Ability to provide clear guidance to others The team Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices.
Ability to provide clear guidance to others The team Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices.
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Cyber Security Officer
Santa Ana, CA · On-site
$115.30K - $155.80K/yr
Develop and conduct cyber risk training - at appropriate levels for employees. Oversee the ... Tests, monitors and performs regular analysis of the effectiveness of the security tools and ...
Cyber Security Officer
Santa Ana, CA · On-site
$115.30K - $155.80K/yr
Develop and conduct cyber risk training - at appropriate levels for employees. Oversee the ... Tests, monitors and performs regular analysis of the effectiveness of the security tools and ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Ability to provide clear guidance to others The team Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices.
Ability to provide clear guidance to others The team Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices.
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
You'll help coach individuals and managers to understand actuarial analytics, Cyber pricing and risk, and how it differs from traditional pricing and other lines of business What you've accomplished ...
You'll help coach individuals and managers to understand actuarial analytics, Cyber pricing and risk, and how it differs from traditional pricing and other lines of business What you've accomplished ...
You'll help coach individuals and managers to understand actuarial analytics, Cyber pricing and risk, and how it differs from traditional pricing and other lines of business What you've accomplished ...
You'll help coach individuals and managers to understand actuarial analytics, Cyber pricing and risk, and how it differs from traditional pricing and other lines of business What you've accomplished ...
Facilitate risk workshops, interviews, and scenario analysis to surface emerging risks and ensure ... Collaborate with second-line SMEs (e.g., IT, cyber, information security, business continuity ...
Facilitate risk workshops, interviews, and scenario analysis to surface emerging risks and ensure ... Collaborate with second-line SMEs (e.g., IT, cyber, information security, business continuity ...
IT Risk & Compliance Analyst
San Francisco, CA · On-site
$110.70K - $111.30K/yr
... supply chain cyber risk program management Primary Responsibilities: * Conduct readiness ... Strong analytical, issue identification, prioritization, resolution, and report writing skills ...
Quick apply
IT Risk & Compliance Analyst
San Francisco, CA · On-site
$110.70K - $111.30K/yr
... supply chain cyber risk program management Primary Responsibilities: * Conduct readiness ... Strong analytical, issue identification, prioritization, resolution, and report writing skills ...
... cyber risk. In this role, you'll support high-impact client environments, collaborate with ... Analyzing vulnerability data, exploitability, attack paths, asset criticality, and exposure trends ...
... cyber risk. In this role, you'll support high-impact client environments, collaborate with ... Analyzing vulnerability data, exploitability, attack paths, asset criticality, and exposure trends ...
R0239638 Cybersecurity Engineer and Risk Analyst The Opportunity: Are you looking for an ... In this role, you'll closely impact Navy missions by championing cybersecurity, discovering cyber ...
R0239638 Cybersecurity Engineer and Risk Analyst The Opportunity: Are you looking for an ... In this role, you'll closely impact Navy missions by championing cybersecurity, discovering cyber ...
... cyber risk. In this role, you'll support high-impact client environments, collaborate with ... Analyzing vulnerability data, exploitability, attack paths, asset criticality, and exposure trends ...
... cyber risk. In this role, you'll support high-impact client environments, collaborate with ... Analyzing vulnerability data, exploitability, attack paths, asset criticality, and exposure trends ...
... cyber risk. In this role, you'll support high-impact client environments, collaborate with ... Analyzing vulnerability data, exploitability, attack paths, asset criticality, and exposure trends ...
... cyber risk. In this role, you'll support high-impact client environments, collaborate with ... Analyzing vulnerability data, exploitability, attack paths, asset criticality, and exposure trends ...
... cyber risk. In this role, you'll support high-impact client environments, collaborate with ... Analyzing vulnerability data, exploitability, attack paths, asset criticality, and exposure trends ...
... cyber risk. In this role, you'll support high-impact client environments, collaborate with ... Analyzing vulnerability data, exploitability, attack paths, asset criticality, and exposure trends ...
... cyber risk. In this role, you'll support high-impact client environments, collaborate with ... Analyzing vulnerability data, exploitability, attack paths, asset criticality, and exposure trends ...
