1

Cyber Security Policy Writer Jobs (NOW HIRING)

Policy Analyst

Springfield, VA · On-site

$96K - $118K/yr

Support the organization's Cybersecurity Strategy. * Analyze internal documents and external ... Highly developed interpersonal and oral/written communication skills, with the ability to ...

Excellent written and verbal communication skills are required. Preferred Qualifications: * CISSP, CISM, or similar certification. * Cybersecurity policy/SOP development experience. * Experience with ...

Excellent written and verbal communication skills are required. Preferred Qualifications: * CISSP, CISM, or similar certification. * Cybersecurity policy/SOP development experience. * Experience with ...

Policy Analyst

Springfield, VA · On-site

$96K - $118K/yr

Support the organization's Cybersecurity Strategy. * Analyze internal documents and external ... Highly developed interpersonal and oral/written communication skills, with the ability to ...

Policy Analyst

Saint Louis, MO · On-site

$92K - $107K/yr

Support the organization's Cybersecurity Strategy. * Analyze internal documents and external ... Highly developed interpersonal and oral/written communication skills, with the ability to ...

Excellent written and verbal communication skills are required. Preferred Qualifications: * CISSP, CISM, or similar certification. * Cybersecurity policy/SOP development experience. * Experience with ...

Policy Analyst

Saint Louis, MO · On-site

$92K - $107K/yr

Support the organization's Cybersecurity Strategy. * Analyze internal documents and external ... Highly developed interpersonal and oral/written communication skills, with the ability to ...

$96K - $118K/yr

Support the organization's Cybersecurity Strategy. * Analyze internal documents and external ... Highly developed interpersonal and oral/written communication skills, with the ability to ...

Showing results 21-40

Cyber Security Policy Writer information

See salary details

$13

$38

$66

How much do cyber security policy writer jobs pay per hour?

As of Sep 12, 2026, the average hourly pay for cyber security policy writer in the United States is $38.94, according to ZipRecruiter salary data. Most workers in this role earn between $28.85 and $47.12 per hour, depending on experience, location, and employer.

What does a Cyber Security Policy Writer do?

A Cyber Security Policy Writer is responsible for developing, drafting, and updating policies, procedures, and guidelines that govern an organization's information security practices. They work closely with IT, legal, and compliance teams to ensure policies meet regulatory requirements and effectively address current cyber threats. Their work helps organizations protect sensitive data, mitigate risks, and maintain compliance with industry standards. The role often involves researching best practices, staying informed about evolving regulations, and communicating complex security concepts in clear, actionable language.

How does a Cyber Security Policy Writer collaborate with technical and non-technical teams during the policy development process?

A Cyber Security Policy Writer regularly works with both technical experts (such as IT security professionals) and non-technical stakeholders (like HR or legal teams) to ensure policies are comprehensive and practical. This collaboration involves gathering input to accurately reflect operational realities, clarify technical requirements, and address compliance needs. Effective communication and the ability to translate complex technical concepts into clear, accessible language are crucial in this role. Frequent meetings, interviews, and review sessions help ensure policies are both technically sound and easily understood by all employees.

What are the key skills and qualifications needed to thrive as a Cyber Security Policy Writer, and why are they important?

To thrive as a Cyber Security Policy Writer, you need a thorough understanding of cybersecurity principles, regulatory frameworks, and strong technical writing skills, often supported by a degree in information security or a related field. Familiarity with frameworks like NIST, ISO 27001, and tools for document management or policy automation is typically required. Attention to detail, clear communication, and the ability to translate complex technical concepts into accessible language are vital soft skills. These competencies ensure that security policies are accurate, effective, and comprehensible, helping organizations maintain compliance and manage cyber risks.

What is the difference between Cyber Security Policy Writer vs Cyber Security Analyst?

