Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
AI Security Engineer
Houston, TX · On-site
... Cyber Engineers for core roles with a new emphasis on AI security, product risk reviews, and ... Familiarity with AI governance frameworks such as the NIST AI Risk Management Framework or the ...
Quick apply
AI Security Engineer
Houston, TX · On-site
... Cyber Engineers for core roles with a new emphasis on AI security, product risk reviews, and ... Familiarity with AI governance frameworks such as the NIST AI Risk Management Framework or the ...
Acting as a subject matter expert on cloud cyber risk for Microsoft Purview, Microsoft Intune ... Through powerful solutions and managed services that simplify complexity, we enable our clients to ...
Acting as a subject matter expert on cloud cyber risk for Microsoft Purview, Microsoft Intune ... Through powerful solutions and managed services that simplify complexity, we enable our clients to ...
Cloud Security Senior Consultant - M365
$55.75 - $76.25/hr
Acting as a subject matter expert on cloud cyber risk for Microsoft Purview, Microsoft Intune ... Through powerful solutions and managed services that simplify complexity, we enable our clients to ...
Cloud Security Senior Consultant - M365
$55.75 - $76.25/hr
Acting as a subject matter expert on cloud cyber risk for Microsoft Purview, Microsoft Intune ... Through powerful solutions and managed services that simplify complexity, we enable our clients to ...
Cyber - Google Cloud Security - Manager
$106K - $143K/yr
Work you'll do As a Google Cloud Security Manager on the Cloud Cyber Risk team, you will be responsible for... * Leading end-to-end delivery of Google Cloud Platform security engagements, overseeing ...
Cyber - Google Cloud Security - Manager
$106K - $143K/yr
Work you'll do As a Google Cloud Security Manager on the Cloud Cyber Risk team, you will be responsible for... * Leading end-to-end delivery of Google Cloud Platform security engagements, overseeing ...
... cyber and risk management regulations: Proficiency in GRC and tracking in Microsoft Excel, project management, and GRC software is required. Familiarity with the organization's core energy software ...
... cyber and risk management regulations: Proficiency in GRC and tracking in Microsoft Excel, project management, and GRC software is required. Familiarity with the organization's core energy software ...
... cyber and risk management regulations: Proficiency in GRC and tracking in Microsoft Excel, project management, and GRC software is required. Familiarity with the organization's core energy software ...
... cyber and risk management regulations: Proficiency in GRC and tracking in Microsoft Excel, project management, and GRC software is required. Familiarity with the organization's core energy software ...
TM cyber risk programs. Join the team developing the future state of cyber risk solutions. Required ... Cloud Security - DevSecOps Manager Position Summary Are you interested in working in a dynamic ...
TM cyber risk programs. Join the team developing the future state of cyber risk solutions. Required ... Cloud Security - DevSecOps Manager Position Summary Are you interested in working in a dynamic ...
Support cyber monitoring, analytics, crisis management, and incident response ... Advise clients on regulatory, operational, and strategic risk management. * Assist with attack ...
Support cyber monitoring, analytics, crisis management, and incident response ... Advise clients on regulatory, operational, and strategic risk management. * Assist with attack ...
Cyber Network Security Architecture - Senior Manager
$106K - $143K/yr
... cyber risk programs * 4+ years of experience managing teams and delivering workstreams in a client service environment * 3+ years of experience serving in a leadership capacity over the ...
Cyber Network Security Architecture - Senior Manager
$106K - $143K/yr
... cyber risk programs * 4+ years of experience managing teams and delivering workstreams in a client service environment * 3+ years of experience serving in a leadership capacity over the ...
Cyber - Google Cloud Security - Senior Manager
$106K - $143K/yr
Overseeing engagement teams, delivery quality, risk, engagement economics, and coordination across ... or cyber risk programs * 4+ years of experience managing teams and delivering workstreams in a ...
Cyber - Google Cloud Security - Senior Manager
$106K - $143K/yr
Overseeing engagement teams, delivery quality, risk, engagement economics, and coordination across ... or cyber risk programs * 4+ years of experience managing teams and delivering workstreams in a ...
Support cyber monitoring, analytics, crisis management, and incident response ... Advise clients on regulatory, operational, and strategic risk management. * Assist with attack ...
Support cyber monitoring, analytics, crisis management, and incident response ... Advise clients on regulatory, operational, and strategic risk management. * Assist with attack ...
Counsel - Digital, IP & Technology
Houston, TX · On-site
$200K - $260K/yr
The successful candidate will help manage cyber and technology risk across bp's operations, support major cyber incidents and business disruptions, advise on emerging digital regulation, and ...
Counsel - Digital, IP & Technology
Houston, TX · On-site
$200K - $260K/yr
The successful candidate will help manage cyber and technology risk across bp's operations, support major cyber incidents and business disruptions, advise on emerging digital regulation, and ...
Through powerful solutions and managed services that simplify complexity, we enable our clients to ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Through powerful solutions and managed services that simplify complexity, we enable our clients to ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Ability to provide clear guidance to others The team Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices.
Ability to provide clear guidance to others The team Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices.
