Back to jobs
New

Senior Subject Matter Expert (SME) - AI Governance & Security Policy

Alexandria, VA

RESULTS. INNOVATION. VALUES. ACCOUNTABILITY. 

That’s RIVA. 

We’re a mission-driven IT services company and systems integrator supporting digital transformation and modernization for federal government agencies. Since 2009, we’ve partnered with our customers to solve complex challenges through smart, practical innovation to deliver real outcomes where they matter most. Our teams are made up of industry-leading experts who are passionate about doing great work and making a difference. We don’t just develop solutions, we support efforts that strengthen communities and serve the public good. 
 
RIVA’s culture is built on four core values: Results, Innovation, Values, and Accountability. They guide how we work, how we collaborate, and how we measure success. Our employee-first approach is rooted in trust, ownership, and meaningful work. By investing in our people and fostering a flexible, supportive environment, employees have the opportunity to grow their skills, contribute ideas, and make an impact from day one. all while supporting missions that matter. 

POSITION OVERVIEW

RIVA Solutions is seeking a Senior Subject Matter Expert (SME) specializing in AI governance, federal data security policy, and regulatory compliance.  This SME provides highly specialized expertise to guide the agency's responsible adoption of AI across its four AI planes—Data, Development, Serving, and Control—and establishes defensible governance frameworks aligned with NIST AI RMF, OMB M-25-21, CISA BOD 26-04, and CISA 2026 agentic AI guidance. The candidate owns the Compliance and Reporting objective (SOO 4.1.4) and co-owns AI Governance and Protection (SOO 4.1.2) as a primary contributor. 

CORE RESPONSIBILITIES

  • Shape and maintain the AI governance framework for the USPTO, applying NIST AI RMF Govern, Map, Measure, and Manage functions to the agency's generative AI adoption across AWS Bedrock, AWS SageMaker, M365 Copilot, and other frontier AI platforms
  • Translate OMB M-25-21 (AI in Federal Government), CISA BOD 26-04, and CISA 2026 agentic AI guidance into actionable use-case playbooks, acceptable-use policies, and enforcement configurations for the UGAP API service broker and AWS Bedrock Guardrails
  • Define and maintain the policy-based enforcement matrix governing allow, block, alert, redact, and route actions across AI platforms routed through the UGAP broker, ensuring each approved use case moves from monitor-only baseline to graduated enforcement with documented Product Owner approval
  • Oversee the governance of the four AI planes: Data (Databricks/Unity Catalog classification coverage), Development (GitLab pipeline artifact security, Snyk Agent Scan findings), Serving (UGAP broker enforcement, Bedrock Guardrails inline controls), and Control (Wiz policy engine, Netskope CASB DLP rules, Okta ICAM access governance)
  • Develop and maintain the AI Governance and Enforcement Configuration, specifying use-case approval criteria, enforcement escalation paths, and Model Context Protocol (MCP) artifact governance policies to address agentic AI security risks
  • Lead the Compliance, Reporting, and Remediation objective: design the three-tier evidence chain (operational, compliance, executive) that flows from XSIAM and QRadar SIEM telemetry into AWS CloudWatch and S3-based reporting outputs, terminating in the COR-reviewed dashboard deliverable
  • Advise on the treatment of sensitive data categories—PII, confidential patent and trademark data, credentials, and export-controlled content—within AI workflows and ensure classification rules reflect agency risk appetite
  • Represent the program at senior stakeholder briefings, governance forums, and monthly COR reviews; translate complex AI policy and security posture data into executive-ready findings
  • Assess emerging agentic AI risks—autonomous tool-use chains, multi-agent orchestration, and MCP server exposure—against CISA 2026 guidance and recommend programmatic responses 

MINIMUM QUALIFICATIONS

  • Bachelor's degree and 10 years of relevant experience, or Master's degree and 8 years of relevant experience in cybersecurity, information assurance, AI policy, or a related field
  • Recognized expertise in federal AI governance frameworks, including NIST AI RMF, OMB M-25-21, and CISA agentic AI guidance; ability to operationalize policy mandates as technical enforcement configurations
  • Deep familiarity with NIST SP 800-53, FISMA, and FedRAMP requirements as applied to AI serving infrastructure (AWS Bedrock, SageMaker) and API brokering platforms
  • Experience designing AI policy enforcement controls using CASB (e.g., Netskope), API gateway brokering patterns, or inline guardrails (e.g., AWS Bedrock Guardrails)
  • Experience advising senior government officials and program offices on AI adoption risk, data security policy, and compliance reporting requirements
  • Demonstrated ability to translate regulatory requirements into actionable technical and operational guidance deliverable within a structured federal program
  • Technical literacy across the enforcement stack the governance framework directs: generative AI and LLM concepts (prompting, retrieval-augmented generation, model routing, system prompts), API gateway policy enforcement patterns, DLP rule logic, and policy-as-code practices with versioned policy definitions maintained in Git 

PREFERRED QUALIFICATIONS

  • Prior work at or with a federal civilian agency on AI adoption, responsible AI frameworks, or enterprise AI governance programs tied to OMB or CISA mandates
  • CISSP, CISM, or equivalent senior cybersecurity credential; familiarity with AI governance certifications or NIST AI RMF practitioner community
  • Experience governing AI platforms such as AWS Bedrock, Azure OpenAI Service Government, or similar frontier model environments in a federal context
  • Familiarity with Model Context Protocol (MCP) security risks, agentic AI orchestration patterns, and CISA 2026 agentic AI guidance
  • Published work, conference presentations, or recognized contributions to federal AI policy, responsible AI, or cybersecurity governance communities
  • Familiarity with AI security testing and evaluation practices: prompt injection and jailbreak red-teaming, data exfiltration testing for AI channels, and AI usage telemetry as governance evidence 

The salary or salary range for this role reflects an estimated range informed by multiple compensation factors. Final offers may vary based on considerations such as relevant experience, education and training, critical skillsets, and overall business needs.


Pay range

$175,000 - $200,000 USD

EQUAL EMPLOYMENT OPPORTUNITY & ACCOMMODATION

We believe great teams are built from different backgrounds, perspectives, and lived experiences, and we mean that beyond the buzzwords. 

RIVA is an equal opportunity employer. We welcome applicants of every race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, and any other characteristic protected by law.

If you need an accommodation at any point in our process, send an email to talent@rivasolutionsinc.com, we'll be happy to help.

VETERAN SUPPORT & ACCESSIBILITY

As a federal contractor, RIVA follows the requirements of the Vietnam Era Veterans' Readjustment Assistance Act (VEVRAA) and Section 503 of the Rehabilitation Act, supporting the employment and advancement of protected veterans and individuals with disabilities. If you're a veteran, we encourage you to self-identify during the application process, it helps us track our hiring commitments and, in some cases, may support priority referral for open roles.

RIVA also invites applicants to voluntarily self-identify as having a disability during the application process, not because it affects your chances of being hired, but because it helps us measure how well we're living up to our commitments and identify where we can do better. Your response is confidential and entirely optional.

 

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in RIVA Solutions, Inc.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...