AspectCyber Security Policy WriterCyber Security Analyst
Required CredentialsCertifications like CISSP, CISA, or Security+; strong writing skillsCertifications like CISSP, CEH, Security+; technical analysis skills
Work EnvironmentOffice or remote; focuses on policy documentation and complianceOffice or remote; focuses on threat detection and incident response
Employer & Industry UsageUsed in organizations with compliance needs, legal teams, and security departmentsUsed in security operations centers, IT departments, and risk management teams

While both roles require cybersecurity knowledge and certifications, the Cyber Security Policy Writer primarily focuses on creating and maintaining security policies and documentation, whereas the Cyber Security Analyst concentrates on monitoring, analyzing, and responding to security threats. Both roles are essential in a comprehensive cybersecurity strategy but serve different functions within an organization.

What are popular job titles related to Cyber Security Policy Writer jobs?

For Cyber Security Policy Writer jobs, the most frequently searched job titles are:

Infographic showing various Cyber Security Policy Writer job openings in the United States as of September 2026, with employment types broken down into 2% As Needed, 80% Full Time, 17% Part Time, and 1% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $81,001 per year, or $38.9 per hour.

Senior Cybersecurity Governance & Policy Specialist ? Level III

Washington, DC • On-site

RIVIDIUM
IT Services • 11 - 50 employees

Full-time

This job post has expired 1 day ago. Applications are no longer accepted.


Key responsibilities

  • Develop, maintain, and update enterprise-wide cybersecurity policies, standards, procedures, and governance frameworks supporting DHS Intelligence Enterprise operations.

  • Analyze and interpret Federal laws, Executive Orders, NSMs, ICDs, and cybersecurity standards to ensure organizational compliance.

  • Prepare responses, supporting documentation, and corrective action plans for audits, reviews, and oversight activities.


Job description

The Senior Cybersecurity Governance & Policy Specialist ? Level III serves as the principal cybersecurity governance and policy advisor supporting the Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE) Chief Information Security Officer (CISO). This senior-level position is responsible for developing, implementing, and maintaining enterprise-wide cybersecurity governance frameworks, policies, standards, and procedures that ensure compliance with Federal, DHS, and Intelligence Community (IC) cybersecurity mandates.

The Senior Cybersecurity Governance & Policy Specialist provides strategic leadership in cybersecurity governance by interpreting complex Federal regulations, Executive Orders, National Security Memoranda (NSMs), Intelligence Community Directives (ICDs), and NIST guidance into actionable organizational policies and implementation strategies. This position serves as a key liaison among DHS leadership, cybersecurity stakeholders, auditors, and Intelligence Community partners while supporting enterprise governance initiatives, regulatory compliance, and cybersecurity modernization efforts.

The ideal candidate is an experienced cybersecurity governance professional with exceptional analytical, policy development, technical writing, and executive communication skills, capable of advising senior leadership on cybersecurity governance and compliance across highly classified environments.

Key Responsibilities

  • Serve as the principal Cybersecurity Governance and Policy Advisor to the DHS Intelligence Enterprise Chief Information Security Officer (CISO).
  • Develop, maintain, and update enterprise-wide cybersecurity policies, standards, procedures, and governance frameworks supporting DHS Intelligence Enterprise operations.
  • Analyze and interpret Federal laws, Executive Orders, National Security Memoranda (NSMs), Office of Management and Budget (OMB) guidance, DHS directives, Intelligence Community Directives (ICDs), and cybersecurity standards to ensure organizational compliance.
  • Develop cybersecurity governance guidance aligned with:
    • NIST Risk Management Framework (RMF)
    • NIST SP 800-53
    • CNSSI 1253
    • ICD 503
    • DHS Sensitive Systems Policy Directive 4300C
    • NIST AI Risk Management Framework (AI RMF)
    • Classified Supply Chain Risk Management (C-SCRM) guidance
  • Conduct policy gap analyses and recommend implementation strategies for new and revised Federal, DHS, and Intelligence Community cybersecurity requirements.
  • Identify requirements for updates to the DHS 4300C Instruction Manual, Security Common Controls Catalog, Supply Chain Risk Management (SCRM) policies, and related governance documentation.
  • Coordinate policy implementation activities with Governance, Risk, and Compliance (GRC) administrators and cybersecurity engineering teams.
  • Research newly issued Executive Orders, Intelligence Community policies, National Security Memoranda, and other cybersecurity directives; prepare implementation guidance and compliance recommendations for DHS leadership.
  • Develop cybersecurity governance strategies supporting emerging technologies, including Zero Trust Architecture (ZTA), Artificial Intelligence (AI), Machine Learning (ML), cloud security, and cybersecurity modernization initiatives.
  • Prepare responses, supporting documentation, and corrective action plans for:
    • Federal Information Security Modernization Act (FISMA) audits
    • Office of Inspector General (OIG) audits
    • Joint Compliance Inspection Program (JCIP) reviews
    • Intelligence Community oversight activities
  • Develop executive-level communications, policy memoranda, briefing papers, white papers, reports, and PowerPoint presentations for the CISO, senior executives, and DHS Intelligence Enterprise leadership.
  • Present cybersecurity governance updates during executive leadership meetings, Intelligence Community Oversight Program (ICOP) sessions, governance boards, and cybersecurity working groups.
  • Monitor cybersecurity policy compliance across DHS Intelligence Enterprise Components and prepare compliance status reports, metrics, and executive dashboards.
  • Manage and maintain cybersecurity governance content on A-LAN and C-LAN SharePoint portals, ensuring policies, standards, guidance, and reference materials remain current.
  • Maintain centralized governance calendars, working group schedules, action item trackers, and policy repositories.
  • Represent DHS Intelligence Enterprise in Intelligence Community cybersecurity governance working groups, interagency meetings, and collaborative policy initiatives.
  • Provide mentorship and technical guidance to junior governance analysts and cybersecurity policy specialists.

Minimum Qualifications

  • Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.
  • Minimum 10 years of progressively responsible experience in cybersecurity governance, policy development, information assurance, or cybersecurity compliance supporting Federal Government or Intelligence Community programs.
  • Demonstrated expertise in:
    • Cybersecurity governance
    • Policy development
    • Regulatory compliance
    • Information assurance
    • Risk Management Framework (RMF)
    • Security policy implementation
  • Expert knowledge of:
    • NIST SP 800-53
    • NIST Risk Management Framework (RMF)
    • CNSSI 1253
    • ICD 503
    • DHS Sensitive Systems Policy Directive 4300C
    • Intelligence Community cybersecurity policies and overlays
  • Demonstrated experience translating complex Federal and Intelligence Community cybersecurity requirements into practical organizational policies, standards, and implementation guidance.
  • Experience supporting cybersecurity audits, inspections, compliance reviews, and corrective action planning.
  • Exceptional technical writing, analytical, and verbal communication skills with demonstrated experience preparing executive-level reports, presentations, policy memoranda, and briefing materials.
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, Public Administration, Political Science, or a related discipline.
  • Master's degree is preferred.

Preferred Qualifications

  • Current Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) certification.
  • Certified Authorization Professional (CAP) certification.
  • Experience supporting DHS Intelligence & Analysis (I&A) or other Intelligence Community cybersecurity organizations.
  • Experience supporting Federal Information Security Modernization Act (FISMA) audits, Office of Inspector General (OIG) reviews, and Joint Compliance Inspection Program (JCIP) assessments.
  • Experience with Governance, Risk, and Compliance (GRC) platforms such as RSA Archer.
  • Experience supporting cybersecurity governance initiatives involving Zero Trust Architecture (ZTA), Artificial Intelligence (AI), cloud security, and Supply Chain Risk Management (SCRM).
  • Experience managing SharePoint collaboration sites and enterprise governance repositories.

Required Certifications

The following current certification is required:

  • Certified Information Systems Security Professional (CISSP) or
  • Certified Information Security Manager (CISM)

Preferred certification:

  • Certified Authorization Professional (CAP)

Clearance Requirement

Active Top Secret/Sensitive Compartmented Information (TS/SCI) Clearance Required