... cyber risk. In this role, you'll support high-impact client environments, collaborate with ... Analyzing vulnerability data, exploitability, attack paths, asset criticality, and exposure trends ...
At Vulcan Cyber, we're modernizing the way enterprises reduce their cyber risk. From detection to ... Analyze customer requirements, provide technical expertise to design and implement Vulcan ...
At Vulcan Cyber, we're modernizing the way enterprises reduce their cyber risk. From detection to ... Analyze customer requirements, provide technical expertise to design and implement Vulcan ...
Sr. Mgr. Information Security
San Jose, CA · On-site
$124.80K - $169.40K/yr
Responds immediately to cybersecurity-related incidents and provides a thorough post-event analysis ... Lead the global cyber risk management framework, aligning with regulatory requirements and business ...
Sr. Mgr. Information Security
San Jose, CA · On-site
$124.80K - $169.40K/yr
Responds immediately to cybersecurity-related incidents and provides a thorough post-event analysis ... Lead the global cyber risk management framework, aligning with regulatory requirements and business ...
Sr. Mgr. Information Security
$124.80K - $169.40K/yr
Responds immediately to cybersecurity-related incidents and provides a thorough post-event analysis ... Lead the global cyber risk management framework, aligning with regulatory requirements and business ...
Sr. Mgr. Information Security
$124.80K - $169.40K/yr
Responds immediately to cybersecurity-related incidents and provides a thorough post-event analysis ... Lead the global cyber risk management framework, aligning with regulatory requirements and business ...
Cyber Risk Analyst information
See California salary details
$43.9K - $53.5K
9% of jobs
$53.5K - $63K
2% of jobs
$63K - $72.6K
6% of jobs
$72.6K - $82.1K
1% of jobs
$86K is the 25th percentile. Wages below this are outliers.
$82.1K - $91.7K
17% of jobs
$91.7K - $101.2K
11% of jobs
The median wage is $105.1K / yr.
$101.2K - $110.8K
11% of jobs
$110.8K - $120.4K
17% of jobs
$122K is the 75th percentile. Wages above this are outliers.
$120.4K - $129.9K
10% of jobs
$129.9K - $139.5K
13% of jobs
$139.5K - $149K
4% of jobs
$43.9K
$106.1K
$149K
How much do cyber risk analyst jobs pay per year?
What are the key skills and qualifications needed to thrive as a Cyber Risk Analyst, and why are they important?
How does a Cyber Risk Analyst typically collaborate with other departments to improve an organization's security posture?
What does a Cyber Risk Analyst do?
What is the difference between Cyber Risk Analyst vs Cyber Security Analyst?
| Aspect | Cyber Risk Analyst | Cyber Security Analyst |
|---|---|---|
| Certifications | Certified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC) | CompTIA Security+, Certified Ethical Hacker (CEH) |
| Work Environment | Risk assessment, policy development, compliance | Network monitoring, threat detection, incident response |
| Employer & Industry | Financial, healthcare, government sectors focusing on risk management | IT departments, cybersecurity firms, tech companies |
While both roles focus on cybersecurity, a Cyber Risk Analyst primarily assesses and manages potential risks to an organization’s information assets, whereas a Cyber Security Analyst concentrates on defending systems from threats and responding to security incidents. The roles often overlap but differ in their core focus areas.

Deloitte rating
8.1
Based on 86 frontline employees who took The Breakroom Quiz
59th of 138 rated financial services
Job description
Join Deloitte's Cyber Defense & Resilience team as a forward deployed engineer supporting client patching and remediation programs. In this role, you'll work directly with client infrastructure, endpoint, server, and application teams to reduce exposure and improve cyber resilience. You'll help translate vulnerability findings into actionable remediation plans, support patch execution across environments, and track progress against risk-reduction goals.
Recruiting for this role ends on 06/30/2026.
Work you'll do
As a Security Engineer II on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for...
- Working directly with client teams to plan, track, and execute patching and remediation activities across endpoint, server, middleware, and application environments
- Translating vulnerability findings, asset context, and threat data into prioritized remediation actions
- Supporting patch deployment, validation, and reporting using enterprise tools and client processes
- Maintaining remediation records, exception tracking, and status reporting to measure exposure reduction
- Supporting automation and process improvement activities that increase patching speed, consistency, and coverage
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber Defense & Resilience team works with clients to design, implement, and operate programs that help protect critical assets, support digital transformation, and respond to evolving threats. Within this practice, forward deployed engineers work alongside client teams to operationalize vulnerability remediation, patching, and exposure reduction across complex technology environments.
Qualifications
Required:
- 3+ years of experience in information technology, information security, vulnerability management, patch management, or a combination of these
- 2+ years of experience supporting forward deployed engineering, remediation delivery, or client-facing technology operations in enterprise environments
- 2+ years of experience executing patching or vulnerability remediation across Windows, Linux, middleware, endpoints, or applications using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite, Windows Server Update Services, Tenable, Rapid7, or Qualys
- 1+ year of experience using PowerShell, Bash, Python, Ansible, Terraform, or JavaScript Object Notation for scripting, automation, or configuration activities
- 1+ year of experience using ServiceNow or another Information Technology Service Management platform to track remediation activities, exceptions, and status
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Preferred:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information Technology, Mathematics, or Physics
- Experience in a consulting environment
- Experience preparing remediation metrics, dashboards, or status reporting
- Experience supporting patch validation, exception management, or change coordination
- Experience with the National Institute of Standards and Technology Cybersecurity Framework, Center for Internet Security, International Organization for Standardization 27001, or Cloud Security Alliance Cloud Controls Matrix
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
This position is aligned with the Core Talent Model. To view the associated benefit package, please reference this document https://resources.deloitte.com/:b:/r/sites/dnet-tod-us/Shared Documents/Benefits/USBenefitsJourneyCDandETAM.pdf?csf=1&web=1&e=pKjS1C
Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at USTalentCICInbox@deloitte.com.
Join Deloitte's Cyber Defense & Resilience team as a forward deployed engineer supporting client patching and remediation programs. In this role, you'll work directly with client infrastructure, endpoint, server, and application teams to reduce exposure and improve cyber resilience. You'll help translate vulnerability findings into actionable remediation plans, support patch execution across environments, and track progress against risk-reduction goals.
Recruiting for this role ends on 06/30/2026.
Work you'll do
As a Security Engineer II on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for...
- Working directly with client teams to plan, track, and execute patching and remediation activities across endpoint, server, middleware, and application environments
- Translating vulnerability findings, asset context, and threat data into prioritized remediation actions
- Supporting patch deployment, validation, and reporting using enterprise tools and client processes
- Maintaining remediation records, exception tracking, and status reporting to measure exposure reduction
- Supporting automation and process improvement activities that increase patching speed, consistency, and coverage
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber Defense & Resilience team works with clients to design, implement, and operate programs that help protect critical assets, support digital transformation, and respond to evolving threats. Within this practice, forward deployed engineers work alongside client teams to operationalize vulnerability remediation, patching, and exposure reduction across complex technology environments.
Qualifications
Required:
- 3+ years of experience in information technology, information security, vulnerability management, patch management, or a combination of these
- 2+ years of experience supporting forward deployed engineering, remediation delivery, or client-facing technology operations in enterprise environments
- 2+ years of experience executing patching or vulnerability remediation across Windows, Linux, middleware, endpoints, or applications using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite, Windows Server Update Services, Tenable, Rapid7, or Qualys
- 1+ year of experience using PowerShell, Bash, Python, Ansible, Terraform, or JavaScript Object Notation for scripting, automation, or configuration activities
- 1+ year of experience using ServiceNow or another Information Technology Service Management platform to track remediation activities, exceptions, and status
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Preferred:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information Technology, Mathematics, or Physics
- Experience in a consulting environment
- Experience preparing remediation metrics, dashboards, or status reporting
- Experience supporting patch validation, exception management, or change coordination
- Experience with the National Institute of Standards and Technology Cybersecurity Framework, Center for Internet Security, International Organization for Standardization 27001, or Cloud Security Alliance Cloud Controls Matrix
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
This position is aligned with the Core Talent Model. To view the associated benefit package, please reference this document https://resources.deloitte.com/:b:/r/sites/dnet-tod-us/Shared Documents/Benefits/USBenefitsJourneyCDandETAM.pdf?csf=1&web=1&e=pKjS1C
Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at USTalentCICInbox@deloitte.com.