The Cybersecurity Risk Analyst supports the organization's cyber risk management program by identifying, assessing, documenting, and communicating cyber risk across systems, applications ...
The Cybersecurity Risk Analyst supports the organization's cyber risk management program by identifying, assessing, documenting, and communicating cyber risk across systems, applications ...
Cybersecurity Risk Analyst
Houston, TX · On-site
The Cybersecurity Risk Analyst supports the organization's cyber risk management program by identifying, assessing, documenting, and communicating cyber risk across systems, applications ...
Cybersecurity Risk Analyst
Houston, TX · On-site
The Cybersecurity Risk Analyst supports the organization's cyber risk management program by identifying, assessing, documenting, and communicating cyber risk across systems, applications ...
The Cybersecurity Risk Analyst supports the organization's cyber risk management program by identifying, assessing, documenting, and communicating cyber risk across systems, applications ...
The Cybersecurity Risk Analyst supports the organization's cyber risk management program by identifying, assessing, documenting, and communicating cyber risk across systems, applications ...
Director - Cyber Third Party Risk Management (CTPRM)
Chicago, IL · Hybrid
$137.40K - $240.40K/yr
Lead cyber risk assessments, oversight, and remediation for critical and high-risk third parties. * Drive continuous improvement in third-party risk processes, automation, and tooling. * Provide ...
Director - Cyber Third Party Risk Management (CTPRM)
Chicago, IL · Hybrid
$137.40K - $240.40K/yr
Lead cyber risk assessments, oversight, and remediation for critical and high-risk third parties. * Drive continuous improvement in third-party risk processes, automation, and tooling. * Provide ...
MD GRC Risk Management and Governance
Quincy, MA · Hybrid
$170K - $282.50K/yr
The Managing Director, Cyber Risk Management & Governance will lead a team responsible for the design, execution, and oversight of the cyber risk management and governance framework. This role ...
MD GRC Risk Management and Governance
Quincy, MA · Hybrid
$170K - $282.50K/yr
The Managing Director, Cyber Risk Management & Governance will lead a team responsible for the design, execution, and oversight of the cyber risk management and governance framework. This role ...
Director - Cyber Third Party Risk Management (CTPRM)
Chicago, IL · On-site
$137.40K - $240.40K/yr
Lead cyber risk assessments, oversight, and remediation for critical and high-risk third parties. * Drive continuous improvement in third-party risk processes, automation, and tooling. * Provide ...
Director - Cyber Third Party Risk Management (CTPRM)
Chicago, IL · On-site
$137.40K - $240.40K/yr
Lead cyber risk assessments, oversight, and remediation for critical and high-risk third parties. * Drive continuous improvement in third-party risk processes, automation, and tooling. * Provide ...
MD GRC Risk Management and Governance
Boston, MA · Hybrid
$170K - $282.50K/yr
The Managing Director, Cyber Risk Management & Governance will lead a team responsible for the design, execution, and oversight of the cyber risk management and governance framework. This role ...
MD GRC Risk Management and Governance
Boston, MA · Hybrid
$170K - $282.50K/yr
The Managing Director, Cyber Risk Management & Governance will lead a team responsible for the design, execution, and oversight of the cyber risk management and governance framework. This role ...
Cyber Risk Senior Associate
Detroit, MI · On-site
$55 - $60/hr
As a Cyber Risk Senior Associate, you will get the opportunity to contribute to our clients' business needs and grow within our practice by applying a collection of cybersecurity capabilities ...
Quick apply
Cyber Risk Senior Associate
Detroit, MI · On-site
$55 - $60/hr
As a Cyber Risk Senior Associate, you will get the opportunity to contribute to our clients' business needs and grow within our practice by applying a collection of cybersecurity capabilities ...
The Senior Manager Cyber Risk & Governance leads cybersecurity governance, cyber risk management, and security awareness programs while ensuring alignment with enterprise risk management strategies ...
The Senior Manager Cyber Risk & Governance leads cybersecurity governance, cyber risk management, and security awareness programs while ensuring alignment with enterprise risk management strategies ...
MD GRC Risk Management and Governance
Quincy, MA · On-site
$170K - $282.50K/yr
The Managing Director, Cyber Risk Management & Governance will lead a team responsible for the design, execution, and oversight of the cyber risk management and governance framework. This role ...
MD GRC Risk Management and Governance
Quincy, MA · On-site
$170K - $282.50K/yr
The Managing Director, Cyber Risk Management & Governance will lead a team responsible for the design, execution, and oversight of the cyber risk management and governance framework. This role ...
The SEI CERT Cyber Risk and Resilience Directorate, enables organizations to achieve operational resilience by performing research in emerging areas of operational risk, producing measurement and ...
The SEI CERT Cyber Risk and Resilience Directorate, enables organizations to achieve operational resilience by performing research in emerging areas of operational risk, producing measurement and ...
The SEI CERT Cyber Risk and Resilience Directorate, enables organizations to achieve operational resilience by performing research in emerging areas of operational risk, producing measurement and ...
The SEI CERT Cyber Risk and Resilience Directorate, enables organizations to achieve operational resilience by performing research in emerging areas of operational risk, producing measurement and ...
Raritan, New Jersey, United States of America Johnson & Johnson is recruiting for a Principal - Third Party Cyber Risk Assessment to join the Information Security & Risk Management (ISRM) Risk ...
Raritan, New Jersey, United States of America Johnson & Johnson is recruiting for a Principal - Third Party Cyber Risk Assessment to join the Information Security & Risk Management (ISRM) Risk ...
The SEI CERT Cyber Risk and Resilience Directorate, enables organizations to achieve operational resilience by performing research in emerging areas of operational risk, producing measurement and ...
The SEI CERT Cyber Risk and Resilience Directorate, enables organizations to achieve operational resilience by performing research in emerging areas of operational risk, producing measurement and ...
Lead enterprise cyber risk quantification using FAIR, Monte Carlo simulation, calibrated estimation, and complementary statistical methods. Define risk analysis scope, assumptions, and ranges; build ...
Lead enterprise cyber risk quantification using FAIR, Monte Carlo simulation, calibrated estimation, and complementary statistical methods. Define risk analysis scope, assumptions, and ranges; build ...
Knowledge/Skills/Abilities: • Lead enterprise cyber risk quantification using FAIR, Monte Carlo simulation, calibrated estimation, and complementary statistical methods. • Define risk analysis ...
Knowledge/Skills/Abilities: • Lead enterprise cyber risk quantification using FAIR, Monte Carlo simulation, calibrated estimation, and complementary statistical methods. • Define risk analysis ...
The SEI CERT Cyber Risk and Resilience Directorate, enables organizations to achieve operational resilience by performing research in emerging areas of operational risk, producing measurement and ...
The SEI CERT Cyber Risk and Resilience Directorate, enables organizations to achieve operational resilience by performing research in emerging areas of operational risk, producing measurement and ...
Raritan, New Jersey, United States of America Johnson & Johnson is recruiting for a Principal - Third Party Cyber Risk Assessment to join the Information Security & Risk Management (ISRM) Risk ...
Raritan, New Jersey, United States of America Johnson & Johnson is recruiting for a Principal - Third Party Cyber Risk Assessment to join the Information Security & Risk Management (ISRM) Risk ...
Lead enterprise cyber risk quantification using FAIR, Monte Carlo simulation, calibrated estimation, and complementary statistical methods. Define risk analysis scope, assumptions, and ranges; build ...
Lead enterprise cyber risk quantification using FAIR, Monte Carlo simulation, calibrated estimation, and complementary statistical methods. Define risk analysis scope, assumptions, and ranges; build ...
Technical Marketing Manager - Cyber Risk Location Remote, US Req ID R434519 Job Type Full Time Category Product Development Date posted 04/09/2026 Job Summary ABOUT DATABEE DataBee ( is a security ...
Technical Marketing Manager - Cyber Risk Location Remote, US Req ID R434519 Job Type Full Time Category Product Development Date posted 04/09/2026 Job Summary ABOUT DATABEE DataBee ( is a security ...
Cyber Risk information
See salary details
$68.5K - $77K
3% of jobs
$77K - $85.5K
0% of jobs
$85.5K - $94K
3% of jobs
$94K - $102.5K
7% of jobs
$102.5K - $111K
10% of jobs
$112.7K is the 25th percentile. Wages below this are outliers.
$111K - $119.5K
5% of jobs
$119.5K - $128K
18% of jobs
The median wage is $129.7K / yr.
$128K - $136.5K
16% of jobs
$144.3K is the 75th percentile. Wages above this are outliers.
$136.5K - $145K
14% of jobs
$145K - $153.5K
13% of jobs
$153.5K - $162K
11% of jobs
$68.5K
$128.9K
$162K
How much do cyber risk jobs pay per year?
What are the key skills and qualifications needed to thrive as a Cyber Risk professional, and why are they important?
What are some typical challenges faced by professionals in a Cyber Risk role, and how can they be addressed?
What is cyber risk?
What is the difference between Cyber Risk vs Cyber Security Analyst?
| Aspect | Cyber Risk | Cyber Security Analyst |
|---|---|---|
| Primary Focus | Identifying, assessing, and managing cybersecurity risks and vulnerabilities | Monitoring, analyzing, and responding to security threats and incidents |
| Required Credentials | Certifications like CISSP, CISM, CRISC; risk management experience | Certifications like CompTIA Security+, CISSP; technical security skills |
| Work Environment | Risk management teams, compliance departments, strategic planning | Security operations centers, IT teams, incident response teams |
| Industry Usage | Used across finance, healthcare, government for risk mitigation | Used in IT and cybersecurity departments for threat defense |
While both roles focus on cybersecurity, Cyber Risk professionals primarily assess and manage potential threats at a strategic level, whereas Cyber Security Analysts focus on technical threat detection and response. Understanding these differences helps organizations allocate resources effectively and align roles with their security objectives.

Job description
As an NRG employee, we encourage you to take charge of your career and development journey. We invite you to explore exciting opportunities across our businesses. You'll find that our dynamic work environment provides variety and challenge. Your growth is key to our ongoing success-take the lead in shaping your career development, goals and future!
JOB SUMMARY:
The Cybersecurity Risk Analyst supports the organization's cyber risk management program by identifying, assessing, documenting, and communicating cyber risk across systems, applications, technologies, and business initiatives. This role partners with Technology, Business, Enterprise Risk and other stakeholders to enable risk-informed decisions and practical risk treatment outcomes.
The role is focused on internal cybersecurity risk assessments evaluating threats, vulnerabilities, control gaps, and business impact while helping stakeholders align on risk acceptance decisions consistent with organizational risk tolerance. Work is guided by the NIST CSF 2.0, with expected familiarity with FAIR and professional AI tools, as well as awareness of emerging technology risks and evolving cyber threats. This role is distinct from team responsibilities centered on third-party risk, vendor contracts, security surveys, or regulatory compliance.
Essential Duties and Responsibilities:
Cybersecurity Risk Assessment- Conduct cybersecurity risk assessments for systems, applications, infrastructure, technologies, projects, and business initiatives.
- Identify, assess, analyze, and document cybersecurity threats, vulnerabilities, control gaps, exploitability considerations, and potential business impacts.
- Evaluate inherent and residual cyber risk and develop clear, supportable risk statements, ratings, and recommendations.
- Apply established cybersecurity risk assessment methodologies, frameworks, and reference materials, including FAIR and other relevant cyber risk analysis approaches.
- Support practical and well-informed cyber risk treatment recommendations, including mitigation, remediation, transfer, avoidance, and acceptance.
- Assist in identifying and documenting reasonable cyber risk acceptance positions aligned with business objectives, governance expectations, and organizational risk tolerance.
- Partner with stakeholders across Technology, Cybersecurity, Business, and Enterprise Risk to gather information and support effective cyber risk assessments.
- Facilitate meetings, workshops, and working sessions to bring the right stakeholders together for risk identification, analysis, treatment, and acceptance discussions.
- Build alignment across teams and help translate technical cybersecurity issues into clear business risk implications and decision points.
- Coordinate with team members responsible for adjacent activities, including third-party risk management, compliance support, contract review, security surveys, and regulatory matters, while maintaining primary focus on internal cyber risk assessment and analysis.
- Work closely with vulnerability management and other cybersecurity teams to understand vulnerability exposure, remediation priorities, compensating controls, and the impact of technical findings on cyber risk.
- Analyze vulnerability data, remediation status, exploitability, and exposure trends to inform cyber risk assessments and recommendations.
- Maintain awareness of emerging cyber threats, attack techniques, threat actor activity, and technology developments that may affect the organization's risk posture.
- Collect, organize, analyze, and report cybersecurity risk metrics, trends, and themes to support leadership reporting and program oversight.
- Prepare clear and concise risk assessment documentation, reports, summaries, and presentations for technical and non-technical stakeholders.
- Support the continuous improvement of cybersecurity risk assessment processes, templates, standards, and reporting practices.
- Use approved AI-enabled tools responsibly to support cyber risk research, analysis, documentation, and operational efficiency in accordance with company requirements.
- Incorporate considerations related to artificial intelligence, generative AI, and other emerging technology risks into cybersecurity risk assessments, as applicable.
Working Conditions:
- Hybrid.
- Travel minimally.
Minimum Requirements:
- A bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, Business, or a related field is preferred but not required.
- A minimum of five years of experience in cybersecurity, information security, cyber risk, technology risk, vulnerability management, IT audit, or a related discipline is essential.
- Demonstrated experience performing cybersecurity or technology risk assessments is required.
- Familiarity with the NIST Cybersecurity Framework (CSF) 2.0 is required.
- Familiarity with FAIR and other recognized cybersecurity risk assessment methodologies, models, or reference resources are required.
- Experience with vulnerability management concepts, processes, and reporting, including the ability to interpret vulnerability data in a risk context, is required.
- Proficiency in Microsoft Office products, including Word, Excel, PowerPoint, and SharePoint, is expected.
- Ability to effectively apply approved AI technologies such as CoPilot in a professional environment is expected.
Additional Knowledge, Skills and Abilities:
Technical & Domain Expertise:- Strong understanding of cybersecurity risk principles, threats, vulnerabilities, control environments, and risk treatment concepts.
- Working knowledge of cybersecurity frameworks and references, including NIST CSF 2.0, and familiarity with related standards such as NIST 800-53, CIS Controls, ISO 27001, or COBIT.
- Familiarity with cyber risk analysis methods such as FAIR; familiarity with quantitative risk analysis concepts, including Monte Carlo simulation, is preferred but not required.
- Knowledge of vulnerability management practices and the ability to connect technical findings to broader business and cyber risk considerations.
- Awareness of artificial intelligence, generative AI, and emerging technology risks, and the ability to incorporate those considerations into cyber risk assessments.
- Experience in energy, utilities, critical infrastructure, or other highly regulated industries is preferred.
- Knowledge of operational technology, industrial control systems, or energy generation and retail environments is preferred.
- Strong analytical, critical thinking, and problem-solving capabilities.
- Effective stakeholder engagement and facilitation skills, with the ability to bring teams together and drive productive risk discussions.
- Ability to gather, interpret, and present risk metrics and related data in a meaningful and actionable manner.
- Strong written and verbal communication skills, including the ability to prepare professional documentation and communicate effectively with both technical and non-technical audiences.
- Ability to translate complex cybersecurity issues into clear, concise, and business-relevant risk information.
- Strong organizational skills and the ability to manage multiple priorities while delivering high-quality work within established deadlines.
- Demonstrated ability to work collaboratively across Cybersecurity, Technology, Business, and Enterprise Risk teams.
Physical Requirements:
- From time to it may be required to move light computer equipment such as laptops.
NRG Energy is committed to a drug and alcohol-free workplace. To the extent permitted by law and any applicable collective bargaining agreement, employees are subject to periodic random drug testing, and post-accident and reasonable suspicion drug and alcohol testing. EOE AA M/F/Vet/Disability. Level, Title and/or Salary may be adjusted based on the applicant's experience or skills.
Official description on file with Talent.
About NRG
Sourced by ZipRecruiter
At NRG, we're bringing the power of energy to people and organizations by putting customers at the center of everything we do. We generate electricity and provide energy solutions and natural gas to millions of customers through our diverse portfolio of retail brands. A Fortune 500 company, operating in the United States and Canada, NRG delivers innovative solutions while advocating for competitive energy markets and customer choice, working towards a sustainable energy future. More information is available at www.nrg.com. Connect with NRG on Facebook, LinkedIn and follow us on Twitter @nrgenergy.
Industry
Oil and coal products manufacturing
Company size
5,001 - 10,000 Employees
Headquarters location
Houston, TX, US