1

Cyber Security Policy Jobs (NOW HIRING)

Senior Cybersecurity Program Analyst

Palmdale, CA · On-site

$106K - $137K/yr

The Cybersecurity Analyst shall ensure that all system and application deliverables meet the requirements of all DoD and AF Cybersecurity policies. This position's primary role is to that the ...

Contribute to cybersecurity policy and standards development. * Enhance risk management documentation, reporting, and governance metrics. * Collaborate with leadership on strategic cybersecurity ...

Director of Cybersecurity - GRC

Newark, NJ · On-site

$116K - $156K/yr

NRC, SOX, DoE, NERC CIP, TSA, Internal Audits, etc.), Cybersecurity Risk, Cybersecurity Policy, Cybersecurity Awareness, and Nth Party Risk Management and Assurance. (S)he coordinates across all ...

The Cybersecurity Engineers will prepare, implement, and ensure compliance with cybersecurity policy, to include Assessment and Authorization requirements. Job Responsibilities Include: * Plan ...

The individual shall ensure that all system and application deliverables meet the requirements of all DoD and Air Force Cybersecurity policies. Responsibilities include but are not limited to: * The ...

Showing results 41-60

Cyber Security Policy information

See salary details

$57K

$133K

$186K

How much do cyber security policy jobs pay per year?

As of Sep 1, 2026, the average yearly pay for cyber security policy in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What is cyber security policy?

A cyber security policy is a set of guidelines, rules, and procedures that organizations create to protect their digital assets and sensitive information from cyber threats. The policy outlines acceptable use of technology, roles and responsibilities, and protocols for responding to security incidents. It helps ensure that everyone in the organization understands how to safeguard data, comply with regulations, and reduce the risk of cyberattacks. A strong cyber security policy is essential for maintaining business continuity, legal compliance, and customer trust.

What are the key skills and qualifications needed to thrive in cyber security policy?

To thrive in Cyber Security Policy, you need a solid understanding of information security principles, risk assessment, compliance frameworks, and typically a degree in cybersecurity, information technology, or a related field. Familiarity with standards such as NIST, ISO 27001, and government regulations, along with certifications like CISSP or CISM, is highly valued. Strong analytical thinking, communication, and collaboration skills help you interpret technical information and craft effective policies. These competencies ensure organizations can mitigate cyber risks, comply with regulations, and maintain robust security postures.

What are some common challenges faced by professionals working in cyber security policy roles?

Professionals in Cyber Security Policy often navigate the challenge of balancing organizational security needs with regulatory compliance and user privacy requirements. They must stay updated on rapidly evolving cyber threats and policy frameworks while ensuring that policies are practical for technical teams to implement. Additionally, they frequently collaborate with legal, IT, and executive departments, requiring strong communication and negotiation skills to align diverse stakeholder interests. Adapting policies to different business units and staying proactive against emerging risks are also key aspects of the role.

What is the difference between Cyber Security Policy vs Cyber Security Analyst?

AspectCyber Security PolicyCyber Security Analyst
Primary FocusDeveloping, implementing, and maintaining security policies and proceduresMonitoring, analyzing, and responding to security threats and incidents
Required CredentialsKnowledge of security frameworks, policies, and compliance standardsCertifications like CISSP, CEH, or Security+; technical skills
Work EnvironmentPolicy development teams, compliance departments, managementSecurity operations centers, IT teams, incident response teams
Industry UsageUsed across organizations to establish security standardsUsed to identify and mitigate security threats

While a Cyber Security Policy focuses on creating and maintaining security guidelines, a Cyber Security Analyst actively monitors and responds to security threats. Both roles are essential for a comprehensive security strategy, with policies providing the framework and analysts ensuring its enforcement and effectiveness.

How to get into cybersecurity policy?

To enter cybersecurity policy, develop a strong understanding of cybersecurity principles, laws, and regulations, often through a degree in cybersecurity, computer science, or law. Gaining experience with policy development, risk management, and familiarity with tools like compliance frameworks (e.g., NIST, ISO) can be beneficial, along with certifications such as CISSP or CISA. Building connections through industry events and staying informed on current cybersecurity issues also support entry into this field.
More about Cyber Security Policy jobs

What cities are hiring for Cyber Security Policy jobs?

Cities with the most Cyber Security Policy job openings:

What states have the most Cyber Security Policy jobs?

States with the most job openings for Cyber Security Policy jobs include:

What job categories do people searching Cyber Security Policy jobs look for?

The top searched job categories for Cyber Security Policy jobs are:

Infographic showing various Cyber Security Policy job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 16% Part Time, and 1% Contract. Highlights an 95% Physical, 2% Hybrid, and 3% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

Senior Security Governance and Policy Analyst

Analygence

Washington, DC • On-site

$108K - $142K/yr

Full-time

Re-posted 27 days ago


Job description

Description
Tharros is seeking a Senior Security Governance and Policy Analyst to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region.
This role will support cybersecurity governance, policy, compliance, and executive communications across a complex mission environment. The ideal candidate can translate Federal, DHS, and Intelligence Community cybersecurity policy into practical implementation plans and help senior cybersecurity leaders drive consistent governance across cloud, on-premise, classified, and unclassified environments.
Responsibilities:
  • Serve as a senior cybersecurity governance and policy advisor supporting cybersecurity leadership.
  • Analyze cybersecurity requirements derived from policies, directives, standards, and guidance.
  • Develop and update cybersecurity policies, standards, governance documentation, and implementation recommendations.
  • Support governance activities related to RMF, FISMA, CNSSI standards, NIST 800-53, security control catalogs, supply chain risk management, AI/ML security considerations, and cybersecurity compliance.
  • Review changes to Federal, DHS, Intelligence Community, and other applicable cybersecurity policies and recommend practical implementation approaches.
  • Support updates to security policy manuals, supply chain risk management policy, security control catalogs, and related governance artifacts.
  • Coordinate with governance, risk, and compliance stakeholders to support accurate control mapping and policy implementation.
  • Research new or updated cybersecurity Executive Orders, Intelligence Community policies, national security guidance, and related requirements.
  • Support cybersecurity audit response activities, including inspection, compliance, and oversight-related efforts.
  • Prepare executive summaries, reports, talking points, briefings, stakeholder communications, and senior-leader presentation materials.
  • Support cybersecurity governance working groups, taskers, data calls, trackers, repositories, and policy reference updates.
  • Help identify opportunities to improve governance processes, streamline policy implementation, and increase consistency across cybersecurity compliance activities.

Requirements
  • Active TS/SCI
  • 10+ years of experience supporting cybersecurity projects of similar size and complexity.
  • Knowledge of Federal, DHS, and Intelligence Community cybersecurity policy and guidance.
  • CISSP or CISM certification, or equivalent.
  • Experience with cloud and on-premise environments.
  • Experience translating cybersecurity policy into implementable plans.
  • Strong written and verbal communication skills.
  • Experience developing cybersecurity policy, governance documentation, executive briefings, reports, and stakeholder communications.
  • Familiarity with RMF, FISMA, CNSSI, NIST 800-53, GRC processes, security control catalogs, and cybersecurity compliance.
  • Ability to work onsite at a Government-approved location as required.
  • Strong written and verbal communication skills.

Preferred Qualifications:
  • Prior DHS, Intelligence Community, CISO office, ISSM, Authorizing Official, or national security cybersecurity governance experience.
  • Experience with classified cybersecurity policy, SCI systems governance, DHS 4300-series guidance, ICD 503, CNSSI 1253, or related security frameworks.
  • Experience with cloud security governance, hybrid environments, AI/ML policy considerations, Zero Trust policy implementation, or supply chain risk management.
  • Experience preparing senior-leader briefings, audit responses, governance materials, working group updates, and stakeholder communications.