1

Cyber Risk Analyst Jobs in Tampa, FL (NOW HIRING)

The IT Risk Analyst helps manage the Firm's GRC and IT risk programs, focusing on information ... cyber insurance, and supports audits. Responsibilities align with ISO/IEC 27001/27002, NIST CSF ...

... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...

... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...

next page

Showing results 1-20

Cyber Risk Analyst information

See Tampa, FL salary details

$42.1K

$101.6K

$142.7K

How much do cyber risk analyst jobs pay per year?

As of Aug 23, 2026, the average yearly pay for cyber risk analyst in Tampa, FL is $101,612.00, according to ZipRecruiter salary data. Most workers in this role earn between $86,500.00 and $119,500.00 per year, depending on experience, location, and employer.

How does a cyber risk analyst typically collaborate with other departments to improve an organization's security posture?

Cyber Risk Analysts work closely with various departments, such as IT, compliance, and business units, to identify and assess potential security threats. They often facilitate risk assessments, conduct training sessions to raise awareness, and help develop incident response plans. Regular communication and collaboration are essential, as analysts must ensure that security recommendations align with business goals and regulatory requirements. This cross-functional teamwork creates a more resilient security environment and helps integrate cybersecurity best practices throughout the organization.

What are the key skills and qualifications needed to thrive as a cyber risk analyst, and why are they important?

To thrive as a Cyber Risk Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and often a degree in cybersecurity, computer science, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), vulnerability assessment tools, and security information and event management (SIEM) systems is typically required, along with certifications like CISSP or CISM. Analytical thinking, attention to detail, and strong communication skills are essential soft skills for this role. These competencies ensure accurate identification, evaluation, and mitigation of cyber risks to protect organizational assets and maintain regulatory compliance.

What is the difference between Cyber Risk Analyst vs Cyber Security Analyst?

AspectCyber Risk AnalystCyber Security Analyst
CertificationsCertified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC)CompTIA Security+, Certified Ethical Hacker (CEH)
Work EnvironmentRisk assessment, policy development, complianceNetwork monitoring, threat detection, incident response
Employer & IndustryFinancial, healthcare, government sectors focusing on risk managementIT departments, cybersecurity firms, tech companies

While both roles focus on cybersecurity, a Cyber Risk Analyst primarily assesses and manages potential risks to an organization’s information assets, whereas a Cyber Security Analyst concentrates on defending systems from threats and responding to security incidents. The roles often overlap but differ in their core focus areas.

How much does a cyber risk analyst make?

The average salary for a cyber risk analyst typically ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in industries with high cybersecurity needs.

What does a cyber risk analyst do?

A cyber risk analyst evaluates an organization's cybersecurity threats and vulnerabilities to identify potential risks. They analyze security data, develop risk mitigation strategies, and often use tools like risk assessment frameworks and security information and event management (SIEM) systems to protect digital assets.

What job categories do people searching Cyber Risk Analyst jobs in Tampa, FL look for?

The top searched job categories for Cyber Risk Analyst jobs in Tampa, FL are:

Infographic showing various Cyber Risk Analyst job openings in Tampa, FL as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 10% Part Time, and 4% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $101,612 per year, or $48.9 per hour.

AI Cyber Risk and Credible Challenge Associate Director

DTCC

Tampa, FL • On-site

Full-time

Medical, Life, Retirement, PTO

Posted 4 days ago


Job description


Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We're committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
Pay and Benefits:
  • Competitive compensation, including base pay and annual incentive
  • Comprehensive health and life insurance and well-being benefits, based on location
  • Pension / Retirement benefits
  • Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
  • DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).

The Impact You will have in this role:
In this role, you will play a key part in executing the Credible Challenge assessment program within the Cyber Security Risk Office (CSRO), with a specialized focus on AI risk oversight across the AI lifecycle. Your work will directly contribute to strengthening DTCC's cyber risk governance by independently assessing First Line functions and evaluating the design and effectiveness of controls.
You will work closely with CSRO leadership, assessment leads, and First Line stakeholders to perform structured assessments, analyze evidence, identify risks and control gaps, and support clear, defensible assessment conclusions.
Your Primary Responsibilities:
  • Lead and execute Credible Challenge assessments of First Line AI risk practices across the AI lifecycle, including planning, scoping, fieldwork, and documentation
  • Perform walkthroughs, interviews, and evidence reviews to assess the design and operating effectiveness of controls governing AI use cases (including GenAI, agentic workflows, and embedded AI)
  • Evaluate alignment of First Line AI practices to the AI Policy, AI Governance Procedure, AI Acceptable Usage Policy, and applicable frameworks (NIST AI RMF, CRI Profile, EU AI Act)
  • Represent CSRO on the AI Working Groups, conducting independent AI use case reviews and applying the AI risk tiering framework to scale challenge intensity to data exposure, automation, and business impact
  • Identify, assess, and communicate material AI risks, control gaps, and thematic issues across cyber, model, data, privacy, and third-party risk domains
  • Engage with senior CSRO and First Line stakeholders to discuss assessment results and remediation of AI control deficiencies
  • Contribute to continuous improvement of the Credible Challenge methodology, standards, and templates as applied to the AI domain
  • Support AI policy awareness and acceptable-usage training, and assist with regulatory and audit responses on AI (e.g., Reg SCI, FRBNY/SEC inquiries)
  • Lead and contribute to special projects including program enhancements, resource coordination, and senior management presentations
  • Develop, communicate and ensure adherence to department risk policies, procedures and best practices
  • Stay abreast of industry and market events that impact cyber risk management processes
  • Foster an environment of regulatory awareness and ensure regulatory compliance
  • Conduct periodic assessments and surveys to gauge DTCC's AI risk and acceptable usage awareness level and recommend adjustments to the program

**NOTE: The Primary Responsibilities of this role are not limited to the details above. **
Qualifications:
  • Minimum of 8 years of related experience in cyber security, cyber operations, cyber risk, IT audit, or technology risk.
  • Cyber security risk background with working knowledge of AI/GenAI risk domains (prompt injection, model drift, hallucination, data leakage, shadow AI)
  • Bachelor's degree preferred or equivalent experience
  • Professional certifications such as CISSP, CISA, CRISC or equivalent are a plus
  • Knowledge of frameworks and regulations, including Cyber Risk Institute (CRI), National Institute of Standards and Technology (NIST) Cybersecurity Framework, Federal Financial Institutions Examination Council (FFIEC), and New York State Department of Financial Services (NYSDFS)

Talents Needed for Success:
  • Naturally curious and eager to learn, with a passion for understanding emerging technologies and complex risk topics.
  • Comfortable asking thoughtful questions, challenging assumptions, and investigating issues beyond the obvious.
  • Strong analytical thinker who thrives in dynamic environments and enjoys solving complex problems.
  • Self-starter who continuously looks for opportunities to improve processes, controls, and risk management practices.

The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
About Us
With over 50 years of experience, DTCC is the premier post-trade market infrastructure for the global financial services industry. From 20 locations around the world, DTCC, through its subsidiaries, automates, centralizes, and standardizes the processing of financial transactions, mitigating risk, increasing transparency, enhancing performance and driving efficiency for thousands of broker/dealers, custodian banks and asset managers. Industry owned and governed, the firm innovates purposefully, simplifying the complexities of clearing, settlement, asset servicing, transaction processing, trade reporting and data services across asset classes, bringing enhanced resilience and soundness to existing financial markets while advancing the digital asset ecosystem. In 2024, DTCC's subsidiaries processed securities transactions valued at U.S. $3.7 quadrillion and its depository subsidiary provided custody and asset servicing for securities issues from over 150 countries and territories valued at U.S. $99 trillion. DTCC's Global Trade Repository service, through locally registered, licensed, or approved trade repositories, processes more than 25 billion messages annually. To learn more, please visit us at www.dtcc.com or connect with us on LinkedIn, X, YouTube, Facebook and Instagram.
DTCC proudly supports Flexible Work Arrangements favoring openness and gives people freedom to do their jobs well, by encouraging diverse opinions and emphasizing teamwork. When you join our team, you'll have an opportunity to make meaningful contributions at a company that is recognized as a thought leader in both the financial services and technology industries. A DTCC career is more than a good way to earn a living. It's the chance to make a difference at a company that's truly one of a kind.
Learn more about Clearance and Settlement by clicking here.
About the Team
Our Risk Management teams work to protect the safety and soundness of our systems and are responsible for identifying, managing, measuring and mitigating a spectrum of key risk types including credit, market, liquidity, systemic, operational and technology in all existing and new products, activities, processes and systems.
The Technology Risk Management department is responsible for setting strategic direction in the areas of IT Risk and Information Security. They are accountable for maintaining DTCC's corporate security policies and control standards and acting as an operational arm for monitoring threat intelligence.