Hybrid - 3 Days per Quarter The role reports to the Head of Cyber Risk Management, inside of ... Help categorize engagement results in a consistent and meaningful manner to support trend analysis ...
Hybrid - 3 Days per Quarter The role reports to the Head of Cyber Risk Management, inside of ... Help categorize engagement results in a consistent and meaningful manner to support trend analysis ...
Cyber Operational Technology/ Industrial Control Systems (OT/ICS) Senior Consultant
Portland, OR · Remote
Perform consequence-based risk assessments for OT environments, utilizing methodologies such as Cyber Process Hazards Analysis (Cyber PHA) to identify, analyze, and prioritize cyber risks. * Lead ...
Cyber Operational Technology/ Industrial Control Systems (OT/ICS) Senior Consultant
Portland, OR · Remote
Perform consequence-based risk assessments for OT environments, utilizing methodologies such as Cyber Process Hazards Analysis (Cyber PHA) to identify, analyze, and prioritize cyber risks. * Lead ...
Cyber Data Protection Manager
Portland, OR · Hybrid
$117K - $159K/yr
Risk & Compliance * Identity & Access Management * Data Protection * Cyber Design * Incident ... and Analysts in developing, implementing, and providing day-to-day support for cyber data ...
Cyber Data Protection Manager
Portland, OR · Hybrid
$117K - $159K/yr
Risk & Compliance * Identity & Access Management * Data Protection * Cyber Design * Incident ... and Analysts in developing, implementing, and providing day-to-day support for cyber data ...
SOC Tier 1 Analyst
Portland, OR · On-site
Escalate confirmed, ambiguous, high-risk, or complex alerts to SOC Analyst 2, SOC Analyst 3, or SOC ... Stay current with common cyber threats, phishing techniques, malware trends, vulnerabilities, user ...
SOC Tier 1 Analyst
Portland, OR · On-site
Escalate confirmed, ambiguous, high-risk, or complex alerts to SOC Analyst 2, SOC Analyst 3, or SOC ... Stay current with common cyber threats, phishing techniques, malware trends, vulnerabilities, user ...
... analysts. Named one of the Best Places to Work in the Washington DC area for 12 consecutive years ... or cyber risk management. * Bachelor's degree in Computer Science, Information Systems ...
... analysts. Named one of the Best Places to Work in the Washington DC area for 12 consecutive years ... or cyber risk management. * Bachelor's degree in Computer Science, Information Systems ...
Cyber Full-Stack Technical Architect/Manager
Portland, OR · On-site
$70.25 - $84.75/hr
Analyzing, implementing user requirements/business needs as new and/or enhanced product ... Contribute to project planning, estimation, capacity planning, and risk management across delivery ...
Cyber Full-Stack Technical Architect/Manager
Portland, OR · On-site
$70.25 - $84.75/hr
Analyzing, implementing user requirements/business needs as new and/or enhanced product ... Contribute to project planning, estimation, capacity planning, and risk management across delivery ...
SOC Tier 3 Analyst
Portland, OR · On-site
$88K - $104K/yr
Provide technical facts, risk context, and recommended response priorities to SOC leadership for ... Stay current with evolving cyber threats, vulnerabilities, adversary tradecraft, detection ...
SOC Tier 3 Analyst
Portland, OR · On-site
$88K - $104K/yr
Provide technical facts, risk context, and recommended response priorities to SOC leadership for ... Stay current with evolving cyber threats, vulnerabilities, adversary tradecraft, detection ...
Creating executive-ready presentations, quantitative analyses, and recommendations to support ... Bachelor's degree * 4+ years of experience in strategy, operations, risk, cybersecurity, trust and ...
Creating executive-ready presentations, quantitative analyses, and recommendations to support ... Bachelor's degree * 4+ years of experience in strategy, operations, risk, cybersecurity, trust and ...
Forensics Analyst Lead
Portland, OR · On-site +1
... cyber incidents, insider threats, data breaches, and legal or regulatory matters. This role ... Translate technical findings into clear business, legal, and risk-based narratives. * Brief senior ...
Forensics Analyst Lead
Portland, OR · On-site +1
... cyber incidents, insider threats, data breaches, and legal or regulatory matters. This role ... Translate technical findings into clear business, legal, and risk-based narratives. * Brief senior ...
Cyber SAP Security and GRC Access & Process Control Senior Consultant / Senior Engineering Manage...
Portland, OR · On-site
... risk and enable business operations. Recruiting for this role ends on 12/31/2026. Work you'll do As ... duties analysis, or sensitive access controls in SAP environments * 2+ years of experience ...
Cyber SAP Security and GRC Access & Process Control Senior Consultant / Senior Engineering Manage...
Portland, OR · On-site
... risk and enable business operations. Recruiting for this role ends on 12/31/2026. Work you'll do As ... duties analysis, or sensitive access controls in SAP environments * 2+ years of experience ...
SOC Tier 2 Analyst
Portland, OR · On-site
Communicate technical findings in clear operational, business, and risk language for SOC leadership ... Stay current with evolving cyber threats, vulnerabilities, detection techniques, and security ...
SOC Tier 2 Analyst
Portland, OR · On-site
Communicate technical findings in clear operational, business, and risk language for SOC leadership ... Stay current with evolving cyber threats, vulnerabilities, detection techniques, and security ...
... cyber threats across global operations. * Deliver High-Impact Audits: Execute audits with a primary ... Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving ...
... cyber threats across global operations. * Deliver High-Impact Audits: Execute audits with a primary ... Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
... cyber threats across global operations. * Deliver High-Impact Audits: Execute audits with a primary ... Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
... cyber threats across global operations. * Deliver High-Impact Audits: Execute audits with a primary ... Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
... cyber threats across global operations. * Deliver High-Impact Audits: Execute audits with a primary ... Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
... cyber threats across global operations. * Deliver High-Impact Audits: Execute audits with a primary ... Execute deep-dive testing and analysis of cybersecurity and enterprise technology risks, driving ...
SOC Chief
Portland, OR · On-site
... risk management, and governance activities related to SOC operations and cyber incident response. Team Leadership & Workforce Development * Lead, mentor, and coordinate SOC analysts and operational ...
SOC Chief
Portland, OR · On-site
... risk management, and governance activities related to SOC operations and cyber incident response. Team Leadership & Workforce Development * Lead, mentor, and coordinate SOC analysts and operational ...
SOC Technical Writer
Portland, OR · On-site
The Cyber Technical Writer develops, maintains, and improves cybersecurity documentation ... The role requires close collaboration with analysts, engineers, assessors, threat intelligence ...
SOC Technical Writer
Portland, OR · On-site
The Cyber Technical Writer develops, maintains, and improves cybersecurity documentation ... The role requires close collaboration with analysts, engineers, assessors, threat intelligence ...
... risk control assessments across industrial control systems, OT networks, cyber-physical systems ... OT/ICS Environment Analysis * Review OT architecture, network segmentation, data flows, asset ...
... risk control assessments across industrial control systems, OT networks, cyber-physical systems ... OT/ICS Environment Analysis * Review OT architecture, network segmentation, data flows, asset ...
Provides claims marketing services by meeting with brokers, risk managers and reinsurers. As ... Demonstrated advanced analytical, decision making and negotiation skills About Us Pay Philosophy:
Provides claims marketing services by meeting with brokers, risk managers and reinsurers. As ... Demonstrated advanced analytical, decision making and negotiation skills About Us Pay Philosophy:
Supervisory IT Cybersecurity Specialist
Portland, OR · On-site +1
$135K - $176K/yr
Summary This position is located with Bonneville Power Administration, in Cyber Assessment ... Oversee the execution of risk analyses and security assessments to identify system vulnerabilities ...
Supervisory IT Cybersecurity Specialist
Portland, OR · On-site +1
$135K - $176K/yr
Summary This position is located with Bonneville Power Administration, in Cyber Assessment ... Oversee the execution of risk analyses and security assessments to identify system vulnerabilities ...
Meet Freddie Mac's University Program: Learn About our 2027 Internship and Full-Time Opportunities
Gresham, OR · On-site
$15.75 - $21.25/hr
... Analytics, Economics, Finance, Risk Management, Technology (including Cyber and Software Development) and more. Join us to hear directly from our University Talent Advisors about: -Who we are and how ...
Meet Freddie Mac's University Program: Learn About our 2027 Internship and Full-Time Opportunities
Gresham, OR · On-site
$15.75 - $21.25/hr
... Analytics, Economics, Finance, Risk Management, Technology (including Cyber and Software Development) and more. Join us to hear directly from our University Talent Advisors about: -Who we are and how ...
Cyber Risk Analyst information
See Oregon salary details
$47K - $57.3K
9% of jobs
$57.3K - $67.5K
2% of jobs
$67.5K - $77.8K
6% of jobs
$77.8K - $88K
1% of jobs
$92.2K is the 25th percentile. Wages below this are outliers.
$88K - $98.2K
17% of jobs
$98.2K - $108.5K
11% of jobs
The median wage is $112.6K / yr.
$108.5K - $118.7K
11% of jobs
$118.7K - $128.9K
17% of jobs
$130.6K is the 75th percentile. Wages above this are outliers.
$128.9K - $139.2K
10% of jobs
$139.2K - $149.4K
13% of jobs
$149.4K - $159.7K
4% of jobs
$47K
$113.7K
$159.7K
How much do cyber risk analyst jobs pay per year?
What does a Cyber Risk Analyst do?
What is the difference between Cyber Risk Analyst vs Cyber Security Analyst?
| Aspect | Cyber Risk Analyst | Cyber Security Analyst |
|---|---|---|
| Certifications | Certified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC) | CompTIA Security+, Certified Ethical Hacker (CEH) |
| Work Environment | Risk assessment, policy development, compliance | Network monitoring, threat detection, incident response |
| Employer & Industry | Financial, healthcare, government sectors focusing on risk management | IT departments, cybersecurity firms, tech companies |
While both roles focus on cybersecurity, a Cyber Risk Analyst primarily assesses and manages potential risks to an organization’s information assets, whereas a Cyber Security Analyst concentrates on defending systems from threats and responding to security incidents. The roles often overlap but differ in their core focus areas.
Can you make $500,000 a year in cyber security?
Which country is no. 1 in cybersecurity?
Is 40 too old for cyber security?
What are the key skills and qualifications needed to thrive as a Cyber Risk Analyst, and why are they important?
How does a Cyber Risk Analyst typically collaborate with other departments to improve an organization's security posture?
What does a cybersecurity risk analyst do?

Job description
Location Designation:Â Hybrid - 3 days per quarterÂ
Red Team Program Lead
Level: MG3/PF6
Location Designation: Hybrid - 3 Days per Quarter
The role reports to the Head of Cyber Risk Management, inside of Technology Risk organization, and supports the execution, governance, and operational management of New York Life's Red Team Program. The Red Team Program Lead is responsible for planning, coordinating, and executing adversary-informed security exercises that help evaluate the company's ability to prevent, detect, respond to, and recover from realistic cyber threats, to include the rapidly developing aspects related to AI driven Red Teaming as well as exercises conducted against AI in its various forms.
Role Overview:
This position plays a key role in leading the program's operating cadence, engagement pipeline, stakeholder coordination, vendor activities, executive reporting, and outcome tracking. The Red Team Program Lead is not expected to be a hands-on technical operator; rather, the role requires strong program-oriented discipline, organizational knowledge, relationship management, and the ability to communicate and drive complex work across technology, cybersecurity, business, and control functions.
The individual will help ensure Red Team engagements are planned, governed, communicated, and reported in a way that maximizes organizational learning while maintaining trust with stakeholders who may be subject to challenging discoveries and other impacts brought about by adversarial exercises. The position requires sound judgment, discretion, attention to detail, and the ability to manage priorities in a dynamic execution environment.
What You'll Do:
Program Leadership & Operating Cadence
- Manage the Red Team Program engagement pipeline, including intake, prioritization, planning, scheduling, execution tracking, and post-engagement follow-up.
- Maintain program plans, milestones, deadlines, dependencies, and deliverables across concurrent exercises and related activities.
- Support annual and quarterly planning activities, including exercise selection, resource planning, stakeholder alignment, and program roadmap maintenance.
- Track program risks, issues, decisions, and dependencies, escalating items as appropriate to leadership.
- Help establish and maintain repeatable processes, templates, procedures, and governance documentation.
Stakeholder Coordination & Relationship Management
- Coordinate across cybersecurity, technology operations, risk, business, and control functions to support the successful planning and execution of Red Team engagements.
- Build and maintain positive relationships with stakeholders, including during exercises that may involve sensitive findings, operational disruption concerns, or adversarial scenarios.
- Serve as a point of coordination between the Red Team Control Board, technical operators, defensive teams, technology owners, business stakeholders, and executive audiences.
- Support pre-engagement communications, rules of engagement, stakeholder briefings, deconfliction activities, and post-engagement readouts.
- Exercise extreme discretion and sound judgment when handling confidential plans, sensitive results, and need-to-know communications.
Engagement Governance & Outcome Tracking
- Support the definition and documentation of engagement scope, objectives, assumptions, constraints, timelines, and success criteria.
- Track observations, findings, themes, and remediation commitments resulting from Red Team exercises and related security assessments.
- Partner with stakeholders to drive follow-up actions, confirm ownership, monitor progress, and support timely resolution of agreed outcomes.
- Help categorize engagement results in a consistent and meaningful manner to support trend analysis, executive reporting, and risk-informed decision-making.
- Maintain accurate records of completed exercises, key outcomes, lessons learned, and program metrics.
Reporting, Metrics & Executive Communications
- Develop and maintain program reporting, dashboards, and executive-level materials summarizing Red Team activity, outcomes, risks, trends, and remediation progress.
- Translate complex cybersecurity concepts and exercise results into clear, practical, and audience-appropriate communications.
- Support recurring updates to cybersecurity leadership, technology leadership, risk partners, and other executive stakeholders.
- Identify recurring control gaps, organizational themes, and opportunities to improve cyber defense capabilities based on engagement results.
- Ensure reporting is accurate, balanced, actionable, and appropriately sensitive to audience and confidentiality considerations.
Vendor, Budget & Resource Management
- Support selection and management of third-party vendors engaged in Red Team, adversary simulation, or related cybersecurity assessment activities.
- Coordinate vendor onboarding, statements of work, timelines, deliverables, invoices, and performance tracking in partnership with procurement and program leadership.
- Assist with budget planning, expense tracking, forecasting, and analysis for Red Team Program activities.
- Monitor resource needs and constraints, helping leadership prioritize or deprioritize work based on risk, business priorities, capacity, and timing.
- Help ensure vendor activities are aligned with internal standards, engagement objectives, and stakeholder expectations.
Process Improvement & Program Maturity
- Identify opportunities to improve program structure, execution discipline, reporting consistency, stakeholder experience, and outcome management.
- Contribute to the development and maintenance of Red Team Program standards, operating procedures, and best practices.
- Support alignment between Red Team activities and broader cybersecurity, Technology Risk, Incident Response, Vulnerability Management, and control improvement efforts.
- Help mature the program's ability to measure effectiveness, communicate value, and drive enterprise-level security improvements.
- Adapt program execution to changing priorities, emerging threats, organizational needs, and operational constraints.
Â
What You'll Bring:
- Prior experience in IT system ownership, cybersecurity program coordination, technology risk, project/program management, or related technology governance roles.
- Experience managing cross-functional initiatives involving technology, cybersecurity, risk, business, vendor, and executive stakeholders.
- Demonstrated experience tracking deadlines, dependencies, action items, budgets, deliverables, and outcomes across complex initiatives.
- Prior experience supporting vendor management activities, including coordination of deliverables, timelines, invoicing, and performance expectations.
- Experience preparing executive-facing materials, status updates, metrics, dashboards, or management reporting.
- Familiarity with cybersecurity, cyber defense, technology infrastructure, application environments, identity and access management, incident response, or security operations concepts.
- Prior experience in a regulated financial services, insurance, or similarly complex enterprise environment preferred.
- Experience supporting offensive security, penetration testing, adversary simulation, purple team, incident response, or cyber resilience programs preferred but not required.
Knowledge and Education
- Bachelor's degree required or equivalent work experience.
- Project or program management experience or exposure.
- Cybersecurity or technology risk certification preferred, such as Security+, CISSP, CISM, CRISC, or similar designation.
- High-level understanding of cyber defense organizations, including security operations, incident response, threat intelligence, vulnerability management, identity, infrastructure, and application security functions.
- High-level understanding of enterprise technology functions, including application ownership, infrastructure, cloud, networking, end-user technology, and technology operations.
- Working knowledge of risk management, issue management, control remediation, and executive reporting practices.
Communications and Collaboration
- Ability to communicate clearly and professionally with technical teams, business partners, risk stakeholders, vendors, and executive audiences.
- Demonstrated ability to build trust and maintain positive working relationships, including in situations involving challenging findings, sensitive topics, or competing priorities.
- Strong organizational, analytical, written communication, and presentation skills.
- Ability to translate technical or complex cybersecurity concepts into practical business language.
- Proven ability to drive accountability and outcomes across teams without direct authority.
- Sound judgment, discretion, and professionalism when handling confidential or sensitive information.
- Self-motivated and detail-oriented, with the ability to manage shifting priorities in a dynamic execution environment.
- Ability to prioritize and deprioritize work based on risk, urgency, stakeholder impact, and available capacity.
#LI-VL1
#LI-HYBRID Â
Pay Transparency
Salary Range:Â $185,000-$225,000Â
Overtime eligible:Â ExemptÂ
Discretionary bonus eligible:Â YesÂ
Sales bonus eligible:Â NoÂ
Actual base salary will be determined based on several factors but not limited to individual's experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
Company OverviewÂ
At New York Life, our 180-year legacy of purpose and integrity fuels our future. As we evolve into a more technology-, data-, and AI-enabled organization, we remain grounded in the values that drive lasting impact.Â
Our diverse business portfolio creates opportunities to make a difference across industries and communities-inviting bold thinking, collaborative problem-solving, and purpose-driven innovation. Here, you'll find the rare balance of long-standing stability and forward momentum, supported by an inclusive team that honors tradition while embracing progress.Â
As a Fortune 100 mutual company, we offer a place to grow your skills, contribute to meaningful work, and deliver solutions that matter. Your ideas drive what's next, and your growth powers it.Â
Our Benefits
We provide a full package of benefits for employees - and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work. Click here to discover more about our comprehensive benefit options or visit our NYL Benefits Site.
Our Commitment to Inclusion
At New York Life, fostering an inclusive workplace is fundamental to who we are and how we serve our communities. We have a longstanding commitment to creating an environment where individuals can contribute their best and succeed together. This foundation is rooted in our core values of humanity and integrity, ensuring that every employee feels valued and supported. By embracing a broad range of perspectives and experiences, we achieve greater success and fulfill our promise of providing financial security and peace of mind to families across all communities. Click here to learn more about New York Life's leadership in this space.
Recognized as one of Fortune's World's Most Admired Companies, New York Life is committed to improving local communities through a culture of employee giving and volunteerism, supported by the Foundation. We're proud that due to our mutuality, we operate in the best interests of our policy owners. To learn more about career opportunities at New York Life, please visit the Careers page of www.NewYorkLife.com.
Visit our LinkedIn to see how our employees and agents are leading the industry and impacting communities.
Visit our Newsroom to learn more about how our company is constantly evolving to meet our clients' and employees' needs.
Job Requisition ID: 94130
About NorCal Orange
Sourced by ZipRecruiter
Industry
Colleges, universities, and professional schools
Company size
11 - 50 Employees
Headquarters location
Syracuse, NY, US