1

Cyber Security Risk Analyst Jobs in Ohio (NOW HIRING)

... Risk Management Frameworks (RMF), cyber security strategies, developing cyber resilient System of ... The Contractor will develop and analyze cyber security engineering artifacts used to support the ...

Cybersecurity SME

Dayton, OH · On-site

$90K - $140K/yr

... Chain Risk Management, Acquisition Security, Cyber Resiliency, and Information Protection ... RMF analysis. * Assist in evaluating the technical implementation of the security design to ...

... Chain Risk Management, Acquisition Security, Cyber Resiliency, and Information Protection ... RMF analysis. * Assist in evaluating the technical implementation of the security design to ...

The GRC Lead Analyst serves as a trusted advisor to senior leadership, influencing risk-based ... Establish and maintain IT control frameworks, including ITGCs, cybersecurity controls, and key risk ...

The GRC Lead Analyst serves as a trusted advisor to senior leadership, influencing risk-based ... Establish and maintain IT control frameworks, including ITGCs, cybersecurity controls, and key risk ...

Assessing and continuously monitoring cybersecurity risk ensuring that legacy and new capabilities ... Experience validating, evaluating and analyzing finding results and developer adjudications using ...

Showing results 41-60

Cyber Security Risk Analyst information

See Ohio salary details

$40.9K

$94.5K

$142.6K

How much do cyber security risk analyst jobs pay per year?

As of Jul 25, 2026, the average yearly pay for cyber security risk analyst in Ohio is $94,499.00, according to ZipRecruiter salary data. Most workers in this role earn between $75,600.00 and $109,800.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Cyber Security Risk Analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

Can you make $200,000 in cyber security?

Cyber Security Risk Analysts with extensive experience, advanced certifications, and specialized skills can potentially earn $200,000 or more annually, especially in high-demand industries or senior roles. Achieving this salary often requires a combination of technical expertise, certifications like CISSP or CISA, and a strong understanding of risk management and security frameworks.

What does a cyber security risk analyst do?

A cyber security risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and recommending measures to mitigate risks. They analyze security data, develop risk management strategies, and often use tools like vulnerability scanners and risk assessment frameworks to protect information systems.

What is a Cyber Security Risk Analyst job?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by Cyber Security Risk Analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

How much does a cybersecurity risk analyst make?

A cybersecurity risk analyst's average salary in the United States ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions typically start around $60,000, while experienced analysts with certifications like CISSP or CISA can earn over $130,000. The role often requires knowledge of risk assessment tools and security frameworks.

Can you make $500,000 a year in cyber security?

Cyber Security Risk Analysts typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary usually requires senior roles such as Chief Information Security Officer (CISO) or executive positions, which involve strategic leadership and extensive industry experience. High salaries in cybersecurity are often associated with leadership, specialized skills, and working in high-demand sectors or organizations.
What are the most commonly searched types of Cyber Security Risk Analyst jobs in Ohio? The most popular types of Cyber Security Risk Analyst jobs in Ohio are:
Infographic showing various Cyber Security Risk Analyst job openings in Ohio as of July 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $94,499 per year, or $45.4 per hour.

Cybersecurity (ISSM)

Astrion

Dayton, OH

$125K - $155K/yr

Full-time

Posted yesterday


Job description

Overview

Cybersecurity (ISSM)

LOCATION: WPAFB, Dayton, OH

JOB STATUS: Full-Time
CLEARANCE: Top Secret, Must be a US Citizen
TRAVEL: 10%

Astrion has an exciting opportunity for a Cybersecurity (ISSM) position at Wright Patterson AFB, OH. This is part of the ISR/SOF Directorate (AFLCMC/WI), which is responsible for equipping our warfighters to win the fight. The Directorate executes a $22 billion acquisition portfolio developing, producing, testing, modifying, fielding, and supporting Air Force ISR and SOF platforms, and related sub-systems.

Required Qualifications:

  • Master’s or Doctorate Degree in a related field and ten years of experience in the respective technical / professional discipline being performed, five years of which must be in the DoD.
  • OR bachelor’s degree in a related field and 12 years of experience in the respective technical/professional discipline being performed, five of which must be in the DoD.
  • OR, 15 years of directly related experience with proper certifications as described in the PWS labor category performance requirements, eight of which must be in the DoD.
  • Certifications: CISSP

Responsibilities:

  • The Contractor will have demonstrated experience related to acquisition platform and cyber security and possess a knowledge base in Risk Management Frameworks (RMF), cyber security strategies, developing cyber resilient System of Systems (SoS), systems engineering, network engineering, and technical interface design to ensure weapon systems meet cyber resilient and system security. It is required for the contractor to have CAP (Certified Authorization Professional) certification, Now CGRC (Certified in Governance, Risk, & Compliance) and it is highly recommended to have CISSP (Certified Information Systems Security Professional).
  • The Contractor will provide cyber security engineering support for traditional acquisition programs as well as Quick Reaction Capabilities (QRC) in a rapid acquisition development environment with minimal government oversight.
  • The Contractor will be responsible for implementing all phases of the RMF processes for weapon systems that will generate both unclassified and classified information.
  • The Contractor will develop and analyze cyber security engineering artifacts used to support the Assessment and Authorization (A&A) process leading to a successful ATO decision.
  • The Contractor will develop risk reduction-based policies and procedures and develop comprehensive cyber security processes to include implementation of continues monitoring.
  • The Contractor will develop the Cyber Security Impact Evaluation Recommendation to assess changes on the system in support of the continuous monitoring plan.
  • The Contractor will document system architectures, utilizing OEM documentation and system interface specifications, to support the cyber analysis, identification, selection, and tailoring of security and privacy controls necessary to protect the system.
  • The contractor will develop, modify, review and coordinate Platform Information Technology (PIT) determination packages, cyber security strategies, system security plans, and RMF artifacts for program review.
  • The Contractor will provide expert level evaluation of designs and proposed implementation solutions to defend weapon systems and critical networks against malicious and non-malicious exploitation throughout the full acquisition life cycle of portfolio programs.
  • The Contractor will evaluate threat data and develop residual risk recommendations and mitigations to senior DoD and AF leadership based on identification and analysis of weapons vulnerabilities.
  • The Contractor will research threat products and develop suitable defense measures, evaluate system changes for security implications, and recommend enhancements, research, and draft cyber security white papers, and provide recommendations to the program manager.
  • The Contractor will review and analyze interoperability requirements and will review, develop and evaluate resultant specifications and internal and external ICDs.
  • The Contractor will review and propose technical recommendations at both the strategic and operational levels regarding critical technologies requiring protection, Program Protection Plans (PPP), and Anti-Tamper (AT) plans, cyber findings, vulnerabilities, and risks.
  • The Contractor will review and/or document the systems Critical Program Information/Critical Technology (CPI/CT) and provide recommendations to the system’s Chief of Security and the Program Manager.
  • Cybersecurity engineering support contractors will be required to have access to classified material and classified information systems to include the Secret Internet Protocol Router Network (SIPRNet) and the Joint Worldwide Intelligence Communications System (JWICS).