1

Information Security Policy Writer Jobs (NOW HIRING)

About the Role The Information Security Officer will have end-to-end ownership of MEDvidi ... Maintain security policies for MEDvidi's distributed workforce, including workstation security ...

Quality - Follows policies and procedures; adapts to and manages changes in the environment ... Must be able to follow written/oral instructions. OTHER SKILLS AND ABILITIES * Demonstrate ...

Information Security Manager

Detroit, MI · Remote

$100K - $130K/yr

You'll manage our Information Security Analysts, work closely with our vCISO, Compliance ... Maintain security policies, standards, procedures, control documentation, and associated review ...

Sr. Information Security Engg.

Phoenix, AZ · On-site

$105K - $143K/yr

... Security policies, along with State statutes regarding privacy and security compliance. The ... The candidate must have strong written and verbal communication and presentation skills including ...

NY · On-site

Support compliance with company policies, regulatory requirements, and generally accepted information security controls. * Deliver strategic network security, access control, and secure transaction ...

Develop and maintain security policies, procedures, operating models, standards, and governance ... Strong verbal and written communication skills with the ability to influence and build consensus ...

Showing results 41-60

Information Security Policy Writer information

See salary details

$42K

$78.9K

$136K

How much do information security policy writer jobs pay per year?

As of Sep 13, 2026, the average yearly pay for information security policy writer in the United States is $78,865.00, according to ZipRecruiter salary data. Most workers in this role earn between $57,500.00 and $102,000.00 per year, depending on experience, location, and employer.

What does an information security policy writer do?

An Information Security Policy Writer is responsible for creating, reviewing, and maintaining policies and procedures that protect an organization's digital information. They work closely with IT, compliance, and legal teams to ensure policies comply with regulations and industry standards. Their duties include drafting clear documentation, updating existing policies to address new threats, and educating staff about security protocols. This role is essential in helping organizations manage risk and maintain a strong cybersecurity posture.

What are some typical challenges faced by an information security policy writer in aligning policies with both compliance standards and organizational culture?

Information Security Policy Writers often encounter the challenge of ensuring that policies meet stringent compliance requirements (such as ISO 27001, NIST, or GDPR) while also being practical and adaptable to the organization's unique culture and workflows. Striking this balance requires close collaboration with IT teams, legal departments, and business stakeholders to interpret regulatory language into actionable, user-friendly guidelines. Additionally, they must regularly review and update policies to keep pace with evolving threats and technologies, which demands continuous learning and strong communication skills.

What are the key skills and qualifications needed to thrive as an information security policy writer, and why are they important?

To thrive as an Information Security Policy Writer, you need a solid understanding of information security principles, regulatory frameworks (like ISO 27001, NIST, or GDPR), and strong writing and analytical skills, typically supported by a degree in information security, computer science, or a related field. Familiarity with governance, risk, and compliance (GRC) tools, as well as experience with document management systems, is often required, and certifications such as CISSP or CISM are highly valued. Exceptional attention to detail, clear communication, and the ability to translate complex technical concepts into accessible language are crucial soft skills. These competencies ensure policies are accurate, compliant, and easily understood, helping organizations mitigate risk and maintain robust security postures.

What is the difference between Information Security Policy Writer vs Cybersecurity Analyst?

AspectInformation Security Policy WriterCybersecurity Analyst
Required CredentialsCertifications like CISSP, CISA, or security policy trainingCertifications like CompTIA Security+, CISSP, or CEH
Work EnvironmentOffice-based, policy development teams, security departmentsSecurity operations centers, IT teams, incident response
Employer & Industry UsageOrganizations needing formal security policies, complianceOrganizations monitoring security threats, incident handling
Search & Comparison IntentUnderstanding policy creation, documentation rolesSecurity threat analysis, incident response roles

The main difference is that an Information Security Policy Writer focuses on creating and maintaining security policies and documentation, while a Cybersecurity Analyst actively monitors and responds to security threats. Both roles require security certifications and work within the cybersecurity industry, but their daily tasks and objectives differ significantly.

What are popular job titles related to Information Security Policy Writer jobs?

For Information Security Policy Writer jobs, the most frequently searched job titles are:

Infographic showing various Information Security Policy Writer job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 71% Full Time, 22% Part Time, 1% Temporary, and 5% Contract. Highlights an 93% Physical, 1% Hybrid, and 6% Remote job distribution, with an average salary of $78,865 per year, or $37.9 per hour.

Engineer, Information Security GRC

Atlanta, GA • On-site

Intercontinental Exchange Holdings, Inc.
Finance and Insurance • 5 - 10K employees

Full-time

Re-posted yesterday


Job description

Overview
Job Purpose
The Engineer, Information Security GRC is part of a team responsible for the global Information Security program. The role would gain exposure to the full suite of businesses and products which underpin the Parent ICE company.
Information Security ("IS") is charged with:
  • Preventing impactful cybersecurity and physical security incidents,
  • maintaining a reputation with customers, regulators, and key stakeholders as running a best-in-class cybersecurity and physical security program, and
  • avoiding negative impact to business agility and growth from cybersecurity and physical security policies and controls.

Governance, Risk, and Compliance maintain said policies, ensure controls are operating effectively via assessment and attestation, and own the vulnerability management program to identify and correct any problems within.
Responsibilities
  • Security Metrics - Uses automated and manual processes to produce regular reports communicating the status of the Information Security program
  • Policies and Procedures - Maintains corporate Information Security policies and departmental procedures and maps them to relevant control standards
  • Regulator, Audit, and Customer Inquiries - Organizes and updates departmental documentation and responds to inquiries in an organized and repeatable fashion
  • Recertification - Operates periodic processes to ensure hire, transfer, and termination protocols are complied with and regular access reviews are conducted
  • Security Awareness - Builds and maintains company awareness and education programs
  • Risk Assessment - Builds and operates the company platform to document, measure, and report assessments, risks, controls, findings, and remediation activity

Knowledge and Experience
  • University degree in Information Security, Engineering, MIS, CIS, or related discipline
  • 3+ years of relevant work experience
  • Experience in Cybersecurity Framework (such as NIST, COBIT)
  • Experience with Systems Administration and/or IP Networking is a plus
  • Experience with Regulatory Compliance
  • Experience in an exchange, trading facility, or financial services a plus
  • Experience in Customer communication and Vendor evaluation
  • Experience with senior management and board metrics generation and communication
  • Advanced certifications (for example, the CISSP)
  • Advanced technical writing and/or communication education and experience

Specific Technologies:
Excel, Workflow automation tools, Data collection, normalization, indexing, correlation, and visualization. Scripting, regular expressions, string-parsing, light SDLC, and project management. NIST Cyber Security Framework, CIS, and GRC Platforms.
-
Intercontinental Exchange, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to legally protected characteristics.