Policy Analyst

Webhosting

Northern (KY)

Hybrid

USD 90,000 - 130,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical coverage
Gym reimbursements
Mental well‑being resources

Job summary

DigiCert seeks a Policy Analyst to join the Trust team. You will untangle complex requirements, assess laws and standards, and translate them into actionable policy and practice. You will work with Legal, Compliance, Security, Product, and Engineering to ensure accuracy and defensible positions.

This role emphasizes finding gaps, challenging assumptions, and driving policy changes to completion. You will partner across teams to validate controls, document evidence, and prepare for audits, while

Qualifications

  • Bachelor's degree or equivalent in law, policy, cybersecurity, or related field.
  • 2+ years of policy analysis, regulatory analysis, or technical writing experience.
  • Experience translating complex requirements into clear documentation.
  • Experience coordinating work across technical and nontechnical stakeholders.
  • Strong analytical skills for interpreting regulatory and contractual requirements.
  • Excellent written and verbal communication skills.
  • Meticulous attention to detail and ability to resolve cross‑references and inconsistencies.
  • Ability to discern mandatory requirements from recommendations or accepted practices.
  • Comfort with ambiguity and rapid learning in technical domains.
  • Familiarity with Jira, Confluence, GitHub, or SharePoint.

Responsibilities

  • Analyze applicable laws and regulations with Legal and Compliance to translate into policy requirements.
  • Draft and maintain policy documents, CPs, CPSs, and related standards.
  • Assess changes and determine affected policies, systems, controls, and training.
  • Establish processes to track policy questions and drive decisions.
  • Review policy language for accuracy, consistency, and enforceability.
  • Coordinate policy changes across multiple teams including audit and product.
  • Track decisions, owners, dependencies, and evidence of compliance.
  • Escalate risks and engage SMEs to fill knowledge gaps.
  • Support audits by explaining requirements and providing documentation.
  • Review procedures and customer materials for policy alignment.
  • Communicate complex conclusions clearly without causing alarm.
  • Participate in standards discussions and remediation activities.

Skills

Policy analysis
Regulatory analysis
Technical writing
Cybersecurity governance
Stakeholder coordination
Jira
Confluence
GitHub
SharePoint
Attention to detail
Written communication

Education

Bachelor's degree in law/public policy

Tools

Jira
Confluence
GitHub
SharePoint

Job description

Not specified Full-time Not specified Operations

Job Description

Who we are

DigiCert is a global leader in intelligent trust. We protect the digital world by ensuring the security, privacy, and authenticity of every interaction. Our AI-powered DigiCert ONE platform unifies PKI, DNS, and certificate lifecycle management, to secure infrastructure, software, devices, messages, AI content and agents. Learn why more than 100,000 organizations, including 90% of the Fortune 500, choose DigiCert to stop today’s threats and prepare for a quantum-safe future at www.digicert.com

Job summary

We are seeking a Policy Analyst to join our Trust team. This role is designed for someone who enjoys untangling complicated requirements and notices when something does not quite add up.

Working across industry standards, laws, regulations, root program policies, audit criteria, and DigiCert’s own Certificate Policies and Certification Practice Statements, you will determine what the requirements say, what they mean in practice, and how DigiCert needs to adhere to them. You won’t spend your day passively summarizing documents. You will be expected to find gaps, challenge assumptions, resolve inconsistencies, and help move policy changes across the finish line.

Working in tandem with compliance, legal, security, product, engineering, validation, PKI operations, audit, and other teams, you will contribute to positions that are accurate, practical, and defensible. You will not always know everything when a question lands on your desk, but you will know how to find the right sources, ask smart questions, and recognize when something doesn’t feel right.

This is policy work that cannot be treated as an academic exercise. A poorly interpreted requirement, an inaccurate CP/CPS statement, or a missed implementation dependency can become an audit finding, a compliance incident, or a certificate problem. The details matter.

This role reports to the Policy and Training Supervisor and is part of DigiCert’s Governance, Risk and Compliance function within the Trust Office.

What you will do

  • Analyze applicable laws and regulations in collaboration with Legal and Compliance and translate confirmed legal interpretations into policy and implementation requirements.
  • Draft, maintain, and improve Certificate Policies, Certification Practice Statements, internal policies, procedures, standards, and related compliance documentation.
  • Assess new and amended requirements, identify what has changed, and determine which policies, systems, controls, processes, and training materials are affected.
  • Help establish structured approaches for tracking and resolving policy questions. You may have policy questions with conflicting interpretations and incomplete facts, but you will need to work out what is actually required and keep the decision moving.
  • Review proposed policy language for accuracy, consistency, enforceability, and alignment with DigiCert’s actual practices.
  • Work with subject‑matter experts to verify that policies accurately reflect technical and operational controls. Validate documented practices through appropriate evidence and consultation with relevant control owners.
  • Coordinate policy changes across compliance, legal, security, engineering, product, validation, PKI operations, audit, and other affected teams.
  • Track policy decisions, open questions, owners, dependencies, effective dates, implementation commitments, and evidence of compliance.
  • Identify and escalation risks before they become problems. You will not have every technical or legal answer yourself, but you should be able to recognize potential compliance, technical, or legal concerns and engage the appropriate subject‑matter experts to fill in the gaps.
  • Support internal and external audits by explaining policy requirements, providing supporting documentation, and helping resolve findings.
  • Review operational procedures, product requirements, implementation plans, and customer‑facing materials for consistency with applicable policies and standards.
  • Communicate complex or unpopular conclusions clearly. You should be able to confidently tell stakeholders that an approach is not compliant without causing panic.
  • Participate in standards discussions, policy reviews, incident analysis, remediation activities, and implementation planning.
  • Maintain accurate change histories, approval records, effective dates, and traceability between external requirements and internal policy documents.

What you will have

  • Bachelor’s degree in law, public policy, compliance, cybersecurity, information systems, technical communication, or related field, or equivalent relevant experience.
  • 2+ years of experience in policy analysis, compliance, regulatory analysis, technical writing, cybersecurity governance, or a related area.
  • Demonstrated experience interpreting complex requirements and translating them into clear written documentation.
  • Experience coordinating work across technical and nontechnical stakeholders.
  • Strong analytical skills and the ability to interpret detailed legal, regulatory, technical, and contractual requirements.
  • Excellent written and verbal communication skills.
  • Proven attention to detail. You notice incorrect cross-references, undefined terms, inconsistent capitalization, unsupported statements, accidental obligations, and the difference between "must" and "may".
  • The ability to distinguish between a mandatory requirement, a recommendation, and an accepted practice.
  • Sound judgement when requirements are ambiguous, incomplete, or spread across several documents.
  • Strong research skills and the discipline to rely on authoritative sources rather than search‑result snippets or institutional folklore.
  • Comfort working in technical subject areas and asking informed questions of engineers, security specialists, auditors, lawyers, product managers, and operations teams.
  • Comfort with ambiguity and rapid learning. You will not know everything when you begin an assignment, but you will figure it out quickly and ask smart questions.
  • Strong organizational skills and the ability to manage several policy changes, reviews, deadlines, and implementation dependencies at once.
  • The ability to work independently while knowing when an issue requires legal, technical, compliance, or executive escalation.
  • Experience using collaboration and work‑management tools such as Jira, Confluence, GitHub, SharePoint, or similar platforms.
  • Health and wellness support, including medical cover (where applicable), gym reimbursements, and mental well‑being resources
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Policy Analyst, Trust & Compliance Architect
Policy Analyst, Trust & Compliance Architect

Webhosting • Northern (KY)

Hybrid
USD 90,000 - 130,000
Medical coverage
Gym reimbursements
Mental well‑being resources
Senior Trust Assurance Analyst
Senior Trust Assurance Analyst

Webhosting • United States

On-site
USD 130,000 - 180,000
Trust Operations Analyst
Trust Operations Analyst

DigiCert • West Virginia

On-site
USD 85,000 - 115,000
Health, dental, vision coverage
401(k) with company match
Paid time off and holidays
+1
Trust Operations Analyst
Trust Operations Analyst

Webhosting • Northern (KY)

Hybrid
USD 70,000 - 110,000
Technical Account Manager (AMS)
Technical Account Manager (AMS)

Webhosting • Northern (KY)

Hybrid
USD 90,000 - 130,000
Health benefits
Gym reimbursement
Mental well-being resources
Policy Analyst
Policy Analyst

Brooksource • Tennessee

On-site
USD 70,000 - 90,000
Trust Operations Analyst
Trust Operations Analyst

Socket.dev • United States

On-site
USD 70,000 - 90,000
Health insurance
Dental insurance
Vision insurance
+4
Associate Authentication Analyst
Associate Authentication Analyst

DigiCert • Lehi (UT)

On-site
USD 42,000 - 60,000
Health insurance
Paid time off
401(k)
Senior Security Engineer
Senior Security Engineer

SHEIN • Los Angeles (CA)

On-site
USD 120,000 - 160,000
Bonus and RSU eligibility
Healthcare benefits
401(k) Savings Plan with company match
+2
Technical Account Manager
Technical Account Manager

DigiCert • Lehi (UT)

On-site
USD 110,000 - 140,000
Health, dental, vision coverage
401(k) matching
Paid time off