1

Cyber Security Policy Analyst Jobs in Michigan (NOW HIRING)

... policy across DLA IT, Cloud, and OT technologies, spanning both unclassified (NIPRNet) and ... Provide analysis of existing and emerging DLA Information Systems, OT, and IT Infrastructure to ...

... policy across DLA IT, Cloud, and OT technologies, spanning both unclassified (NIPRNet) and ... Provide analysis of existing and emerging DLA Information Systems, OT, and IT Infrastructure to ...

... policy across DLA IT, Cloud, and OT technologies, spanning both unclassified (NIPRNet) and ... Provide analysis of existing and emerging DLA Information Systems, OT, and IT Infrastructure to ...

... cause analysis, impact assessments, and remediation activities. * Assist in developing, maintaining, and improving cybersecurity policies, standards, procedures, and technical documentation.

... cause analysis, impact assessments, and remediation activities. * Assist in developing, maintaining, and improving cybersecurity policies, standards, procedures, and technical documentation.

next page

Showing results 1-20

Cyber Security Policy Analyst information

See Michigan salary details

$37.5K

$86.6K

$130.7K

How much do cyber security policy analyst jobs pay per year?

As of Aug 28, 2026, the average yearly pay for cyber security policy analyst in Michigan is $86,636.00, according to ZipRecruiter salary data. Most workers in this role earn between $69,300.00 and $100,700.00 per year, depending on experience, location, and employer.

What does a cyber security policy analyst do?

A Cyber Security Policy Analyst develops, implements, and reviews policies and procedures to protect an organization's information systems from cyber threats. They analyze current security measures, stay updated on regulations and emerging threats, and ensure that the organization’s security policies comply with legal and regulatory requirements. Additionally, they may provide recommendations for policy improvements, conduct risk assessments, and educate staff on security best practices.

What are the key skills and qualifications needed to thrive as a cyber security policy analyst?

To thrive as a Cyber Security Policy Analyst, you need a deep understanding of cyber security frameworks, risk assessment, and policy development, usually supported by a bachelor's degree in cyber security, information technology, or a related field. Familiarity with regulatory standards (such as NIST, ISO 27001), governance tools, and, sometimes, certifications like CISSP or CISM is important. Excellent analytical thinking, written communication, and stakeholder collaboration skills help you translate technical risks into effective policies. These skills ensure that organizations remain compliant, minimize cyber risks, and build resilient security postures.

What are some common challenges faced by cyber security policy analysts when translating technical risks into actionable policies?

Cyber Security Policy Analysts often face the challenge of bridging the gap between highly technical security risks and practical, understandable policies for non-technical stakeholders. They must ensure that policies are comprehensive yet accessible, balancing security needs with business operations. Additionally, keeping policies current with evolving threats and regulatory requirements can be demanding. Effective communication and collaboration with IT, legal, and executive teams are essential to address these challenges and ensure successful policy implementation.

What is the difference between Cyber Security Policy Analyst vs Cyber Security Analyst?

AspectCyber Security Policy AnalystCyber Security Analyst
CredentialsBachelor's degree in cybersecurity, IT, or related field; certifications like CISSP, CISABachelor's degree in cybersecurity, IT, or related field; certifications like CompTIA Security+, CEH
Work EnvironmentPolicy development, compliance, risk assessment, often in office settingsSecurity monitoring, incident response, vulnerability assessment, often in security operations centers
Employer & IndustryGovernment agencies, corporations, consulting firms focusing on policy and complianceIT departments, security firms, organizations with active cybersecurity operations

The main difference is that a Cyber Security Policy Analyst focuses on creating and managing security policies, ensuring compliance, and assessing risks, while a Cyber Security Analyst primarily monitors systems, responds to threats, and handles technical security issues. Both roles require cybersecurity knowledge but serve different functions within an organization.

What are popular job titles related to Cyber Security Policy Analyst jobs in Michigan?

For Cyber Security Policy Analyst jobs in Michigan, the most frequently searched job titles are:

What job categories do people searching Cyber Security Policy Analyst jobs in Michigan look for?

The top searched job categories for Cyber Security Policy Analyst jobs in Michigan are:

What cities in Michigan are hiring for Cyber Security Policy Analyst jobs?

Cities in Michigan with the most Cyber Security Policy Analyst job openings:

Infographic showing various Cyber Security Policy Analyst job openings in Michigan as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 17% Part Time, 2% Temporary, 2% Contract, and 1% Nights. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $86,636 per year, or $41.7 per hour.

Cybersecurity Subject Matter Expert Lead

Goldbelt, Inc.

Battle Creek, MI

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 16 days ago


Job description

Overview

Please note that this position is contingent upon the successful award of a contract currently under bid.

Global in service but local in approach, Nisga'a Tek is committed to high-quality service to those who defend us. Nisga'a Tek ensures mission assurance and execution for customers and warfighters. Providing intelligence, IT, cyber security, training, logistics, administrative, acquisition, and background investigation services. 

Summary:

The Cybersecurity Subject Matter Expert Lead provides expert support, research and analysis of exceptionally complex problems, and processes relating to them.

Responsibilities

Essential Job Functions:

  • Serves as technical expert to the Cybersecurity Assessment Program providing technical direction, interpretation, and alternatives to complex problems.
  • Thinks independently and demonstrates exceptional written and oral communications skills.
  • Applies advanced technical principles, theories, and concepts.
  • Contributes to the development of new principles, concepts, and methodologies.
  • Works on unusually complex technical problems and provides highly innovative and ingenious solutions.
  • Recommends cybersecurity software tools and assists in the development of software tool requirements and selection criteria to include the development of product specific STIGs from applicable DISA SRGs.
  • Works under consultative direction toward predetermined long-range goals and objectives.
  • Assignments are often self-initiated.
  • Determines and pursues courses of action necessary to obtain desired results.
  • Develops advanced technological ideas and guides their development into a final product.
Qualifications

Necessary Skills and Knowledge:

  • Demonstrated expertise in leading and mentoring teams, providing clear guidance, quality oversight, and technical direction to ensure all cybersecurity artifacts meet DoD standards, organizational expectations, and inspection ready quality levels.
  • Provin real world hands-on experience preparing enterprise environments for DoD cybersecurity inspections (CCRI, CORA, Blue Team assessments)
  • SME level experience in assessing security controls and conducting authorization reviews for large, complex organizations.
  • SME level understanding of DoD cybersecurity requirements, including documenting and developing artifacts for STIGs, TCG configuration guides, IAVMs, and Task Orders
  • Oversees end to end POA&M lifecycle management, ensuring accurate documentation, status tracking, and closure of all remediation actions
  • Exceptional ability to develop, maintain, and validate RMF artifacts and cybersecurity documentation
  • Expert ability to interpret new and evolving DoD cybersecurity documentation, templates, and compliance requirements to develop high quality cyber security artifacts even when guidance is incomplete, ambiguous, or inconsistently applied.
  • Skilled in analyzing and interpreting cybersecurity guidance from the ISSM/ISSO to produce authoritative system documents such as the SSP, CONOPS, Incident Response Plan, Contingency Plan, Configuration Management Plan, and other required artifacts
  • Proven ability to work independently and collaboratively with minimal oversight
  • Strong research, analytical, and problem solving skills
  • Proficiency with analytical tools such as Microsoft Excel, Access, Power BI, and Power Platforms
  • Ability to generate clear, accurate, and audit ready cybersecurity reports, including vulnerability summaries, compliance status updates, and risk findings for technical and leadership audiences
  • Ability to generate detailed analytics and trend reports using data from vulnerability scanners, configuration tools, and security platforms to support decision making and inspection readiness
  • Excellent written and verbal communication skills, including the ability to brief leadership and produce clear documentation
  • Experienced in the general tenets supporting the overall DOD implementation of its authorization process, to include supporting cybersecurity policy, procedures, and processes.
  • Knowledgeable in the cybersecurity of emerging technology areas such as Cloud, information technology (IT), Industrial Control Systems (ICSs), or Operational Technology (OT) infrastructures.
  • Strong analytical and problem-solving skills for resolving security issues.

Minimum Qualifications:

  • Certification Requirements:
    • Required Training Certifications In: ICS300 or relevant Operational Technology "OT" or Industrial Control System "ICS" Cybersecurity Certifications, ACAS, and Tanium
    • Computing Environment: DLA approved CE (D Account Access)
    • Current Requirement: DOD 8570 - IAT 3
    • Future Requirement: DOD 8140
    • Primary Cyber Work Role:
      • Work Element: Cybersecurity (CS)
      • Work Role: 722 - Information Systems Security Manager
      • Proficiency Level: Advanced
  • Ten (10) years IT experience
  • Ten (10) years DOD Cybersecurity experience
  • Ten (10) years of Risk Management Framework (RMF) and NIST A&A experience
  • Expert experience in cybersecurity and evaluations
  • DOD Secret Clearance and must possess IT-II Non-Critical Sensitive security clearance or Tier 3 (T3) at time of proposal submission.

Preferred Qualifications:

  • Bachelor's degree

Pay and BenefitsAt Goldbelt, we value and reward our team's dedication and hard work. We provide a competitive base salary commensurate with your qualifications and experience. As an employee, you'll enjoy a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.

Employment Type: FULL_TIME