1

Cyber Risk Manager Jobs in Hawaii (NOW HIRING)

The Sr. Manager, IT Security serves as a key advisor to IT and business leadership, translates cyber risk into business impact, and contributes to enterprise technology decisionmaking. ESSENTIAL ...

... , IT Risk Manager, Threat Assessment Analyst, Systems Compliance Auditor, Cyber Risk Analyst, etc. DEGREE (Level Desired) Bachelor's Degree DEGREE (Focus) Cybersecurity, Information Technology ...

... Risk Manager, Threat Assessment Analyst, Systems Compliance Auditor, Cyber Risk Analyst, etc. DEGREE (Level Desired)Bachelor's DegreeDEGREE (Focus)Cybersecurity, Information Technology, Computer ...

Cyber Data Protection Manager

Honolulu, HI · Hybrid

$109K - $148K/yr

Risk & Compliance * Identity & Access Management * Data Protection * Cyber Design * Incident Response * Security Architecture * Business Partnership Qualifications Required: * Bachelor's degree or ...

$99K - $225K/yr

Cyber threats are everywhere, and the constantly evolving nature of these threats can make ... governance, risk management, and compliance. Work with us as we protect our military ...

Cyber and IT Risk Management Job Qualifications: Skills: Cyber Security Architecture, Information System Security, Risk Management Framework Certifications: None Experience: 15 + years of related ...

Cybersecurity Analyst

Aiea, HI · On-site

$141K - $236K/yr

Performing cyber risk assessments on third-party vendors and supply chain systems in accordance with security requirements. * Developing, managing, and enforcing OPSEC procedures and Incident ...

Cyber and IT Risk Management Job Qualifications: Skills: Identity and Access Managment (IAM), Secure Network Architecture, Zero Trust Certifications: None Experience: 15 + years of related experience ...

Cybersecurity Analyst

Aiea, HI · Hybrid

$141K - $236K/yr

Performing cyber risk assessments on third-party vendors and supply chain systems in accordance with security requirements. * Developing, managing, and enforcing OPSEC procedures and Incident ...

next page

Showing results 1-20

Cyber Risk Manager information

See Hawaii salary details

$53.5K

$115.9K

$176.6K

How much do cyber risk manager jobs pay per year?

As of Jun 23, 2026, the average yearly pay for cyber risk manager in Hawaii is $115,902.00, according to ZipRecruiter salary data. Most workers in this role earn between $93,500.00 and $134,000.00 per year, depending on experience, location, and employer.

How does a Cyber Risk Manager typically collaborate with other departments to strengthen an organization's cybersecurity posture?

A Cyber Risk Manager frequently works with IT, legal, compliance, and business units to identify, assess, and mitigate cyber risks across the organization. This collaboration involves leading risk assessments, facilitating security awareness training, and ensuring that cybersecurity policies align with business objectives. Regular cross-department meetings and incident response simulations are common, fostering a shared responsibility for cyber resilience. Effective communication and relationship-building skills are essential in this role to bridge technical and non-technical teams.

What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?

AspectCyber Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, security firms, corporate environments

The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.

What are the key skills and qualifications needed to thrive as a Cyber Risk Manager, and why are they important?

To thrive as a Cyber Risk Manager, you need a solid background in information security, risk assessment, and compliance, often supported by a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC tools, and relevant certifications like CISSP or CISM is typically required. Excellent analytical thinking, communication, and leadership skills set top performers apart in this role. These skills are crucial for identifying risks, implementing effective controls, and ensuring the organization’s digital assets remain secure and compliant.

Can you make $500,000 a year in cyber security?

Cyber Risk Managers and senior cybersecurity professionals can potentially earn $500,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and leadership roles such as Chief Information Security Officer (CISO). High salaries are often associated with large organizations, specialized skills, and strategic responsibilities in cybersecurity management. However, such compensation levels are typically reached after many years of experience and proven expertise in the field.

Is CISO a high paying job?

