Cybersecurity Governance & Policy Specialist — Level II

Rividium
  • Washington, District of Columbia
    10 days ago

    Job Description

    Position Overview

    RiVidium Inc. is seeking an experienced Cybersecurity Governance & Policy Specialist - Level II to support the development, implementation, and maintenance of cybersecurity policies, standards, procedures, and governance processes within a federal environment.

    The Cybersecurity Governance & Policy Specialist will help ensure cybersecurity practices align with federal requirements, organizational policies, industry standards, and risk management objectives. This role will work closely with cybersecurity, compliance, risk management, IT, and program teams to translate regulatory and security requirements into practical policies and procedures.

    The ideal candidate will have a strong understanding of cybersecurity governance and compliance, excellent technical writing skills, and the ability to interpret complex security requirements and communicate them clearly to technical and non-technical stakeholders.

    Key Responsibilities

    • Develop, review, update, and maintain cybersecurity policies, standards, procedures, guidelines, and governance documentation.
    • Analyze federal cybersecurity requirements and determine their impact on organizational policies and security practices.
    • Translate cybersecurity regulations, standards, and frameworks into actionable organizational requirements.
    • Support the implementation and enforcement of cybersecurity governance processes.
    • Conduct policy and compliance reviews to identify gaps, inconsistencies, and areas requiring improvement.
    • Assist with developing cybersecurity governance frameworks and operating procedures.
    • Support the alignment of cybersecurity policies with NIST, FISMA, and other applicable federal requirements.
    • Research emerging cybersecurity threats, regulations, standards, and industry best practices.
    • Perform gap assessments against applicable cybersecurity policies, standards, and regulatory requirements.
    • Develop recommendations for addressing identified policy, governance, and compliance gaps.
    • Collaborate with cybersecurity engineers, ISSOs, ISSMs, system owners, security assessors, and program leadership.
    • Support Risk Management Framework (RMF), security authorization, continuous monitoring, and compliance activities.
    • Assist with the development and maintenance of cybersecurity governance metrics and reporting.
    • Support cybersecurity risk management and compliance assessments.
    • Review security documentation for consistency with established policies and requirements.
    • Assist with policy exception, waiver, and risk acceptance processes.
    • Support internal and external cybersecurity audits, assessments, and inspections.
    • Prepare executive briefings, presentations, reports, and other governance materials.
    • Maintain documentation repositories and ensure cybersecurity policies remain current and properly version controlled.
    • Provide guidance to stakeholders on cybersecurity policy interpretation and implementation.
    • Participate in cybersecurity working groups, governance boards, and customer meetings.
    • Support continuous improvement of cybersecurity governance processes and organizational security posture.

    Required Qualifications

    • Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Computer Science, Political Science, or a related field.
    • Demonstrated experience in cybersecurity governance, policy, compliance, information assurance, risk management, or a related discipline.
    • Working knowledge of cybersecurity policies, standards, frameworks, and regulatory requirements.
    • Experience developing, reviewing, or implementing cybersecurity policies and procedures.
    • Ability to interpret complex cybersecurity requirements and translate them into practical organizational guidance.
    • Knowledge of cybersecurity risk management and compliance principles.
    • Familiarity with the NIST Risk Management Framework (RMF).
    • Understanding of federal cybersecurity requirements and information security best practices.
    • Strong technical writing, editing, research, and documentation skills.
    • Strong analytical and problem-solving abilities.
    • Excellent verbal and written communication skills.
    • Ability to work effectively with technical teams, management, and government stakeholders.

    Preferred Certification

    • CompTIA Security+

    Additional cybersecurity, governance, risk, or compliance certifications are desirable.

    Preferred Qualifications

    • Experience supporting federal civilian or Department of Defense (DoD) cybersecurity programs.
    • Knowledge of NIST SP 800-53, NIST SP 800-37, and FISMA.
    • Experience developing policies aligned with federal cybersecurity requirements.
    • Experience with RMF, Assessment & Authorization (A&A), and security control requirements.
    • Familiarity with cybersecurity governance frameworks and industry standards.
    • Experience conducting cybersecurity policy and compliance gap assessments.
    • Experience supporting cybersecurity audits and regulatory assessments.
    • Familiarity with GRC platforms such as RSA Archer, ServiceNow GRC, or eMASS.
    • Experience with cybersecurity risk assessments and risk acceptance processes.
    • Knowledge of cloud security governance and compliance.
    • Experience developing cybersecurity awareness, policy, and training materials.
    • Familiarity with security control implementation and assessment processes.
    • Certifications such as CISM, CISSP, CAP, CRISC, or CGRC are a plus.

    Technical Skills

    • Cybersecurity Governance
    • Cybersecurity Policy Development
    • Security Standards and Procedures
    • Governance, Risk & Compliance (GRC)
    • Cybersecurity Risk Management
    • Regulatory Compliance
    • NIST Frameworks
    • NIST SP 800-53
    • NIST SP 800-37
    • FISMA
    • Risk Management Framework (RMF)
    • Assessment & Authorization (A&A)
    • Security Controls
    • Continuous Monitoring
    • Compliance Assessments
    • Gap Analysis
    • Risk Assessments
    • Policy Exception Management
    • Risk Acceptance
    • Security Documentation
    • Technical Writing
    • Cybersecurity Metrics and Reporting
    • RSA Archer
    • ServiceNow GRC
    • eMASS

    RiVidium Inc is seeking a 'Cybersecurity Governance & Policy Specialist - Level II' to support a federal client. This position is contingent upon contract award and funding approval. As such, this job posting is intended to identify qualified candidates for a potential future opportunity and does not represent a currently available position. Compensation has not yet been determined and will be established based on contract requirements, candidate qualifications, experience, and applicable market conditions.

     

    Numbers & Facts

    LocationWashington, District of Columbia

    Skills

    • Access Authorizationunmatched
    • Analysis Skillsunmatched
    • Best Practicesunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Candidate Qualificationunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • CompTIA Security+unmatched
    • Computer Scienceunmatched
    • Continuous Improvementunmatched
    • Documentationunmatched
    • External Auditunmatched
    • FISMA - Federal Information Security Management Actunmatched
    • Fundingunmatched
    • Gap Analysisunmatched
    • Governmentunmatched
    • Industry Standardsunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internal Auditunmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Maintain Complianceunmatched
    • Metricsunmatched
    • Operations Processesunmatched
    • People Managementunmatched
    • Policy Developmentunmatched
    • Policy Implementationunmatched
    • Political Scienceunmatched
    • Presentation/Verbal Skillsunmatched
    • Problem Solving Skillsunmatched
    • Procedure Implementationunmatched
    • Process Improvementunmatched
    • Regulationsunmatched
    • Regulatory Complianceunmatched
    • Regulatory Requirementsunmatched
    • Requirements Managementunmatched
    • Research Skillsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • ServiceNowunmatched
    • Team Playerunmatched
    • Technical Editingunmatched
    • Technical Leadershipunmatched
    • Technical Writingunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Department of Defense (DoD)unmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder