2

Remote Cybersecurity Policy Analyst Jobs (NOW HIRING)

About the role Concept Plus is seeking a Cybersecurity Policy and RMF Analyst to provide Risk Management Support to identify shortfalls in the assessment and authorization process, track and manage ...

Remote Cybersecurity SME Lead - RMF & Policy

Virginia, MN · Remote

$106.80K - $144.30K/yr

The role is fully remote and contingent on contract award. Responsibilities include guiding cybersecurity policies, ensuring compliance with DoD regulations, and developing innovative solutions for ...

Remote Cybersecurity TOPM RMF & Policy Lead

Virginia, MN · Remote

$106.80K - $144.30K/yr

A cybersecurity consultancy is seeking a Cybersecurity Task Order Project Manager to support a key government cybersecurity program. This fully remote role involves leading the execution and ...

Satellite Policy Analyst

Washington, DC · On-site +1

$85K - $100K/yr

SATELLITE POLICY ANALYST SpaceX is leveraging its experience building rockets and spacecraft to ... Remote work is not considered. * Must be willing to work extended hours and weekends as needed to ...

Create and update cybersecurity related policies and procedures. * Participate in the creation of ... Strong analytical skills and ability to effectively prioritize and coordinate multiple deliverables ...

next page

Showing results 1-20

Remote Cybersecurity Policy Analyst information

See salary details

$43K

$99.4K

$150K

How much do remote cybersecurity policy analyst jobs pay per year?

As of May 30, 2026, the average yearly pay for remote cybersecurity policy analyst in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What is the difference between Remote Cybersecurity Policy Analyst vs Remote Cybersecurity Analyst?

AspectRemote Cybersecurity Policy AnalystRemote Cybersecurity Analyst
Primary FocusDeveloping, analyzing, and implementing cybersecurity policies and compliance standardsMonitoring, detecting, and responding to security threats and vulnerabilities
Required CredentialsCertifications like CISSP, CISA, or CISM; knowledge of policies and regulationsCertifications such as CompTIA Security+, CEH; technical security skills
Work EnvironmentMostly office-based or remote, collaborating with legal and compliance teamsPrimarily technical, often remote, working with security tools and incident response teams

The Remote Cybersecurity Policy Analyst focuses on creating and managing security policies to ensure compliance, while the Remote Cybersecurity Analyst concentrates on technical threat detection and response. Both roles often require certifications like CISSP or Security+ and can be performed remotely, but their core responsibilities differ significantly.

More about Remote Cybersecurity Policy Analyst jobs
What cities are hiring for Remote Cybersecurity Policy Analyst jobs? Cities with the most Remote Cybersecurity Policy Analyst job openings:
What are the most commonly searched types of Cybersecurity Policy Analyst jobs? The most popular types of Cybersecurity Policy Analyst jobs are:
What states have the most Remote Cybersecurity Policy Analyst jobs? States with the most job openings for Remote Cybersecurity Policy Analyst jobs include:
Infographic showing various Remote Cybersecurity Policy Analyst job openings in the United States as of May 2026, with employment types broken down into 33% Full Time, 54% Part Time, and 13% Contract. Highlights an 90% Physical, 8% Hybrid, and 2% Remote job distribution, with an average salary of $99,400 per year, or $47.8 per hour.
Cybersecurity Policy & RMF Analyst

Cybersecurity Policy & RMF Analyst

Concept Plus

Remote

Full-time

Medical, Dental, Vision, Life, PTO

Posted 21 days ago


Job description

About Concept Plus
Concept Plus is a growing consulting firm headquartered in Fairfax, VA. We are an Oracle Gold Partner, offering deep technical expertise, combined with business insights and an experienced team focused on providing technical solutions for our clients. We are proud to have been recognized as one of the "25 Most Powerful Oracle Solution Providers" in the area! We offer great benefits including competitive pay, comprehensive health insurance, dental and vision insurance, paid life insurance, paid time off, 11 paid holidays, bonuses, tuition reimbursement, unlimited training, and the opportunity to work in a collaborative, flexible, innovative environment! For additional information about our dynamic organization, please visit our website. at www.conceptplus.com.
About the role
Concept Plus is seeking a Cybersecurity Policy and RMF Analyst to provide Risk Management Support to identify shortfalls in the assessment and authorization process, track and manage Risk Assessments, assist in implementing a Risk Management strategy and tie together the business continuity of operations plan (COOP) and the IT COOP plans.
What you'll do
  • Adhere to the DoD cybersecurity policy requirements set forth in DoDI 8500.01, "Cybersecurity," and DoDI 8510.01, "Risk Management Framework (RMF) for DoD Information Technology (IT)" and their successors.
  • Monitor identified risks and track response actions to ensure they support the customer Risk Management Strategy and are properly documented in a risk registry.
  • Provide recommendations to business and IT leaders on best business practices followed in the industry to mitigate or remediate risks • Schedule, conduct, and track RMF validations for each IT Portfolio.
  • Review of security controls, as part of a risk assessment, as needed to support an Authorization to Operate (ATO) of an investment.
  • Review vulnerabilities and identify potential risks based on the type of vulnerability and the potential impact.
  • Identify actions needed to protect information flows to ensure adherence to legal and regulatory standards.
  • Coordinate the development of plans and procedures to ensure that business-critical services are recovered in the event of a digital risk event. • Facilitate and support the development of asset inventories, including digital assets in cloud. • Track all technology requests.
  • Track open vulnerabilities and provide a status on each open risk for each IT Portfolio / Investment. Ensure POAMs are current and reflects all known weaknesses.
  • Stay up-to-date with the latest Azure and FedRAMP regulatory changes and industry trends, advising teams on potential impacts and necessary adjustments.

Required Qualifications
  • US Citizenship
  • Active DoD Secret Clearance (or able to obtain)
  • Bachelor's Degree in an IT related field
  • Meet DoD 8570/8140 Information Assurance Technician (IAT) Level II or Higher (Sec+ CE or Higher)
  • 1+ Years Experience with the Risk Management Framework Process
  • 1+ Years Experience operating the Enterprise Mission Assurance Support Service Application (eMASS)

Preferred Qualifications
  • Experience in performing IT audits, security planning and policy development
  • An understanding of related information technology (e.g. firewalls, VPN, virtualization, identity management systems etc.)
  • Knowledge of domain structure, user authentication, data encryption, access audits and end-use security best practices
  • CompTIA CySA+, CEH and/or CompTIA Pen Test+ Certifications a plus

Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.