Policy Analyst

The Hershey Company•Lower Swatara Township, PA
•$70,240 - $87,800•Hybrid

About The Position

The Policy Analyst, GRC (Governance, Risk & Compliance) supports the development, maintenance, and lifecycle management of IT and Information Security policies, standards, procedures, and guidelines. This role partners with IT, Information Security, and business stakeholders to help ensure governance documentation is clear, current, and aligned with Hershey’s common controls framework, risk management practices, operational requirements, and applicable industry frameworks. This position provides an opportunity to build foundational experience in Governance, Risk & Compliance (GRC) while supporting the continued maturity of Hershey’s IT governance program.

Requirements

  • At least 1 year of professional experience in Information Technology, Information Security, Governance, Risk & Compliance, audit, business analysis, policy administration, or a related discipline.
  • Foundational understanding of IT, Information Security, risk management, compliance, or internal controls preferred.
  • Strong written and verbal communication skills.
  • Ability to organize and maintain detailed documentation.
  • Ability to collaborate with both technical and non-technical stakeholders.
  • Strong attention to detail and willingness to learn new processes, technologies, and GRC concepts.

Nice To Haves

  • Familiarity with GRC platforms, policy management tools, or ServiceNow is a plus.
  • Exposure to industry frameworks such as NIST, ISO, SOX, or PCI is a plus.

Responsibilities

  • Support the creation, review, maintenance, and lifecycle management of IT and Information Security policies, standards, procedures, and guidelines.
  • Work with IT, Information Security, and business stakeholders to develop and update governance documentation and coordinate reviews, feedback, approvals, and publication.
  • Provide templates, guidance, and support to IT and Information Security teams when developing standards and supporting governance documentation.
  • Help align policies and standards with Hershey’s common controls framework and applicable industry and regulatory frameworks, including NIST, ISO, SOX, and PCI.
  • Support updates to governance documentation resulting from risk assessments, control changes, audit findings, compliance requirements, issues, and remediation activities.
  • Assist with administration and tracking of policy exceptions, including documentation, status, expiration dates, and stakeholder follow-up.
  • Support governance metrics and reporting and identify opportunities to improve policy processes, templates, workflows, and documentation.
  • Build knowledge of governance, risk management, compliance, internal controls, and industry best practices through hands-on experience and collaboration with GRC team members.

Benefits

  • Medical, dental, and vision coverage
  • Wellness programs that support your physical and mental health
  • Competitive pay
  • Annual incentive opportunities
  • 401(k) with company match
  • Paid time off
  • Company holidays
  • Flexible ways of working where applicable
  • Career development programs
  • Learning opportunities
  • Internal mobility
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service