Cyber Oracle Cloud Security - Manager / Engineering Manager II
Houston, TX · On-site
$106K - $143K/yr
Cyber Oracle Cloud Security - Manager / Engineering Manager II Are you interested in working in a ... Design and deploy Oracle Risk Management Cloud capabilities, including Advanced Access Controls ...
Cyber Oracle Cloud Security - Manager / Engineering Manager II
Houston, TX · On-site
$106K - $143K/yr
Cyber Oracle Cloud Security - Manager / Engineering Manager II Are you interested in working in a ... Design and deploy Oracle Risk Management Cloud capabilities, including Advanced Access Controls ...
Utilizing cyber risk quantification to reduce uncertainty around cyber risk and improve executive ... Managing cybersecurity risk arising from third parties and the supply chain. * Designing ...
Utilizing cyber risk quantification to reduce uncertainty around cyber risk and improve executive ... Managing cybersecurity risk arising from third parties and the supply chain. * Designing ...
Cyber Data Protection/PKI Manager
$106K - $143K/yr
Work you'll do As a Manager, Strategy, Growth, and Transformation on the Cyber Strategy ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Cyber Data Protection/PKI Manager
$106K - $143K/yr
Work you'll do As a Manager, Strategy, Growth, and Transformation on the Cyber Strategy ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Leading Azure cloud cyber risk engagements across governance, identity, application security ... Managing project delivery activities across onshore and offshore teams, including solution design ...
Leading Azure cloud cyber risk engagements across governance, identity, application security ... Managing project delivery activities across onshore and offshore teams, including solution design ...
Cyber Risk Manager information
See Houston, TX salary details
$49.2K - $59.4K
4% of jobs
$59.4K - $69.7K
6% of jobs
$69.7K - $80K
11% of jobs
$83.9K is the 25th percentile. Wages below this are outliers.
$80K - $90.3K
11% of jobs
The median wage is $98.5K / yr.
$90.3K - $100.6K
23% of jobs
$100.6K - $110.9K
13% of jobs
$117.6K is the 75th percentile. Wages above this are outliers.
$110.9K - $121.1K
12% of jobs
$121.1K - $131.4K
8% of jobs
$131.4K - $141.7K
6% of jobs
$141.7K - $152K
4% of jobs
$152K - $162.3K
2% of jobs
$49.2K
$106.5K
$162.3K
How much do cyber risk manager jobs pay per year?
How does a cyber risk manager collaborate with other departments to strengthen an organization's cybersecurity posture?
What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?
| Aspect | Cyber Risk Manager | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CISSP, CEH |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability testing |
| Employer & Industry Usage | Financial, healthcare, large enterprises | IT departments, security firms, corporate environments |
The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.
What are the key skills and qualifications needed to thrive as a cyber risk manager, and why are they important?

Other
This job post has expired 1 day ago. Applications are no longer accepted.
Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
45th of 150 rated financial services
Job description
Power and Utilities OT (Operational Technology) - Senior Consultant
Position Summary
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cyber team and become a member of the largest group of cybersecurity professionals worldwide.
Recruiting for this role ends on 12/21/2026
Work you'll do
Responsibilities:
- Identify and evaluate complex business and technology risks
- Develop remediation methods to mitigate risks
- Demonstrate problem solving, critical thinking and logical structuring skills
- Assist in the selection and tailoring of approaches, methods and tools to support service offering or industry projects
- Actively participate in decision making with engagement management and seek to understand the broader impact of current decisions
- Facilitate use of technology-based tools or methodologies to review, design and/or implement products and services
- Identify opportunities to improve engagement profitability and manage engagement economics
- Demonstrate ability to with identify and address client needs: building solid relationships with clients; developing an awareness of Firm services; communicating with the client in an organized and knowledgeable manner; delivering clear requests for information; demonstrating flexibility in prioritizing and completing tasks; and communicating potential conflicts to the manager
- Demonstrate a general knowledge of market trends, competitor activities, Deloitte Advisory products and service lines
Required Skills:
- 5+ years of demonstrate advanced understanding and experience governing and implementing power and utility regulations and standards including:
- North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP)
- NERC Operations and Planning (O&P)
- Federal Energy Regulatory Commission
- Transportation Security Administration (TSA) Cybersecurity
- IEC 62443 standard - Securing Industrial Automation and Control Systems (IACS)
- Nuclear Energy Institute (NEI) - NEI 08-09, 10 CFR 73.54
- 5+ years of demonstrate advanced understanding and cyber risk management in at least two of the following areas:
- SCADA with experience in securing ICS (Industrial Control Systems) security
- Internet of Things (IOT) architecture and security
- OT (Operational Technology) security
- NERC CIP-015 - Internal Network Security Monitoring (INMS)
- Embedded systems security
- OT network segmentation (zones/conduits), jump hosts, secure remote access
- Passive OT discovery/asset inventory, OT IDS, SIEM integration/use cases
- Incident response in OT (containment with availability/safety constraints)
- Vendor/OEM risk management, SBOM/patch constraints, compensating controls
- Security experience in the field environment within the Power, Utilities & Renewables, Oil & Gas, or Industrial Products & Construction industry sectors
- 5+ years of demonstrate advanced understanding of business processes and cyber risk management in an OT / SCADA environment in two or more areas such as:
- Cyber security
- Secure Supply Chain
- Security Analytics
- Security Operations Centers
- Vulnerability and Threat Management
- Data Security
- Secure Dev Ops
- Business continuity management
- Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF)
- Limited sponsorship opportunities may be available
Additional Requirements:
- Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve
- Locations include: Houston, Dallas, Cleveland, Detroit, St. Louis, Pittsburgh, Boston, Charlotte, Atlanta, Miami, Memphis, Denver, Phoenix, Salt Lake City, Los Angeles, San Diego, San Franciso, Seattle. Must be within a reasonable commute and willing to work part-time in the Deloitte and/or client offices.
Preferred:
- Minimum of 2 years working in an OT environment (e.g. OT security, ICS security, IOT security, SCADA, etc.)
- Minimum 2 years designing security for infrastructure, network and application architectures
- Experience in the Power Utilities & Renewables, Oil & Gas, or Industrial Products & Construction sector
- Demonstrated experience working with cloud platforms (AWS, Azure)
- 5+ years implementing security solutions
- BA/BS in cyber security, information security, engineering, computer science, information technology, information management, information sciences, business administration, or related field preferred
- CISSP, CISM, or CISA certification a plus
- Excellent verbal and written communication
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberES26
Power and Utilities OT (Operational Technology) - Senior Consultant
Position Summary
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cyber team and become a member of the largest group of cybersecurity professionals worldwide.
Recruiting for this role ends on 12/21/2026
Work you'll do
Responsibilities:
- Identify and evaluate complex business and technology risks
- Develop remediation methods to mitigate risks
- Demonstrate problem solving, critical thinking and logical structuring skills
- Assist in the selection and tailoring of approaches, methods and tools to support service offering or industry projects
- Actively participate in decision making with engagement management and seek to understand the broader impact of current decisions
- Facilitate use of technology-based tools or methodologies to review, design and/or implement products and services
- Identify opportunities to improve engagement profitability and manage engagement economics
- Demonstrate ability to with identify and address client needs: building solid relationships with clients; developing an awareness of Firm services; communicating with the client in an organized and knowledgeable manner; delivering clear requests for information; demonstrating flexibility in prioritizing and completing tasks; and communicating potential conflicts to the manager
- Demonstrate a general knowledge of market trends, competitor activities, Deloitte Advisory products and service lines
Required Skills:
- 5+ years of demonstrate advanced understanding and experience governing and implementing power and utility regulations and standards including:
- North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP)
- NERC Operations and Planning (O&P)
- Federal Energy Regulatory Commission
- Transportation Security Administration (TSA) Cybersecurity
- IEC 62443 standard - Securing Industrial Automation and Control Systems (IACS)
- Nuclear Energy Institute (NEI) - NEI 08-09, 10 CFR 73.54
- 5+ years of demonstrate advanced understanding and cyber risk management in at least two of the following areas:
- SCADA with experience in securing ICS (Industrial Control Systems) security
- Internet of Things (IOT) architecture and security
- OT (Operational Technology) security
- NERC CIP-015 - Internal Network Security Monitoring (INMS)
- Embedded systems security
- OT network segmentation (zones/conduits), jump hosts, secure remote access
- Passive OT discovery/asset inventory, OT IDS, SIEM integration/use cases
- Incident response in OT (containment with availability/safety constraints)
- Vendor/OEM risk management, SBOM/patch constraints, compensating controls
- Security experience in the field environment within the Power, Utilities & Renewables, Oil & Gas, or Industrial Products & Construction industry sectors
- 5+ years of demonstrate advanced understanding of business processes and cyber risk management in an OT / SCADA environment in two or more areas such as:
- Cyber security
- Secure Supply Chain
- Security Analytics
- Security Operations Centers
- Vulnerability and Threat Management
- Data Security
- Secure Dev Ops
- Business continuity management
- Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF)
- Limited sponsorship opportunities may be available
Additional Requirements:
- Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve
- Locations include: Houston, Dallas, Cleveland, Detroit, St. Louis, Pittsburgh, Boston, Charlotte, Atlanta, Miami, Memphis, Denver, Phoenix, Salt Lake City, Los Angeles, San Diego, San Franciso, Seattle. Must be within a reasonable commute and willing to work part-time in the Deloitte and/or client offices.
Preferred:
- Minimum of 2 years working in an OT environment (e.g. OT security, ICS security, IOT security, SCADA, etc.)
- Minimum 2 years designing security for infrastructure, network and application architectures
- Experience in the Power Utilities & Renewables, Oil & Gas, or Industrial Products & Construction sector
- Demonstrated experience working with cloud platforms (AWS, Azure)
- 5+ years implementing security solutions
- BA/BS in cyber security, information security, engineering, computer science, information technology, information management, information sciences, business administration, or related field preferred
- CISSP, CISM, or CISA certification a plus
- Excellent verbal and written communication
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberES26