Technical Writer cybersecurity
Job Description
The contractor will develop, revise, and maintain information security governance documentation. The work includes creating technically accurate, enforceable documentation aligned with cybersecurity frameworks and organizational objectives.
Primary Responsibilities
- Develop and revise information security policies.
- Develop technical standards supporting approved security policies.
- Develop operational procedures and implementation guidance.
- Create security baselines and configuration documentation.
- Develop compliance documentation to ensure technical accuracy, consistency, completeness, and enforceability.
- Recommend improvements to governance documentation structure and organization.
- Produce clear documentation suitable for technical staff, management, auditors, and external reviewers.
- Work with subject matter experts (SMEs) to accurately document existing processes and required security controls.
- Maintain document version control and support periodic reviews.
Required Skills & Qualifications
- Technical writing experience involving cybersecurity or IT governance.
- Demonstrated experience with several of the following:
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-53
- IRS Publication 1075
- CIS Critical Security Controls (CIS Controls)
- Security Governance and Risk Management
- Identity and Access Management (IAM)
- Incident Response
- Vulnerability Management
- Disaster Recovery (DR) and Business Continuity (BC)
- Vendor Risk Management
- Security Awareness and Training
- Policy Lifecycle Management
Preferred Qualifications
- Experience writing documentation aligned with:
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-53
- IRS Publication 1075
- One or more of the following certifications:
- CISSP (Certified Information Systems Security Professional)
- CISA (Certified Information Systems Auditor)
- CGRC (Certified in Governance, Risk and Compliance)
- CompTIA Security+
- Or an equivalent cybersecurity certification