1

Cism Jobs in Ohio (NOW HIRING)

Senior GRC Analyst

Westerville, OH · On-site

$92K - $121K/yr

Certifications such as CISSP, CISM, CRISC, or CISA * Experience with vendor risk or data governance tools What Success Looks Like * Strong, adopted security policies * Improved data governance ...

Senior GRC Analyst

Westerville, OH

$92K - $121K/yr

Certifications such as CISSP, CISM, CRISC, or CISA * Experience with vendor risk or data governance tools What Success Looks Like * Strong, adopted security policies * Improved data governance ...

At least one recognized security professional certification such as CISSP, CISM, Security+, CEH, and GIAC. * Minimum 2 years' experience creating technical security architecture design documentation ...

At least one recognized security professional certification such as CISSP, CISM, Security+, CEH, and GIAC. * Minimum 2 years' experience creating technical security architecture design documentation ...

next page

Showing results 1-20

Cism information

See Ohio salary details

$28K

$90.2K

$162.1K

How much do cism jobs pay per year?

As of Aug 6, 2026, the average yearly pay for cism in Ohio is $90,246.00, according to ZipRecruiter salary data. Most workers in this role earn between $47,100.00 and $121,200.00 per year, depending on experience, location, and employer.

What are some common challenges faced by CISMs when implementing information security policies across different departments?

One of the main challenges CISMs encounter is ensuring consistent adoption of security policies across diverse departments with varying needs and priorities. Each department may have unique workflows or legacy systems that require tailored approaches, making it essential for CISMs to collaborate closely and communicate the importance of compliance. Balancing security requirements with business operations often requires negotiation and ongoing education, as well as staying updated on evolving threats to adjust policies accordingly. Building strong relationships and demonstrating the value of security initiatives are keys to overcoming resistance and ensuring organization-wide adherence.

What are the key skills and qualifications needed to thrive as a Certified Information Security Manager (CISM), and why are they important?

To thrive as a Certified Information Security Manager (CISM), you need a strong background in information security governance, risk management, and incident response, usually supported by a relevant degree and the CISM certification. Familiarity with industry-standard frameworks like ISO/IEC 27001, as well as tools for security monitoring, compliance, and risk assessment, is essential. Exceptional leadership, strategic thinking, and communication skills set successful CISM professionals apart by enabling effective collaboration and policy enforcement. These qualifications and skills are crucial for protecting organizational assets, ensuring regulatory compliance, and driving a robust information security strategy.

What is the difference between Cism vs CISSP?

CriteriaCismCISSP
CertificationsCertified Information Security Manager (CISM)Certified Information Systems Security Professional (CISSP)
FocusInformation security management and governanceBroad cybersecurity knowledge and security architecture
Work EnvironmentSecurity management roles, policy developmentSecurity analyst, architect, consultant roles
Industry UsageOrganizations emphasizing security managementOrganizations requiring comprehensive security expertise

The Cism and CISSP certifications are both highly valued in cybersecurity but serve different roles. Cism focuses on security management and governance, ideal for those leading security teams. CISSP covers a broad range of security topics, suitable for technical and strategic roles. Understanding these differences helps professionals choose the right certification for their career path.

What jobs can I get with a CISM certification?

CISM stands for Certified Information Security Manager. CISM certification provides access to a variety of jobs, most of which focus on information security, governance, and risk analysis. In this field, you may help assess the digital security needs of your employer's data projects, review existing security measures, and propose new defenses to counter developing threats. You may also be required to study for other exam processes to stay current with security techniques and emerging technology. Most jobs that require CISM certification are relatively senior positions that only hire people who already have several years of industry experience, so certification alone may not be enough to qualify you a security position.

What is a CISM?

CISM stands for Certified Information Security Manager. It is a globally recognized certification for professionals who manage, design, and oversee an enterprise’s information security program. Earning a CISM demonstrates expertise in information security governance, risk management, program development, and incident management. This credential is ideal for those pursuing or advancing careers in information security management, and is often required for senior security positions.

Is CISM in demand?

CISM (Certified Information Security Manager) is a highly sought-after certification for information security managers, with strong demand in industries such as finance, healthcare, and government. Organizations value CISM professionals for their expertise in managing and governing enterprise security programs, leading to good job prospects and competitive salaries.
What are the most commonly searched types of Cism jobs in Ohio? The most popular types of Cism jobs in Ohio are:
What are popular job titles related to Cism jobs in Ohio? For Cism jobs in Ohio, the most frequently searched job titles are:
What cities in Ohio are hiring for Cism jobs? Cities in Ohio with the most Cism job openings:
Infographic showing various Cism job openings in Ohio as of August 2026, with employment types broken down into 82% Full Time, 12% Part Time, and 6% Contract. Highlights an 77% Physical, 8% Hybrid, and 15% Remote job distribution, with an average salary of $90,246 per year, or $43.4 per hour.

