1

Cyber Risk Management Jobs in Kentucky (NOW HIRING)

This role, with guidance from the SVP, Enterprise Technology, provides enterprise leadership across cybersecurity governance, cyber risk management, security operations, operational technology (OT ...

Plans and facilitates regular operations meeting with Cyber Risk Defense Center (CRDC) teams ... Serves as a liaison between stage teams and upper management by identifying issues, improvement ...

Oversee third-party cyber risk management across vendors, contractors, cloud providers, EPC partners, and strategic service providers. * Operational Technology & Critical Infrastructure Security

Cyber Data Protection Manager

Louisville, KY · On-site

$106K - $144K/yr

If so, consider joining Deloitte & Touche LLP's growing Cyber Risk Digital Trust & Privacy practice ... Familiarity with change management, deployment and operational processes in large IT organizations

$90K/yr

The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ...

Design and implement automated control testing workflows in partnership with the Cyber Risk & Assurance Manager, including detailed automation playbooks for compliance and control testing * Own and ...

Build and operate the annual Cyber Supply Chain Risk Management (C-SCRM) program, including the strategy and implementation plan, vendor risk assessment framework and scoring rubric, and quarterly ...

... cyber risk profiles, estimating security risks, defining security controls, interacting with ... Ten (10) years of cybersecurity and/or cybersecurity risk management experience supporting medical ...

... cyber risk profiles, estimating security risks, defining security controls, interacting with ... Ten (10) years of cybersecurity and/or cybersecurity risk management experience supporting medical ...

$81K - $110K/yr

Our experts bring decades of experience in cyber risk consultancy, helping organizations across the world simplify and reduce the complexity of implementing, transforming, and managing their cyber ...

Cyber, Technology, or Risk Certifications (CISSP, CRISC, CISM, PMP, CRCM, CIPP, ABA Risk Mgmt Certification)****At this time, Capital One will not sponsor a new applicant for employment authorization ...

$95K - $165K/yr

Morgan Stanley is seeking a Risk professional to join the Cyber, Technology and Information ... It defines the overall framework and standards for effective management of CTIS risks, including ...

$73K - $95K/yr

Determine system vulnerabilities and residual risk based on analysis of technical artifacts ... Support Operations Manager/Task Lead with program execution, deliver program deliverables, and ...

... auto, umbrella, cyber, and management liability insurance programs. * Coordinate insurance ... Risk Analysis and Loss Prevention * Analyze loss trends and identify areas for risk reduction ...

... Audit Management (GRAM) team based at our Global Headquarters in Hunt Valley, Maryland. The ... This individual serves as the strategic leader in advancing global technology and cyber risk ...

Participate in program protection and risk management activities to ensure cybersecurity ... cyber operations, vulnerability analysis, reverse engineering, network security, embedded systems ...

You have excellent judgment, communication, and stakeholder-management skills * You have experience with vendor oversight, technology risk, or cyber testing programs. * You have held a FINRA Series ...

Showing results 41-60

Cyber Risk Management information

See Kentucky salary details

$12

$26

$64

How much do cyber risk management jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for cyber risk management in Kentucky is $26.35, according to ZipRecruiter salary data. Most workers in this role earn between $16.92 and $33.61 per hour, depending on experience, location, and employer.

What is cyber risk management?

A Cyber Risk Management job involves identifying, assessing, and mitigating cybersecurity risks that could impact an organization. Professionals in this field develop risk management frameworks, implement security controls, and ensure compliance with industry regulations. They work closely with IT and business teams to minimize cyber threats, such as data breaches and ransomware attacks. Their goal is to protect sensitive information and maintain business continuity.

What are some common challenges faced in a cyber risk management role, and how are they typically addressed?

Professionals in Cyber Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, ensuring compliance with complex regulations, and balancing security needs with business objectives. Addressing these issues requires continuous learning, leveraging up-to-date threat intelligence, and collaborating closely with IT, legal, and management teams to develop effective risk mitigation strategies. Many organizations encourage ongoing training and participation in industry events to stay current, while fostering a culture of open communication to quickly identify and address vulnerabilities. Embracing a proactive and adaptable approach ensures that cyber risks are managed effectively while supporting the organization’s goals.

What are the key skills and qualifications needed to thrive in cyber risk management, and why are they important?

To thrive in Cyber Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance, often supported by a degree in cybersecurity, information technology, or a related field. Familiarity with tools such as risk management software, vulnerability assessment platforms, and certifications like CISSP, CISM, or CRISC is highly valued. Excellent analytical thinking, communication, and problem-solving skills help professionals effectively advise stakeholders and coordinate incident response efforts. These skills are crucial for identifying, evaluating, and mitigating cyber risks to safeguard organizational assets and ensure business continuity.

How much does a cyber risk management professional make?

Cyber risk management professionals typically earn a median annual salary ranging from $80,000 to $130,000, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity frameworks and risk assessment tools can earn higher salaries, often exceeding $150,000 annually.

What does a cyber risk management do?

A cyber risk management professional identifies, assesses, and prioritizes cybersecurity threats to an organization. They develop strategies and implement controls to mitigate risks, often using frameworks like NIST or ISO, and may hold certifications such as CISSP or CISM. Their work helps protect sensitive data and ensure business continuity in a constantly evolving threat landscape.

What are popular job titles related to Cyber Risk Management jobs in Kentucky?

For Cyber Risk Management jobs in Kentucky, the most frequently searched job titles are:

What job categories do people searching Cyber Risk Management jobs in Kentucky look for?

The top searched job categories for Cyber Risk Management jobs in Kentucky are:

Infographic showing various Cyber Risk Management job openings in Kentucky as of August 2026, with employment types broken down into 1% As Needed, 80% Full Time, 10% Part Time, 7% Temporary, and 2% Contract. Highlights an 82% Physical, 3% Hybrid, and 15% Remote job distribution, with an average salary of $54,804 per year, or $26.3 per hour.

Senior Director, Information and Cybersecurity (Northern)

Eastern, KY • On-site

Full-time

This job post has expired 1 day ago. Applications are no longer accepted.


Key responsibilities

  • Support the establishment, operation, and improvement of cybersecurity, technology risk, operational resilience, AI governance, and critical infrastructure protection capabilities.

  • Lead enterprise cybersecurity activities including threat detection, vulnerability management, incident response, and cyber defense.

  • Partner with various teams to ensure cybersecurity, resilience, and technology risk management are integrated into enterprise operations and strategic decisions.


Job description

The Senior Director, Information and Cybersecurity is accountable for supporting SVP, Enterprise Technology in establishing, operating, and continuously improving the cybersecurity, technology risk, operational resilience, AI governance, and critical infrastructure protection capabilities that enable Pattern Energy to operate safely, reliably, and securely.

This role, with guidance from the SVP, Enterprise Technology, provides enterprise leadership across cybersecurity governance, cyber risk management, security operations, operational technology (OT) security, cyber resilience, identity and access governance, third-party risk management, AI security, and regulatory compliance activities. The role is responsible for protecting Pattern’s corporate, cloud, operational technology, generation, storage, and transmission environments while supporting business growth, operational reliability, and technology modernization.

The Senior Director, Information and Cybersecurity partners closely with Enterprise Technology, Power Operations, Engineering, EPC, Legal, Compliance, Internal Audit, Enterprise Excellence, and executive leadership teams to ensure cybersecurity, resilience, and technology risk management capabilities are embedded into enterprise operations and strategic decision-making.

Success in the role requires balancing operational reliability, safety, regulatory compliance, cybersecurity risk reduction, enterprise scalability, and disciplined execution while enabling innovation and reducing unnecessary complexity.

The Senior Director, Information and Cybersecurity is also accountable for ensuring the resilience, recoverability, and cybersecurity readiness of enterprise and operational technology environments supporting Pattern’s generation, storage, and transmission assets. This includes executive accountability for cybersecurity governance supporting NERC CIP obligations, cyber crisis management, operational resilience, and AI security governance.

This role helps drive enterprise prioritization, governance, and operational execution discipline in partnership with business leadership, Enterprise Excellence, and other enterprise stakeholders. The role is expected to build durable internal cybersecurity capability, improve cyber governance maturity, and reduce organizational dependency on fragmented processes and external implementation coordination.

The role serves as an advisor to the CEO, COO, Executive Leadership Team, and Board on cybersecurity, technology risk, operational resilience, AI governance, and critical infrastructure protection.

Key Accountabilities Cybersecurity Strategy, Risk & Governance
  • Develop and execute a multi-year cybersecurity, resilience, technology risk, and AI governance strategy aligned with enterprise objectives, operational priorities, and growth plans.
  • Establish enterprise cybersecurity governance, risk management, and reporting processes that improve accountability, transparency, and decision quality.
  • Ensure cybersecurity, resilience, AI, and technology risks are appropriately incorporated into enterprise planning, investment decisions, acquisitions, integrations, and strategic initiatives.
  • Develop and manage cybersecurity operating and capital budgets, ensuring investments align with enterprise priorities, risk reduction objectives, resilience requirements, and regulatory obligations.
  • Develop cybersecurity investment plans and assess initiatives based on risk reduction, operational resilience, business value, and long-term sustainability.
  • With support from the SVP, Enterprise Technology, provide regular reporting to executive leadership and the Board regarding cyber risk posture, material incidents, resilience capabilities, emerging threats, regulatory developments, NERC CIP readiness, and strategic priorities.
  • Conduct periodic cyber maturity assessments, benchmarking exercises, and independent reviews to support continuous improvement and strategic planning.
  • Establish enterprise security awareness, education, executive cyber literacy, and AI awareness programs that promote a culture of security, resilience, and responsible technology use across the organization.
Cybersecurity Operations & Resilience
  • Lead enterprise cybersecurity capabilities across threat detection, threat intelligence, vulnerability management, identity security, cloud security, incident response, cyber defense, and attack surface management.
  • Ensure effective security governance and protection capabilities across enterprise infrastructure, cloud platforms, operational technology environments, and critical business systems.
  • Ensure effective capabilities exist to identify, assess, respond to, and recover from cyber threats affecting enterprise and operational technology environments.
  • Establish cyber crisis management, cyber recovery, business continuity, and disaster recovery capabilities appropriate for a critical infrastructure operating environment.
  • Support incident response, disaster recovery, operational resilience, and technology risk management activities across the enterprise.
  • Leverage automation and AI-enabled capabilities to improve cybersecurity effectiveness, operational efficiency, threat detection, investigation, response, and resilience outcomes.
  • Ensure third-party cyber risk management capabilities appropriately address vendors, contractors, cloud providers, operational technology suppliers, EPC partners, and strategic service providers.
Operational Technology & Critical Infrastructure Security
  • Lead cybersecurity strategy and governance supporting operational technology environments associated with generation, storage, transmission, SCADA, plant communications, industrial control systems, and operational support systems.
  • Establish cybersecurity and resilience standards supporting operational technology architecture, remote access, network segmentation, monitoring, asset visibility, vendor connectivity, and secure operations.
  • Support operational readiness, secure operations, recoverability, and resilience across critical infrastructure environments.
  • Coordinate with operational stakeholders to ensure technology environments meet reliability, safety, resilience, and compliance expectations.
  • Support secure integration of new facilities, operational technologies, acquisitions, and strategic growth initiatives.
  • Ensure cybersecurity capabilities evolve in alignment with emerging threats affecting operational technology and critical infrastructure environments.
Regulatory Compliance & NERC CIP
  • Ensure cybersecurity operations align with applicable regulatory, cybersecurity, operational risk management, and NERC CIP requirements.
  • Serve as the executive sponsor for NERC CIP cybersecurity governance, audit readiness, compliance activities, and remediation programs.
  • Oversee compliance reporting, evidence management, remediation tracking, control validation, and regulatory readiness activities.
  • Partner with Legal, Compliance, Internal Audit, Enterprise Technology, and operational stakeholders to maintain effective governance and regulatory alignment.
  • Monitor evolving regulatory requirements and industry standards and ensure timely adaptation of policies, controls, and operating procedures.
  • Establish metrics and reporting that provide visibility into compliance posture, control effectiveness, audit readiness, and remediation progress.
AI Security & Governance
  • Establish enterprise governance, risk management, and security practices supporting responsible adoption of AI technologies.
  • Ensure AI systems, AI agents, autonomous workflows, and third-party AI services are appropriately inventoried, governed, monitored, and secured.
  • Establish governance and security requirements for AI systems, AI agents, and autonomous workflows used across enterprise and operational environments, ensuring appropriate human oversight, accountability, and risk management.
  • Protect AI-enabled business processes, models, training data, prompts, retrieval data, and outputs from unauthorized access, misuse, manipulation, or disclosure.
  • Support adoption of AI technologies while maintaining appropriate cybersecurity, privacy, operational, and regulatory safeguards.
  • Drive adoption of AI-enabled cybersecurity capabilities that improve operational efficiency, threat detection, vulnerability management, response, and resilience outcomes.
Enterprise Architecture & Technology Modernization
  • Partner with Enterprise Technology leadership to ensure cybersecurity, resilience, AI governance, and regulatory requirements are embedded into enterprise architecture, cloud transformation, operational technology initiatives, and digital modernization programs.
  • Support scalable technology architectures that improve resilience, security, maintainability, and operational effectiveness.
  • Reduce fragmentation, unnecessary complexity, and inconsistency of cybersecurity controls across the enterprise technology landscape.
  • Support enterprise technology modernization, integration activities, and strategic operational initiatives.
  • Ensure cybersecurity requirements are integrated into technology acquisition, development, deployment, and operational support processes.
Third-Party Risk Management
  • Establish and govern a risk-based third-party cybersecurity and supply chain risk management program.
  • Ensure cybersecurity risks are appropriately assessed and managed across vendors, contractors, cloud provide