1

Cyber Risk Analyst Jobs in Illinois (NOW HIRING)

Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic ... analysis, investigation, and remediation of insider risk-related inquiries • Leading client ...

Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic ... the triage, analysis, investigation, and remediation of insider risk-related inquiries Leading ...

Sr. Risk Analyst | Primient About Primient Primient is a century old company with an ... cyber, and other specialized policies. Claims Management: * Collaborate with internal stakeholders ...

Sr. Risk Analyst | Primient About Primient Primient is a century old company with an ... cyber, and other specialized policies. Claims Management: * Collaborate with internal stakeholders ...

Cyber Security Risk Analyst Work Location: Required onsite work at the client location at Scott Air ... Integrate metrics with cyber readiness framework * Analyze and define data requirements and ...

Cyber Risk Analyst W-2 Only (no 1099) Must be a U.S. Citizen Company's Location: Lemont, IL Background: Companys Cyber Security Program Office (CSPO) promotes the safe and secure use of technology.

Cyber Risk Analyst W-2 Only (no 1099) Must be a U.S. Citizen Company's Location: Lemont, IL Background: Companys Cyber Security Program Office (CSPO) promotes the safe and secure use of technology.

next page

Showing results 1-20

Cyber Risk Analyst information

See Illinois salary details

$43.1K

$104.2K

$146.3K

How much do cyber risk analyst jobs pay per year?

As of Aug 29, 2026, the average yearly pay for cyber risk analyst in Illinois is $104,191.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,700.00 and $122,600.00 per year, depending on experience, location, and employer.

How does a cyber risk analyst typically collaborate with other departments to improve an organization's security posture?

Cyber Risk Analysts work closely with various departments, such as IT, compliance, and business units, to identify and assess potential security threats. They often facilitate risk assessments, conduct training sessions to raise awareness, and help develop incident response plans. Regular communication and collaboration are essential, as analysts must ensure that security recommendations align with business goals and regulatory requirements. This cross-functional teamwork creates a more resilient security environment and helps integrate cybersecurity best practices throughout the organization.

What are the key skills and qualifications needed to thrive as a cyber risk analyst, and why are they important?

To thrive as a Cyber Risk Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and often a degree in cybersecurity, computer science, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), vulnerability assessment tools, and security information and event management (SIEM) systems is typically required, along with certifications like CISSP or CISM. Analytical thinking, attention to detail, and strong communication skills are essential soft skills for this role. These competencies ensure accurate identification, evaluation, and mitigation of cyber risks to protect organizational assets and maintain regulatory compliance.

What is the difference between Cyber Risk Analyst vs Cyber Security Analyst?

AspectCyber Risk AnalystCyber Security Analyst
CertificationsCertified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC)CompTIA Security+, Certified Ethical Hacker (CEH)
Work EnvironmentRisk assessment, policy development, complianceNetwork monitoring, threat detection, incident response
Employer & IndustryFinancial, healthcare, government sectors focusing on risk managementIT departments, cybersecurity firms, tech companies

While both roles focus on cybersecurity, a Cyber Risk Analyst primarily assesses and manages potential risks to an organization’s information assets, whereas a Cyber Security Analyst concentrates on defending systems from threats and responding to security incidents. The roles often overlap but differ in their core focus areas.

How much does a cyber risk analyst make?

The average salary for a cyber risk analyst typically ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in industries with high cybersecurity needs.

What does a cyber risk analyst do?

A cyber risk analyst evaluates an organization's cybersecurity threats and vulnerabilities to identify potential risks. They analyze security data, develop risk mitigation strategies, and often use tools like risk assessment frameworks and security information and event management (SIEM) systems to protect digital assets.

What job categories do people searching Cyber Risk Analyst jobs in Illinois look for?

The top searched job categories for Cyber Risk Analyst jobs in Illinois are:

Infographic showing various Cyber Risk Analyst job openings in Illinois as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 14% Part Time, and 2% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $104,191 per year, or $50.1 per hour.

