1

Cybersecurity Policy Analyst Jobs (NOW HIRING)

Cybersecurity Policy Analyst Annual Policy Review Prudent Technology is seeking a Cybersecurity Policy Analyst Annual Policy Review who will support the Federal client's Annual Policy Review work ...

AGE Solutions is looking for a Cybersecurity Policy Analyst to leads the review, consolidation, and development of cybersecurity policies in alignment with government standards. Ensures that these ...

A minimum of 15 years of IT cybersecurity experience, including direct support for the US Government and 7 years serving as a Policy Analyst for an enterprise IT systems OR a relevant Master's Degree ...

Support the organization's Cybersecurity Strategy. * Analyze internal documents and external issuances (e.g., IC/DoW policy, Executive Orders) to identify policy impacts, conflicts, or gaps.

Policy Analyst Unlock the secrets of intelligence with MANTECH! Join a dynamic team at the ... Lead the development, review, and coordination of corporate, IT service, and cybersecurity ...

next page

Showing results 1-20

Cybersecurity Policy Analyst information

See salary details

$43K

$99.4K

$150K

How much do cybersecurity policy analyst jobs pay per year?

As of Jul 21, 2026, the average yearly pay for cybersecurity policy analyst in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What does a cybersecurity policy analyst do?

A cybersecurity policy analyst develops, reviews, and implements security policies and procedures to protect an organization’s information systems. They analyze security risks, ensure compliance with regulations, and recommend improvements, often using tools like risk assessment frameworks and security standards. Strong communication skills and knowledge of cybersecurity best practices are essential for this role.

What are Cybersecurity Policy Analysts?

Cybersecurity Policy Analysts are professionals who develop, implement, and evaluate policies and regulations to protect an organization’s digital assets and information systems. They analyze current security measures, assess risks, and ensure compliance with laws and industry standards. Their work helps organizations respond to evolving cyber threats and maintain robust security protocols. Cybersecurity Policy Analysts often collaborate with IT teams, legal advisors, and management to create effective security policies and incident response plans.

What is the difference between Cybersecurity Policy Analyst vs Cybersecurity Analyst?

AspectCybersecurity Policy AnalystCybersecurity Analyst
Required CredentialsBachelor's in cybersecurity, IT, or related field; certifications like CISSP, CISABachelor's in cybersecurity, IT, or related field; certifications like CompTIA Security+ or CISSP
Work EnvironmentPolicy development, compliance, and strategic planning in office settingsTechnical security monitoring, incident response, and system analysis
Employer & Industry UsageGovernment agencies, corporations, consulting firms focusing on security policiesIT departments, security firms, and organizations managing technical security

The main difference is that a Cybersecurity Policy Analyst focuses on creating and managing security policies and ensuring compliance, while a Cybersecurity Analyst handles technical security measures and threat mitigation. Both roles require similar credentials but serve different functions within cybersecurity teams.

Is 30 too old for cyber security?

Cybersecurity Policy Analysts can enter the field at any age, as experience, skills, and certifications like CISSP or CompTIA Security+ are often more important than age. Many professionals transition into cybersecurity later in their careers, bringing valuable perspectives and expertise. Age should not be a barrier to starting or advancing in cybersecurity roles.

How much does a cyber policy analyst make?

A cybersecurity policy analyst typically earns between $70,000 and $120,000 annually, depending on experience, education, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISM can earn higher salaries, especially in larger organizations or specialized sectors.

How does a Cybersecurity Policy Analyst typically collaborate with technical and non-technical teams within an organization?

A Cybersecurity Policy Analyst often acts as a bridge between technical security teams and non-technical stakeholders such as legal, compliance, and executive leadership. They interpret complex cybersecurity regulations and translate them into actionable policies that align with organizational goals. Regular collaboration involves attending cross-functional meetings, providing policy guidance during security incidents, and ensuring everyone understands their roles in maintaining compliance. This collaborative environment helps ensure that security policies are both technically sound and practically applicable across the organization.

What are the key skills and qualifications needed to thrive as a Cybersecurity Policy Analyst, and why are they important?

To thrive as a Cybersecurity Policy Analyst, you need a strong understanding of cybersecurity principles, risk management, regulatory frameworks, and typically a degree in cybersecurity, information technology, or a related field. Familiarity with policy development tools, compliance management systems, and certifications like CISSP or CISM are often required. Excellent analytical thinking, communication, and stakeholder engagement skills will help you translate technical risks into actionable policy recommendations. These skills ensure organizations develop effective security policies that comply with regulations and mitigate cyber threats.

Can you make $500,000 a year in cyber security?

Cybersecurity Policy Analysts typically earn between $70,000 and $150,000 annually, depending on experience, location, and organization size. Reaching a $500,000 salary usually requires senior roles such as Chief Information Security Officer (CISO) or executive-level positions, which often involve extensive experience, advanced certifications, and leadership responsibilities.
More about Cybersecurity Policy Analyst jobs
What cities are hiring for Cybersecurity Policy Analyst jobs? Cities with the most Cybersecurity Policy Analyst job openings:
What are the most commonly searched types of Cybersecurity Policy Analyst jobs? The most popular types of Cybersecurity Policy Analyst jobs are:
What states have the most Cybersecurity Policy Analyst jobs? States with the most job openings for Cybersecurity Policy Analyst jobs include:
What job categories do people searching Cybersecurity Policy Analyst jobs look for? The top searched job categories for Cybersecurity Policy Analyst jobs are:
Infographic showing various Cybersecurity Policy Analyst job openings in the United States as of July 2026, with employment types broken down into 1% Locum Tenens, 1% Internship, 86% Full Time, 6% Part Time, 1% Temporary, and 5% Contract. Highlights an 82% Physical, 5% Hybrid, and 13% Remote job distribution, with an average salary of $99,400 per year, or $47.8 per hour.
Cybersecurity Policy Analyst

Full-time

Posted 5 days ago


Job description

Job Description:

Dynamo Technologies, LLC is seeking a Cybersecurity Policy Analyst to support the Defense Logistics Agency (DLA) Technology Foundation Services (TFS) Vulnerability Management Program. The selected candidate will review, consolidate, and develop cybersecurity policies in accordance with government requirements and provide technical support to programs by assessing IT policies, standards, guidelines, and procedures. This position will support the implementation of DoD cybersecurity policies, procedures, and processes while ensuring a balance between security requirements and operational objectives. The Cybersecurity Policy Analyst will brief senior management on cybersecurity policy changes, updates, and program progress.

Duties/ Responsibilities

  • Review, consolidate, and develop cybersecurity policies in accordance with government requirements.
  • Provide technical support and assistance to programs regarding cybersecurity policies, standards, guidelines, and procedures.
  • Assess existing IT policies and procedures to ensure alignment with operational and security requirements.
  • Support implementation of DoD cybersecurity policies, procedures, and processes.
  • Develop cybersecurity artifacts supporting STIGs, TCG configuration guides, IAVMs, and Task Orders.
  • Develop, maintain, and validate RMF artifacts and cybersecurity documentation.
  • Update and track POA&M entries by documenting findings, remediation actions, and milestone status.
  • Generate cybersecurity reports including vulnerability summaries, compliance status updates, and risk findings.
  • Produce analytics and trend reports using data from vulnerability scanners, configuration tools, and security platforms.
  • Support cybersecurity compliance and inspection readiness activities.
  • Conduct cybersecurity research and analysis to support policy development and implementation.
  • Brief senior management on cybersecurity policy changes, updates, and progress.

Required Skills/Abilities

  • Experience supporting the implementation of DoD cybersecurity policies, procedures, and processes.
  • Ability to develop cybersecurity artifacts for STIGs, TCG configuration guides, IAVMs, and Task Orders.
  • Ability to develop, maintain, and validate RMF artifacts and cybersecurity documentation.
  • Experience updating and tracking POA&M entries and remediation activities.
  • Proven ability to work independently and collaboratively with minimal oversight.
  • Strong research and analytical skills.
  • Proficiency with Microsoft Excel, Microsoft Access, Power BI, and Microsoft Power Platform tools.
  • Ability to generate clear, accurate, and audit-ready cybersecurity reports.
  • Experience producing detailed analytics and trend reports using vulnerability management and security platform data.
  • Excellent written and verbal communication skills, including briefing senior leadership.

Nice to Have Skills

  • Experience supporting RMF activities and cybersecurity compliance initiatives.
  • Experience supporting vulnerability management programs.
  • Familiarity with NIST-based cybersecurity frameworks and assessment processes.
  • Experience supporting cybersecurity inspections, audits, and assessments.
  • Knowledge of enterprise IT environments and cybersecurity governance.
  • Experience supporting DoD cybersecurity programs.

Education and Experience:

  • Seven (7) years of relevant cybersecurity policy experience.
  • Required Certifications:
    • ACAS and Tanium.
    • DLA Approved Computing Environment (D Account Access).
    • DoD 8570 – IAT Level II.

Travel Requirement:

  • Travel may be required in support of audits, inspections, assessments, and stakeholder coordination activities.

Clearance Requirement:

  • Must possess a DoD Secret Clearance and be eligible for an IT-II Non-Critical Sensitive security clearance or Tier 3 (T3) upon assignment.

Dynamo is a full lifecycle digital transformation company providing best-in-class technology and mission support services to our clients. Dynamo’s mission is to lead the digital transformation industry and provide best-in-class solutions for our clients with a truly human touch.

We leverage industry leading practices to empower our clients, ultimately providing them with the necessary tools, knowledge, and information required to successfully achieve their strategic goals, while optimizing their operations.

Through our partnerships, boldness, and authenticity, Dynamo goes against the grain of a traditional government contracting company by providing top-caliber team members, delivering quality results, and always exceeding expectations.

Dynamo Technologies is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, national origin, religion, sex, pregnancy, disability, protected veteran status, age, or any other characteristic protected by law.