Cybervance is looking for a Security Policy and Compliance Manager in Washington, D.C. to lead the development and oversight of security documentation and compliance with federal security standards.
Responsibilities: Responsibilities include developing and managing security documentation, conducting risk assessments, and leading continuous monitoring activities to ensure compliance with NIST and federal standards.
Skills: Required skills include extensive experience with A&A documentation, implementing NIST 800-53A controls, risk management frameworks, data analysis, excellent communication, and strong analytical abilities.
Qualifications: Preferred qualifications include a Bachelor's degree in a related field and CISSP certification, with additional certifications such as CISM, CISA, or Security+ being desirable.
Location: On Site - Washington, D.C.
Compensation: Not provided by employer. Typical compensation ranges for this position are between $110,000 - $150,000.
Position Title: Security Policy and Compliance Manager
Location: On Site - Washington, D.C.
Clearance Required: Public Trust
Cybervance is a rapidly growing information security and information technology company in Washington, D.C., and we are an equal opportunity employer that designs, develops, and manages the successful execution of training programs for government and private sector organizations. Cybervance believes in creating innovative solutions to deliver measured results.
Cybervance is seeking a highly skilled Security Policy and Compliance Lead to support our federal customer in ensuring security standards, policies, and regulatory requirements are met across enterprise systems.
The Security Policy and Compliance Lead will be responsible for developing, maintaining, and overseeing security documentation, implementing and assessing security controls, and leading risk management efforts in alignment with NIST and federal standards. The ideal candidate will bring hands-on expertise in security authorization and assessment (A&A), continuous monitoring, and policy oversight, coupled with strong leadership skills and the ability to communicate effectively with both technical and executive stakeholders.
Responsibilities:
• Develop, maintain, and manage security documentation required for the Authorization and Accreditation (A&A) package, including System Security Plans (SSPs), Contingency Plans (CPs), and Security Assessment Reports (SARs).
• Provide oversight and development of Plans of Action and Milestones (POA&Ms) and ensure timely remediation of identified risks.
• Lead and perform all continuous monitoring activities, ensuring security controls remain effective and compliant with federal regulations.
• Conduct and document risk assessments based on NIST standards, ensuring that system design and implementation sufficiently mitigate Information Assurance (IA) risks.
• Implement, assess, and validate NIST SP 800-53A security controls for federal agencies, ensuring systems achieve and maintain compliance.
• Apply advanced risk management techniques to identify vulnerabilities and provide recommendations for mitigation strategies.
• Collaborate with technical teams to integrate security into system development life cycles and operational processes. Utilize data analysis, data mining, and business intelligence techniques to correlate data from disparate sources, identify trends, and create informative risk/compliance dashboards and visualizations.
• Provide guidance on security policy, compliance requirements, and audit readiness to technical and business stakeholders.
• Stay current with evolving federal security requirements, emerging technologies, and industry best practices to maintain a compliance posture.
Required Skills and Experience:
• At least 5 years of hands-on experience developing required A&A documentation (SSP, CP, SAR) and overseeing POA&Ms, with continuous monitoring responsibilities performed within the last three years.
• CISSP certification required.
• Minimum of 5 years’ experience implementing NIST 800-53A security controls in federal environments.
• Strong expertise in applying risk management frameworks and conducting risk assessments in accordance with NIST standards.
• 1+ years of experience working with data structures, data mining, and business intelligence, including correlating disparate data sources and creating data-driven visualizations.
• Strong understanding of federal security and compliance requirements (e.g., NIST RMF, FISMA, FedRAMP).
• Excellent written and verbal communication skills, with proven ability to prepare clear, concise, and compliant documentation.
• Strong analytical and problem-solving skills with attention to detail.
• Ability to collaborate effectively across technical, compliance, and executive teams.
Education and Certifications:
• Bachelor’s degree in computer science, Information Systems, Cybersecurity, or a related field (or equivalent experience).
• CISSP certification required.
• Additional certifications such as CISM, CISA, CAP, or Security+ are desirable.
If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.
Cybervance seeks an experienced Cybersecurity Operations Technical Manager (SOC Engineer/SME) to lead SOC engineering, manage dispersed teams, and enhance security operations for a Washington, D.C. mission environment.
Experienced Cybersecurity Architect needed to lead architecture, implementation, and team delivery of advanced security systems for enterprise and federal environments in Washington, D.C.
HopSkipDrive is hiring a remote Legal Operations Manager to streamline legal workflows, oversee contract lifecycle management, and drive legal technology and AI adoption.
Serve as TrustArc’s customer-facing privacy expert, aligning regulatory guidance with product solutions and go-to-market strategies for global enterprise clients.
Handshake is hiring a Privacy and Compliance Program Manager to lead privacy operations and ensure compliance with GDPR, CCPA, LGPD and other global privacy requirements while enabling product innovation.
Toast is looking for a Product Counsel to partner closely with product, engineering, and marketing teams to deliver compliant, consumer-facing Guest products and AI-enabled features.
Associate Legal Counsel responsible for negotiating commercial agreements and providing broad in-house legal support to Hudl's commercial and product teams.
Scholastic seeks a licensed U.S. Customs Broker with 10+ years of trade compliance experience to lead HTS classification, tariff engineering, and import/export documentation as Senior Manager of Global Trade (remote, New York-based).
Wilson Elser's Baltimore office is hiring a General Liability Associate Attorney to independently manage defense litigation matters and support partners in complex tort and casualty cases within a flexible hybrid arrangement.
RethinkFirst seeks an experienced Corporate Counsel to manage commercial contracting, ensure regulatory compliance, and drive legal operations improvements at a mission-driven behavioral health tech company.
Veolia is hiring a Health and Safety Specialist to lead safety and industrial hygiene programs, ensure regulatory compliance, and drive continuous improvement at the Arkadelphia facility.
An established pet care leader seeks a Manager of Regulatory Affairs to lead pesticide product registrations and compliance across North America.
The United Firm is hiring an admitted Immigration Attorney experienced in consular processing and waivers to manage cases, represent clients before USCIS, and lead paralegal workflow in our Los Angeles office.
MarcoPolo Learning seeks an organized Education Partnerships & Contracting Specialist to manage contracts, procurement, RFPs, and compliance for its education partnerships and vendor ecosystem.
Acelero Learning seeks a mission-driven Director of Monitoring and Compliance to lead compliance, quality improvement, and health & safety across its early childhood programs.