1

Cyber Risk Assessment Jobs in Houston, MS (NOW HIRING)

Cyber Risk Assessment information

What is a cyber risk assessment?

A cyber risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities in an organization's information systems. It helps organizations understand the potential impact of cyber threats and determine the likelihood of such events occurring. By conducting a cyber risk assessment, businesses can implement appropriate security controls and strategies to mitigate risks, comply with regulatory requirements, and protect sensitive data from cyberattacks. Regular assessments are essential to adapt to evolving threats and maintain a strong cybersecurity posture.

What are the key skills and qualifications needed to thrive as a cyber risk assessor?

To thrive as a Cyber Risk Assessor, you need a strong understanding of cybersecurity principles, risk management frameworks, and relevant regulations, often backed by a degree in information security or related certifications like CISSP or CISA. Familiarity with security assessment tools, vulnerability scanners, and risk analysis platforms is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills for accurately identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets and ensuring compliance in an evolving threat landscape.

What are some common challenges faced by professionals in cyber risk assessment, and how can they be addressed?

Professionals in Cyber Risk Assessment often encounter challenges such as rapidly evolving threat landscapes, keeping up with regulatory changes, and ensuring clear communication of technical risks to non-technical stakeholders. To address these, staying current with industry trends through continuous learning, leveraging robust risk assessment frameworks, and developing strong communication skills are essential. Additionally, collaborating closely with IT, compliance, and business units helps ensure comprehensive and effective risk management.

What is the difference between Cyber Risk Assessment vs Cyber Security Analyst?

AspectCyber Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating cybersecurity risks and vulnerabilitiesMonitoring, detecting, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk management teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams
ResponsibilitiesRisk analysis, vulnerability assessments, complianceThreat detection, incident response, security monitoring

While both roles involve cybersecurity, Cyber Risk Assessments focus on evaluating potential risks and vulnerabilities to inform security strategies, whereas Cyber Security Analysts actively monitor and respond to ongoing security threats. Understanding these differences helps organizations assign the right roles for comprehensive cybersecurity management.

Infographic showing various Cyber Risk Assessment job openings in Houston, MS as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 15% Part Time, 2% Contract, and 1% Nights. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Manager of Cybersecurity Strategy and Governance

Huntington

Tupelo, MS • On-site

$105K - $142K/yr

Full-time

Medical, Life, Retirement, PTO

Posted 6 days ago


Job description

Description

This position is an onsite position and available to be filled at any Huntington Corporate office location:

  • Birmingham, AL
  • Tupelo, MS
  • Atlanta, GA
  • Houston, Tx
  • Dallas/Houston, TX
  • Minnetonka, MN
  • Detroit, MI

Job Summary:
The Manager of Cybersecurity Strategy and Governance is responsible for supporting the execution of strategic cybersecurity initiatives, maintaining governance processes, and collaborating with Cybersecurity teams to identify improvements to enhance the organization's overall security posture. Reporting to the Director of Cybersecurity Strategy, Innovation, and Governance (DCSIG), this role acts as a key leader responsible for translating strategic direction into actionable workstreams, partnering across cybersecurity and business units to promote governance discipline, control maturity, and innovation enablement.

The ideal candidate is detail-oriented, execution-focused, and capable of managing cross-functional efforts to ensure successful delivery of cybersecurity initiatives, reporting, and process enhancements.

Key Responsibilities:

Strategic Program Execution

  • Support the collaborative design and execution of a comprehensive cybersecurity strategy aligned with business objectives, risk management goals, regulatory and industry guidance, and long-term growth.
  • Operationalize components of the cybersecurity Strategy, Governance, and Innovation roadmap in close partnership with the DCSIG and Cybersecurity Leadership team.
  • Track progress against defined maturity goals and report key milestones, risks, and dependencies to leadership.
  • Continuously assess and refine the strategy to stay ahead of emerging threats, technologic advancements, banking trends, business direction, and evolving regulatory requirements.

Cybersecurity Governance & Policy Management

  • Support the lifecycle of cybersecurity policies and standards, including drafting, reviews, socialization, and periodic updates, in alignment with applicable regulations and industry standards (e.g., FFIEC, NIST, GLBA, SOX, PCI, DSS, CRI, ISO 27001).
  • Support the implementation of governance processes to ensure alignment with regulatory requirements and internal risk frameworks.
  • Coordinate inputs to governance forums, including meeting materials, charters, and action item follow-ups.

Risk & Compliance Support

  • Maintain and update the cybersecurity risk and control matrix (RCM) to reflect current-state control environment and ownership.
  • Partner with internal stakeholders to collect and validate cybersecurity-related inputs into enterprise risk assessments, RCSAs, and self-assessments.
  • Track and support closure of cybersecurity audit issues, regulatory findings, and control remediation items.

Continuous Improvement

  • Collaborate with cyber operations, engineering, and architecture teams to pilot and integrate innovative capabilities.
  • Participate in process improvement efforts, including current state mapping, metric tracking, and performance analysis.

Cybersecurity Metrics & Reporting

  • Develop, maintain, and operationalize cybersecurity metrics and dashboards to support executive and risk committee reporting.
  • Ensure data accuracy and alignment of metrics with business outcomes and program maturity goals.
  • Help automate and streamline reporting processes, reducing manual data collection efforts.

Stakeholder Engagement & Coordination

  • Coordinate working groups, task forces, and project teams related to cybersecurity governance and strategy implementation.
  • Facilitate collaboration across Legal, Compliance, Risk, and Technology functions to ensure cohesive program execution.
  • Serve as a resource for teams seeking clarification or support related to cybersecurity policies, controls, or governance processes.

Basic Qualifications:

  • Bachelor's degree in Cybersecurity, Risk Management, Information Systems, or a related field or 4+ additional years of equivalent experience.
  • 5+ years of experience in cybersecurity, risk, compliance, or governance functions.
  • 3+ years' experience utilizing cybersecurity frameworks (e.g., NIST CSF, FFIEC CAT, ISO 27001, CRI).
  • 3+ years' experience with regulatory and risk management practices, particularly in financial services or regulated industries.

Preferred Qualifications:

  • Proven experience managing cross-functional projects and delivering results in matrixed environments.
  • Strong communication and interpersonal skills, with the ability to translate technical concepts into business terms.
  • Proficiency in GRC platforms, data visualization tools, and metrics reporting.
  • Detail-oriented with strong organizational and execution skills.
  • Ability to thrive in a fast-paced environment with shifting priorities and multiple workstreams.


Exempt Status: (Yes= not eligible for overtime pay) (No= eligible for overtime pay)

Yes

Workplace Type:

Office

Our Approach to Office Workplace Type

Certain positions outside our branch network may be eligible for a flexible work arrangement. We're combining the best of both worlds: in-office and work from home. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. Remote roles will also have the opportunity to come together in our offices for moments that matter. Specific work arrangements will be provided by the hiring team.

Compensation Range:

$102,000 - $208,000 Annual Salary

The compensation range represents the anticipated low and high end of the base compensation range for this position. Actual compensation will vary based on various factors including but not limited to location, experience, and education. Colleagues in this position are also eligible to participate in an applicable incentive compensation plan. In addition, Huntington provides a variety of benefits to colleagues, including health insurance coverage, wellness program, life and disability insurance, retirement savings plan, paid leave programs, paid holidays and paid time off (PTO).


Huntington is an Equal Opportunity Employer.


Tobacco-Free Hiring Practice: Visit Huntington's Career Web Site for more details.


Note to Agency Recruiters: Huntington will not pay a fee for any placement resulting from the receipt of an unsolicited resume. All unsolicited resumes sent to any Huntington colleagues, directly or indirectly, will be considered Huntington property. Recruiting agencies must have a valid, written and fully executed Master Service Agreement and Statement of Work for consideration.