Senior Cyber Risk and Vulnerability Analyst

Chicago, IL • On-site

1 point system
IT Services • 51 - 200 employees

$103K - $132K/yr

Contractor

Posted 14 days ago


Job description

-Office Requirement: We would require this candidate to be in the office 2-3 days a week, preferably on days when the rest of the team is also in the office for collaborative purposes. (Mon-Thurs)
 
Job Description Summary - We are seeking a skilled and motivated Senior Cyber Risk and Vulnerability Analyst to strengthen our cybersecurity risk management and vulnerability management capabilities. This role will conduct security risk assessments, support risk quantification and reporting, coordinate vulnerability remediation, and provide security consultation to business and technology stakeholders. The analyst will also contribute to security awareness and day-to-day operational security activities that help maintain a secure and resilient environment.
Requirements: 
Bachelor’s degree in cybersecurity, information technology, or a related field, or an equivalent combination of education and relevant experience. Relevant security or cloud certifications, such as Security+, Microsoft Azure, or AWS certifications, are preferred.
Five or more years of relevant experience in cybersecurity, technology risk, vulnerability management, security governance, or a related field, including demonstrated experience conducting security risk assessments and coordinating remediation activities.
Security risk assessment experience:Working knowledge of NIST CSF, NIST SP 800-53, ISO 27001, CIS Controls, or comparable security and control frameworks.
Experience evaluating technical and administrative controls.
Experience applying qualitative or quantitative methods to assess, prioritize, and communicate security risk.
Strong documentation and report-writing skills.
Ability to communicate risk to non-technical audiences.
Experience with vulnerability scanning tools such as Nexpose, Qualys or Nessus or similar vulnerability management platforms
Vulnerability management or remediation-governance experience
Experience developing and tracking remediation plans in partnership with technical teams
Excellent analytical and problem-solving skills.   
Be a clear and confident public speaker, able to tailor messaging around technical concepts to diverse audiences. 
Ability to quickly learn new processes and tools
Ability to think critically, ask thoughtful questions, and challenge assumptions in a constructive manner.
Naturally curious and driven to understand how technologies, applications, and business processes operate.
 
Preferred: 
Familiarity of Infrastructure, Container, SAST, DAST vulnerability remediation concepts from a vulnerability management remediation perspective is a plus. This role will work with existing application security resources to enhance the existing vulnerability management program.
Experience with ServiceNow Vulnerability Response Module is a plus
Self-starter who can work independently as well as in a team setting 
Experience analyzing security data in Tableau, Power BI, or comparable tools to identify trends, and develop metrics that support operational and strategic decision-making.
 
Key Responsibilities: 
Strengthen and expand the organization's Cyber Risk Management capabilities through risk assessments, advisory services, governance activities, and reporting.
Support risk analysis, quantification, and reporting efforts to improve organizational understanding and prioritization of cybersecurity risk.
Support the development, operationalization, and ongoing maintenance of the Security Risk Register, including risk documentation, scoring, stakeholder consultation, remediation tracking, governance, and reporting.
Demonstrates intellectual curiosity and a desire to continuously learn, investigate security concerns, challenge assumptions, and identify emerging risks, threats, and opportunities for security improvement.
Work with existing staff to identify and create process improvements to the existing vulnerability management and security awareness programs
Work with remediation teams to create and track plans to address discovered vulnerabilities.  
Identify and evaluate vulnerability metrics to determine areas of concern and improvement.  
Develop, maintain, and adhere to documented procedures, standards, and operational processes.
Conduct security risk assessments of applications, technologies, vendors, projects, and business initiatives to evaluate security control effectiveness and identify areas of risk.
Contribute to Security Awareness efforts on an as needed basis.
Support misc. operational tasks via ticket system
We are looking for additional support in the below operational support areas: 
Manage and resolve incoming service requests and incidents through a ticketing system. 
Evaluate new technologies and solutions to ensure alignment with organizational security policies, standards, and risk tolerance before adoption. 
Review and assess third-party SOC2 reports as part of vendor security evaluations. 
Review and respond to phishing emails reported by users, and escalate if necessary.