Security Policy and Compliance Lead
Listed on 2026-09-14
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Koniag Operations Services, LLC (KOS), a Koniag Government Services company is seeking a Security Policy and Compliance Lead to support KOS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.
Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits, and tuition reimbursement.
We are seeking an experienced Security Policy and Compliance Lead to support the U.S. Small Business Administration (SBA). The ideal candidate is a seasoned cybersecurity professional with deep expertise in federal security policy development, compliance program management, and the application of federal cybersecurity frameworks and regulations within complex federal government environments. This individual will serve as the primary subject matter expert (SME) for security policy and compliance activities at the SBA, providing strategic guidance, technical leadership, and hands‑on program management to ensure the agency's cybersecurity policies, procedures, and practices align with applicable federal laws, regulations, executive orders, and industry best practices.
The Security Policy and Compliance Lead will serve as the senior expert responsible for leading and managing SBA's security policy and compliance programs, ensuring the agency's cybersecurity posture aligns with federal security requirements, regulatory obligations, and organizational risk tolerance.
Principal responsibilities will include but are not limited to:- Serve as the primary subject matter expert (SME) and program lead for SBA's security policy and compliance programs, providing strategic direction, technical guidance, and hands‑on leadership to ensure the agency's cybersecurity policies, procedures, and practices meet all applicable federal security requirements and regulatory obligations.
- Lead the development, review, maintenance, and continuous improvement of SBA's cybersecurity policy framework, including agency-wide security policies, standards, procedures, guidelines, and baselines, ensuring alignment with NIST, FISMA, OMB, and CISA requirements and directives.
- Oversee and manage SBA's compliance program, ensuring the agency's IT systems, security controls, and operational practices comply with applicable federal cybersecurity laws, regulations, executive orders, and OMB mandates, including FISMA, OMB Circular A-130, and relevant CISA Binding Operational Directives (BODs) and Emergency Directives (EDs).
- Lead and support the NIST Risk Management Framework (RMF) process across SBA's system portfolio, providing expert guidance on security categorization, control selection, implementation, assessment, authorization, and continuous monitoring activities.
- Develop, maintain, and continuously improve SBA's continuous monitoring program, including the development of monitoring strategies, assessment schedules, and reporting mechanisms to track the ongoing security posture of SBA's information systems and
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).