Source Job

US

  • Research, draft, and analyze policies to align with stakeholder needs and organizational goals.
  • Conduct gap analyses against frameworks and regulations to recommend policy enhancements.
  • Collaborate with security engineers and compliance officers to ensure policies are technically sound.

Policy Analysis Technical Writing NIST CSF Security Frameworks

20 jobs similar to Policy Specialist

Jobs ranked by similarity.

$70,000–$90,000/yr
US

  • Research and apply federal and state policy, guidance, and regulations using analytical writing to respond to policy help desk inquiries.
  • Perform data analysis using tools like Jira, ServiceNow, and Excel to produce reports and draft policy answers for stakeholders.
  • Support the development of frameworks, operational plans, and integrated documentation while proactively identifying and resolving gaps.

LMI is a private, nonprofit digital solutions provider and government consulting firm dedicated to accelerating government impact with innovation, speed, and mission-ready technology. Headquartered in Tysons, Virginia, it serves defense, space, healthcare, and energy sectors with a focus on agility, collaboration, and delivering impactful results.

$110,000–$150,000/yr

  • Support and maintain the company-wide information security program.
  • Facilitate IT risk assessments with business units and define acceptable risk levels.
  • Monitor the external threat environment and advise stakeholders on emerging risks.

Zensurance is a leading InsurTech company redefining commercial insurance for Canadian businesses. They leverage advanced technology and industry expertise to deliver tailored insurance solutions. Zensurance values ownership, collaboration, and innovation within their team, which has been recognized multiple times by Deloitte as a Technology Fast 50/500 company.

US

  • Maintain and manage Active Directory Group Policies for Windows 11 desktops, applications, and security hardening guides.
  • Provide Tier 3 support for hardware, software, and configuration issues, escalating to vendors and managing MBAM encryption.
  • Conduct testing, evaluation, and documentation for GSA baseline images, hardware certification, and BIOS guides.

Empower AI provides AI-driven tools to enable digital transformation and enhance productivity for U.S. federal government agencies. Headquartered in Reston, Virginia, the company has over three decades of experience and is recognized as a military-friendly employer with a focus on Health, Defense, and Civilian missions.

$130,000–$160,000/yr
US Canada Unlimited PTO

  • Maintain and improve information security policies, standards, and procedures.
  • Support SOC 2, ISO 27001, and HITRUST readiness, audit preparation, and evidence collection.
  • Support vendor security reviews, third-party risk assessments, and remediation tracking.

Benepass is making benefits easy through its customizable fintech platform. They enable People teams to implement, administer, and track benefits that meet employees where they are. The company has raised approximately $75 million in equity capital and is backed by leading investors.

$100,000–$155,000/yr
US

  • Assess customer's Falcon environment and ensure alignment with Falcon Complete standards.
  • Provide customers with security recommendations and create remediations to improve their security posture.
  • Partner with internal teams to troubleshoot issues and ensure customer satisfaction.

CrowdStrike is a global leader in cybersecurity with an AI-native platform designed to stop breaches. The company has a mission-driven culture that provides employees flexibility and autonomy, and it supports customers across all industries.

Global

  • Translate group security frameworks into practical policies, controls, and procedures.
  • Build and strengthen a Security-by-Design culture across projects, platforms, and teams.
  • Support teams in identifying risks, defining actions, and tracking real progress.

Q8 is a well-respected, reliable, and trustworthy energy supplier that has been operating since 1983, with nearly 5,000 service stations in Europe. They are committed to developing a wide range of innovative and sustainable products and services. Their culture is focused on growing together in a digital and inspiring environment of trust, focused on continuous learning.

US

  • Lead IT system security consultation within CMMC, NIST, and other regulatory frameworks.
  • Develop System Security Plans and supporting documentation for clients.
  • Manage project tasks and priorities to meet delivery targets.

Jobgether is a platform that helps connect candidates with companies. They use an AI-powered matching process to ensure applications are reviewed quickly, objectively, and fairly.

US Unlimited PTO

  • Deliver world-class cyber security assessment and advisory services while ensuring customer satisfaction.
  • Work effectively as a team member on large engagements and remain current on technical knowledge.
  • Demonstrate GuidePoint’s Core Values at all times: Take Charge and Complete Our Mission.

GuidePoint Security provides trusted cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. They have over 1,200 employees and focus on core values to establish an enjoyable workplace atmosphere.

US

  • Lead the development of security architecture guidance, standards, and reference diagrams for on-premise and cloud platforms, supporting macro and micro security design for a large government agency.
  • Design Zero Trust security architectures and associated guidance, working in iterations to tighten least privilege access controls and automate Zero Trust controls.
  • Assess and evaluate security postures, review candidate architectures, identify protection needs, and determine how new systems impact enterprise security.

Abile Group LLC partners with the Intelligence Community and their Contractors in Enterprise Analytics & Performance Management, IT & Systems Engineering, and Program & Project Management. It is an EDWOSB dedicated to its employees and clients, focusing on high-performing talent to develop solutions combining industry best practices with client expertise.

12w maternity 12w paternity

  • Manage and expand Valon's security and privacy compliance program across key frameworks and regulations.
  • Build and scale modern Security GRC capabilities that leverage AI-enabled tools and processes, reducing manual overhead while optimizing risk and compliance operations.
  • Maintain and evolve Valon's risk management practices; facilitate risk assessments across teams and track remediation of identified issues to closure.

Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. We're a Series C company backed by a16z, transforming industries that others have written off as too complex to innovate.

$4,750–$6,250/mo
Poland

  • Lead and maintain the IT Compliance Program, ensuring alignment with industry best practices and regulatory requirements.
  • Stay abreast of relevant laws, regulations, and industry standards (e.g. GDPR, ISO 27001, NIS2, SOC 2,...).
  • Serve as a main point of contact for senior management and stakeholders on regulatory and IT compliance matters.

EcoVadis is the leading provider of business sustainability ratings, offering solutions backed by experts and technology. They analyze data to provide companies with insights into their environmental, social, and ethical risks, fostering a culture of global sustainability change.

US

  • Learn and understand procedures supporting the assessment of risks to federal facilities.
  • Conduct in-depth reviews of FPS Facility Security Assessments (FSAs) for 4 FPS regions and provide written documentation on deficiencies.
  • Validate information contained in FPS building inventory and correct incongruent information with internal and external sources and partners.

Dynamis, Inc. provides analytical and advisory services. They focus on interpreting and applying policies and program requirements. I am unable to find information on employee size or culture for the company.

US

  • Develop cybersecurity policy and provide RMF support for cloud deployment in support of the US Army.
  • Develop plans delineating how to work within existing policies and procedures.
  • Oversee the delivery of continuous monitoring tools and capabilities that deliver accountable governance.

Millennium is part of the Markon enterprise, a network supporting critical national security missions. They have an elite team of over 300 professionals with expertise in cybersecurity, red team operations, defensive cyber operations, software engineering, and technical engineering.

US

  • Provides technical assistance to computer users, answering questions or resolving problems via phone, email, or instant message.
  • Performs clerical and administrative duties for remote assistance, including replying to trouble tickets and maintaining audit trails.
  • Offers expert support for password resets, email, directories, desktop applications, smartphones, and network connectivity.

DIGIT is a leading provider of advanced information technology solutions and professional services to U.S. federal government agencies. They drive digital transformation using forward-leaning technologies and best practices, emphasizing a flexible service delivery model and adoption of emerging technologies like AI and machine learning.

$140,000–$160,000/yr
US Canada Unlimited PTO

  • Build detections and security signal pipelines in Datadog.
  • Serve as the subject matter expert on AWS Cloud and on-prem infrastructure security.
  • Act as the technical lead during security incidents, including investigation and remediation.

Voltus is the leading platform connecting distributed energy resources to electricity markets, delivering less expensive, more reliable, and more sustainable electricity. Our company appears to be a remote-first company, and values diversity and inclusion.

$115,500–$213,000/yr
US

  • Own the governance framework for Life360's agentic systems and define the policies and control sets that govern how agents are built and deployed.
  • Take an agentic approach to GRC itself by automating evidence collection, drafting control narratives and triaging vendor questionnaires using AI and internal tooling.
  • Build the policy program as code with policies in Git and requirements expressed as enforceable rules and automated checks.

Life360's mission is to keep people close to the ones they love. They have a category-leading mobile app and other tracking devices to empower members to protect people, pets and things. Life360 has more than 500 remote-first employees and is growing.

US

  • Provides first-line technical support to end users via phone, email, and instant message for issues including password resets, email, standard Windows applications, and network connectivity.
  • Performs ticket processing and resolution management, ensuring detailed documentation of problems and actions taken to resolve user issues.
  • Assists with application support, software installation, configuration, and interacts daily with customers to ensure productivity and provide feedback.

Empower AI provides AI solutions and platforms specifically for federal government agencies to enhance workforce productivity and drive meaningful transformation. The company has three decades of experience in Health, Defense, and Civilian missions, is headquartered in Reston, Virginia, and is recognized as a Military Friendly Employer, reflecting its commitment to hiring veterans and active-duty personnel.

$160,000–$220,000/yr
US

  • Help design the architecture of a system with multiple AI models, a set of backend APIs, and a frontend web application.
  • Write code within a small team, striking a reasonable balance between velocity and writing maintainable code.
  • Work with users and other team members to help define and refine product requirements, and translate them into a roadmap and code.

ConductorAI values candidates who can manage complexity and work independently. They are an equal opportunity employer using state-of-the-art tech to solve novel problems with mission partners.

$90,000–$125,000/yr
US

  • Partner with engineers and security SMEs to design, improve, and implement Identity and Access Management (IAM) solutions for VA.gov products.
  • Analyze security metrics and access management trends to inform how the program approaches security architecture.
  • Develop and document requirements for IAM solutions including identity lifecycle, role management, separation of duties, and access workflows.

Oddball believes that the best products are built when companies understand and value the things they are working on. They value learning and growth and the ability to make a big impact at a small company.

US

  • Manage day-to-day security operations and maintain ATO for DoD information systems under the RMF framework.
  • Develop and maintain RMF artifacts like SSP, SAP, and POA&M, and shepherd packages through eMASS or equivalent.
  • Track vulnerabilities and STIG compliance, manage POA&M closure, coordinate audits, and translate policy into clear engineering guidance.

LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed by bringing commercial-grade platforms and mission-ready AI to federal agencies. With a focus on agility and collaboration, the company serves defense, space, healthcare, and energy sectors, and is headquartered in Tysons, Virginia, committed to delivering impactful results.