The ISO is responsible for leading the organization's Security Risk Analysis (SRA), cybersecurity risk management, PCI compliance, data governance, AI governance, vendor risk management, and ...
The ISO is responsible for leading the organization's Security Risk Analysis (SRA), cybersecurity risk management, PCI compliance, data governance, AI governance, vendor risk management, and ...
The ISO is responsible for leading the organization's Security Risk Analysis (SRA), cybersecurity risk management, PCI compliance, data governance, AI governance, vendor risk management, and ...
The ISO is responsible for leading the organization's Security Risk Analysis (SRA), cybersecurity risk management, PCI compliance, data governance, AI governance, vendor risk management, and ...
Senior Risk and Vulnerability Analyst with Security Clearance
Chandler, AZ · On-site
$104K - $166K/yr
The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by ... Bachelor's degree in Cybersecurity, Information Technology, or related field. An additional 4 years ...
Senior Risk and Vulnerability Analyst with Security Clearance
Chandler, AZ · On-site
$104K - $166K/yr
The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by ... Bachelor's degree in Cybersecurity, Information Technology, or related field. An additional 4 years ...
Job Title: Cyber Security Remediation Analyst Location: Phoenix, AZ (Remote) Job Type: Contract ... Track ownership, remediation milestones, evidence, exceptions, and risk acceptance requests
Job Title: Cyber Security Remediation Analyst Location: Phoenix, AZ (Remote) Job Type: Contract ... Track ownership, remediation milestones, evidence, exceptions, and risk acceptance requests
Strong troubleshooting and analytical problem-solving skills. * Excellent written and verbal ... Experience conducting cybersecurity risk assessments. * Experience implementing Security Technical ...
Strong troubleshooting and analytical problem-solving skills. * Excellent written and verbal ... Experience conducting cybersecurity risk assessments. * Experience implementing Security Technical ...
Experience performing system vulnerability analysis and remediation. * Working knowledge of ... Experience conducting cybersecurity risk assessments. * Experience implementing Security Technical ...
Experience performing system vulnerability analysis and remediation. * Working knowledge of ... Experience conducting cybersecurity risk assessments. * Experience implementing Security Technical ...
Strong analytical, communication, and executive stakeholder management skills. Preferred Qualifications * Advanced degree in Computer Science, Information Systems, Cybersecurity, Risk Management, or ...
Strong analytical, communication, and executive stakeholder management skills. Preferred Qualifications * Advanced degree in Computer Science, Information Systems, Cybersecurity, Risk Management, or ...
Cyber Security Analyst/ISSO with Security Clearance
Tucson, AZ · On-site
$88K - $110K/yr
Areté is immediately seeking a full-time Cyber Security Analyst/Information Systems Security ... Perform and document system audits and risk analysis. * Manage and execute Continuous Monitoring ...
Cyber Security Analyst/ISSO with Security Clearance
Tucson, AZ · On-site
$88K - $110K/yr
Areté is immediately seeking a full-time Cyber Security Analyst/Information Systems Security ... Perform and document system audits and risk analysis. * Manage and execute Continuous Monitoring ...
Knowledge in identifying cybersecurity and privacy issues that stem from connections with internal ... Skill Risk Management Framework (RMF) Certification Education License Other Skill Windows/Unix ...
Quick apply
Knowledge in identifying cybersecurity and privacy issues that stem from connections with internal ... Skill Risk Management Framework (RMF) Certification Education License Other Skill Windows/Unix ...
Sr Cyber Security
Tempe, AZ · On-site
As a Sr Cyber Security Architect/Engineer here at Honeywell, you will lead the design and ... Conduct in-depth security assessments and risk analysis to identify vulnerabilities and recommend ...
Sr Cyber Security
Tempe, AZ · On-site
As a Sr Cyber Security Architect/Engineer here at Honeywell, you will lead the design and ... Conduct in-depth security assessments and risk analysis to identify vulnerabilities and recommend ...
Cybersecurity Analyst
Tempe, AZ · On-site
$64K - $83K/yr
Cybersecurity Analyst Job ID: 322802 Location: District Support Services Cntr Full/Part Time ... Evaluates network and system configurations against best practices (e.g., CIS benchmarks) and risk ...
Cybersecurity Analyst
Tempe, AZ · On-site
$64K - $83K/yr
Cybersecurity Analyst Job ID: 322802 Location: District Support Services Cntr Full/Part Time ... Evaluates network and system configurations against best practices (e.g., CIS benchmarks) and risk ...
Cybersecurity Product & Service Delivery Specialist, AVP
Tempe, AZ · On-site
$13.25 - $16.50/hr
Partner with cybersecurity, risk, and control teams to coordinate remediation efforts, track ... Strong analytical and decision-making skills with the ability to manage multiple workstreams and ...
Cybersecurity Product & Service Delivery Specialist, AVP
Tempe, AZ · On-site
$13.25 - $16.50/hr
Partner with cybersecurity, risk, and control teams to coordinate remediation efforts, track ... Strong analytical and decision-making skills with the ability to manage multiple workstreams and ...
Cybersecurity Product & Service Delivery Specialist, AVP
Tempe, AZ · Hybrid
$13.25 - $16.50/hr
Partner with cybersecurity, risk, and control teams to coordinate remediation efforts, track ... Strong analytical and decision-making skills with the ability to manage multiple workstreams and ...
Cybersecurity Product & Service Delivery Specialist, AVP
Tempe, AZ · Hybrid
$13.25 - $16.50/hr
Partner with cybersecurity, risk, and control teams to coordinate remediation efforts, track ... Strong analytical and decision-making skills with the ability to manage multiple workstreams and ...
Risk Treatment Specialist
Tempe, AZ · Hybrid
$108K - $185K/yr
Produce impactful and insightful thematic analysis to support proactive risk management * Maintain ... Operational Risk, Financial Risk,Cyber Resilience, Cybersecurity, Risk Management, IT ...
Risk Treatment Specialist
Tempe, AZ · Hybrid
$108K - $185K/yr
Produce impactful and insightful thematic analysis to support proactive risk management * Maintain ... Operational Risk, Financial Risk,Cyber Resilience, Cybersecurity, Risk Management, IT ...
Demonstrated experience leveraging or governing AI/ML, automation, or advanced analytics within cybersecurity, risk, or compliance domains preferred. * Strong understanding of data architectures ...
Demonstrated experience leveraging or governing AI/ML, automation, or advanced analytics within cybersecurity, risk, or compliance domains preferred. * Strong understanding of data architectures ...
Serve as the primary authority on test design, data analysis, and risk assessment for the system's cybersecurity posture. * Develop and manage all strategic cyber assessment documentation, including ...
Serve as the primary authority on test design, data analysis, and risk assessment for the system's cybersecurity posture. * Develop and manage all strategic cyber assessment documentation, including ...
Risk Treatment Specialist
Tempe, AZ · On-site
$108K - $185K/yr
Produce impactful and insightful thematic analysis to support proactive risk management * Maintain ... Operational Risk, Financial Risk, Cyber Resilience, Cybersecurity, Risk Management, IT Risk and ...
Risk Treatment Specialist
Tempe, AZ · On-site
$108K - $185K/yr
Produce impactful and insightful thematic analysis to support proactive risk management * Maintain ... Operational Risk, Financial Risk, Cyber Resilience, Cybersecurity, Risk Management, IT Risk and ...
Cybersecurity Program Management - Leadership
Chandler, AZ · On-site +1
$123K - $207K/yr
... case analysis, including Earned Value Management (EVM) and/or return on investment analysis ... Working with DHS HQ and/or Component experts to draft and publish supply chain security and risk ...
Cybersecurity Program Management - Leadership
Chandler, AZ · On-site +1
$123K - $207K/yr
... case analysis, including Earned Value Management (EVM) and/or return on investment analysis ... Working with DHS HQ and/or Component experts to draft and publish supply chain security and risk ...
Demonstrated experience leveraging or governing AI/ML, automation, or advanced analytics within cybersecurity, risk, or compliance domains preferred. * Strong understanding of data architectures ...
Demonstrated experience leveraging or governing AI/ML, automation, or advanced analytics within cybersecurity, risk, or compliance domains preferred. * Strong understanding of data architectures ...
IAM Risk Audit (CIAM) - Lead
Tempe, AZ · On-site
$99K - $169K/yr
This position partners with cyber security, risk management, audit, compliance, technology teams ... The role combines risk management, analytical reporting, process improvement, and a strong ...
IAM Risk Audit (CIAM) - Lead
Tempe, AZ · On-site
$99K - $169K/yr
This position partners with cyber security, risk management, audit, compliance, technology teams ... The role combines risk management, analytical reporting, process improvement, and a strong ...
Cyber Security Risk Analyst information
See Arizona salary details
$40.1K - $49.1K
1% of jobs
$49.1K - $58.2K
6% of jobs
$58.2K - $67.3K
10% of jobs
$73.4K is the 25th percentile. Wages below this are outliers.
$67.3K - $76.3K
12% of jobs
$76.3K - $85.4K
15% of jobs
The median wage is $89.3K / yr.
$85.4K - $94.5K
15% of jobs
$94.5K - $103.5K
10% of jobs
$107.5K is the 75th percentile. Wages above this are outliers.
$103.5K - $112.6K
16% of jobs
$112.6K - $121.7K
7% of jobs
$121.7K - $130.7K
5% of jobs
$130.7K - $139.8K
3% of jobs
$40.1K
$92.6K
$139.8K
How much do cyber security risk analyst jobs pay per year?
What are the key skills and qualifications needed to thrive in the cyber security risk analyst position, and why are they important?
A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.
What is a cyber security risk analyst?
A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.
What are some typical challenges faced by cyber security risk analysts on the job?
Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.
What does a cybersecurity risk analyst do?
How much does a cyber security risk analyst make?

Full-time
Re-posted 2 days ago
Job description
The Information Security Officer (ISO) is responsible for. providing enterprise leadership, accountability and subject matter expertise for information security, cybersecurity, compliance, risk management, and governance activities. The ISO serves as the organization's primary authority on the protection, governance, and responsible use of information assets, ensuring compliance with regulatory requirements while supporting organizational growth, innovation, and patient care.
This position develops and maintains enterprise-wide security, governance, and risk management frameworks that safeguard organizational data and technology resources. The ISO collaborates closely with executive leadership, Information Technology, Clinical Informatics, Compliance, Operations, Human Resources, and business stakeholders to establish policies, standards, and governance processes that support organizational objectives.
The ISO is responsible for leading the organization's Security Risk Analysis (SRA), cybersecurity risk management, PCI compliance, data governance, AI governance, vendor risk management, and regulatory compliance programs.
The ISO serves as a trusted advisor to executive leadership regarding cybersecurity strategy, HIPAA Security Rule compliance, contingency planning, data governance, AI governance, enterprise risk management, regulatory compliance, and emerging technology risks.
Marana Health is a Federally Qualified Community Health Center (FQHC), with 11 sites in Tucson and Pima County. Our mission is to improve our community by providing exceptional, whole-person healthcare.
The following qualifications are required:
- Bachelor's degree in Information Security, Cybersecurity, Information Technology, Information Systems, Computer Science, Healthcare Informatics, Business Administration, or related field required.
- Minimum seven (7) years of progressively responsible experience in information security, cybersecurity, risk management, governance, compliance, or healthcare technology leadership, including experience conducting Security Risk Analyses (SRA), risk management activities, and regulatory compliance initiatives.
- Minimum three (3) years of experience developing, implementing, or managing enterprise security, governance, or compliance programs.
- Fingerprint Clearance Card through the Arizona Department of Public Safety.
- Current Arizona driver's license with clean driving record and proof of current vehicle insurance (39-month MVR will be run by MH)
- Experience conducting risk assessments, developing policies, and implementing security controls.
- Experience managing vendor security reviews and regulatory compliance initiatives.
- Experience leading cross-functional projects and organizational initiatives.
- Experience presenting information to executive leadership and organizational stakeholders.
- Strong understanding of ambulatory healthcare workflows and healthcare operations.
The following qualifications are preferred:
- Master's degree in Information Security, Cybersecurity, Information Technology, Healthcare Informatics, Business Administration, or related field.
- Experience supporting Federally Qualified Health Centers (FQHCs), healthcare systems, or ambulatory healthcare organizations.
- Experience serving as a HIPAA Security Officer or equivalent security leadership role.
- Experience implementing NIST Cybersecurity Framework, CIS Controls, HITRUST, or similar governance and security frameworks.
- Experience leading enterprise data governance initiatives.
- Experience developing AI governance programs and responsible technology governance frameworks.
- Experience managing regulatory audits, security assessments, and compliance reviews.
- Experience leading enterprise Security Risk Analyses (SRA), risk remediation programs, and regulatory compliance initiatives.
- Experience managing PCI DSS compliance programs, assessments, and remediation activities.
CERTIFICATIONS
One or more of the following certifications is preferred:
- CISSP - Certified Information Systems Security Professional
- HCISPP - Healthcare Information Security and Privacy Practitioner
- CISM - Certified Information Security Manager
- CRISC - Certified in Risk and Information Systems Control
- CISA - Certified Information Systems Auditor
- CDMP - Certified Data Management Professional
- Security+
Equivalent combination of education and experience may be considered if applicable and must be directly related to the functions and body of knowledge required to successfully perform the job.
The ideal candidate will also possess the following knowledge, skills, and abilities:
- Thorough knowledge of HIPAA Security Rule requirements and healthcare cybersecurity practices.
- Strong understanding of data governance, data stewardship, data quality, data lifecycle management, and information management principles.
- Knowledge of NIST Cybersecurity Framework, CIS Controls, HITRUST, and other industry-recognized security standards.
- Understanding of cloud security, identity and access management, network security, endpoint protection, vulnerability management, and incident response.
- Knowledge of vendor risk management, third-party security assessments, and contract security requirements.
- Understanding of AI governance frameworks, emerging technologies, and associated security and compliance risks.
- Knowledge of Security Risk Analysis (SRA) methodologies, risk assessment frameworks, and risk management best practices.
- Knowledge of PCI DSS requirements and payment card security standards.
- Ability to develop and implement organizational policies, standards, and governance frameworks.
- Ability to communicate complex technical concepts effectively to executive, clinical, operational, and non-technical audiences.
- Knowledge of contingency planning, business continuity planning, disaster recovery planning, and emergency preparedness frameworks.
- Ability to develop, implement, test, and maintain organizational contingency and recovery plans for critical business and technology functions.
- Strong analytical, organizational, problem-solving, and project management skills.
- Ability to build collaborative relationships across departments and influence organizational decision-making.
- Excellent written, verbal, presentation, and facilitation skills.
- Ability to manage multiple priorities and initiatives in a dynamic healthcare environment.
Duties and Responsibilities:
Information Security Leadership
- Develop, implement, and maintain a comprehensive enterprise information security program aligned with organizational goals and industry best practices.
- Establish and maintain information security policies, standards, procedures, and controls.
- Lead cybersecurity governance initiatives and provide strategic guidance to executive leadership.
- Develop and maintain cybersecurity, compliance, governance, and risk management metrics, dashboards, and key performance indicators (KPIs) for executive leadership and organizational reporting.
- Conduct organizational security risk assessments and develop mitigation strategies.
- Monitor and communicate emerging cybersecurity threats and risks affecting healthcare organizations.
- Provide leadership for security-related projects and organizational initiatives.
Data Governance and Information Management
- Coordinate and facilitate organizational data governance activities and maintain accountablility in partnership with Clinical Informatics, Analytics, Compliance, and operational leaders
- Establish enterprise data governance policies, standards, and procedures.
- Partner with clinical, operational, financial, and technology leaders to define data ownership, stewardship, and accountability.
- Coordinate Data Governance Committee activities and governance initiatives.
- Establish standards for data classification, retention, access, sharing, archival, and disposal.
- Promote data quality, integrity, consistency, and reliability across organizational systems.
- Maintain enterprise data inventories and support data lineage and information asset management efforts.
- Collaborate with Clinical Informatics, Enterprise Analytics, Compliance, and operational leadership to establish governance standards for clinical, operational, financial, and artificial intelligence data assets.
- Monitor organizational data quality issues and facilitate remediation efforts.
- Establish governance processes supporting responsible and ethical use of organizational data.
Cybersecurity Operations
- Oversee vulnerability management, security monitoring, incident response, and threat mitigation efforts.
- Coordinate investigations and response activities related to security incidents and data breaches.
- Lead business continuity and disaster recovery security planning activities.
- Review and provide security oversight for new systems, applications, integrations, cloud services, artificial intelligence technologies, and technology initiatives to ensure alignment with organizational security standards, regulatory requirements, and risk management objectives.
- Collaborate with Information Technology teams to implement and maintain appropriate security controls.
- Monitor organizational compliance with established security standards and policies.
Incident Response and Cybersecurity Event Management
- Serve as the organizational lead for cybersecurity incidents, coordinating incident response activities, executive communications, regulatory notification requirements, remediation efforts, and post-incident reviews.
- Coordinate with Information Technology, Compliance, Human Resources, Legal, and executive leadership during cybersecurity incidents, data breaches, and security investigations.
- Develop and maintain incident response procedures, escalation processes, and communication plans.
- Conduct periodic incident response exercises and lessons-learned reviews to improve organizational preparedness and resilience.
HIPAA Security and Regulatory Compliance
- Serve as the organization's designated HIPAA Security Officer and maintain accountability for implementation, monitoring, and ongoing compliance with HIPAA Security Rule requirements.
- Ensure compliance with HIPAA Security Rule requirements and other applicable regulatory requirements.
- Own, coordinate, and execute the organization's enterprise-wide Security Risk Analysis (SRA) program, including annual assessments, ongoing risk evaluations, risk identification, remediation planning, and executive reporting.
- Develop, maintain, and monitor corrective action plans resulting from Security Risk Analyses, security audits, penetration tests, vulnerability assessments, and compliance reviews.
- Coordinate and maintain required security risk analyses and risk management activities.
- Lead security-related audit preparation and responses.
- Develop and maintain documentation supporting regulatory compliance.
- Monitor changes in regulations and industry standards and advise leadership regarding organizational impacts.
- Collaborate with Compliance and Legal teams on privacy and security initiatives.
Contingency Planning, Business Continuity, and Disaster Recovery
- Develop, implement, and maintain the organization's contingency planning program in accordance with HIPAA Security Rule requirements and industry best practices.
- Lead the development and maintenance of Business Continuity Plans (BCPs), Disaster Recovery Plans (DRPs), Emergency Operations Plans, and technology recovery procedures.
- Conduct Business Impact Analyses (BIAs) to identify critical systems, applications, processes, and recovery priorities.
- Coordinate periodic testing, tabletop exercises, and validation of contingency, business continuity, and disaster recovery plans.
- Partner with Information Technology, Clinical Operations, Facilities, and organizational leadership to ensure continuity plans support patient care and business operations during disruptions.
- Monitor and report on organizational readiness related to business continuity, disaster recovery, and emergency preparedness activities.
- Coordinate corrective action plans resulting from contingency plan testing, disaster recovery exercises, and actual events.
- Ensure contingency planning activities align with organizational risk management, regulatory compliance, cybersecurity, and operational resilience objectives.
Vendor Risk Management
- Develop and maintain a third-party risk management program.
- Conduct security assessments of vendors, business associates, and technology partners.
- Review Business Associate Agreements (BAAs) and security requirements for third-party relationships.
- Participate in procurement and contract review processes to ensure appropriate security and compliance protections.
- Identify and mitigate risks associated with vendor relationships and system integrations.
Artificial Intelligence (AI) Governance
- Maintain accountability for AI governance standards while providing security, privacy, and risk guidance related to AI initiatives
- Evaluate privacy, security, ethical, and regulatory considerations associated with AI technologies.
- Collaborate with Clinical Informatics, Operations, Compliance, and IT leadership regarding AI initiatives.
- Establish governance frameworks supporting responsible AI adoption and use.
- Monitor emerging AI regulations, guidance, and industry best practices.
- Ensure AI initiatives align with organizational g