
- trade policy jobs Washington DC


