Safeguards Policy Analyst, Cyber Harms
The analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.
About the job
Responsibilities
- Develop and maintain cyber product policy artifacts, including usage-policy language, help-center and enforcement guidance, and launch policy notes.
- Analyze the constitution and cyber-related usage policies to verify that enforcement decisions and safeguards align with them; maintain a gap log and propose text fixes.
- Collaborate with threat intelligence, enforcement, engineering, and policy teams to ensure cyber safety standards are met.
- Review enforcement decisions regularly, identify policy drift, and report findings.
- Coordinate cyber policy inputs for model releases, launch reviews, model cards, regulatory requirements, and regulator pre-briefs.
- Support access-requirements policy and consolidation of the controlled-access framework.
- Keep cyber policy commitments current with industry and regulatory standards and map them to technical safeguards.
- Draft reporting inputs for partners and regulators.
- Translate technical evaluation and safeguard work into policy positions and internal guidance.
- Engage with technical teams on probes, classifiers, and trusted-access programs.
Requirements
- Demonstrated ability to write clear policy analysis in a professional or academic setting.
- Familiarity with AI platform usage-policy enforcement, cybersecurity policy, standards, or regulatory frameworks such as usage policies/AUPs, trust and safety enforcement, NIST CSF, or CVD.
- Ability to interpret technical security material, including vulnerability reports and threat assessments.
- Strong cross-functional collaboration and written communication skills.
- Bachelor's degree or equivalent combination of education, training, and experience.
Nice-to-haves
- Cybersecurity policy experience, including coordinated vulnerability disclosure.
- Exposure to government information-sharing and incident-notification frameworks.
- Experience engaging with government agencies, regulators, or standards bodies on cybersecurity or AI matters.
- Experience with legal, technical, or policy aspects of vulnerabilities and disclosure.
- Experience supporting model-release or product-launch reviews.
- Familiarity with trust-and-safety or platform product-policy work, including usage policies, enforcement appeals, and policy communications.
Compensation and Benefits
- Annual salary: $190,000–$285,000 USD.
- Competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office collaboration space.
- Hybrid policy requiring staff to work from an office at least 25% of the time; some roles may require more.
Skills
Cybersecurity Policy, Usage Policies, Trust And Safety, Nist Csf, Coordinated Vulnerability Disclosure, Threat Intelligence, Vulnerability Reports, Threat Assessments, Policy Analysis, Access Control, Security Classifiers, Model Cards, Incident Notification
Similar jobs
Security Engineering jobsOwn and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.
Manages Decagon’s governance, risk, and compliance program, including enterprise certifications, audit evidence, vendor risk, customer security assessments, and RFP responses. Requires 3–5 years of GRC experience, strong communication and project management skills, and familiarity with technical security controls and privacy regulations.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.
Build and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.
Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.