1

Information Security Policy Writer Jobs (NOW HIRING)

$150K - $175K/yr

This role provides dedicated doctrine and policy writing support, leveraging operational experience ... information required for the preparation of reports, studies, and analyses, and edit customer ...

Strong knowledge of information security policies, risk management, internal controls, and audit ... Strong technical documentation, analytical, written, and verbal communication skills. Roles ...

next page

Showing results 1-20

Information Security Policy Writer information

See salary details

$42K

$78.9K

$136K

How much do information security policy writer jobs pay per year?

As of Sep 12, 2026, the average yearly pay for information security policy writer in the United States is $78,865.00, according to ZipRecruiter salary data. Most workers in this role earn between $57,500.00 and $102,000.00 per year, depending on experience, location, and employer.

What does an information security policy writer do?

An Information Security Policy Writer is responsible for creating, reviewing, and maintaining policies and procedures that protect an organization's digital information. They work closely with IT, compliance, and legal teams to ensure policies comply with regulations and industry standards. Their duties include drafting clear documentation, updating existing policies to address new threats, and educating staff about security protocols. This role is essential in helping organizations manage risk and maintain a strong cybersecurity posture.

What are some typical challenges faced by an information security policy writer in aligning policies with both compliance standards and organizational culture?

Information Security Policy Writers often encounter the challenge of ensuring that policies meet stringent compliance requirements (such as ISO 27001, NIST, or GDPR) while also being practical and adaptable to the organization's unique culture and workflows. Striking this balance requires close collaboration with IT teams, legal departments, and business stakeholders to interpret regulatory language into actionable, user-friendly guidelines. Additionally, they must regularly review and update policies to keep pace with evolving threats and technologies, which demands continuous learning and strong communication skills.

What are the key skills and qualifications needed to thrive as an information security policy writer, and why are they important?

To thrive as an Information Security Policy Writer, you need a solid understanding of information security principles, regulatory frameworks (like ISO 27001, NIST, or GDPR), and strong writing and analytical skills, typically supported by a degree in information security, computer science, or a related field. Familiarity with governance, risk, and compliance (GRC) tools, as well as experience with document management systems, is often required, and certifications such as CISSP or CISM are highly valued. Exceptional attention to detail, clear communication, and the ability to translate complex technical concepts into accessible language are crucial soft skills. These competencies ensure policies are accurate, compliant, and easily understood, helping organizations mitigate risk and maintain robust security postures.

What is the difference between Information Security Policy Writer vs Cybersecurity Analyst?

AspectInformation Security Policy WriterCybersecurity Analyst
Required CredentialsCertifications like CISSP, CISA, or security policy trainingCertifications like CompTIA Security+, CISSP, or CEH
Work EnvironmentOffice-based, policy development teams, security departmentsSecurity operations centers, IT teams, incident response
Employer & Industry UsageOrganizations needing formal security policies, complianceOrganizations monitoring security threats, incident handling
Search & Comparison IntentUnderstanding policy creation, documentation rolesSecurity threat analysis, incident response roles

The main difference is that an Information Security Policy Writer focuses on creating and maintaining security policies and documentation, while a Cybersecurity Analyst actively monitors and responds to security threats. Both roles require security certifications and work within the cybersecurity industry, but their daily tasks and objectives differ significantly.

What are popular job titles related to Information Security Policy Writer jobs?

For Information Security Policy Writer jobs, the most frequently searched job titles are:

Infographic showing various Information Security Policy Writer job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 71% Full Time, 22% Part Time, 1% Temporary, and 5% Contract. Highlights an 93% Physical, 1% Hybrid, and 6% Remote job distribution, with an average salary of $78,865 per year, or $37.9 per hour.

Information Security Policy Manager (ISPM)

Greenwich, CT • On-site

Solomon Page
Recruiting and Staffing Services • 201 - 500 employees

$200K - $250K/yr

Full-time

Posted 11 days ago


Job description

Our client is looking to fill the role of Information Security Policy Manager. The Information Security Policy Manager develops, maintains, and communicates information security policies aligned to regulatory requirements, industry best practices, and control environment and risk appetite. This role is responsible for formal information security policy library, ensuring security program is supported by well-considered policy mandates.
  • The Base Salary range is $200k to $250k
Responsibilities:
  • Maintain and extend information security policy library to align with regulatory requirements, business risk appetite, industry-accepted risk frameworks, and control environment.
  • Coordinate and drive the development, review, and update of information security policies and standards based on identified need and defined maintenance intervals.
  • Map security policies to, and analyze gaps against, applicable risk and regulatory frameworks and laws, such as DORA, FFIEC, NIST CSF.
  • Support security-related external assessments, audits, and regulatory examinations by providing evidence of compliance.
  • Partner with the Information Security Controls Manager to ensure policies are supported by appropriate controls and testing procedures.
  • Evaluate security controls, identify opportunities for improvement, and communicate constructive recommendations.
  • Other duties, as assigned
Required skills:
  • 7+ years of experience in information / cyber security experience, including 3+ years developing and managing information security policies in a regulated industry (preferably financial services) and 3+ years hands-on, technical cybersecurity roles.
  • Fluent understanding of regulatory requirements affecting cybersecurity, including DORA, SEC, FFIEC, and common regulations issued in Europe (EBA) and APAC (SFC, MAS).
  • Working familiarity with common security frameworks, including NIST CSF and ISO 27001/27002.
  • Prior experience as owner of policies or technical standards documentation.
  • Experience as lead responder to regulatory examinations, audit requests, and client due diligence questionnaires related to policy and compliance.
  • Proven ability to write clear, actionable policies addressing complex regulatory and technical requirements, grounded in industry accepted practices and risk management concepts, and based on existing controls and technology environments
  • Experience working with GRC (Governance, Risk, and Compliance) tooling a plus.
  • Experience building cross functional consensus as an individual contributor
  • Bachelor's degree in Information Security, Computer Science, Information Technology or a related field, or equivalent experience
  • CISM certification a plus.
To be successful:
  • Strong critical thinking, analytical, organizational, time management, and writing and editing skills - all with attention to detail.
  • Track record of building bridges with technology practitioners and translating complex technical concepts into simple, accessible language for business audiences.
  • A self-motivated, open, collaborative, client-centric, consensus-building problem-solving mentality
  • Ability to exercise good judgment when solving problems with incomplete information

If you meet the required qualifications and are interested in this role, please apply today.
The Solomon Page Distinction
Our teams, comprised of subject matter experts, develop an interest in your preferences and goals and we act as an advisor for your career advancement. Solomon Page has an extensive network of established clients which allows us to present opportunities that are well-suited to your respective goals and needs - this specialized approach sets us apart in the industries we serve.
About Solomon Page
Founded in 1990, Solomon Page is a specialty niche provider of staffing and executive search solutions across a wide array of functions and industries. The success of Solomon Page reflects an organic growth strategy supported by a highly entrepreneurial culture. Acting as a strategic partner to our clients and candidates, we focus on providing customized solutions and building long-term relationships based on trust, respect, and the consistent delivery of excellent results. For more information and additional opportunities, visit: solomonpage.com and connect with us on Facebook , and LinkedIn .
Opportunity Awaits.
#LI-JM1