A Chief Information Security Officer (CISO) is typically a high-paying executive role in cybersecurity, with salaries often exceeding six figures depending on the organization size and industry. CISOs usually have extensive experience, leadership skills, and certifications like CISSP or CISM, which contribute to their compensation. The role involves strategic oversight of an organization's security posture and risk management.

What does a cyber risk manager do?

A cyber risk manager assesses and mitigates cybersecurity threats to an organization’s information systems. They identify vulnerabilities, develop risk management strategies, and implement security controls, often using tools like risk assessment frameworks and security software. The role requires strong analytical skills and relevant certifications such as CISSP or CISM.

What is the 80 20 rule in cyber security?

The 80/20 rule in cybersecurity suggests that approximately 80% of security issues are caused by 20% of vulnerabilities or threats. Cyber Risk Managers focus on identifying and mitigating these critical vulnerabilities to improve overall security posture efficiently.
What job categories do people searching Cyber Risk Manager jobs in Hawaii look for? The top searched job categories for Cyber Risk Manager jobs in Hawaii are:
Infographic showing various Cyber Risk Manager job openings in Hawaii as of June 2026, with employment types broken down into 84% Full Time, 15% Part Time, and 1% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $115,902 per year, or $55.7 per hour.
Sr. Manager, IT Security

Sr. Manager, IT Security

Hawaii Gas

Honolulu, HI

$109K - $170K/yr

Full-time

Posted 4 days ago


Job description

PURPOSE STATEMENT

The Sr. Manager, IT Security is responsible for leading and operating a comprehensive, riskbased cybersecurity and information protection program for a regulated utility environment. This role will provide enterprise leadership for security strategy, governance, risk management, security operations, incident response, identity and access management, vulnerability management, and security architecture. This position requires deep technical breadth, strong management skills, and executivelevel judgment. The Sr. Manager, IT Security serves as a key advisor to IT and business leadership, translates cyber risk into business impact, and contributes to enterprise technology decisionmaking.


ESSENTIAL FUNCTIONS/RESPONSIBILITIES

Leadership & People Management

  • Manages a team to oversee security operations, including monitoring, detection, investigation, and response activities.
  • Leads succession planning, talent development, workforce planning, and organizational capability building for the IT Security function.
  • Develops and manages the cybersecurity budget, including strategic planning for staffing, technology investments, consulting services, and managed security providers.

Cybersecurity Strategy & Governance

  • Leads the design, implementation, and continuous improvement of the enterprise information security program.
  • Develops and executes the organization's long-term cybersecurity vision, strategy, and roadmap in alignment with business objectives and technology initiatives.
  • Develops and maintains security strategy, policies, standards, procedures, and multi-year roadmaps aligned with business objectives and regulatory requirements.
  • Serves as the primary cybersecurity advisor to executive leadership, providing recommendations regarding enterprise risk, security investments, and emerging threats.
  • Leads enterprise-wide cybersecurity governance, ensuring security policies, standards, and controls are consistently implemented across all business units and technology environments.
  • Sponsors and drives cybersecurity program maturity initiatives through the adoption of industry frameworks, best practices, and continuous improvement efforts.

Security Operations & Incident Response

  • Leads cybersecurity incident investigations, coordinates containment and recovery activities, and engages external resources as required.
  • Develops, maintains, and regularly tests incident response plans and playbooks, including tabletop exercises with IT and business stakeholders.
  • Manages security technologies and platforms, including but not limited to email security, endpoint detection and response (EDR), vulnerability management, identity protection, and logging/SIEM solutions.
  • Stays current on emerging cybersecurity threats, vulnerabilities, and industry-specific risk trends affecting utility operations.

Risk Management, Compliance & Audit

  • Establishes and maintains a cybersecurity risk management framework, including risk identification, assessment, prioritization, mitigation, and reporting to executive leadership.
  • Maintains an enterprise security risk register, including risk assessments, remediation plans, and formal risk acceptance documentation.
  • Oversees cybersecurity compliance efforts related to applicable regulatory, legal, contractual, and industry requirements.
  • Leads enterprise cybersecurity audits, assessments, and third-party reviews, ensuring timely remediation of identified findings and recommendations.
  • Directs third-party cybersecurity risk management activities, including security due diligence, vendor assessments, and ongoing monitoring of critical suppliers and service providers.

Vulnerability & Security Engineering Management

  • Leads vulnerability scanning, prioritization, remediation tracking, and reporting across infrastructure, applications, and cloud environments.
  • Partners with Infrastructure, Applications, OT, and Operations teams to manage patching cadence, exceptions, and remediation SLAs.
  • Directs security architecture and security-by-design initiatives to ensure cybersecurity requirements are integrated into infrastructure, applications, cloud environments, and operational technology (OT) systems.
  • Oversees cybersecurity considerations for mergers, acquisitions, major technology implementations, and other strategic business initiatives, as applicable.

Security Awareness & Culture

  • Creates programs designed to increase cybersecurity awareness within the company, such as phishing campaigns and annual cybersecurity training programs.

Metrics, Reporting & Executive Communication

  • Establishes security metrics and dashboards to measure effectiveness and report risk posture to IT leadership and executives.
  • Establishes key performance indicators (KPIs), key risk indicators (KRIs), and cybersecurity program metrics to measure effectiveness and support strategic decision-making.
  • Provides executive-level reporting and presentations regarding cybersecurity posture, program maturity, key risks, incidents, trends, and strategic initiatives.

OTHER FUNCTIONS/RESPONSIBILITIES:

  • Ensure compliance with IT controls, including preparing and approving audit reports.
  • Manage operational budget and expenses related to both new purchases and existing cybersecurity services.
  • Effectively manage strategic and highly visible projects related to cybersecurity and other IT initiatives.
  • Complies with all safety rules and cooperates in the fullest in the promotion of safety and safe work habits, to include the reporting of any unsafe conditions or acts. Maintains all EH&S training on a current basis.
  • Complies with all applicable corporate and Hawaii Gas policies and procedures.
  • Maintains assigned work area and equipment in a clean, orderly and safe manner; performs housekeeping duties as required and/or instructed. Works in a safe and responsible manner.
  • Performs all other related duties as instructed by supervisor/manager.

Required Education and/or Work Experience:

  • Bachelor’s degree in management information systems, information technology, computer science, or related field.
  • Minimum ten (10) years of progressively responsible experience in information technology and/or cybersecurity.
  • Minimum five (5) years of experience managing a technical team.
  • Experience in IT operations and management, including leading technical projects, analyzing business processes, and implementing systems and process improvements.
  • Demonstrated experience developing, implementing, and managing enterprise cybersecurity programs, including security operations, incident response, vulnerability management, risk management, and security governance.
  • Demonstrated experience leading and managing systems and vendor relationships with SOC and SIEM services.
  • Demonstrated experience in managing large technical projects with budgets > $100K.
  • Proficient in Microsoft 365 tools, especially Word, Excel, Project, Visio, and PowerPoint.

Preferred Education and/or Work Experience:

  • Master’s degree in management information systems, information technology, computer science, or related field.
  • Two (2) or more years of experience in software development.
  • Two (2) or more years of experience in using scripting languages (e.g., Python, PowerShell).
  • Graduate degree in Information Science, Engineering, or a similar discipline preferred.
  • Hands-on experience with cloud-based SaaS, IaaS, and PaaS solutions.
  • Experience in the energy and utilities industry.
  • Experience in development of AI strategy in risk management and productivity applications.
  • Knowledgeable in business processes such as sales, accounting, and IT service management.
  • Familiarity with SOX audit requirements.

Required Licensure, Certification, Registration, or Designation:

  • CISSP or equivalent cybersecurity certifications.
  • Valid Hawaii Driver’s License.

Preferred Licensure, Certification, Registration, or Designation:

  • IT Information Library Version (ITIL) 3 or 4 certifications.
  • Six Sigma Green Belt or higher.
  • PMP (Project Management Professional).
  • The Open Group Architectural Framework (TOGAF) 9.x or 10.x certification.