1

Cyber Security Risk Analyst Jobs in Kentucky (NOW HIRING)

$95 - $166/hr

... cybersecurity education program, developing risk-based campaigns and targeted training initiatives that improve employee awareness and cyber resilience. * Analyze phishing simulation results ...

Posted today

$80 - $95/hr

Description Quantum Sky is searching for a JourneymanCybersecurity Analyst for an exciting ... Perform FISMA required risk assessment of policies, procedures, supplemental plans addressing ...

New

$80 - $110/hr

Cybersecurity Risk Management - Identifies and assesses the potential impact of Cybersecurity risks ... Analyze cybersecurity control findings from assessments, audits, and internal reviews. Translate ...

New

$120 - $140/hr

Senior Cybersecurity & Compliance Specialist MINNEAPOLIS, MN, United States Job Info * Job Category ... party risk management practices. * Strong organizational and documentation skills, an analytical ...

$140 - $190/hr

... cybersecurity controls, and information security governance frameworks within a regulated financial institution or similarly regulated environment. Ability to analyze complex risk issues, balance ...

$110 - $160/hr

Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and ... Strong analytical, communication, and collaborative skills * US citizenship with Active or Current ...

$90 - $130/hr

Analyze risk score trends and ascertain potential root causes to risk score anomalies. * Track ... Cybersecurity #J-18808-Ljbffr

New

$73 - $133/hr

Cybersecurity Analyst Location: Keyport, WA Help Protect Critical Naval Operations Leidos is ... In this role, you will support Risk Management Framework (RMF) security and compliance activities ...

New

$100 - $110/hr

This position will provide cybersecurity and risk management support with a focus on Risk ... The Cybersecurity Analyst will work closely with government and contractor teams to identify and ...

Posted today

$70 - $95/hr

Cybersecurity Analyst US 7 days ago Requisition ID: 1212 Location and Travel Details: Remote We are ... This role will assist the Information System Security Officer (ISSO) with Risk Management Framework ...

New

$120 - $160/hr

Lead enterprise-wide risk assessments--both qualitative and quantitative--to prioritize threats and ... Assess regional cybersecurity maturity and implement continuous improvement initiatives

New

$120 - $170/hr

Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and ... Strong analytical, communication, and collaborative skills * US citizenship with Active or Current ...

$100 - $150/hr

Cybersecurity Analyst - Crypto ModernizationLocation:Clearance TS/SCI ScheduleShift Day The ... The analyst provides technical research, policy analysis, systems engineering support, risk ...

New

$83 - $90/hr

We are seeking a versatile Business Impact & Information Security Analyst to join our enterprise risk management team. This dual-focused role combines business continuity planning with cybersecurity ...

New

$131 - $237/hr

Conduct cybersecurity risk assessments and provide prioritized risk mitigation recommendations in ... Analyze candidate architectures by evaluating against defined security requirements to identify ...

$140 - $190/hr

Bachelor's degree and 8+ years of Cybersecurity / Risk Management Framework (RMF) experience. * Active DoD Secret * Certified Information Systems Security Professional (CISSP) * NIST 800-53 Rev5 ...

$110 - $150/hr

The Cybersecurity Analyst provides cybersecurity, information assurance, risk management, and compliance support across Digital Services initiatives. The role supports Authorization to Operate (ATO ...

Posted today

$90 - $130/hr

Cybersecurity Engineer Location: Panama City Beach, FL Clearance: Secret Position Title ISPA ... Conduct security assessments, vulnerability scans, and risk analyses * Support Authority to Operate ...

$110 - $175/hr

Research new Cybersecurity capabilities, complete trade‑studies, perform risk analysis, develop unconventional mitigations, and continuously integrate lessons learned and emerging knowledge into ...

New

$183 - $213/hr

The Cyber Security Engineer provides senior cybersecurity engineering, assessment, risk, policy ... The position supports security evaluation, vulnerability analysis, risk determination, remediation ...

New

Showing results 21-40

Cyber Security Risk Analyst information

See Kentucky salary details

$37.3K

$86.3K

$130.3K

How much do cyber security risk analyst jobs pay per year?

As of Sep 4, 2026, the average yearly pay for cyber security risk analyst in Kentucky is $86,332.00, according to ZipRecruiter salary data. Most workers in this role earn between $69,000.00 and $100,300.00 per year, depending on experience, location, and employer.

What is a cyber security risk analyst?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by cyber security risk analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

What are the key skills and qualifications needed to thrive in the cyber security risk analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

How much does a cyber security risk analyst make?

The average salary for a cyber security risk analyst in the United States ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions typically start around $60,000, while experienced analysts with certifications like CISSP or CISA can earn over $130,000. The role often requires knowledge of risk assessment tools and security frameworks.

What job categories do people searching Cyber Security Risk Analyst jobs in Kentucky look for?

The top searched job categories for Cyber Security Risk Analyst jobs in Kentucky are:

Infographic showing various Cyber Security Risk Analyst job openings in Kentucky as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $86,332 per year, or $41.5 per hour.

Principal Information Security Engineer - Governance, Risk & Security Awareness

Ferguson Enterprises, Inc.

On-site

$95 - $166/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 21 hours ago

Posted today


Ferguson Waterworks rating

9.3

Company rating: 9.3 out of 10

Based on 14 frontline employees who took The Breakroom Quiz

14th of 428 rated retail wholesalers


Job description

Location

This role is approved to be fully remote and can be based anywhere in the continental United States.

Duties & Responsibilities
  • Lead cybersecurity risk assessments and security maturity evaluations using industry frameworks, including NIST CSF, identifying control gaps, emerging risks, and opportunities to strengthen Ferguson's security posture.
  • Develop risk mitigation strategies, remediation plans, and governance recommendations, partnering with business and technology teams to drive sustainable risk reduction.
  • Support the development and continuous improvement of cybersecurity governance processes, security roadmaps, risk registers, and program performance metrics.
  • Coordinate and support internal and external audits, independent security assessments, regulatory reviews, and risk management initiatives.
  • Lead Ferguson's enterprise simulated phishing exercises and cybersecurity education program, developing risk-based campaigns and targeted training initiatives that improve employee awareness and cyber resilience.
  • Analyze phishing simulation results, reporting trends, and awareness metrics to identify risks, measure efficiency, and drive ongoing improvement of security culture.
  • Partner with business leaders, Human Resources, Corporate Communications, and Information Security teams to reduce phishing susceptibility and increase employee engagement in security procedures.
  • Conduct security assessments of vendors, suppliers, and technology partners as part of Ferguson's third-party risk management program.
  • Review security questionnaires, SOC reports, penetration test results, compliance certifications, and other security documentation to evaluate vendor risk.
  • Identify, assess, and communicate third-party security risks, providing recommendations to support informed business decisions and remediation efforts.
  • Collaborate with Procurement, Legal, and business customers to help ensure appropriate security requirements are incorporated into third-party engagements.
  • Develop and maintain cybersecurity dashboards, scorecards, important metrics, KRIs, and executive reporting that provide access to risk, compliance, and program performance.
  • Apply reporting and automation tools to improve the efficiency, effectiveness, and scalability of Governance, Risk, and Compliance (GRC) activities.
  • Translate technical risks into business-focused insights, helping leaders understand risk exposure, prioritize remediation efforts, and make informed decisions.
  • Serve as a trusted advisor on cybersecurity governance, risk management, and compliance matters, building strong partnerships across business and technology teams.
  • Communicate security risks, recommendations, and program outcomes effectively to both technical and non-technical audiences, including senior leadership.
Qualifications & Requirements
  • Bachelor's degree in Information Security, Cybersecurity, Information Systems, Computer Science, Business Administration, or a related field; equivalent combination of education and experience will be considered.
  • 5+ years of experience in Information Security, Cybersecurity, IT Risk Management, IT Audit, Governance, Risk & Compliance (GRC), or related disciplines.
  • Experience conducting security risk assessments and evaluating security controls across on-premises, cloud, and third-party environments.
  • Solid understanding of cybersecurity governance, risk management, compliance frameworks, and third-party risk management practices.
  • Extensive knowledge of industry frameworks and standards, including NIST CSF, ISO 27001, COBIT, COSO, and IT General Controls (ITGCs).
  • Experience developing and maintaining security policies, standards, controls, and governance processes.
  • Experience supporting audits, regulatory compliance initiatives, risk assessments, and remediation activities.
  • Ability to identify, assess, prioritize, and communicate risk across applications, infrastructure, cloud services, and vendors.
  • Strong analytical, problem-solving, and critical thinking skills, with the ability to translate sophisticated risks into actionable recommendations.
  • Excellent written, verbal, presentation, and customer management skills, with experience presenting findings and recommendations to technical and business leaders.
  • Experience working with Microsoft technologies, cloud platforms, and security governance or reporting tools preferred.
  • Proven ability to lead complex initiatives, influence interested parties, and drive outcomes through multi-functional collaboration.

Preferred Certifications CISSP, CISM, CRISC, CISA, and/or ISO 27001 Lead Auditor/Lead Implementer certification.

Benefits

At Ferguson, we care for each other. We value our well-being just as much as our hard work. We are committed to a holistic approach towards benefits plans and programs that support the mental, physical and financial well-being of our associates. Our competitive offering not only includes benefits like health, dental, vision, paid time off, life insurance and a 401(k) with a company match, but our associates also enjoy additional meaningful and inclusive enhancements that are adaptable to their diverse situations and needs, including mental health coverage, gender affirming and family building benefits, paid parental leave, associate discounts, community involvement opportunities and more!

Pay Range
  • Actual pay rate may vary depending upon location. The estimated pay range for this position is below. The specific rate will depend on a candidate’s qualifications and prior experience.
  • $8,470.59 - $14,834.37
  • Estimated Ranges displayed are Monthly for Salaried roles OR Hourly for all other roles.
  • This role is Bonus or Incentive Plan eligible.
  • Ferguson complies with all wage regulations. The starting wage may be higher in certain locations based on local or state wage requirements.
Equal Employment Statement

The Company is an equal opportunity employer as well as a government contractor that shall abide by the requirements of 41 CFR 60-300.5(a), which prohibits discrimination against qualified protected Veterans and the requirements of 41 CFR 60-741.5(A), which prohibits discrimination against qualified individuals on the basis of disability.

Ferguson Enterprises, LLC. is an equal employment employer F/M/Disability/Vet/Sexual Orientation/Gender Identity.

Equal Employment Opportunity and Reasonable Accommodation Information Ferguson is a project success company providing expertise, solutions and products from infrastructure, plumbing and appliances to HVAC, fire, fabrication and more. As a leading value-added distributor of residential and commercial plumbing supplies and pipe, valves and fittings in the U.S., we exist to make our customers’ complex projects simple, successful and sustainable. The professionals we serve help transform the world we live in, and we are their trusted partners with the scale to provide peace of mind.

Company Background

Founded in 1953, Ferguson is part of Ferguson plc, which is listed on the New York Stock Exchange (NYSE: FERG) and London Stock Exchange (LSE: FERG). With approximately 36,000 associates across 1,700 locations, Ferguson plc serves customers in all 50 states, Canada, Puerto Rico, Mexico and the Caribbean.

#J-18808-Ljbffr

What Ferguson Waterworks employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom