1

Security Policy Analyst Jobs (NOW HIRING)

Analyze, design, develop, deliver, and evaluate current and future security policies. * Provide analysis, assessment, applicability, and communication of security policy impacts to leadership.

Analyze, design, develop, deliver, and evaluate current and future security policies. * Provide analysis, assessment, applicability, and communication of security policy impacts to leadership.

Security Policy Analyst

Chantilly, VA · On-site

$119K - $199K/yr

Analyze, design, develop, deliver, and evaluate current and future security policies. * Provide analysis, assessment, applicability, and communication of security policy impacts to leadership.

Sr Security Policy Analyst

Saint Louis, MO

$86K - $113K/yr

Additional Information About the Role BJC is hiring for a Sr. Security Policy Analyst. We are looking for applicants in the St. Louis or Kansas City area. This role will be responsible for ...

Perform ongoing analysis and review of security policies and standards to ensure accuracy, completeness, and consistency with NIST 800-53, NIST CSF, OMB guidance, FISMA, and other applicable mandates.

TS/SCI with a Polygraph Position # 688016842 Synertex is seeking a Senior Policy Analyst to work ... security policies and priorities. * Review documents for technical correction and edits in the ...

Policy Analyst

Arlington, VA · On-site +1

$115K - $145K/yr

... security issues. With over 50 years of business expertise and consistent growth, we are known for ... SPA has an immediate need for a Senior Policy Analyst. This is a full-time position seated at the ...

Policy Analyst

Arlington, VA · On-site

$115K - $145K/yr

... security issues. With over 50 years of business expertise and consistent growth, we are known for ... SPA has an immediate need for a Senior Policy Analyst. This is a full-time position seated at the ...

next page

Showing results 1-20

Security Policy Analyst information

See salary details

$39.5K

$107.3K

$141K

How much do security policy analyst jobs pay per year?

As of Aug 20, 2026, the average yearly pay for security policy analyst in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What does a security policy analyst do?

A Security Policy Analyst is responsible for developing, reviewing, and implementing policies and procedures that protect an organization’s information and assets. They analyze current security systems, identify vulnerabilities, and recommend improvements to ensure compliance with laws and industry standards. Security Policy Analysts also educate staff on security policies and may conduct risk assessments or audits to ensure policies are effective. Their work helps organizations mitigate risks and respond appropriately to security threats.

What are some common challenges security policy analysts face when implementing new policies within an organization?

Security Policy Analysts often encounter challenges such as balancing organizational needs with regulatory compliance, gaining stakeholder buy-in, and addressing resistance to change. They must ensure that new policies are both practical and enforceable, while minimizing disruption to daily operations. Collaboration with IT, legal, and business teams is key, as is effective communication to explain the rationale and benefits of policy changes. Staying current with evolving threats and regulations also adds complexity to the role.

What are the key skills and qualifications needed to thrive as a security policy analyst, and why are they important?

To thrive as a Security Policy Analyst, you need expertise in risk assessment, policy development, and an understanding of cybersecurity or physical security frameworks, often supported by a degree in security studies, public policy, or a related field. Familiarity with regulatory compliance tools, security standards (such as NIST, ISO 27001), and sometimes certifications like CISSP or CISM is typically expected. Strong analytical thinking, written communication, and stakeholder collaboration skills distinguish top performers in this role. These competencies are crucial for crafting effective security policies that mitigate risks and align with organizational and regulatory requirements.

What is the difference between Security Policy Analyst vs Security Compliance Specialist?

AspectSecurity Policy AnalystSecurity Compliance Specialist
CredentialsBachelor's in cybersecurity, IT, or related field; certifications like CISSP, CISASimilar credentials; often holds CISSP, CISA, or CompTIA Security+
Work EnvironmentGovernment agencies, corporations, consulting firmsOrganizations with regulatory requirements, auditing firms
Employer & IndustryFocus on developing and analyzing security policiesFocus on ensuring compliance with security standards and regulations
Search & Comparison IntentUnderstanding roles in security policy developmentUnderstanding roles in security compliance and audits

While both roles require cybersecurity knowledge and similar certifications, a Security Policy Analyst primarily develops and analyzes security policies, whereas a Security Compliance Specialist ensures these policies meet regulatory standards. Both roles are vital in maintaining organizational security and often work together within the same industry environments.

More about Security Policy Analyst jobs

What cities are hiring for Security Policy Analyst jobs?

Cities with the most Security Policy Analyst job openings:

What are the most commonly searched types of Security Policy Analyst jobs?

The most popular types of Security Policy Analyst jobs are:

What states have the most Security Policy Analyst jobs?

States with the most job openings for Security Policy Analyst jobs include:

Infographic showing various Security Policy Analyst job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $107,334 per year, or $51.6 per hour.

Security Policy Analyst

MANTECH

Chantilly, VA • On-site

Full-time

Re-posted 25 days ago


ManTech rating

9.0

Company rating: 9.0 out of 10

Based on 14 frontline employees who took The Breakroom Quiz

33rd of 245 rated software companies


Job description

MANTECH seeks a motivated, career and customer-oriented Security Policy Analyst to join our team in Chantilly, VA.

Responsibilities include but are not limited to:

  • Analyze, design, develop, deliver, and evaluate current and future security policies.
  • Provide analysis, assessment, applicability, and communication of security policy impacts to leadership.
  • Provide analytical support to assist with the research, development, coordination, maintenance, review, and revision of security policies.
  • Provide subject matter expertise reviews of security waivers and manage the security waiver module.
  • Provide subject matter expertise reviews of actions for security leadership.
  • Assist the government as the Assessable Unit Coordinator in support of the Management Control Program.
  • Conduct domestic and OCONUS travel up to 25% of the time.

Minimum Qualifications:

  • High School Diploma with 20+ years, Associate's Degree with 17+ years, Bachelor’s Degree with 10+ years, or Master's Degree with 7+ years of relevant security experience.
  • Strong foundation in writing and research with the ability to organize ideas and present findings in a logical manner.
  • Ability to manage a steady flow of work, balance limited information, and quickly shift priorities under tight deadlines.
  • Working knowledge and operational experience implementing Intelligence Community Directives (ICDs) as well as agency-specific directives and instructions.
  • Skilled in effective oral communication techniques to explain, justify, or discuss complex security issues with facts and objective analysis.
  • Comprehensive knowledge of Intelligence Community, Department of Defense, and alternative government agency security policies.

Preferred Qualifications:

  • Prior experience interfacing directly with senior government executives to deliver policy impact briefings.
  • Advanced certifications in federal enterprise security management or policy analysis.
  • Experience managing or optimizing automated workflows for policy tracking and waiver documentation.

Clearance Requirements:

  • Must have a current and active TS/SCI with Polygraph.

Physical Requirements:

  • Must be able to remain in a stationary position 50% of the time.
  • Needs to occasionally move about inside the office to access file cabinets, office machinery, and other common workspace gear.
  • Frequently communicates with co-workers, management, and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations.

What ManTech employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom