Summary
Policy Analyst
The Policy Analyst, GRC (Governance, Risk & Compliance) supports the development, maintenance, and lifecycle management of IT and Information Security policies, standards, procedures, and guidelines. This role partners with IT, Information Security, and business stakeholders to help ensure governance documentation is clear, current, and aligned with Hershey's common controls framework, risk management practices, operational requirements, and applicable industry frameworks. This position provides an opportunity to build foundational experience in Governance, Risk& Compliance (GRC) while supporting the continued maturity of Hershey's IT governance program.
What will you do?
- Policy & Governance Management: Support the creation, review, maintenance, and lifecycle management of IT and Information Security policies, standards, procedures, and guidelines.
- Stakeholder Collaboration: Work with IT, Information Security, and business stakeholders to develop and update governance documentation and coordinate reviews, feedback, approvals, and publication.
- Standards Development: Provide templates, guidance, and support to IT and Information Security teams when developing standards and supporting governance documentation.
- Controls & Framework Alignment: Help align policies and standards with Hershey's common controls framework and applicable industry and regulatory frameworks, including NIST, ISO, SOX, and PCI.
- Risk & Compliance Alignment: Support updates to governance documentation resulting from risk assessments, control changes, audit findings, compliance requirements, issues, and remediation activities.
- Policy Exception Support: Assist with administration and tracking of policy exceptions, including documentation, status, expiration dates, and stakeholder follow-up.
- Governance Reporting & Improvement: Support governance metrics and reporting and identify opportunities to improve policy processes, templates, workflows, and documentation.
- GRC Development: Build knowledge of governance, risk management, compliance, internal controls, and industry best practices through hands-on experience and collaboration with GRC team members.
Minimum Education & Requirements Experience At least 1 year of professional experience in Information Technology, Information Security, Governance, Risk & Compliance, audit, business analysis, policy administration, or a related discipline. Foundational understanding of IT, Information Security, risk management, compliance, or internal controls preferred. Strong written and verbal communication skills. Ability to organize and maintain detailed documentation. Ability to collaborate with both technical and non-technical stakeholders. Strong attention to detail and willingness to learn new processes, technologies, and GRC concepts. Familiarity with GRC platforms, policy management tools, or ServiceNow is a plus. Exposure to industry frameworks such as NIST, ISO, SOX, or PCI is a plus. Education Bachelor's degree in Information Technology, Information Security, Cybersecurity, Business, Risk Management, or a related discipline preferred, or equivalent relevant experience.
Benefits and Perks At Hershey, we offer competitive pay and a comprehensive total rewards package designed to support your wellbeing, financial security, and life outside of work. Health & Wellbeing: Medical, dental, and vision coverage, plus wellness programs that support your physical and mental health Financial Security: Competitive pay, annual incentive opportunities, and a 401(k) with company match Time Off & Flexibility: Paid time off, company holidays, and flexible ways of working where applicable Growth & Development: Career development programs, learning opportunities, and internal mobility Benefits may vary based on role, location, and eligibility. The anticipated base salary range for this role is $70,240 to $87,800 per year. The actual base salary offered will depend on a variety of job‑related factors, including, but not limited to, experience, skill set, education, and training. In addition to a market-competitive base salary, our Total Rewards package includes performance‑based incentives and a comprehensive, competitive benefits package designed to support overall physical, mental, and financial well‑being (as applicable).
The Hershey Company is an Equal Opportunity Employer. The policy of The Hershey Company is to extend opportunities to qualified applicants and employees on an equal basis regardless of an individual's race, color, gender, age, national origin, religion, citizenship status, marital status, sexual orientation, gender identity, transgender status, physical or mental disability, protected veteran status, genetic information, pregnancy, or any other categories protected by applicable federal, state or local laws. The Hershey Company is an Equal Opportunity Employer - Minority/Female/Disabled/Protected Veterans.
Job Description
Policy Analyst
The Policy Analyst, GRC (Governance, Risk & Compliance) supports the development, maintenance, and lifecycle management of IT and Information Security policies, standards, procedures, and guidelines. This role partners with IT, Information Security, and business stakeholders to help ensure governance documentation is clear, current, and aligned with Hershey's common controls framework, risk management practices, operational requirements, and applicable industry frameworks. This position provides an opportunity to build foundational experience in Governance, Risk& Compliance (GRC) while supporting the continued maturity of Hershey's IT governance program.
What will you do?
- Policy & Governance Management: Support the creation, review, maintenance, and lifecycle management of IT and Information Security policies, standards, procedures, and guidelines.
- Stakeholder Collaboration: Work with IT, Information Security, and business stakeholders to develop and update governance documentation and coordinate reviews, feedback, approvals, and publication.
- Standards Development: Provide templates, guidance, and support to IT and Information Security teams when developing standards and supporting governance documentation.
- Controls & Framework Alignment: Help align policies and standards with Hershey's common controls framework and applicable industry and regulatory frameworks, including NIST, ISO, SOX, and PCI.
- Risk & Compliance Alignment: Support updates to governance documentation resulting from risk assessments, control changes, audit findings, compliance requirements, issues, and remediation activities.
- Policy Exception Support: Assist with administration and tracking of policy exceptions, including documentation, status, expiration dates, and stakeholder follow-up.
- Governance Reporting & Improvement: Support governance metrics and reporting and identify opportunities to improve policy processes, templates, workflows, and documentation.
- GRC Development: Build knowledge of governance, risk management, compliance, internal controls, and industry best practices through hands-on experience and collaboration with GRC team members.
Minimum Education & Requirements Experience At least 1 year of professional experience in Information Technology, Information Security, Governance, Risk & Compliance, audit, business analysis, policy administration, or a related discipline. Foundational understanding of IT, Information Security, risk management, compliance, or internal controls preferred. Strong written and verbal communication skills. Ability to organize and maintain detailed documentation. Ability to collaborate with both technical and non-technical stakeholders. Strong attention to detail and willingness to learn new processes, technologies, and GRC concepts. Familiarity with GRC platforms, policy management tools, or ServiceNow is a plus. Exposure to industry frameworks such as NIST, ISO, SOX, or PCI is a plus. Education Bachelor's degree in Information Technology, Information Security, Cybersecurity, Business, Risk Management, or a related discipline preferred, or equivalent relevant experience.
Benefits and Perks At Hershey, we offer competitive pay and a comprehensive total rewards package designed to support your wellbeing, financial security, and life outside of work. Health & Wellbeing: Medical, dental, and vision coverage, plus wellness programs that support your physical and mental health Financial Security: Competitive pay, annual incentive opportunities, and a 401(k) with company match Time Off & Flexibility: Paid time off, company holidays, and flexible ways of working where applicable Growth & Development: Career development programs, learning opportunities, and internal mobility Benefits may vary based on role, location, and eligibility. The anticipated base salary range for this role is $70,240 to $87,800 per year. The actual base salary offered will depend on a variety of job‑related factors, including, but not limited to, experience, skill set, education, and training. In addition to a market-competitive base salary, our Total Rewards package includes performance‑based incentives and a comprehensive, competitive benefits package designed to support overall physical, mental, and financial well‑being (as applicable).
The Hershey Company is an Equal Opportunity Employer. The policy of The Hershey Company is to extend opportunities to qualified applicants and employees on an equal basis regardless of an individual's race, color, gender, age, national origin, religion, citizenship status, marital status, sexual orientation, gender identity, transgender status, physical or mental disability, protected veteran status, genetic information, pregnancy, or any other categories protected by applicable federal, state or local laws. The Hershey Company is an Equal Opportunity Employer - Minority/Female/Disabled/Protected Veterans.
Government Careers
Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.
Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.
Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.
MORE JOBS
-
Lead Statistical Assistant (Administrative Specialist 1)
- Trenton, New Jersey
- New Jersey Judiciary
- Sep 30, 2026
-
$200,000 - $250,000 Annually
Chief Administrative Officer
- Riverdale Park, Maryland
- Maryland-National Capital Park and Planning Commission
- Sep 30, 2026
-
Site W/Classified Support Engineer
- Herndon, Virginia
- GovCIO LLC
- Oct 07, 2026
-
INTELLIGENCE ANALYST
- Washington, DC
- Beyond SOF
- Oct 07, 2026
-
Supervisory Program Specialist (Deputy Chief)
- Washington, DC
- Offices, Boards and Divisions
- Oct 07, 2026
-
Evening Bird Conservation Field Intern
- Coatesville, Pennsylvania
- Theuniversityunion
- Oct 07, 2026