Skip to main content
Diligent Solutions logo

Cyber Policy Analyst / Technical Writer

Diligent Solutions
2 days ago
Remote
Remote Writing

Cyber Policy Analyst / Technical Writer
Location: On site, Washington, DC

About the Role

You will own the cybersecurity policy program for a federal civilian agency. You will write, review and manage security, privacy and records-management policies and procedures. You will also be the program’s advisor on policy questions. The customer’s environment includes FISMA systems, ranging from cloud platforms to operational technology environments.

What You’ll Do

  • Develop, review and manage security documents so that they are high quality and meet customer standards.
  • Advise the cybersecurity program on policy matters.
  • Maintain cybersecurity, privacy and records-management policies, SOPs and related documents, following federal correspondence, style and branding standards.
  • Review every policy, procedure and SOP each year against government-wide and customer guidance on IT security, privacy and records management, and update them.
  • Find gaps in existing policies, procedures and guides, recommend fixes, and carry out the approved fixes.
  • Write new policy and documentation as new requirements come up, such as executive orders, OMB memos, NIST revisions and agency directives.
  • Build a cybersecurity core services catalog.
  • Review, update and maintain the customer’s security control catalog and Minimum Security Parameters.
  • Build and run a cybersecurity document repository with version control and publishing.
  • Run an annual gap analysis of the policy and governance program and report on its maturity.
  • Turn requirements from FISMA, the NIST SP 800 series, OMB A-130 and agency directives into clear, enforceable policy.
  • Work with ISSOs, assessors, privacy and audit staff so that policy matches how the RMF, continuous monitoring, POA&M and incident response processes actually run.
  • Prepare briefings and presentations on policy changes for the CISO and system owners.

Required Qualifications

  • Bachelor’s degree in computer science or an IT-related field
  • 10+ years writing, reviewing, researching and editing security and technical documents and presentations
  • 10+ years of related information security experience
  • CISSP or an equivalent certification. Equivalent means it covers a similar level of information security domains, or a similar depth of knowledge or experience. Assurit accepts CISSP, CISM, CISA or CGRC.
  • Hands-on information security policy and procedure development under FISMA and the NIST SP 800 series
  • Working knowledge of RMF, POA&M management and security assessments or audits
  • U.S. citizen, able to pass a High Risk background investigation
  • Able to work on site in Washington, DC during core hours, 8:00 AM-4:00 PM

Desired Qualifications

  • Experience writing policy for a federal civilian agency or other regulated organization
  • Has built or maintained a NIST 800-53 Rev 5 control catalog or an organization-defined parameter baseline
  • Experience with the policy and compliance modules in ServiceNow GRC/IRM
  • Has written policy covering OT, SCADA or industrial control systems
  • Plain-language writing and editing; federal correspondence style
  • Experience writing Zero Trust or cloud security policy
  • Active Tier 5 or Top Secret investigation