1

Information Security Policy Writer Jobs (NOW HIRING)

Strong knowledge of information security policies, risk management, internal controls, and audit ... Strong technical documentation, analytical, written, and verbal communication skills. Roles ...

Review and maintain review of information and physical security policies, standards, and guidelines ... Excellent verbal, written, and interpersonal communication skills. * Exercises awareness with ...

Help the security team coordinate Information Technology activities in the information and cybersecurity. Assist with security policy and procedures development and policy enforcement. Ensure the ...

We are seeking a Manager, Information Security to own the company\'s overall security posture end ... This is a hands-on, builder-oriented role, not a purely governance or policy-writing position. The ...

Showing results 21-40

Information Security Policy Writer information

See salary details

$42K

$78.9K

$136K

How much do information security policy writer jobs pay per year?

As of Sep 13, 2026, the average yearly pay for information security policy writer in the United States is $78,865.00, according to ZipRecruiter salary data. Most workers in this role earn between $57,500.00 and $102,000.00 per year, depending on experience, location, and employer.

What does an information security policy writer do?

An Information Security Policy Writer is responsible for creating, reviewing, and maintaining policies and procedures that protect an organization's digital information. They work closely with IT, compliance, and legal teams to ensure policies comply with regulations and industry standards. Their duties include drafting clear documentation, updating existing policies to address new threats, and educating staff about security protocols. This role is essential in helping organizations manage risk and maintain a strong cybersecurity posture.

What are some typical challenges faced by an information security policy writer in aligning policies with both compliance standards and organizational culture?

Information Security Policy Writers often encounter the challenge of ensuring that policies meet stringent compliance requirements (such as ISO 27001, NIST, or GDPR) while also being practical and adaptable to the organization's unique culture and workflows. Striking this balance requires close collaboration with IT teams, legal departments, and business stakeholders to interpret regulatory language into actionable, user-friendly guidelines. Additionally, they must regularly review and update policies to keep pace with evolving threats and technologies, which demands continuous learning and strong communication skills.

What are the key skills and qualifications needed to thrive as an information security policy writer, and why are they important?

To thrive as an Information Security Policy Writer, you need a solid understanding of information security principles, regulatory frameworks (like ISO 27001, NIST, or GDPR), and strong writing and analytical skills, typically supported by a degree in information security, computer science, or a related field. Familiarity with governance, risk, and compliance (GRC) tools, as well as experience with document management systems, is often required, and certifications such as CISSP or CISM are highly valued. Exceptional attention to detail, clear communication, and the ability to translate complex technical concepts into accessible language are crucial soft skills. These competencies ensure policies are accurate, compliant, and easily understood, helping organizations mitigate risk and maintain robust security postures.

What is the difference between Information Security Policy Writer vs Cybersecurity Analyst?

AspectInformation Security Policy WriterCybersecurity Analyst
Required CredentialsCertifications like CISSP, CISA, or security policy trainingCertifications like CompTIA Security+, CISSP, or CEH
Work EnvironmentOffice-based, policy development teams, security departmentsSecurity operations centers, IT teams, incident response
Employer & Industry UsageOrganizations needing formal security policies, complianceOrganizations monitoring security threats, incident handling
Search & Comparison IntentUnderstanding policy creation, documentation rolesSecurity threat analysis, incident response roles

The main difference is that an Information Security Policy Writer focuses on creating and maintaining security policies and documentation, while a Cybersecurity Analyst actively monitors and responds to security threats. Both roles require security certifications and work within the cybersecurity industry, but their daily tasks and objectives differ significantly.

What are popular job titles related to Information Security Policy Writer jobs?

For Information Security Policy Writer jobs, the most frequently searched job titles are:

Infographic showing various Information Security Policy Writer job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 71% Full Time, 22% Part Time, 1% Temporary, and 5% Contract. Highlights an 93% Physical, 1% Hybrid, and 6% Remote job distribution, with an average salary of $78,865 per year, or $37.9 per hour.

Information Security Analyst

Tolleson, AZ • On-site

Techvilla Solutions
IT Services • 51 - 200 employees

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

We are seeking an experienced Information Security Analyst with strong expertise in cybersecurity risk management, security audits, compliance, internal controls, and security governance.

Required Skills
  • Experience performing security risk assessments, audits, control reviews, and compliance assessments.

  • Strong knowledge of NIST SP 800-53 Rev. 5, RMF, IRS Publication 1075, HIPAA/HITECH, HITRUST, CJIS, and MARS-E.

  • Experience with security and privacy control selection, implementation, assessment, and authorization.

  • Strong knowledge of information security policies, risk management, internal controls, and audit practices.

  • Experience identifying security gaps, developing findings, recommendations, POA&Ms, and remediation plans.

  • Ability to investigate suspicious activity and support security incident reporting.

  • Understanding of IT environments including Windows, Unix/Linux, databases, networking, and software development.

  • Strong technical documentation, analytical, written, and verbal communication skills.

Roles & Responsibilities
  • Conduct security assessments, audits, and risk reviews and document findings and recommendations.

  • Prepare audit reports, risk assessments, security plans, incident reports, and POA&Ms.

  • Review and maintain security policies, audit plans, risk documentation, and compliance artifacts.

  • Evaluate security controls and identify areas of non-compliance and improvement.

  • Track remediation activities and report outcomes to management.

  • Research cybersecurity regulations, standards, and industry best practices to support compliance.

  • Identify cybersecurity and privacy risks across internal and external systems and recommend mitigation strategies.

  • Support project teams with security and compliance requirements.

  • Collaborate with IT, security, audit, compliance, and business teams.

  • Provide security guidance and develop training/user-support materials as required.