1

Cyber Risk Assessment Jobs (NOW HIRING)

Cyber Risk Analyst

Cincinnati, OH ยท On-site +1

$35/hr

Document job aids and support stakeholder communications. Assist in updating and maintaining cyber risk assessments and tracking forms Prepare draft meeting materials for review Maintain dashboards ...

This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk identification. The ideal candidate has deep ...

Perform detailed analysis and a cyber risk assessment of Cloud Service Providers (CSPs). * Engage with vendors to review controls, certifications, and risks in support of the associated business need ...

Perform detailed analysis and a cyber risk assessment of Cloud Service Providers (CSPs). * Engage with vendors to review controls, certifications, and risks in support of the associated business need ...

Perform detailed analysis and a cyber risk assessment of Cloud Service Providers (CSPs). * Engage with vendors to review controls, certifications, and risks in support of the associated business need ...

This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk identification. The ideal candidate has deep ...

This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk identification. The ideal candidate has deep ...

Perform detailed analysis and a cyber risk assessment of Cloud Service Providers (CSPs). * Engage with vendors to review controls, certifications, and risks in support of the associated business need ...

Apply established cybersecurity risk assessment methodologies, frameworks, and reference materials, including FAIR and other relevant cyber risk analysis approaches. * Support practical and well ...

Apply established cybersecurity risk assessment methodologies, frameworks, and reference materials, including FAIR and other relevant cyber risk analysis approaches. * Support practical and well ...

Apply established cybersecurity risk assessment methodologies, frameworks, and reference materials, including FAIR and other relevant cyber risk analysis approaches. * Support practical and well ...

Apply established cybersecurity risk assessment methodologies, frameworks, and reference materials, including FAIR and other relevant cyber risk analysis approaches. * Support practical and well ...

Senior Cyber Risk Analyst

Chicago, IL ยท Hybrid

$110K - $130K/yr

As a Senior Cyber Risk Analyst at Tempus AI, you will be the driving force behind our Cyber Risk ... Apply standardized risk assessment methodologies to accurately calculate risk impact/severity ...

next page

Showing results 1-20

Cyber Risk Assessment information

What are the key skills and qualifications needed to thrive as a Cyber Risk Assessor, and why are they important?

To thrive as a Cyber Risk Assessor, you need a strong understanding of cybersecurity principles, risk management frameworks, and relevant regulations, often backed by a degree in information security or related certifications like CISSP or CISA. Familiarity with security assessment tools, vulnerability scanners, and risk analysis platforms is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills for accurately identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets and ensuring compliance in an evolving threat landscape.

What are some common challenges faced by professionals in Cyber Risk Assessment, and how can they be addressed?

Professionals in Cyber Risk Assessment often encounter challenges such as rapidly evolving threat landscapes, keeping up with regulatory changes, and ensuring clear communication of technical risks to non-technical stakeholders. To address these, staying current with industry trends through continuous learning, leveraging robust risk assessment frameworks, and developing strong communication skills are essential. Additionally, collaborating closely with IT, compliance, and business units helps ensure comprehensive and effective risk management.

What is a cyber risk assessment?

A cyber risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities in an organization's information systems. It helps organizations understand the potential impact of cyber threats and determine the likelihood of such events occurring. By conducting a cyber risk assessment, businesses can implement appropriate security controls and strategies to mitigate risks, comply with regulatory requirements, and protect sensitive data from cyberattacks. Regular assessments are essential to adapt to evolving threats and maintain a strong cybersecurity posture.

Can you make $500,000 a year in cyber security?

Cyber Risk Assessment professionals with extensive experience, advanced certifications, and specialized skills can potentially earn salaries approaching or exceeding $500,000 annually, especially in senior or executive roles. Achieving this level often requires a combination of technical expertise, leadership responsibilities, and working in high-demand industries or organizations. However, such salaries are not typical for entry- or mid-level positions in cybersecurity.

What is the difference between Cyber Risk Assessment vs Cyber Security Analyst?

AspectCyber Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating cybersecurity risks and vulnerabilitiesMonitoring, detecting, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk management teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams
ResponsibilitiesRisk analysis, vulnerability assessments, complianceThreat detection, incident response, security monitoring

While both roles involve cybersecurity, Cyber Risk Assessments focus on evaluating potential risks and vulnerabilities to inform security strategies, whereas Cyber Security Analysts actively monitor and respond to ongoing security threats. Understanding these differences helps organizations assign the right roles for comprehensive cybersecurity management.

More about Cyber Risk Assessment jobs
What cities are hiring for Cyber Risk Assessment jobs? Cities with the most Cyber Risk Assessment job openings:
What states have the most Cyber Risk Assessment jobs? States with the most job openings for Cyber Risk Assessment jobs include:
Infographic showing various Cyber Risk Assessment job openings in the United States as of May 2026, with employment types broken down into 82% Full Time, 16% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Principal - Third Party Cyber Risk Assessment

Jj

Raritan, NJ โ€ข On-site, Remote

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago


Job description

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

Raritan, New Jersey, United States of America

Job Description:

Johnson & Johnson is recruiting for a Principal - Third Party Cyber Risk Assessment to join the Information Security & Risk Management (ISRM) Risk Assessment Center of Excellence (CoE). This role is based in the United States with the Raritan, NJ location preferred, but also available internally to our ISRM Service Centers in Sao Jose dos Campos, Sao Paulo, Brasil and Warsaw, Poland.

Please note that this role is available across multiple countries and may be posted under different requisition numbers to comply with local requirements. While you are welcome to apply to any or all of the postings, we recommend focusing on the specific country(s) that align with your preferred location(s): Raritan NJ, Sao Jose dos Campos, Sao Paulo, Brasil and Warsaw, Poland.

Sao Jose dos Campos, Brazil- Requisition Number: R-073330

Warsaw, Poland- Requisition Number: R-073331

Remember, whether you apply to one or all of these requisition numbers, your applications will be considered as a single submission.

This role serves as a senior technical authority and thought leader for thirdparty cyber risk assessments across Johnson & Johnson's global ecosystem of vendors, SaaS providers, and strategic partners.

Are you ready to use your technical knowledge to change the trajectory of health for humanity? We have a position for you!

Caring for the world, one person at a time inspired and united the people of Johnson & Johnson for over 130 years. We embrace research and science -- bringing innovative ideas, products, and services to advance the health and well-being of people.

At Johnson & Johnson, we believe good health is the foundation of vibrant lives, thriving communities and forward progress. That's why for more than 130 years, we have aimed to keep people well at every age and every stage of life. Today, as the world's largest and most broadly-based healthcare company, we are committed to using our reach and size for good. We strive to improve access and affordability, create healthier communities, and put a healthy mind, body and environment within reach of everyone, everywhere. Every day, our more than 130,000 employees across the world are blending heart, science and ingenuity to profoundly change the trajectory of health for humanity.

Thriving on a diverse company culture, celebrating the uniqueness of our employees, and committed to inclusion. Proud to be an equal opportunity employer!

As an integral member of the ISRM Risk Assessment Center of Excellence team, you will identify and assess cyber risks within the Third-Party Risk Assessment (TPRA) service. In this role, you will work with a diverse, global team of skilled cyber security professionals.

Key Responsibilities:

  • Perform and lead third-party risk assessments, risk rankings, and collaboration on remediation strategies as needed.
  • Perform deep technical reviews of thirdparty security controls, evidence artifacts, attestations, and independent reports to assess control design, implementation, and operating effectiveness.
  • Evaluate complex risk scenarios involving sensitive data types, regulatory obligations, complex architectures, and crossborder data flows.
  • Identify, document, and riskrate thirdparty cyber issues, ensuring consistent severity determination and alignment to ISRM standards.
  • Drive automation and process improvements as identified and through relevant projects and/or operations.
  • Communicate cybersecurity third-party risk assessment results to senior leaders and provide input on remediation plans.
  • Enhance third-party cyber risk assessment processes by defining and implementing process improvements.
  • Offer consulting support to the larger cybersecurity team on third-party risk assessment understanding and remediation.
  • Lead and mentor junior members of the team, ensure ongoing learning, and support special projects as needed.

Qualifications

Education:

  • A bachelor's degree in Computer Science, Engineering or Information Security/Cybersecurity or equivalent degree is required.
  • Security certifications such as CISSP, CCSP, CISA, CRISC etc. are preferred.
  • An advanced degree is preferred.

Experience and Skills:

Required:

  • 5+ years of direct third-party cybersecurity risk assessment experience, including application of third-party risk assessment concepts and internal controls.
  • 5+ years using ServiceNow GRC tool to support security risk objectives.
  • Proficiency in conducting and leading third-party risk assessments, including data classification, risk scoring, and mitigation planning.
  • Ability to translate technical findings into business impact for key partners.
  • Strong analytical and problem-solving skills.
  • Strong interpersonal skills to build and maintain relationships with internal partners.

Preferred:

  • Foundational knowledge of regulatory requirements (e.g., SOX404, Privacy, HIPAA, GxP, cyber regulations).
  • Experience assessing third-party risk in a large, dynamic, multinational organization.
  • Experience in identifying key security risks, security controls, and providing consulting services to customers throughout the third-party vendor lifecycle.
  • Experience with security standards and control frameworks (e.g. FAIR, HITRUST, ISO27001, NIST, SOC 2, etc.).
  • Demonstrable record of effectively collaborating with virtual, global teams, including diverse groups of people with varied backgrounds and cultural experiences.

#LI-Hybrid

#JNJTECH

#LI-RW1

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants' needs. If you are an individual with a disability and would like to request an accommodation, please contact us via https://www.jnj.com/contact-us/careers or contact AskGS to be directed to your accommodation resource.

Required Skills:

Preferred Skills:

Business Process Design, Crisis Management, Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Organizing, Presentation Design, Process Optimization, Root Cause Analysis (RCA), Security Architecture Design, Security Policies, Technical Credibility, Vulnerability Management

The anticipated base pay range for this position is :

The anticipated base pay range for this position is: $102,000- $177,100

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees and/or eligible dependents are eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance. Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, Employees are eligible for the following time off benefits: Vacation -120 hours per calendar year Sick time - 40 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year Holiday pay, including Floating Holidays -13 days per calendar year Work, Personal and Family Time - up to 40 hours per calendar year Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child Condolence Leave - 30 days for an immediate family member: 5 days for an extended family member Caregiver Leave - 10 days Volunteer Leave - 4 days Military Spouse Time-Off - 80 hours Additional information can be found through the link below. https://www.careers.jnj.com/employee-benefits