1

Cyber Security Policy Analyst Jobs (NOW HIRING)

Cybersecurity Policy Analyst Annual Policy Review Prudent Technology is seeking a Cybersecurity Policy Analyst Annual Policy Review who will support the Federal client's Annual Policy Review work ...

AGE Solutions is looking for a Cybersecurity Policy Analyst to leads the review, consolidation, and development of cybersecurity policies in alignment with government standards. Ensures that these ...

A minimum of 15 years of IT cybersecurity experience, including direct support for the US Government and 7 years serving as a Policy Analyst for an enterprise IT systems OR a relevant Master's Degree ...

Support the organization's Cybersecurity Strategy. * Analyze internal documents and external issuances (e.g., IC/DoW policy, Executive Orders) to identify policy impacts, conflicts, or gaps.

Policy Analyst Unlock the secrets of intelligence with MANTECH! Join a dynamic team at the ... Lead the development, review, and coordination of corporate, IT service, and cybersecurity ...

next page

Showing results 1-20

Cyber Security Policy Analyst information

See salary details

$43K

$99.4K

$150K

How much do cyber security policy analyst jobs pay per year?

As of Jul 22, 2026, the average yearly pay for cyber security policy analyst in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What does a Cyber Security Policy Analyst do?

A Cyber Security Policy Analyst develops, implements, and reviews policies and procedures to protect an organization's information systems from cyber threats. They analyze current security measures, stay updated on regulations and emerging threats, and ensure that the organization’s security policies comply with legal and regulatory requirements. Additionally, they may provide recommendations for policy improvements, conduct risk assessments, and educate staff on security best practices.

What is the difference between Cyber Security Policy Analyst vs Cyber Security Analyst?

AspectCyber Security Policy AnalystCyber Security Analyst
CredentialsBachelor's degree in cybersecurity, IT, or related field; certifications like CISSP, CISABachelor's degree in cybersecurity, IT, or related field; certifications like CompTIA Security+, CEH
Work EnvironmentPolicy development, compliance, risk assessment, often in office settingsSecurity monitoring, incident response, vulnerability assessment, often in security operations centers
Employer & IndustryGovernment agencies, corporations, consulting firms focusing on policy and complianceIT departments, security firms, organizations with active cybersecurity operations

The main difference is that a Cyber Security Policy Analyst focuses on creating and managing security policies, ensuring compliance, and assessing risks, while a Cyber Security Analyst primarily monitors systems, responds to threats, and handles technical security issues. Both roles require cybersecurity knowledge but serve different functions within an organization.

What are some common challenges faced by Cyber Security Policy Analysts when translating technical risks into actionable policies?

Cyber Security Policy Analysts often face the challenge of bridging the gap between highly technical security risks and practical, understandable policies for non-technical stakeholders. They must ensure that policies are comprehensive yet accessible, balancing security needs with business operations. Additionally, keeping policies current with evolving threats and regulatory requirements can be demanding. Effective communication and collaboration with IT, legal, and executive teams are essential to address these challenges and ensure successful policy implementation.

What are the key skills and qualifications needed to thrive as a Cyber Security Policy Analyst, and why are they important?

To thrive as a Cyber Security Policy Analyst, you need a deep understanding of cyber security frameworks, risk assessment, and policy development, usually supported by a bachelor's degree in cyber security, information technology, or a related field. Familiarity with regulatory standards (such as NIST, ISO 27001), governance tools, and, sometimes, certifications like CISSP or CISM is important. Excellent analytical thinking, written communication, and stakeholder collaboration skills help you translate technical risks into effective policies. These skills ensure that organizations remain compliant, minimize cyber risks, and build resilient security postures.
More about Cyber Security Policy Analyst jobs
What cities are hiring for Cyber Security Policy Analyst jobs? Cities with the most Cyber Security Policy Analyst job openings:
What states have the most Cyber Security Policy Analyst jobs? States with the most job openings for Cyber Security Policy Analyst jobs include:
Infographic showing various Cyber Security Policy Analyst job openings in the United States as of July 2026, with employment types broken down into 89% Full Time, 6% Part Time, 1% Temporary, and 4% Contract. Highlights an 83% Physical, 7% Hybrid, and 10% Remote job distribution, with an average salary of $99,400 per year, or $47.8 per hour.
Cybersecurity Policy Analyst

