1

Cyber Security Risk Analyst Jobs in Kentucky (NOW HIRING)

$123 - $185/hr

The Principal Cybersecurity Analyst plays a critical role in shaping and advancing enterprise-wide governance, risk, and compliance (GRC) programs, with expanded accountability for emerging AI ...

New

Cybersecurity Engineer

Melbourne, KY · On-site

$80 - $120/hr

The Ideal Candidate You are more than simply analytical, you are innovative, forward‑thinking ... Perform regular vulnerability scans, risk assessments, and remediation tracking in accordance with ...

Cyber Security Tutor

Lexington, KY · Remote

$18 - $40/hr

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk ...

Cyber Security Tutor

Louisville, KY · Remote

$18 - $40/hr

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk ...

$255 - $295/hr

Cybersecurity, Risk, and Compliance*** Own and mature the company's security program including ... Establish an enterprise approach to data governance, retention, access control, and analytics ...

New

Our ideal candidate has strong problem-solving skills, an analytical mindset and the ability to ... Strong understanding of network and application security, threat modeling, risk assessment ...

$100 - $130/hr

Cybersecurity, Compliance & Risk Oversight * Lead enterprise cybersecurity operations including ... Utilize reporting, analytics, and operational dashboards to support data-driven infrastructure and ...

New

Serve as the go-to analyst across high-impact domains, facilitating rapid adaptation as priorities ... Cyber Security vigilantly protects Deloitte and client data. The team leads a strategic cyber risk ...

next page

Showing results 1-20

Cyber Security Risk Analyst information

See Kentucky salary details

$37.3K

$86.3K

$130.3K

How much do cyber security risk analyst jobs pay per year?

As of Aug 14, 2026, the average yearly pay for cyber security risk analyst in Kentucky is $86,332.00, according to ZipRecruiter salary data. Most workers in this role earn between $69,000.00 and $100,300.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the cyber security risk analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

What is a cyber security risk analyst?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by cyber security risk analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

What does a cybersecurity risk analyst do?

A cybersecurity risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and analyzing risks to information systems. They develop strategies to mitigate risks, often using tools like risk assessment frameworks and security audits, and may hold certifications such as CISSP or CISA. Their work helps organizations protect sensitive data and ensure compliance with security standards.

How much does a cyber security risk analyst make?

The average salary for a cyber security risk analyst is around $80,000 to $110,000 per year, depending on experience, certifications, and location. Entry-level positions typically start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. The role often requires knowledge of risk assessment tools and security frameworks.

What are popular job titles related to Cyber Security Risk Analyst jobs in Kentucky?

For Cyber Security Risk Analyst jobs in Kentucky, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Analyst jobs in Kentucky look for?

The top searched job categories for Cyber Security Risk Analyst jobs in Kentucky are:

Infographic showing various Cyber Security Risk Analyst job openings in Kentucky as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $86,332 per year, or $41.5 per hour.

Principal Cybersecurity Analyst - Risk Mgmt & AI Security

University of Texas MD Anderson Cancer Center

On-site

$123 - $185/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted yesterday

New


Job description

The University of Texas MD Anderson Cancer Center is seeking a highly skilled Principal Cybersecurity Analyst to serve as a technical authority within its Cybersecurity department. The Principal Cybersecurity Analyst plays a critical role in shaping and advancing enterprise-wide governance, risk, and compliance (GRC) programs, with expanded accountability for emerging AI security and governance initiatives. This role operates at a strategic and architectural level while also ensuring operational effectiveness across cybersecurity risk management practices. The Principal Cybersecurity Analyst contributes directly to safeguarding sensitive data, maintaining regulatory compliance, and strengthening the organization's security posture through innovative, data-driven risk management and governance strategies. The Principal Cybersecurity Analyst serves as a trusted advisor, architect, and leader within the cybersecurity function. The ideal candidate brings advanced education in information systems or cybersecurity, extensive experience leading enterprise risk management or GRC programs, and strong knowledge of frameworks such as NIST, HIPAA, and HITRUST. Preferred candidates will also have hands-on experience assessing AI/ML risk, strong executive communication skills, and certifications such as CISSP, CISM, or PMP. Minimum $123,000 - Midpoint $154,000 - Maximum $185,000 Work Location: Remote 100%

Why Us?

At UT MD Anderson, the Principal Cybersecurity Analyst plays an essential role in advancing cybersecurity innovation in a mission-driven healthcare environment. This position offers the opportunity to shape enterprise risk strategy, influence executive decision-making, and lead emerging AI governance practices, all while supporting an organization dedicated to saving lives. Employees benefit from a collaborative culture, professional development opportunities, and a strong commitment to work-life balance.

  • Employer-paid medical coverage starting day one for employees working 30+ hours/week, plus optional group dental, vision, life, AD&D, and disability insurance.
  • Accruals for PTO and Extended Illness Bank, plus paid holidays, wellness, childcare, and other leave options.
  • Tuition Assistance Program after six months of service and access to extensive wellness, fitness, and employee resource groups.
  • Defined-benefit pension through the Teachers Retirement System, voluntary retirement plans, and employer-paid life and reduced salary protection programs.

Responsibilities

Governance, Risk & Compliance (GRC) Architecture & Risk Management Program Leadership

  • Serve as principal architect and subject matter expert for enterprise GRC and cybersecurity risk programs
  • Define and maintain risk assessment methodologies, control frameworks, and risk scoring models
  • Establish workflows across development, staging, and production environments
  • Develop SOPs, roles, segregation of duties, and change management processes
  • Lead design and execution of enterprise risk management strategies

Security & Risk Platform Integration and Automation

  • Architect and maintain integrations across Archer, Tenable, ServiceNow, Microsoft Configuration Manager (SCCM/MECM), and Medigate
  • Design automated workflows consolidating asset, vulnerability, and risk data
  • Enable enterprise-wide risk visibility and reporting through data-driven systems
  • Ensure data quality, reconciliation, and interoperability across platforms and CMDB

Regulatory & Compliance Framework Management

  • Apply frameworks including NIST CSF, NIST 800-53, HIPAA, and HITRUST
  • Conduct control mapping, gap assessments, and compliance reporting
  • Advise stakeholders on remediation strategies and regulatory requirements
  • Align institutional policies with regulatory and accreditation standards

AI Security & Governance

  • Establish and mature AI security and governance programs
  • Develop AI risk assessment criteria and governance standards
  • Align controls to NIST AI Risk Management Framework and institutional policies
  • Evaluate AI/ML tools and vendors for data protection and compliance risks
  • Partner with data governance, privacy, and legal teams on AI initiatives

Strategic Risk Visioning, Assessment & Executive Advisory

  • Develop multi-year roadmaps, milestones, and resource plans
  • Lead enterprise and project-level risk assessments
  • Translate technical findings into executive-level reporting and dashboards
  • Advise leadership on risk posture and investment prioritization
  • Provide technical leadership and mentorship across teams

EDUCATION

  • Required: Bachelor\'s Degree Computer Information Systems, Business Information Systems, Computer Science or related field.
  • Preferred: Master\'s Degree Information Security, Computer Science or related field

WORK EXPERIENCE

  • Required: 7 years In information security and/or cybersecurity experience including multiple security domains, to include two years lead/supervisory experience.
  • May substitute required education degree with additional years of equivalent experience on a one to one basis.
  • Preferred: At least 7-8 years of progressive cybersecurity experience, hands-on risk management (risk assessment, risk register ownership, control evaluation, or risk quantification), led or owned a security risk management program or framework implementation (e.g., NIST RMF/CSF, ISO 27005, FAIR, or equivalent), direct hands-on experience assessing the security or risk posture of AI/ML systems or GenAI deployments, ability to translate technical risk into business-level language for executive and governance audiences (e.g., briefing a CISO, risk committee, or board), experience using Archer, excellent communication skills, risk management, and cybersecurity framework is a must.

LICENSES AND CERTIFICATIONS

  • Preferred: CISSP - Cert IS Security Professional Issued by the International Information Systems Security Certification Consortium ((ISC).
  • Preferred: CISM - Cert Info Security Manager Issued by Information Systems Audit and Control Association (ISACA).
  • Preferred: PMP - Project Mgt Professional Issued by the Project Management Institute (PMI).
  • Preferred: Other applicable security industry certifications.

The University of Texas MD Anderson Cancer Center offers excellent benefits, including medical, dental, paid time off, retirement, tuition benefits, educational opportunities, and individual and team recognition.

This position may be responsible for maintaining the security and integrity of critical infrastructure, as defined in Section 113.001(2) of the Texas Business and Commerce Code and therefore may require routine reviews and screening. The ability to satisfy and maintain all requirements necessary to ensure the continued security and integrity of such infrastructure is a condition of hire and continued employment.

It is the policy of The University of Texas MD Anderson Cancer Center to provide equal employment opportunity without regard to race, color, religion, age, national origin, sex, gender, sexual orientation, gender identity/expression, disability, protected veteran status, genetic information, or any other basis protected by institutional policy or by federal, state, or local laws unless such distinction is required by law. It is a policy statement of equal opportunity.

Additional Information

  • Requisition ID: 181706
  • Employment Status: Full-Time
  • Employee Status: Regular
  • Work Week: Days
  • Minimum Salary: US Dollar (USD) 123,000
  • Midpoint Salary: US Dollar (USD) 154,000
  • Maximum Salary : US Dollar (USD) 185,000
  • FLSA: exempt and not eligible for overtime pay
  • Fund Type: Hard
  • Work Location: Remote (within Texas only)
  • Pivotal Position: Yes
  • Referral Bonus Available?: Yes
  • Relocation Assistance Available?: Yes

LI-Remote

#J-18808-Ljbffr