Cyber Policy Analyst/Technical Writer
Listed on 2026-10-08
-
IT/Tech
Cybersecurity, Information Security & Data Protection
About the Role:
You will own the cybersecurity policy program for a federal civilian agency. You will write, review and manage security, privacy and records-management policies and procedures. You will also be the program’s advisor on policy questions. The customer’s environment includes FISMA systems, ranging from cloud platforms to operational technology environments.
Location: On site, Washington, DC
Key Responsibilities:- Develop, review and manage security documents so that they are high quality and meet customer standards.
- Advise the cybersecurity program on policy matters.
- Maintain cybersecurity, privacy and records-management policies, SOPs and related documents, following federal correspondence, style and branding standards.
- Review every policy, procedure and SOP each year against government-wide and customer guidance on IT security, privacy and records management, and update them.
- Find gaps in existing policies, procedures and guides, recommend fixes, and carry out the approved fixes.
- Write new policy and documentation as new requirements come up, such as executive orders, OMB memos, NIST revisions and agency directives.
- Build a cybersecurity core services catalog.
- Review, update and maintain the customer’s security control catalog and Minimum Security Parameters.
- Build and run a cybersecurity document repository with version control and publishing.
- Run an annual gap analysis of the policy and governance program and report on its maturity.
- Turn requirements from FISMA, the NIST SP 800 series, OMB A-130 and agency directives into clear, enforceable policy.
- Work with ISSOs, assessors, privacy and audit staff so that policy matches how the RMF, continuous monitoring, POA&M and incident response processes actually run.
- Prepare briefings and presentations on policy changes for the CISO and system owners.
- Bachelor’s degree in computer science or an IT-related field
- 10+ years writing, reviewing, researching and editing security and technical documents and presentations
- 10+ years of related information security experience
- CISSP or an equivalent certification. Equivalent means it covers a similar level of information security domains, or a similar depth of knowledge or experience. Assurit accepts CISSP, CISM, CISA or CGRC.
- Hands-on information security policy and procedure development under FISMA and the NIST SP 800 series
- Working knowledge of RMF, POA&M management and security assessments or audits
- U.S. citizen, able to pass a High Risk background investigation
- Able to work on site in Washington, DC during core hours, 8:00 AM-4:00 PM
- Experience writing policy for a federal civilian agency or other regulated organization
- Has built or maintained a NIST 800-53 Rev 5 control catalog or an organization-defined parameter baseline
- Experience with the policy and compliance modules in Service Now GRC/IRM
- Has written policy covering OT, SCADA or industrial control systems
- Plain-language writing and editing; federal correspondence style
- Experience writing Zero Trust or cloud security policy
- Active Tier 5 or Top Secret investigation
Assurit is an award winning, certified small business headquartered in Fairfax, VA. We offer a highly competitive compensation and benefits package inclusive of medical and dental coverage, as well as paid time off.
Founded in 2013, Assurit has become a trusted provider of cybersecurity expertise to customers across federal, state and local governments, as well as the commercial sector. We are an employee-centric organization that focuses on the growth and development of our greatest asset – our people. We believe that if our Team is trained and educated, we will always be able to deliver our promise of customer success.
If you enjoy work environments focused on continuous learning and growth, Assurit will be a great fit for you.
Assurit is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).