Full-time

Posted 7 days ago


Job description

Job Description:

Dynamo Technologies, LLC is seeking a Cybersecurity Policy Analyst to support the Defense Logistics Agency (DLA) Technology Foundation Services (TFS) Vulnerability Management Program. The selected candidate will review, consolidate, and develop cybersecurity policies in accordance with government requirements and provide technical support to programs by assessing IT policies, standards, guidelines, and procedures. This position will support the implementation of DoD cybersecurity policies, procedures, and processes while ensuring a balance between security requirements and operational objectives. The Cybersecurity Policy Analyst will brief senior management on cybersecurity policy changes, updates, and program progress.

Duties/ Responsibilities

  • Review, consolidate, and develop cybersecurity policies in accordance with government requirements.
  • Provide technical support and assistance to programs regarding cybersecurity policies, standards, guidelines, and procedures.
  • Assess existing IT policies and procedures to ensure alignment with operational and security requirements.
  • Support implementation of DoD cybersecurity policies, procedures, and processes.
  • Develop cybersecurity artifacts supporting STIGs, TCG configuration guides, IAVMs, and Task Orders.
  • Develop, maintain, and validate RMF artifacts and cybersecurity documentation.
  • Update and track POA&M entries by documenting findings, remediation actions, and milestone status.
  • Generate cybersecurity reports including vulnerability summaries, compliance status updates, and risk findings.
  • Produce analytics and trend reports using data from vulnerability scanners, configuration tools, and security platforms.
  • Support cybersecurity compliance and inspection readiness activities.
  • Conduct cybersecurity research and analysis to support policy development and implementation.
  • Brief senior management on cybersecurity policy changes, updates, and progress.

Required Skills/Abilities

  • Experience supporting the implementation of DoD cybersecurity policies, procedures, and processes.
  • Ability to develop cybersecurity artifacts for STIGs, TCG configuration guides, IAVMs, and Task Orders.
  • Ability to develop, maintain, and validate RMF artifacts and cybersecurity documentation.
  • Experience updating and tracking POA&M entries and remediation activities.
  • Proven ability to work independently and collaboratively with minimal oversight.
  • Strong research and analytical skills.
  • Proficiency with Microsoft Excel, Microsoft Access, Power BI, and Microsoft Power Platform tools.
  • Ability to generate clear, accurate, and audit-ready cybersecurity reports.
  • Experience producing detailed analytics and trend reports using vulnerability management and security platform data.
  • Excellent written and verbal communication skills, including briefing senior leadership.

Nice to Have Skills

  • Experience supporting RMF activities and cybersecurity compliance initiatives.
  • Experience supporting vulnerability management programs.
  • Familiarity with NIST-based cybersecurity frameworks and assessment processes.
  • Experience supporting cybersecurity inspections, audits, and assessments.
  • Knowledge of enterprise IT environments and cybersecurity governance.
  • Experience supporting DoD cybersecurity programs.

Education and Experience:

  • Seven (7) years of relevant cybersecurity policy experience.
  • Required Certifications:
    • ACAS and Tanium.
    • DLA Approved Computing Environment (D Account Access).
    • DoD 8570 – IAT Level II.

Travel Requirement:

  • Travel may be required in support of audits, inspections, assessments, and stakeholder coordination activities.

Clearance Requirement:

  • Must possess a DoD Secret Clearance and be eligible for an IT-II Non-Critical Sensitive security clearance or Tier 3 (T3) upon assignment.

Dynamo is a full lifecycle digital transformation company providing best-in-class technology and mission support services to our clients. Dynamo’s mission is to lead the digital transformation industry and provide best-in-class solutions for our clients with a truly human touch.

We leverage industry leading practices to empower our clients, ultimately providing them with the necessary tools, knowledge, and information required to successfully achieve their strategic goals, while optimizing their operations.

Through our partnerships, boldness, and authenticity, Dynamo goes against the grain of a traditional government contracting company by providing top-caliber team members, delivering quality results, and always exceeding expectations.

Dynamo Technologies is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, national origin, religion, sex, pregnancy, disability, protected veteran status, age, or any other characteristic protected by law.