Policy Analyst
Summary
Analyze laws, regulations, and industry standards to draft and maintain Certificate Policies and Certification Practice Statements (CP/CPS). Collaborate with cross-functional teams using tools like Jira and Confluence to ensure compliance with CA/Browser Forum, ETSI, and WebTrust requirements for PKI and digital certificates.
Who we are
DigiCert is a global leader in intelligent trust. We protect the digital world by ensuring the security, privacy, and authenticity of every interaction. Our AI-powered DigiCert ONE platform unifies PKI, DNS, and certificate lifecycle management, to secure infrastructure, software, devices, messages, AI content and agents. Learn why more than 100,000 organizations, including 90% of the Fortune 500, choose DigiCert to stop today’s threats and prepare for a quantum-safe future at
Job summary
We are seeking a Policy Analyst to join our Trust team. This role is designed for someone who enjoys untangling complicated requirements and notices when something does not quite add up.
Working across industry standards, laws, regulations, root program policies, audit criteria, and DigiCert’s own Certificate Policies and Certification Practice Statements, you will determine what the requirements say, what they mean in practice, and how DigiCert needs to adhere to them. You won’t spend your day passively summarizing documents. You will be expected to find gaps, challenge assumptions, resolve inconsistencies, and help move policy changes across the finish line.
Working in tandem with compliance, legal, security, product, engineering, validation, PKI operations, audit, and other teams, you will contribute to positions that are accurate, practical, and defensible. You will not always know everything when a question lands on your desk, but you will know how to find the right sources, ask smart questions, and recognize when something doesn’t feel right.
This is policy work that cannot be treated as an academic exercise. A poorly interpreted requirement, an inaccurate CP/CPS statement, or a missed implementation dependency can become an audit finding, a compliance incident, or a certificate problem. The details matter.
This role reports to the Policy and Training Supervisor and is part of DigiCert’s Governance, Risk and Compliance function within the Trust Office.
What you will do
- Analyze applicable laws and regulations in collaboration with Legal and Compliance and translate confirmed legal interpretations into policy and implementation requirements.
- Draft, maintain, and improve Certificate Policies, Certification Practice Statements, internal policies, procedures, standards, and related compliance documentation.
- Assess new and amended requirements, identify what has changed, and determine which policies, systems, controls, processes, and training materials are affected.
- Assist with detailed gap assessments against requirements issued by organizations such as the CA/Browser Forum, ETSI, WebTrust, root store operators, regulators, and other relevant standards bodies.
- Help establish structured approaches for tracking and resolving policy questions. You may have policy questions with conflicting interpretations and incomplete facts, but you will need to work out what is actually required and keep the decision moving.
- Review proposed policy language for accuracy, consistency, enforceability, and alignment with DigiCert’s actual practices.
- Work with subject-matter experts to verify that policies accurately reflect technical and operational controls. Validate documented practices through appropriate evidence and consultation with relevant control owners.
- Coordinate policy changes across compliance, legal, security, engineering, product, validation, PKI operations, audit, and other affected teams.
- Track policy decisions, open questions, owners, dependencies, effective dates, implementation commitments, and evidence of compliance.
- Identify and escalate risks before they become problems. You will not have every technical or legal answer yourself, but you should be able to recognize potential compliance, technical, or legal concerns and engage the appropriate subject-matter experts to fill in the gaps.
- Support internal and external audits by explaining policy requirements, providing supporting documentation, and helping resolve findings.
- Review operational procedures, product requirements, implementation plans, and customer-facing materials for consistency with applicable policies and standards.
- Communicate complex or unpopular conclusions clearly. You should be able to confidently tell stakeholders that an approach is not compliant without causing panic.
- Participate in standards discussions, policy reviews, incident analysis, remediation activities, and implementation planning.
- Maintain accurate change histories, approval records, effective dates, and traceability between external requirements and internal policy documents.
What you will have
- Bachelor’s degree in law, public policy, compliance, cybersecurity, information systems, technical communication, or related field, or equivalent relevant experience.
- 2+ years of experience in policy analysis, compliance, regulatory analysis, technical writing, cybersecurity governance, or a related area.
- Demonstrated experience interpreting complex requirements and translating them into clear written documentation.
- Experience coordinating work across technical and nontechnical stakeholders.
- Strong analytical skills and the ability to interpret detailed legal, regulatory, technical, and contractual requirements.
- Excellent written and verbal communication skills.
- Proven attention to detail. You notice incorrect cross-references, undefined terms, inconsistent capitalization, unsupported statements, accidental obligations, and the difference between “must” and “may.”
- The ability to distinguish between a mandatory requirement, a recommendation, and an accepted practice.
- Sound judgement when requirements are ambiguous, incomplete, or spread across several documents.
- Strong research skills and the discipline to rely on authoritative sources rather than search-result snippets or institutional folklore.
- Comfort working in technical subject areas and asking informed questions of engineers, security specialists, auditors, lawyers, product managers, and operations teams.
- Comfort with ambiguity and rapid learning. You will not know everything when you begin an assignment, but you will figure it out quickly and ask smart questions.
- Strong organizational skills and the ability to manage several policy changes, reviews, deadlines, and implementation dependencies at once.
- The ability to work independently while knowing when an issue requires legal, technical, compliance, or executive escalation.
- Experience using collaboration and work-management tools such as Jira, Confluence, GitHub, SharePoint, or similar platforms.
Nice to have
- Experience working within a publicly trusted certification authority, trust service provider, regulated technology company, or other high-assurance environments.
- Familiarity with public key infrastructure, digital certificates, digital signatures, certificate lifecycle management, cryptographic key management, or related trust services.
- Knowledge of CA/Browser Forum Baseline Requirements, Extended Validation Guidelines, Network and Certificate System Security Requirements, S/MIME requirements, or Code Signing requirements.
- Familiarity with, or demonstrated ability to develop working knowledge of ETSI standards, eIDAS, WebTrust, ISO 27001, SOC 2, NIST publications, or root program requirements.
- Experience preparing or reviewing Certificate Policies and Certification Practice Statements.
- Experience conducting compliance gap assessments or supporting internal and external audits.
- Experience working with version-controlled documentation and formal change management processes.
Benefits
- Competitive compensation and comprehensive benefits package
- Generous paid time off, including holidays and additional leave options
- Family-friendly leave policies, including maternity, paternity, and other supportive leave programs
- Health and wellness support, including medical cover (where applicable), gym reimbursements, and mental well-being resources
- Pension, life insurance, and income protection benefits (location dependent)
- Employee Assistance Program with 24/7 confidential support for employees and their families
- Education assistance and professional development opportunities
- Access to LinkedIn Learning and continuous learning resources
- Employee referral bonus program and additional company perks and discounts
- Business travel insurance and global employee support programs
To protect candidate information and maintain a secure hiring process, all applications must be submitted through our careers portal. Resumes or CVs sent directly via email will not be reviewed or considered.
#LI-FP1
__PRESENT
__PRESENT
__PRESENT
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location
- Are you comfortable working from 15h00 - 24h00 Monday to Friday? This is a mandatory business requirement choose one
- Have you completed secondary education or its equivalent? choose one · optional
- Are you legally authorized to work in the country in which this role is located? choose one
- Will you now or in the future require sponsorship to work in the country where this role is based? choose one
- Please confirm the Country in which you currently reside? choose one
- If the country you currently live in is NOT listed in the question above, please confirm in which country you live? optional
- What are your salary expectations for this role?
- Were you referred for this position? choose one
- If you were referred for this position, please provide the full name of the referrer optional
- Please provide a link to your LinkedIn profile.
- As part of the employment process, all candidates are subject to employment and education verification, as well as a comprehensive background check, in accordance with applicable laws and company policies. I understand that I will be provided with additional information and asked to provide authorization before any such checks are conducted. choose one
- I understand that all information provided in my application must be accurate and truthful, and that any misrepresentation may result in disqualification from the hiring process or termination of employment if discovered after hire. choose one
- I acknowledge that DigiCert and its service providers may collect and process my image and related identity verification information to verify my identity, prevent fraud, maintain security, and administer the hiring process. I understand that this information will be used only for these purposes and retained in accordance with DigiCert's applicable policies and legal obligations. If I choose not to provide the information required to complete identity verification, DigiCert may be unable to continue processing my application. Do you acknowledge and agree? choose one