Policy Analyst
Listed on 2026-08-30
-
Engineering
Regulatory Compliance Specialist, Cybersecurity
Who we are
Digi Cert is a global leader in intelligent trust. We protect the digital world by ensuring the security, privacy, and authenticity of every interaction. Our AI-powered Digi Cert ONE platform unifies PKI, DNS, and certificate lifecycle management, to secure infrastructure, software, devices, messages, AI content and agents. Learn why more than 100,000 organizations, including 90% of the Fortune 500, choose Digi Cert to stop today's threats and prepare for a quantum-safe future at
Job summaryWe are seeking a Policy Analyst to join our Trust team. This role is designed for someone who enjoys untangling complicated requirements and notices when something does not quite add up.
Working across industry standards, laws, regulations, root program policies, audit criteria, and Digi Cert's own Certificate Policies and Certification Practice Statements, you will determine what the requirements say, what they mean in practice, and how Digi Cert needs to adhere to them. You won't spend your day passively summarizing documents. You will be expected to find gaps, challenge assumptions, resolve inconsistencies, and help move policy changes across the finish line.
Working in tandem with compliance, legal, security, product, engineering, validation, PKI operations, audit, and other teams, you will contribute to positions that are accurate, practical, and defensible. You will not always know everything when a question lands on your desk, but you will know how to find the right sources, ask smart questions, and recognize when something doesn't feel right.
This is policy work that cannot be treated as an academic exercise. A poorly interpreted requirement, an inaccurate CP/CPS statement, or a missed implementation dependency can become an audit finding, a compliance incident, or a certificate problem. The details matter.
This role reports to the Policy and Training Supervisor and is part of Digi Cert's Governance, Risk and Compliance function within the Trust Office.
What you will do- Analyze applicable laws and regulations in collaboration with Legal and Compliance and translate confirmed legal interpretations into policy and implementation requirements.
- Draft, maintain, and improve Certificate Policies, Certification Practice Statements, internal policies, procedures, standards, and related compliance documentation.
- Assess new and amended requirements, identify what has changed, and determine which policies, systems, controls, processes and training materials are affected.
- Assist with detailed gap assessments against requirements issued by organizations such as the CA/Browser Forum, ETSI, Web Trust, root store operators, regulators, and other relevant standards bodies.
- Help establish structured approaches for tracking and resolving policy questions. You may have policy questions with conflicting interpretations and incomplete facts, but you will need to work out what is actually required and keep the decision moving.
- Review proposed policy language for accuracy, consistency, enforce ability, and alignment with Digi Cert's actual practices.
- Work with subject-matter experts to verify that policies accurately reflect technical and operational controls. Validate documented practices through appropriate evidence and consultation with relevant control owners.
- Coordinate policy changes across compliance, legal, security, engineering, product, validation, PKI operations, audit and other affected teams.
- Track policy decisions, open questions, owners, dependencies, effective dates, implementation commitments, and evidence of compliance.
- Identify and upgrade risks before they become problems. You will not have every technical or legal answer yourself, but you should be able to recognise potential compliance, technical, or legal concerns and engage the appropriate subject-matter experts to fill in the gaps.
- Support internal and external audits by explaining policy requirements, providing supporting documentation, and helping resolve findings.
- Review operational procedures, product requirements, implementation plans, and customer-facing materials for consistency with applicable policies and standards.
- Communicate complex or unpopular conclusions clearly. You should be able to confidently tell stakeholders that an approach is not compliant without causing panic.
- Participate in standards discussions, policy reviews, incident analysis, remediation activities and implementation planning.
- Maintain accurate change histories, approval records, effective dates, and traceability between external requirements and internal policy documents.
- Bachelor's degree in law, public policy, compliance, cybersecurity, information systems, technical communication or related field, or equivalent relevant experience.
- 2+ years of experience in policy analysis, compliance, regulatory analysis, technical writing, cybersecurity governance or a related area.
- Demonstrated experience interpreting co...
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: