... management. * Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance ...
... management. * Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance ...
... management. * Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance ...
... management. * Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance ...
Are you an experienced cybersecurity professional looking to help organizations reduce cyber risk ... Leading vulnerability and patch management operations across infrastructure, middleware, and ...
Are you an experienced cybersecurity professional looking to help organizations reduce cyber risk ... Leading vulnerability and patch management operations across infrastructure, middleware, and ...
... management. * Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance ...
... management. * Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance ...
Are you an experienced cybersecurity professional looking to help organizations reduce cyber risk ... Leading vulnerability and patch management operations across infrastructure, middleware, and ...
Are you an experienced cybersecurity professional looking to help organizations reduce cyber risk ... Leading vulnerability and patch management operations across infrastructure, middleware, and ...
Cyber Governance - Advisor II
Berkeley Heights, NJ · On-site
$115K - $156K/yr
As a Cyber Risk Manager, you will help identify, assess, manage, and communicate cybersecurity risk across business initiatives, platforms, and services. You will be a partner with business ...
Cyber Governance - Advisor II
Berkeley Heights, NJ · On-site
$115K - $156K/yr
As a Cyber Risk Manager, you will help identify, assess, manage, and communicate cybersecurity risk across business initiatives, platforms, and services. You will be a partner with business ...
Mature risk-based prioritization models leveraging threat intelligence and exploitability. * Drive ... Build integrated exposure management capabilities across security and infrastructure teams.
Mature risk-based prioritization models leveraging threat intelligence and exploitability. * Drive ... Build integrated exposure management capabilities across security and infrastructure teams.
Cyber Governance - Advisor II
$115K - $156K/yr
As a Cyber Risk Manager, you will help identify, assess, manage, and communicate cybersecurity risk across business initiatives, platforms, and services. You will be a partner with business ...
Cyber Governance - Advisor II
$115K - $156K/yr
As a Cyber Risk Manager, you will help identify, assess, manage, and communicate cybersecurity risk across business initiatives, platforms, and services. You will be a partner with business ...
Vice President, Global Cyber Exposure Management & Cyber Engineering and Architecture
Princeton, NJ · On-site
Mature risk-based prioritization models leveraging threat intelligence and exploitability. * Drive ... Build integrated exposure management capabilities across security and infrastructure teams.
Vice President, Global Cyber Exposure Management & Cyber Engineering and Architecture
Princeton, NJ · On-site
Mature risk-based prioritization models leveraging threat intelligence and exploitability. * Drive ... Build integrated exposure management capabilities across security and infrastructure teams.
Technology Operational Risk Management Director - Executive Director
Jersey City, NJ · On-site
$200 - $350/hr
As part of Risk Management and Compliance, you help keep the firm strong and resilient by ... Shape technology and cyber risk strategy with senior tech and digital leaders * Identify technology ...
Technology Operational Risk Management Director - Executive Director
Jersey City, NJ · On-site
$200 - $350/hr
As part of Risk Management and Compliance, you help keep the firm strong and resilient by ... Shape technology and cyber risk strategy with senior tech and digital leaders * Identify technology ...
... on cyber risks for IT and business management with both summary and detailed reporting • ... IT risk management or investigations Preferred : • Demonstrated experience analyzing IT control ...
... on cyber risks for IT and business management with both summary and detailed reporting • ... IT risk management or investigations Preferred : • Demonstrated experience analyzing IT control ...
Mature risk-based prioritization models leveraging threat intelligence and exploitability. * Drive ... Build integrated exposure management capabilities across security and infrastructure teams.
Mature risk-based prioritization models leveraging threat intelligence and exploitability. * Drive ... Build integrated exposure management capabilities across security and infrastructure teams.
Senior Legal Director, Cyber & Data Risk
New Brunswick, NJ · On-site
$178 - $307/hr
As the Senior Legal Director, Cyber & Data Risk, you will serve as the principal legal advisor to ... Manage outside counsel supporting specialized cybersecurity legal matters, as appropriate.
New
Senior Legal Director, Cyber & Data Risk
New Brunswick, NJ · On-site
$178 - $307/hr
As the Senior Legal Director, Cyber & Data Risk, you will serve as the principal legal advisor to ... Manage outside counsel supporting specialized cybersecurity legal matters, as appropriate.
New
Cyber Security Technical GRC - VP
Jersey City, NJ · Hybrid
$115K - $156K/yr
Cloud & Cyber Risk Management * Drive risk management initiatives formulticloud environments; ensure alignment with enterprise security standards and regulatory expectations. * Understand ...
Cyber Security Technical GRC - VP
Jersey City, NJ · Hybrid
$115K - $156K/yr
Cloud & Cyber Risk Management * Drive risk management initiatives formulticloud environments; ensure alignment with enterprise security standards and regulatory expectations. * Understand ...
Cyber Security Technical GRC - VP
Jersey City, NJ · Hybrid
$115K - $156K/yr
Cloud & Cyber Risk Management * Drive risk management initiatives formulticloud environments; ensure alignment with enterprise security standards and regulatory expectations. * Understand ...
Cyber Security Technical GRC - VP
Jersey City, NJ · Hybrid
$115K - $156K/yr
Cloud & Cyber Risk Management * Drive risk management initiatives formulticloud environments; ensure alignment with enterprise security standards and regulatory expectations. * Understand ...
Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
Cyber Security Technical GRC - VP
Jersey City, NJ · On-site
$115K - $156K/yr
Cloud & Cyber Risk Management * Drive risk management initiatives for multicloud environments; ensure alignment with enterprise security standards and regulatory expectations. * Understand the ...
Cyber Security Technical GRC - VP
Jersey City, NJ · On-site
$115K - $156K/yr
Cloud & Cyber Risk Management * Drive risk management initiatives for multicloud environments; ensure alignment with enterprise security standards and regulatory expectations. * Understand the ...
Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
IT Security Manager
Plainsboro, NJ · On-site
$145K - $187K/yr
... Cyber Risk & Audit to design, mature, and lead our vendor risk management strategy. As global digital supply chains become more complex, the integrity of our partners is a critical component of our ...
IT Security Manager
Plainsboro, NJ · On-site
$145K - $187K/yr
... Cyber Risk & Audit to design, mature, and lead our vendor risk management strategy. As global digital supply chains become more complex, the integrity of our partners is a critical component of our ...
Cyber Risk Management information
See New Jersey salary details
$19.58 is the 25th percentile. Wages below this are outliers.
$14.64 - $20.14
28% of jobs
The median wage is $23.43 / hr.
$20.14 - $25.65
37% of jobs
$25.65 - $31.15
6% of jobs
$34.59 is the 75th percentile. Wages above this are outliers.
$31.15 - $36.65
6% of jobs
$36.65 - $42.15
12% of jobs
$42.15 - $47.66
0% of jobs
$47.66 - $53.16
0% of jobs
$53.16 - $58.66
8% of jobs
$58.66 - $64.16
0% of jobs
$64.16 - $69.66
0% of jobs
$69.66 - $75.17
2% of jobs
$14
$30
$75
How much do cyber risk management jobs pay per hour?
What is cyber risk management?
A Cyber Risk Management job involves identifying, assessing, and mitigating cybersecurity risks that could impact an organization. Professionals in this field develop risk management frameworks, implement security controls, and ensure compliance with industry regulations. They work closely with IT and business teams to minimize cyber threats, such as data breaches and ransomware attacks. Their goal is to protect sensitive information and maintain business continuity.
What are the key skills and qualifications needed to thrive in cyber risk management, and why are they important?
To thrive in Cyber Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance, often supported by a degree in cybersecurity, information technology, or a related field. Familiarity with tools such as risk management software, vulnerability assessment platforms, and certifications like CISSP, CISM, or CRISC is highly valued. Excellent analytical thinking, communication, and problem-solving skills help professionals effectively advise stakeholders and coordinate incident response efforts. These skills are crucial for identifying, evaluating, and mitigating cyber risks to safeguard organizational assets and ensure business continuity.
How much does a cyber risk manager make?
What are some common challenges faced in a cyber risk management role, and how are they typically addressed?
Professionals in Cyber Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, ensuring compliance with complex regulations, and balancing security needs with business objectives. Addressing these issues requires continuous learning, leveraging up-to-date threat intelligence, and collaborating closely with IT, legal, and management teams to develop effective risk mitigation strategies. Many organizations encourage ongoing training and participation in industry events to stay current, while fostering a culture of open communication to quickly identify and address vulnerabilities. Embracing a proactive and adaptable approach ensures that cyber risks are managed effectively while supporting the organization’s goals.
What does a cyber risk management do?

Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
45th of 150 rated financial services
Job description
Are you interested in improving the cyber and organizational risk profiles of leading companies? Do you want to build the data foundations that power the next generation of AI-enabled cyber defense?
If yes, then Deloitte's Cyber team could be the place for you.
We are looking for a hands-on Data Engineer to build and operate the governed data foundations powering cyber risk, compliance evidence, and agentic AI-enabled cyber workflows. You will design production-grade pipelines and services that support risk reporting, continuous controls monitoring, and AI-assisted security operations-built with strong governance, lineage, privacy-by-design, and audit-ready evidence.
This role is ideal for engineers who can bridge modern data engineering and software development with Governance, Risk, and Compliance (GRC) expectations in regulated enterprise environments.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Senior Consultant, Strategy, Growth and Transformation on the Cyber team, you will be responsible for:
- Building scalable batch and stream processing pipelines that ingest security telemetry, control evidence, and compliance artifacts into governed data stores.
- Designing data models for risk and controls domains, including key risk indicators, issues and defects, risk acceptance, control testing outcomes, audit evidence, and policy exceptions, and enabling self-service analytics and dashboards.
- Implementing data quality checks, lineage, metadata, and access controls to support auditability, regulatory defensibility, and repeatable evidence generation.
- Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer, investigation copilots, ticket triage, and exception reasoning using agentic patterns, workflow orchestration, and retrieval-augmented generation.
- Engineering integrations between data platforms, governance, risk, and compliance workflows, and enterprise systems using application programming interfaces, event patterns, and connectors, with observability and runbooks for production support.
- Partnering with Cyber, Risk, Compliance, Privacy, and Legal stakeholders to translate requirements into implementable controls and developer-ready guardrails.
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
You will join a cyber engineering team focused on enabling resilient, secure, and compliant operations through modern data platforms and AI-enabled automation. The team builds repeatable assets-reference architectures, accelerators, and governance patterns-to help clients modernize and scale cyber and GRC programs.
Qualifications
Required:
- Bachelor's degree or equivalent practical experience.
- 4+ years of experience in data engineering and software development using Python and SQL.
- Experience building production data pipelines and data models for batch processing, stream processing, or both, and deploying solutions using cloud platforms, containers, infrastructure as code, application programming interfaces, and secrets management.
- Experience implementing data governance controls including data classification, personally identifiable information handling, least-privilege access, encryption, secrets management, retention, audit logging, and lineage or metadata management.
- Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance, risk, and compliance tool integrations, and large language model-enabled applications using retrieval-augmented generation, vector or hybrid retrieval, tool or function calling, evaluation or monitoring, prompt-injection defenses, and secure access patterns.
- Ability to travel 0-25%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Experience in consulting or a Big 4 environment.
- Experience with Java, Go, or JavaScript.
- Experience integrating with ServiceNow GRC, Archer, OneTrust, or BigID and building evidence pipelines mapped to control objectives.
- Experience building pipelines for security information and event management, security orchestration, automation, and response, vulnerability, identity, or cloud security posture data.
- Experience operationalizing large language model operations or machine learning operations capabilities, including evaluation, monitoring, versioning, and governance workflows.
- Security certification such as CompTIA Security+, Certified Information Security Manager, Certified Information Systems Auditor, Certified Information Systems Security Professional, or a cloud certification.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberDTP27
Are you interested in improving the cyber and organizational risk profiles of leading companies? Do you want to build the data foundations that power the next generation of AI-enabled cyber defense?
If yes, then Deloitte's Cyber team could be the place for you.
We are looking for a hands-on Data Engineer to build and operate the governed data foundations powering cyber risk, compliance evidence, and agentic AI-enabled cyber workflows. You will design production-grade pipelines and services that support risk reporting, continuous controls monitoring, and AI-assisted security operations-built with strong governance, lineage, privacy-by-design, and audit-ready evidence.
This role is ideal for engineers who can bridge modern data engineering and software development with Governance, Risk, and Compliance (GRC) expectations in regulated enterprise environments.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Senior Consultant, Strategy, Growth and Transformation on the Cyber team, you will be responsible for:
- Building scalable batch and stream processing pipelines that ingest security telemetry, control evidence, and compliance artifacts into governed data stores.
- Designing data models for risk and controls domains, including key risk indicators, issues and defects, risk acceptance, control testing outcomes, audit evidence, and policy exceptions, and enabling self-service analytics and dashboards.
- Implementing data quality checks, lineage, metadata, and access controls to support auditability, regulatory defensibility, and repeatable evidence generation.
- Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer, investigation copilots, ticket triage, and exception reasoning using agentic patterns, workflow orchestration, and retrieval-augmented generation.
- Engineering integrations between data platforms, governance, risk, and compliance workflows, and enterprise systems using application programming interfaces, event patterns, and connectors, with observability and runbooks for production support.
- Partnering with Cyber, Risk, Compliance, Privacy, and Legal stakeholders to translate requirements into implementable controls and developer-ready guardrails.
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
You will join a cyber engineering team focused on enabling resilient, secure, and compliant operations through modern data platforms and AI-enabled automation. The team builds repeatable assets-reference architectures, accelerators, and governance patterns-to help clients modernize and scale cyber and GRC programs.
Qualifications
Required:
- Bachelor's degree or equivalent practical experience.
- 4+ years of experience in data engineering and software development using Python and SQL.
- Experience building production data pipelines and data models for batch processing, stream processing, or both, and deploying solutions using cloud platforms, containers, infrastructure as code, application programming interfaces, and secrets management.
- Experience implementing data governance controls including data classification, personally identifiable information handling, least-privilege access, encryption, secrets management, retention, audit logging, and lineage or metadata management.
- Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance, risk, and compliance tool integrations, and large language model-enabled applications using retrieval-augmented generation, vector or hybrid retrieval, tool or function calling, evaluation or monitoring, prompt-injection defenses, and secure access patterns.
- Ability to travel 0-25%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Experience in consulting or a Big 4 environment.
- Experience with Java, Go, or JavaScript.
- Experience integrating with ServiceNow GRC, Archer, OneTrust, or BigID and building evidence pipelines mapped to control objectives.
- Experience building pipelines for security information and event management, security orchestration, automation, and response, vulnerability, identity, or cloud security posture data.
- Experience operationalizing large language model operations or machine learning operations capabilities, including evaluation, monitoring, versioning, and governance workflows.
- Security certification such as CompTIA Security+, Certified Information Security Manager, Certified Information Systems Auditor, Certified Information Systems Security Professional, or a cloud certification.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberDTP27