... risk management in an OT / SCADA environment in two or more areas such as: * Cyber security * Secure Supply Chain * Security Analytics * Security Operations Centers * Vulnerability and Threat ...
... risk management in an OT / SCADA environment in two or more areas such as: * Cyber security * Secure Supply Chain * Security Analytics * Security Operations Centers * Vulnerability and Threat ...
... risk management in an OT / SCADA environment in two or more areas such as: * Cyber security * Secure Supply Chain * Security Analytics * Security Operations Centers * Vulnerability and Threat ...
... risk management in an OT / SCADA environment in two or more areas such as: * Cyber security * Secure Supply Chain * Security Analytics * Security Operations Centers * Vulnerability and Threat ...
HITRUST Junior Consultant
$18K - $22K/yr
... cybersecurity frameworks, including NIST and HIPAA regulations. Ability to critically analyze data, findings, and risk assessments to support client objectives. Familiarity with project management ...
HITRUST Junior Consultant
$18K - $22K/yr
... cybersecurity frameworks, including NIST and HIPAA regulations. Ability to critically analyze data, findings, and risk assessments to support client objectives. Familiarity with project management ...
Creating executive-ready presentations, quantitative analyses, and recommendations to support ... Bachelor's degree * 4+ years of experience in strategy, operations, risk, cybersecurity, trust and ...
Creating executive-ready presentations, quantitative analyses, and recommendations to support ... Bachelor's degree * 4+ years of experience in strategy, operations, risk, cybersecurity, trust and ...
AI Security Architect - Erlanger, KY
Erlanger, KY · On-site
$92K - $172K/yr
AI Security Architect - Erlanger, KY Position Summary ADM's Global Information & Cyber Security ... Apply AI risk management standards to assess and mitigate risks in AI pipelines. Required Skills ...
AI Security Architect - Erlanger, KY
Erlanger, KY · On-site
$92K - $172K/yr
AI Security Architect - Erlanger, KY Position Summary ADM's Global Information & Cyber Security ... Apply AI risk management standards to assess and mitigate risks in AI pipelines. Required Skills ...
AI Security Architect - Erlanger, KY
$92K - $172K/yr
Apply AI risk management standards to assess and mitigate risks in AI pipelines.Required Skills ... Strong analytical, communication, and documentation skills.Ability to explain complex AI security ...
AI Security Architect - Erlanger, KY
$92K - $172K/yr
Apply AI risk management standards to assess and mitigate risks in AI pipelines.Required Skills ... Strong analytical, communication, and documentation skills.Ability to explain complex AI security ...
Serve as the primary point of contact for technology-related audits, risk assessments, incident ... Strong knowledge of cybersecurity, cloud computing, data analytics, and enterprise systems in ...
Serve as the primary point of contact for technology-related audits, risk assessments, incident ... Strong knowledge of cybersecurity, cloud computing, data analytics, and enterprise systems in ...
... in cybersecurity. Join our team to deliver powerful solutions that help clients navigate an ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... in cybersecurity. Join our team to deliver powerful solutions that help clients navigate an ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... in cybersecurity. Join our team to deliver powerful solutions that help clients navigate an ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... in cybersecurity. Join our team to deliver powerful solutions that help clients navigate an ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
Analyzing, implementing user requirements/business needs as new and/or enhanced product ... Join us as we work with technologies shaping the future of Cybersecurity to build future ...
Analyzing, implementing user requirements/business needs as new and/or enhanced product ... Join us as we work with technologies shaping the future of Cybersecurity to build future ...
CyberArk Senior Consultant
Louisville, KY · On-site
Analyzing, implementing user requirements/business needs as new and/or enhanced product ... Join us as we work with technologies shaping the future of Cybersecurity to build future ...
CyberArk Senior Consultant
Louisville, KY · On-site
Analyzing, implementing user requirements/business needs as new and/or enhanced product ... Join us as we work with technologies shaping the future of Cybersecurity to build future ...
Manager Technical Services
Owensboro, KY · On-site
$114K - $115K/yr
Lead failure mode & effects analysis (FMEA), root cause analysis (RCA), and corrective action plans ... Lead controls/automation reliability and cybersecurity standards in partnership with IT/OT.
Manager Technical Services
Owensboro, KY · On-site
$114K - $115K/yr
Lead failure mode & effects analysis (FMEA), root cause analysis (RCA), and corrective action plans ... Lead controls/automation reliability and cybersecurity standards in partnership with IT/OT.
Develop clear narratives and recommendations--current state → gaps → future state--paired with comparative analyses (pros/cons, risk, TCO/ROI) across multiple options. * Collaborate with supplier ...
Quick apply
Develop clear narratives and recommendations--current state → gaps → future state--paired with comparative analyses (pros/cons, risk, TCO/ROI) across multiple options. * Collaborate with supplier ...
Principal Product Security Engineer
Frankfort, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Principal Product Security Engineer
Frankfort, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Cloud Security Manager - Azure Infrastructure & AI
Louisville, KY · On-site
$63 - $83.50/hr
Leading Azure cloud cyber risk engagements across governance, identity, application security ... Cybersecurity certification such as Certified Cloud Security Professional (CCSP), Certificate of ...
Cloud Security Manager - Azure Infrastructure & AI
Louisville, KY · On-site
$63 - $83.50/hr
Leading Azure cloud cyber risk engagements across governance, identity, application security ... Cybersecurity certification such as Certified Cloud Security Professional (CCSP), Certificate of ...
Principal Product Security Engineer
Louisville, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Principal Product Security Engineer
Louisville, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Principal Product Security Engineer
Covington, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Principal Product Security Engineer
Covington, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Principal Product Security Engineer
Lexington, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Principal Product Security Engineer
Lexington, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Principal Product Security Engineer
Bowling Green, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Principal Product Security Engineer
Bowling Green, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Principal Product Security Engineer
Owensboro, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Principal Product Security Engineer
Owensboro, KY · On-site +1
Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams ... NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk ...
Cyber Security Risk Analyst information
See Kentucky salary details
$37.3K - $45.8K
1% of jobs
$45.8K - $54.2K
6% of jobs
$54.2K - $62.7K
10% of jobs
$68.5K is the 25th percentile. Wages below this are outliers.
$62.7K - $71.1K
12% of jobs
$71.1K - $79.6K
15% of jobs
The median wage is $83.2K / yr.
$79.6K - $88K
15% of jobs
$88K - $96.5K
10% of jobs
$100.1K is the 75th percentile. Wages above this are outliers.
$96.5K - $104.9K
16% of jobs
$104.9K - $113.4K
7% of jobs
$113.4K - $121.8K
5% of jobs
$121.8K - $130.3K
3% of jobs
$37.3K
$86.3K
$130.3K
How much do cyber security risk analyst jobs pay per year?
Is 40 too old for cyber security?
Is SOC an entry level job?
What are the key skills and qualifications needed to thrive in the Cyber Security Risk Analyst position, and why are they important?
A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.
What is a Cyber Security Risk Analyst job?
A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.
What are some typical challenges faced by Cyber Security Risk Analysts on the job?
Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.
What does a cybersecurity risk analyst do?
Can you make $500,000 a year in cyber security?
Other
Posted 17 days ago
Deloitte rating
8.1
Based on 86 frontline employees who took The Breakroom Quiz
58th of 138 rated financial services
Job description
Power and Utilities OT (Operational Technology) - Manager
Position Summary
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cyber team and become a member of the largest group of cybersecurity professionals worldwide.
Recruiting for this role ends on 12/21/2026
Work you'll do
Responsibilities:
- Identify and evaluate complex business and technology risks
- Develop remediation methods to mitigate risks
- Demonstrate problem solving, critical thinking and logical structuring skills
- Assist in the selection and tailoring of approaches, methods and tools to support service offering or industry projects
- Actively participate in decision making with engagement management and seek to understand the broader impact of current decisions
- Facilitate use of technology-based tools or methodologies to review, design and/or implement products and services
- Identify opportunities to improve engagement profitability and manage engagement economics
- Demonstrate ability to with identify and address client needs: building solid relationships with clients; developing an awareness of Firm services; communicating with the client in an organized and knowledgeable manner; delivering clear requests for information; demonstrating flexibility in prioritizing and completing tasks; and communicating potential conflicts to the manager
- Demonstrate a general knowledge of market trends, competitor activities, Deloitte Advisory products and service lines
Required Skills:
- 7+ years of demonstrate advanced understanding and experience governing and implementing power and utility regulations and standards including:
- North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP)
- NERC Operations and Planning (O&P)
- Federal Energy Regulatory Commission
- Transportation Security Administration (TSA) Cybersecurity
- IEC 62443 standard - Securing Industrial Automation and Control Systems (IACS)
- Nuclear Energy Institute (NEI) - NEI 08-09, 10 CFR 73.54
- 7+ years of demonstrate advanced understanding and cyber risk management in at least two of the following areas:
- SCADA with experience in securing ICS (Industrial Control Systems) security
- Internet of Things (IOT) architecture and security
- OT (Operational Technology) security
- NERC CIP-015 - Internal Network Security Monitoring (INMS)
- Embedded systems security
- OT network segmentation (zones/conduits), jump hosts, secure remote access
- Passive OT discovery/asset inventory, OT IDS, SIEM integration/use cases
- Incident response in OT (containment with availability/safety constraints)
- Vendor/OEM risk management, SBOM/patch constraints, compensating controls
- Security experience in the field environment within the Power, Utilities & Renewables, Oil & Gas, or Industrial Products & Construction industry sectors
- 7+ years of demonstrate advanced understanding of business processes and cyber risk management in an OT / SCADA environment in two or more areas such as:
- Cyber security
- Secure Supply Chain
- Security Analytics
- Security Operations Centers
- Vulnerability and Threat Management
- Data Security
- Secure Dev Ops
- Business continuity management
- Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF)
- Limited sponsorship opportunities may be available
Additional Requirements:
- Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve
- Locations include: Houston, Dallas, Cleveland, Detroit, St. Louis, Pittsburgh, Boston, Charlotte, Atlanta, Miami, Memphis, Denver, Phoenix, Salt Lake City, Los Angeles, San Diego, San Franciso, Seattle. Must be within a reasonable commute and willing to work part-time in the Deloitte and/or client offices.
Preferred:
- Minimum of 4 years working in an OT environment (e.g. OT security, ICS security, IOT security, SCADA, etc.)
- Minimum 4 years designing security for infrastructure, network and application architectures
- Experience in the Power Utilities & Renewables, Oil & Gas, or Industrial Products & Construction sector
- Demonstrated experience working with cloud platforms (AWS, Azure)
- 5+ years implementing security solutions
- BA/BS in cyber security, information security, engineering, computer science, information technology, information management, information sciences, business administration, or related field preferred
- CISSP, CISM, or CISA certification a plus
- Excellent verbal and written communication
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberES26
Power and Utilities OT (Operational Technology) - Manager
Position Summary
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cyber team and become a member of the largest group of cybersecurity professionals worldwide.
Recruiting for this role ends on 12/21/2026
Work you'll do
Responsibilities:
- Identify and evaluate complex business and technology risks
- Develop remediation methods to mitigate risks
- Demonstrate problem solving, critical thinking and logical structuring skills
- Assist in the selection and tailoring of approaches, methods and tools to support service offering or industry projects
- Actively participate in decision making with engagement management and seek to understand the broader impact of current decisions
- Facilitate use of technology-based tools or methodologies to review, design and/or implement products and services
- Identify opportunities to improve engagement profitability and manage engagement economics
- Demonstrate ability to with identify and address client needs: building solid relationships with clients; developing an awareness of Firm services; communicating with the client in an organized and knowledgeable manner; delivering clear requests for information; demonstrating flexibility in prioritizing and completing tasks; and communicating potential conflicts to the manager
- Demonstrate a general knowledge of market trends, competitor activities, Deloitte Advisory products and service lines
Required Skills:
- 7+ years of demonstrate advanced understanding and experience governing and implementing power and utility regulations and standards including:
- North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP)
- NERC Operations and Planning (O&P)
- Federal Energy Regulatory Commission
- Transportation Security Administration (TSA) Cybersecurity
- IEC 62443 standard - Securing Industrial Automation and Control Systems (IACS)
- Nuclear Energy Institute (NEI) - NEI 08-09, 10 CFR 73.54
- 7+ years of demonstrate advanced understanding and cyber risk management in at least two of the following areas:
- SCADA with experience in securing ICS (Industrial Control Systems) security
- Internet of Things (IOT) architecture and security
- OT (Operational Technology) security
- NERC CIP-015 - Internal Network Security Monitoring (INMS)
- Embedded systems security
- OT network segmentation (zones/conduits), jump hosts, secure remote access
- Passive OT discovery/asset inventory, OT IDS, SIEM integration/use cases
- Incident response in OT (containment with availability/safety constraints)
- Vendor/OEM risk management, SBOM/patch constraints, compensating controls
- Security experience in the field environment within the Power, Utilities & Renewables, Oil & Gas, or Industrial Products & Construction industry sectors
- 7+ years of demonstrate advanced understanding of business processes and cyber risk management in an OT / SCADA environment in two or more areas such as:
- Cyber security
- Secure Supply Chain
- Security Analytics
- Security Operations Centers
- Vulnerability and Threat Management
- Data Security
- Secure Dev Ops
- Business continuity management
- Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF)
- Limited sponsorship opportunities may be available
Additional Requirements:
- Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve
- Locations include: Houston, Dallas, Cleveland, Detroit, St. Louis, Pittsburgh, Boston, Charlotte, Atlanta, Miami, Memphis, Denver, Phoenix, Salt Lake City, Los Angeles, San Diego, San Franciso, Seattle. Must be within a reasonable commute and willing to work part-time in the Deloitte and/or client offices.
Preferred:
- Minimum of 4 years working in an OT environment (e.g. OT security, ICS security, IOT security, SCADA, etc.)
- Minimum 4 years designing security for infrastructure, network and application architectures
- Experience in the Power Utilities & Renewables, Oil & Gas, or Industrial Products & Construction sector
- Demonstrated experience working with cloud platforms (AWS, Azure)
- 5+ years implementing security solutions
- BA/BS in cyber security, information security, engineering, computer science, information technology, information management, information sciences, business administration, or related field preferred
- CISSP, CISM, or CISA certification a plus
- Excellent verbal and written communication
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberES26