Cyber Policy Analyst / Technical Writer

Diligent Solutions•,
•Onsite

About The Position

You will own the cybersecurity policy program for a federal civilian agency. You will write, review and manage security, privacy and records-management policies and procedures. You will also be the program’s advisor on policy questions. The customer’s environment includes FISMA systems, ranging from cloud platforms to operational technology environments.

Requirements

  • Bachelor’s degree in computer science or an IT-related field
  • 10+ years writing, reviewing, researching and editing security and technical documents and presentations
  • 10+ years of related information security experience
  • CISSP or an equivalent certification. Equivalent means it covers a similar level of information security domains, or a similar depth of knowledge or experience. Assurit accepts CISSP, CISM, CISA or CGRC.
  • Hands-on information security policy and procedure development under FISMA and the NIST SP 800 series
  • Working knowledge of RMF, POA&M management and security assessments or audits
  • U.S. citizen, able to pass a High Risk background investigation
  • Able to work on site in Washington, DC during core hours, 8:00 AM-4:00 PM

Nice To Haves

  • Experience writing policy for a federal civilian agency or other regulated organization
  • Has built or maintained a NIST 800-53 Rev 5 control catalog or an organization-defined parameter baseline
  • Experience with the policy and compliance modules in ServiceNow GRC/IRM
  • Has written policy covering OT, SCADA or industrial control systems
  • Plain-language writing and editing; federal correspondence style
  • Experience writing Zero Trust or cloud security policy
  • Active Tier 5 or Top Secret investigation

Responsibilities

  • Develop, review and manage security documents so that they are high quality and meet customer standards.
  • Advise the cybersecurity program on policy matters.
  • Maintain cybersecurity, privacy and records-management policies, SOPs and related documents, following federal correspondence, style and branding standards.
  • Review every policy, procedure and SOP each year against government-wide and customer guidance on IT security, privacy and records management, and update them.
  • Find gaps in existing policies, procedures and guides, recommend fixes, and carry out the approved fixes.
  • Write new policy and documentation as new requirements come up, such as executive orders, OMB memos, NIST revisions and agency directives.
  • Build a cybersecurity core services catalog.
  • Review, update and maintain the customer’s security control catalog and Minimum Security Parameters.
  • Build and run a cybersecurity document repository with version control and publishing.
  • Run an annual gap analysis of the policy and governance program and report on its maturity.
  • Turn requirements from FISMA, the NIST SP 800 series, OMB A-130 and agency directives into clear, enforceable policy.
  • Work with ISSOs, assessors, privacy and audit staff so that policy matches how the RMF, continuous monitoring, POA&M and incident response processes actually run.
  • Prepare briefings and presentations on policy changes for the CISO and system owners.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service