Cyber Security Analyst Columbus Ohio

Mars Tavares LLC

Columbus, OH • On-site

Other

Posted 3 days ago

New


Job description

ONSITE ROLE AT COLUMBUS OHIO
Responsibilities:
Perform security risk assessments, security reviews, and technical evaluations of new and existing systems, applications, and technology initiatives.
Conduct vendor security reviews and evaluate SOC reports, security questionnaires, architecture diagrams, and compliance documentation.
Support compliance activities related to CMS, HIPAA, NIST, ARC-AMP-E/MARS-E, IRS Publication 1075, and other applicable federal and state security requirements.
Participate in audit preparation, evidence collection, audit response activities, remediation tracking, and corrective action planning.
Identify cybersecurity risks and collaborate with business units, ITS teams, vendors, and project teams to develop mitigation strategies.
Support Governance, Risk, and Compliance (GRC) activities, including policies, standards, procedures, and documentation.
Participate in security monitoring, incident response coordination, vulnerability management, and security operations supporting ODM enterprise systems.
Review system architecture, cloud solutions, infrastructure changes, and third-party integrations to ensure compliance with ODM security requirements.
Coordinate with the Agency CISO, Risk Manager, Privacy Officer, Infrastructure teams, project managers, business units, and vendors.
Track security findings, vulnerabilities, POA&Ms, and remediation activities.
Assist with implementation and maintenance of NIST-aligned security controls and ODM security standards.
Support continuous monitoring, vulnerability remediation, and operational security improvements.
Develop executive security reports, compliance documentation, risk summaries, and security metrics.
Participate in SDLC activities to ensure security requirements are incorporated throughout project implementation.
Provide security consultation for cloud services, enterprise applications, third-party integrations, and emerging technologies.
Develop and maintain security documentation, procedures, standards, and compliance artifacts.
Communicate technical security risks and recommendations to technical and non-technical stakeholders.
Perform additional cybersecurity, governance, risk management, compliance, and security operations duties as assigned.
ESSENTIAL REQUIREMENTS:
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field preferred.
Minimum 5 years of professional experience in cybersecurity, information security, governance, risk management, or compliance.
Minimum 3 years conducting security risk assessments, vendor security reviews, or compliance evaluations.
Experience supporting NIST, CMS, HIPAA, ARC-AMP-E/MARS-E, IRS Publication 1075, or comparable frameworks.
Experience supporting Governance, Risk, and Compliance (GRC) programs.
Experience with vulnerability management, audit readiness, evidence collection, remediation tracking, and continuous monitoring.
Experience reviewing cloud technologies, enterprise architecture, and third-party integrations.
Strong analytical, documentation, communication, and organizational skills.
DESIRED Skill Sets:
CISSP, CISM, CISA, Security+, CGRC, or equivalent certification preferred.
Experience with Azure, AWS, or Google Cloud security.
Experience with SIEM technologies and security monitoring.
Experience performing vendor security assessments and third-party risk management.
Knowledge of Medicaid systems or state government security practices preferred.
Experience supporting Agile project environments.
Excellent written and verbal communication skills.
Strong leadership, analytical thinking, and problem-solving abilities.
|
Required/Desired Skills
Skill Required/Desired Amount of Experience Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or related field preferred. Required experience in cybersecurity, information security, governance, risk management, or compliance. Required 5.0 Years conducting security risk assessments, vendor security reviews, or compliance evaluations. Required 3.0 Years supporting NIST, CMS, HIPAA, ARC-AMP-E/MARS-E, IRS Publication 1075, or comparable frameworks. Required Governance, Risk, and Compliance (GRC) programs. Required Experience with vulnerability management, audit readiness, evidence collection, remediation tracking, and continuous monitoring. Required Experience reviewing cloud technologies, enterprise architecture, and third-party integrations. Required CISSP, CISM, CISA, Security+, CGRC, or equivalent certification preferred. Highly desired Experience with Azure, AWS, or Google Cloud security. Highly desired Experience with SIEM technologies and security monitoring. Highly desired Knowledge of Medicaid systems or state government security practices preferred Highly desired