1

Cyber Risk Manager Jobs in Hanover, MD (NOW HIRING)

Provide subject matter expertise in enterprise risk management, operational risk, cyber risk, and program risk management. * Develop, maintain, and execute comprehensive risk management strategies ...

Provide subject matter expertise in enterprise risk management, operational risk, cyber risk, and program risk management. * Develop, maintain, and execute comprehensive risk management strategies ...

Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone ...

Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone ...

Cyber GRC Specialist

Washington, DC · On-site

$90 - $130/hr

* Support and mature cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and leadership reporting * Maintain the cyber ...

Through solutions and managed services that simplify complexity, we help clients operate with resilience, grow with confidence, and proactively manage cyber, risk, and technology programs. Recruiting ...

next page

Showing results 1-20

Cyber Risk Manager information

See Hanover, MD salary details

$51.2K

$111K

$169.1K

How much do cyber risk manager jobs pay per year?

As of Aug 25, 2026, the average yearly pay for cyber risk manager in Hanover, MD is $110,998.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,500.00 and $128,400.00 per year, depending on experience, location, and employer.

How does a cyber risk manager collaborate with other departments to strengthen an organization's cybersecurity posture?

A Cyber Risk Manager frequently works with IT, legal, compliance, and business units to identify, assess, and mitigate cyber risks across the organization. This collaboration involves leading risk assessments, facilitating security awareness training, and ensuring that cybersecurity policies align with business objectives. Regular cross-department meetings and incident response simulations are common, fostering a shared responsibility for cyber resilience. Effective communication and relationship-building skills are essential in this role to bridge technical and non-technical teams.

What are the key skills and qualifications needed to thrive as a cyber risk manager, and why are they important?

To thrive as a Cyber Risk Manager, you need a solid background in information security, risk assessment, and compliance, often supported by a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC tools, and relevant certifications like CISSP or CISM is typically required. Excellent analytical thinking, communication, and leadership skills set top performers apart in this role. These skills are crucial for identifying risks, implementing effective controls, and ensuring the organization’s digital assets remain secure and compliant.

What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?

AspectCyber Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, security firms, corporate environments

The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.

How much does a cyber risk manager make?

A cyber risk manager's salary typically ranges from $90,000 to $150,000 annually, depending on experience, certifications, and industry. Senior roles or those in high-demand sectors can earn higher compensation, often supplemented with bonuses and benefits.

What does a cyber risk manager do?

A cyber risk manager assesses and mitigates cybersecurity threats to an organization’s information systems. They identify vulnerabilities, develop risk management strategies, and implement security controls, often using tools like risk assessment frameworks and security software. Certification such as CISSP or CISM can enhance their effectiveness in managing cyber risks.

What cities near Hanover, MD are hiring for Cyber Risk Manager jobs?

Cities near Hanover, MD with the most Cyber Risk Manager job openings:

Infographic showing various Cyber Risk Manager job openings in Hanover, MD as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 84% Physical, 2% Hybrid, and 14% Remote job distribution, with an average salary of $110,998 per year, or $53.4 per hour.

GRC Lead / Cyber Risk Manager

CyberLinx Solutions LLC

Washington, DC

$125K - $169K/yr

Full-time

Re-posted 15 days ago


Job description

CyberLinx Solutions LLC is seeking a forward thinking Cybersecurity GRC Lead / Cyber Risk Manager responsible for leading the organization’s cybersecurity governance, risk, and compliance (GRC) program. This role oversees enterprise risk assessments, regulatory compliance, policy development, and security control implementation aligned to industry frameworks such as NIST CSF and NIST RMF.

The ideal candidate will serve as a strategic advisor to leadership, ensuring cybersecurity risks are identified, assessed, and managed in alignment with business objectives and regulatory requirements.

Key Responsibilities:

Governance & Program Leadership

  • Lead and manage the enterprise GRC program, including policies, standards, and procedures
  • Serve as the primary advisor on cybersecurity risk and compliance matters
  • Align cybersecurity strategy with business objectives and regulatory requirements
  • Provide executive-level reporting on risk posture, compliance status, and remediation efforts

Risk Management:

  • Conduct enterprise and system-level cybersecurity risk assessments
  • Develop and maintain risk registers aligned to NIST SP 800-53 and NIST SP 800-171
  • Define risk tolerance, scoring methodologies, and mitigation strategies
  • Perform gap assessments and maturity evaluations using NIST CSF

Compliance & Audit

  • Ensure compliance with federal, state, and industry regulations for NIST RMF, and FISMA as applicable.
  • Lead audit readiness efforts and coordinate internal/external audits
  • Develop Plans of Action & Milestones (POA&M) and track remediation activities
  • Maintain documentation supporting Authority to Operate (ATO) processes

Security Controls & Frameworks

  • Oversee implementation and validation of security controls
  • Map controls across frameworks (NIST CSF, NIST 800-53, ISO 27001)
  • Collaborate with technical teams to ensure control effectiveness

Third-Party Risk Management

  • Evaluate vendor and third-party cybersecurity risks
  • Conduct security assessments and due diligence reviews
  • Ensure contractual security and compliance requirements are met

Required Qualifications:

  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or related field
  • 8+ years of experience in cybersecurity, with at least 3–5 years in GRC or risk management leadership roles
  • Strong knowledge of:
    • NIST Cybersecurity Framework (CSF)
    • NIST Risk Management Framework (RMF)
    • NIST SP 800-53 / 800-171
  • Experience supporting audits, compliance programs, and regulatory frameworks
  • Proven ability to lead cross-functional teams and communicate with executive leadership