Reporting directly to the Chief Information Officer, the Deputy CISO will be responsible for all cybersecurity operations, cyber risk management, security architecture, incident response, governance ...
Reporting directly to the Chief Information Officer, the Deputy CISO will be responsible for all cybersecurity operations, cyber risk management, security architecture, incident response, governance ...
AnaVation is seeking a highly experienced Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM) to provide senior-level technical, analytical, and advisory support to the U.S. Army ...
AnaVation is seeking a highly experienced Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM) to provide senior-level technical, analytical, and advisory support to the U.S. Army ...
AnaVation is seeking a highly experienced Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM) to provide senior-level technical, analytical, and advisory support to the U.S. Army ...
Quick apply
AnaVation is seeking a highly experienced Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM) to provide senior-level technical, analytical, and advisory support to the U.S. Army ...
Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM)
Fort George G Meade, MD · On-site
$205K - $235K/yr
AnaVation is seeking a highly experienced Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM) to provide senior-level technical, analytical, and advisory support to the U.S. Army ...
Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM)
Fort George G Meade, MD · On-site
$205K - $235K/yr
AnaVation is seeking a highly experienced Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM) to provide senior-level technical, analytical, and advisory support to the U.S. Army ...
Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM)
Fort George G Meade, MD · On-site
$205K - $235K/yr
The Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM) serves as the senior technical lead for integrating cybersecurity, supply chain risk management, and acquisition best ...
Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM)
Fort George G Meade, MD · On-site
$205K - $235K/yr
The Cybersecurity Architect - Cyber Supply Chain Risk Management (C-SCRM) serves as the senior technical lead for integrating cybersecurity, supply chain risk management, and acquisition best ...
COLSA is seeking an Information Security Analyst (Advanced) to lead assigned cybersecurity, Information Assurance (IA), Risk Management Framework (RMF), vulnerability assessment, and cyber risk ...
COLSA is seeking an Information Security Analyst (Advanced) to lead assigned cybersecurity, Information Assurance (IA), Risk Management Framework (RMF), vulnerability assessment, and cyber risk ...
Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
COLSA is seeking an Information Security Analyst (Advanced) to lead assigned cybersecurity, Information Assurance (IA), Risk Management Framework (RMF), vulnerability assessment, and cyber risk ...
COLSA is seeking an Information Security Analyst (Advanced) to lead assigned cybersecurity, Information Assurance (IA), Risk Management Framework (RMF), vulnerability assessment, and cyber risk ...
... management tools; and collaboration, voice, and video tools in a secure, flexible, distributed ... Establishes a framework by which cyber risk can be measured and quantified in the marketplace.
Quick apply
... management tools; and collaboration, voice, and video tools in a secure, flexible, distributed ... Establishes a framework by which cyber risk can be measured and quantified in the marketplace.
COLSA is seeking an Information Security Analyst (Advanced) to lead assigned cybersecurity, Information Assurance (IA), Risk Management Framework (RMF), vulnerability assessment, and cyber risk ...
COLSA is seeking an Information Security Analyst (Advanced) to lead assigned cybersecurity, Information Assurance (IA), Risk Management Framework (RMF), vulnerability assessment, and cyber risk ...
Cyber Data Protection Manager
Baltimore, MD · On-site
$110K - $149K/yr
If so, consider joining Deloitte & Touche LLP's growing Cyber Risk Digital Trust & Privacy practice ... Familiarity with change management, deployment and operational processes in large IT organizations
Cyber Data Protection Manager
Baltimore, MD · On-site
$110K - $149K/yr
If so, consider joining Deloitte & Touche LLP's growing Cyber Risk Digital Trust & Privacy practice ... Familiarity with change management, deployment and operational processes in large IT organizations
COLSA is seeking an Information Security Analyst (Advanced) to lead assigned cybersecurity, Information Assurance (IA), Risk Management Framework (RMF), vulnerability assessment, and cyber risk ...
COLSA is seeking an Information Security Analyst (Advanced) to lead assigned cybersecurity, Information Assurance (IA), Risk Management Framework (RMF), vulnerability assessment, and cyber risk ...
Information Security Analyst (Advanced)
Patuxent River, MD · On-site
$130K - $170K/yr
COLSA is seeking an Information Security Analyst (Advanced) to lead assigned cybersecurity, Information Assurance (IA), Risk Management Framework (RMF), vulnerability assessment, and cyber risk ...
Information Security Analyst (Advanced)
Patuxent River, MD · On-site
$130K - $170K/yr
COLSA is seeking an Information Security Analyst (Advanced) to lead assigned cybersecurity, Information Assurance (IA), Risk Management Framework (RMF), vulnerability assessment, and cyber risk ...
IT and Cyber Risk Auditor Principal
La Plata, MD · On-site
$119K - $161K/yr
Cyber and IT Risk Management Job Qualifications: Skills: Cyber Risks, Cybersecurity Controls, NIST 800-53 Certifications: None Experience: 8 + years of related experience US Citizenship Required: Yes ...
IT and Cyber Risk Auditor Principal
La Plata, MD · On-site
$119K - $161K/yr
Cyber and IT Risk Management Job Qualifications: Skills: Cyber Risks, Cybersecurity Controls, NIST 800-53 Certifications: None Experience: 8 + years of related experience US Citizenship Required: Yes ...
Customer Success Team Lead Jobs
Lexington Park, MD · On-site
$150K - $180K/yr
This leader is laser-focused on customer success-ensuring every customer fully realizes the operational, security, and strategic value of the Naval Enterprise Cyber Supply Chain Risk Management (C ...
Customer Success Team Lead Jobs
Lexington Park, MD · On-site
$150K - $180K/yr
This leader is laser-focused on customer success-ensuring every customer fully realizes the operational, security, and strategic value of the Naval Enterprise Cyber Supply Chain Risk Management (C ...
The Senior Director Identity, Cybersecurity Governance & Risk is a senior cybersecurity leader responsible for enterprise Identity and Access Management (IAM), cybersecurity governance, cyber risk ...
The Senior Director Identity, Cybersecurity Governance & Risk is a senior cybersecurity leader responsible for enterprise Identity and Access Management (IAM), cybersecurity governance, cyber risk ...
Cybersecurity Governance Manager
Baltimore, MD · On-site
$110K - $149K/yr
Partner and coordinate with the enterprise risk management team, internal audit, and other functions within the cyber risk team to ensure appropriate oversight and management of cyber risks and ...
Cybersecurity Governance Manager
Baltimore, MD · On-site
$110K - $149K/yr
Partner and coordinate with the enterprise risk management team, internal audit, and other functions within the cyber risk team to ensure appropriate oversight and management of cyber risks and ...
The Senior Director Identity, Cybersecurity Governance & Risk is a senior cybersecurity leader responsible for enterprise Identity and Access Management (IAM), cybersecurity governance, cyber risk ...
The Senior Director Identity, Cybersecurity Governance & Risk is a senior cybersecurity leader responsible for enterprise Identity and Access Management (IAM), cybersecurity governance, cyber risk ...
... cyber risk management, third-party risk management, compliance, and security performance measurement. This role owns strategy, implementation, operations, and continuous improvement of IAM ...
... cyber risk management, third-party risk management, compliance, and security performance measurement. This role owns strategy, implementation, operations, and continuous improvement of IAM ...
... Conduct continuous cyber risk assessments. - Deploy privacy-preserving computation methods ... management processes.
... Conduct continuous cyber risk assessments. - Deploy privacy-preserving computation methods ... management processes.
Cyber Risk Management information
See Maryland salary details
$18.72 is the 25th percentile. Wages below this are outliers.
$14 - $19.26
28% of jobs
The median wage is $22.40 / hr.
$19.26 - $24.52
37% of jobs
$24.52 - $29.78
6% of jobs
$33.07 is the 75th percentile. Wages above this are outliers.
$29.78 - $35.04
6% of jobs
$35.04 - $40.30
12% of jobs
$40.30 - $45.56
0% of jobs
$45.56 - $50.82
0% of jobs
$50.82 - $56.08
8% of jobs
$56.08 - $61.34
0% of jobs
$61.34 - $66.60
0% of jobs
$66.60 - $71.86
2% of jobs
$13
$29
$71
How much do cyber risk management jobs pay per hour?
What is cyber risk management?
A Cyber Risk Management job involves identifying, assessing, and mitigating cybersecurity risks that could impact an organization. Professionals in this field develop risk management frameworks, implement security controls, and ensure compliance with industry regulations. They work closely with IT and business teams to minimize cyber threats, such as data breaches and ransomware attacks. Their goal is to protect sensitive information and maintain business continuity.
What are some common challenges faced in a cyber risk management role, and how are they typically addressed?
Professionals in Cyber Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, ensuring compliance with complex regulations, and balancing security needs with business objectives. Addressing these issues requires continuous learning, leveraging up-to-date threat intelligence, and collaborating closely with IT, legal, and management teams to develop effective risk mitigation strategies. Many organizations encourage ongoing training and participation in industry events to stay current, while fostering a culture of open communication to quickly identify and address vulnerabilities. Embracing a proactive and adaptable approach ensures that cyber risks are managed effectively while supporting the organization’s goals.
What are the key skills and qualifications needed to thrive in cyber risk management, and why are they important?
To thrive in Cyber Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance, often supported by a degree in cybersecurity, information technology, or a related field. Familiarity with tools such as risk management software, vulnerability assessment platforms, and certifications like CISSP, CISM, or CRISC is highly valued. Excellent analytical thinking, communication, and problem-solving skills help professionals effectively advise stakeholders and coordinate incident response efforts. These skills are crucial for identifying, evaluating, and mitigating cyber risks to safeguard organizational assets and ensure business continuity.
How much does a cyber risk management professional make?
What does a cyber risk management do?
What are popular job titles related to Cyber Risk Management jobs in Maryland?
For Cyber Risk Management jobs in Maryland, the most frequently searched job titles are:
What job categories do people searching Cyber Risk Management jobs in Maryland look for?
The top searched job categories for Cyber Risk Management jobs in Maryland are:
What cities in Maryland are hiring for Cyber Risk Management jobs?
Cities in Maryland with the most Cyber Risk Management job openings:

Deputy CISO
Baltimore, MD
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 8 days ago
RK&K rating
7.5
Based on 9 frontline employees who took The Breakroom Quiz
Job description
RK&K's Baltimore office is seeking a Deputy Chief Information Security Officer to lead the development and execution of a dedicated cybersecurity program. Reporting directly to the Chief Information Officer, the Deputy CISO will be responsible for all cybersecurity operations, cyber risk management, security architecture, incident response, governance, compliance, and the long-term strategy required to protect RK&K's people, data, systems, clients, and business operations.
This is a foundational leadership role. This position will be responsible for building a standalone cybersecurity function from the ground up. The Deputy CISO will separate cybersecurity responsibilities from traditional IT operations, establish clear ownership of security controls and risk decisions, and create a scalable security operating model that supports RK&K's continued growth.
The Deputy CISO will partner closely with the CIO to define cybersecurity strategy, prioritize investments, strengthen cyber resilience, and align security initiatives with business objectives. This role requires a hands-on leader who can operate strategically while also building practical capabilities, policies, processes, tools, and teams.
Essential Functions
Cybersecurity Leadership and Strategy
Serve as RK&K's senior cybersecurity leader responsible for day-to-day cyber operations and execution of the firm's cybersecurity roadmap.
Partner with the CIO to develop, maintain, and execute a multi-year cybersecurity strategy aligned with RK&K's business goals, client expectations, regulatory obligations, and risk appetite.
Provide regular reporting to the CIO and executive leadership on security posture, risk trends, major initiatives, incidents, metrics, and investment needs.
Advise the CIO on cybersecurity budget priorities, technology investments, staffing plans, vendor selection, and risk tradeoffs.
Create annual and multi-year security plans with measurable goals, timelines, milestones, and success criteria.
Represent cybersecurity in strategic technology planning, enterprise architecture decisions, digital transformation initiatives, acquisitions, client requirements, and major business initiatives.
Cyber Operations
Develop and lead RK&K's cyber operations program, including security monitoring, detection, response, vulnerability management, endpoint security, identity security, email security, cloud security, and threat management.Governance, Risk, and Compliance
Develop and lead RK&K's cybersecurity governance, risk, and compliance program.
Lead a formal cyber risk acceptance and exception process.
Align cybersecurity compliance with contractual, regulatory, client-driven, and industry-specific cybersecurity requirements.
Security Architecture and Engineering
Establish security architecture principles, standards, and review processes for infrastructure, applications, cloud services, networks, endpoints, and identity platforms.
Partner with IT operations and enterprise architecture teams to ensure security is embedded into technology design and implementation.
Data Protection and Privacy Support
Establish data protection strategies for sensitive business information, client data, employee data, financial data, intellectual property, and regulated information.
Establish security requirements for document management, collaboration platforms, file shares, project data, client deliverables, and mobile access.
Incident Response, Resilience, and Business Continuity
Develop incident response policies, plans, playbooks, communication templates, escalation matrices, and decision trees.
Conduct tabletop exercises with executive leadership, IT, legal, HR, finance, communications, and business stakeholders.
Establish ransomware readiness plans, including containment strategies, backup validation, recovery priorities, communication plans, and decision-making processes.
Ensure backup environments are protected from compromise, unauthorized deletion, encryption by ransomware, and credential abuse.
Define and maintain metrics for mean time to detect, mean time to respond, incident volume, root causes, recurring issues, and control failures.
Required Skills and Experience
Bachelor's degree in computer science, information technology, business administration, or related field.
10 or more years of progressive experience in information technology, cybersecurity, risk management, security engineering, infrastructure, or related disciplines.
5 or more years of cybersecurity leadership experience, including responsibility for security operations, incident response, governance, or cyber risk management.
Experience developing cybersecurity strategy, roadmaps, policies, standards, operating models, and governance processes.
Strong understanding of cybersecurity operations, including monitoring, detection, response, vulnerability management, endpoint security, identity security, and incident response.
Experience with cyber risk assessments, risk registers, control maturity assessments, remediation planning, and executive risk reporting.
Experience leading incident response activities, tabletop exercises, post-incident reviews, and cyber crisis coordination.
Familiarity with enterprise security technologies such as SIEM, EDR/XDR, MDR, vulnerability management platforms, firewalls, email security, identity platforms, DLP, CASB, PAM, and cloud security tools.
Strong knowledge of identity and access management, privileged access, multi-factor authentication, conditional access, single sign-on, and access reviews.
Experience supporting security audits, client questionnaires, contract security requirements, cyber insurance, or compliance reviews.
Ability to lead strategically while also operating hands-on in a developing security environment.
Preferred Skills and Experience
Professional certifications such as CISSP, CISM, CISA, CRISC, GIAC, CCSP, CGRC, or similar credentials.
Experience supporting organizations with distributed offices, remote employees, field operations, project-based work, or client-driven security requirements.
Experience developing or overseeing managed detection and response, managed SOC, or co-managed security operations models.
Experience with data classification, data loss prevention, records management, secure collaboration, and document protection.
Experience with business continuity, disaster recovery, ransomware readiness, and backup resilience.
Experience presenting cybersecurity risks, plans, and investment needs to executive leadership or board-level audiences.
Experience leading organizational change, especially where security responsibilities are being separated from legacy IT operations.
Other Duties
This job description indicates the general nature and level of work, knowledge, skills, abilities, and other essential functions (as covered under ADA). It is not designed to cover or contain a comprehensive listing of all activities and duties required of the employee. Other duties are assigned as required.
What We Offer
RK&K offers excellent potential for career advancement and professional growth. We also offer attractive compensation packages commensurate with experience and a comprehensive benefits package including:
- Paid time off
- Matching 401(k) plan
- Student Loan Retirement Match Program
- Paid Holidays
- Tuition reimbursement
- Health, dental, vision, life, and disability insurances
- Paid parental leave
- Wellness programs and employee resource groups
- Career Development
- Much, much more!
Why RK&K?
As a full-service engineering and construction management firm, RK&K gives you the opportunity to directly impact the communities in which we live and work. What sets RK&K apart is an award-winning culture that has fostered a spirit of collaboration and trust for over 100 years. To its clients, the firm delivers concepts, processes, and outcomes designed for success. RK&K has earned its reputation as a trusted partner, responsive employer, and community steward.
Design your career at RK&K-Apply Today!
Visa Sponsorship: This position is not eligible for employer-sponsored work authorization. Applicants must be currently authorized to work in the United States without the need for current or future sponsorship.
Salary Range: $180K-$220K
About RK&K
Sourced by ZipRecruiter
Industry
Civil engineering construction
Company size
1,001 - 5,000 Employees
Headquarters location
Baltimore, MD, US
Year founded
1923