1

Cyber Security Risk Analyst Jobs in Austin, TX (NOW HIRING)

... cybersecurity risk and improve organizational awareness. The selected individual will be ... Analyze, validate, and distribute Critical and Zero-Day CVE advisories to impacted stakeholders.

New

This role is responsible for monitoring, analyzing, and operationalizing cyber threat intelligence across enterprise environments to reduce cybersecurity risk and improve organizational awareness.

Work also involves conducting security risk management activities including security control ... analyze cybersecurity threat indicators and their behaviors for the prevention, detection ...

New

Work also involves protecting cybersecurity assets and delivering cybersecurity incident detection ... risk assessments and reviews of account permissions. 4. Perform forensic analysis of information ...

... risk controls (including IT and cybersecurity) * Document findings and prepare clear, decision ... Demonstrated analytical rigor, attention to detail, and structured problem-solving * Effective ...

Enterprise Risk Manager

Austin, TX

  • Medical

  • Life

  • Retirement

  • PTO

Use analytics, automation, visualization tools, and AI-enabled capabilities to improve risk ... Monitor emerging risks related to AI, cybersecurity threats, regulatory change, digital innovation ...

The analyst will collaborate closely with cybersecurity, server operations, and infrastructure teams to ensure timely remediation of high-risk vulnerabilities. Responsibilities : • Review, triage ...

Cyber Security Engineer

Austin, TX · On-site

  • Medical

  • Retirement

  • PTO

Job Title: Cyber Security Engineer Job Category: Engineering Time Type: Full time Minimum Clearance ... Analyze ACAS/Nessus and STIG/SCAP results at the engineering level to separate genuine risk from ...

Cyber Security Tutor

Austin, TX · Remote

$18 - $40/hr

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk ...

Showing results 21-40

Cyber Security Risk Analyst information

See Austin, TX salary details

$42.6K

$98.5K

$148.7K

How much do cyber security risk analyst jobs pay per year?

As of Aug 15, 2026, the average yearly pay for cyber security risk analyst in Austin, TX is $98,526.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,800.00 and $114,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the cyber security risk analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

What is a cyber security risk analyst?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by cyber security risk analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

What does a cybersecurity risk analyst do?

A cybersecurity risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and analyzing risks to information systems. They develop strategies to mitigate risks, often using tools like risk assessment frameworks and security audits, and may hold certifications such as CISSP or CISA. Their work helps organizations protect sensitive data and ensure compliance with security standards.

How much does a cyber security risk analyst make?

The average salary for a cyber security risk analyst is around $80,000 to $110,000 per year, depending on experience, certifications, and location. Entry-level positions typically start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. The role often requires knowledge of risk assessment tools and security frameworks.

What are the most commonly searched types of Cyber Security Risk Analyst jobs in Austin, TX?

The most popular types of Cyber Security Risk Analyst jobs in Austin, TX are:

What job categories do people searching Cyber Security Risk Analyst jobs in Austin, TX look for?

The top searched job categories for Cyber Security Risk Analyst jobs in Austin, TX are:

What cities near Austin, TX are hiring for Cyber Security Risk Analyst jobs?

Cities near Austin, TX with the most Cyber Security Risk Analyst job openings:

Infographic showing various Cyber Security Risk Analyst job openings in Austin, TX as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $98,526 per year, or $47.4 per hour.

Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring

Marathon Petroleum

Blanco, TX • On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 3 days ago

New


Marathon Petroleum rating

6.3

Company rating: 6.3 out of 10

Based on 202 frontline employees who took The Breakroom Quiz

66th of 86 rated oil and gas companies


Job description

An exciting career awaits you


At MPC, we’re committed to being a great place to work – one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment.

Position Summary

The GRC Automation & Continuous Controls Monitoring (CCM) Senior Cybersecurity Engineer is a strategic and technical role, responsible or helping turn GRC into a trust engine for the business: reducing audit friction, improving business risk exposure visibility, accelerating evidence readiness, and enabling stronger operational confidence.

The role serves as the technical focal for GRC automation, developing automated evidence collection, control testing, risk intelligence, and AI-enabled governance capabilities across cloud, on-premises, identity, operational technology (OT), and security platforms. The role collaborates closely with Cyber Fusion, Enterprise Architecture, and Cyber Engineering, to design and build deterministic control-testing logic where deterministic approaches are enough; and AI agents and LLM-backed workflows where reasoning, summarization, or judgment is required, such as evidence-to-control mapping, attestation drafting, drift detection, and audit-package assembly.

This position belongs to a family of jobs with increasing responsibility, competency, and skill level. Actual position title and pay grade will be based on the selected candidate’s experience and qualifications.

Key Responsibilities
  • Conducts detailed analyses on changes to cybersecurity solutions and its relationship to internal and external systems to assess control effectiveness and cybersecurity risk. Resolves complex multi-functional technical issues.
  • Leverages cybersecurity assessments, standards, control testing methodologies, and compliance frameworks to ensure compliance across security systems.
  • Improves the efficiency and effectiveness of Security solutions, governance processes, automated controls, and monitoring capabilities.
  • Analyzes existing processes and procedures and leads efforts for implementing improvements, automation opportunities, or remediation activities.
  • Responsible for development and submission of Standard Operating Procedures.
  • Analyzes business impacting events, performs initial investigation, and evaluates control performance, exceptions, and risk indicators through continuous monitoring activities.
  • Investigates and analyzes the nature and scope of cyber incidents, control failures, and compliance exceptions. Assists in the development of risk mitigation and remediation plans to ensure regulatory and internal compliance. compliance.
  • Leads implementation of global security initiatives, policies, compliance requirements, and continuous control monitoring practices. Collects, validates, and reports security metrics, control performance results, and remediation efforts associated with them.
  • Manages cyber security-related consulting, guidance, and support to customers and stakeholders.
  • Translates security principles to assist configuration teams with incorporating security and compliance requirements into build and configuration processes.
  • Monitors emerging IT/OT, cybersecurity, automation, and artificial intelligence technologies as well as their impact on the security, risk, and compliance landscape.
Education and Experience
  • Bachelor’s Degree in Information Technology, related field or equivalent experience.
  • 5+ years of relevant experience required
  • Experience designing, implementing, and scaling GRC, CCM, or compliance automation solutions within a regulated environment required 
  • Experience in Python or comparable automation technologies, proficient in developing, integrating, and supporting automated workflows and REST API-based data integrations across multiple enterprise systems required.  
  • Hands-on experience integrating security-control data sources into a GRC / CCM evidence pipeline for continuous control testing required. This includes normalizing API, telemetry, configuration, vulnerability, identity, ticketing, and assessment data into control-level evidence, exception logic, ownership, frequency, and audit-ready records across at least three domains such as CNAPP / CSPM, SIEM / security data lake / XDR, CTEM / VM / ASPM, DSPM, ITSM, IAM, GRC / CCM, or AI/agent governance required.
  • Experience building LLM-backed agentic workflows on Azure AI Foundry, GitHub, or open-source frameworks preferred.  
  • Familiarity with NIST AI RMF, the OWASP LLM Top 10, or comparable AI risk frameworks preferred.  
Skills
  • Adaptability - Maintaining effectiveness when experiencing major changes in work responsibilities or environment (e.g., people, processes, structure, or culture); adjusting effectively to change by exploring the benefits, trying new approaches, and collaborating with others to make the change successful.
  • AI Fundamentals - Understanding of core AI concepts and methods, ability to apply AI to job-relevant use cases and capacity to contribute to organizational AI reimagination.
  • Change Management - Change Management refers to a systematic approach for defining and implementing procedures and/or technologies to deal with changes in the environment. It can mean adapting to change, controlling change and/or effecting change.
  • Authentic Communicator - Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue.
  • Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework.
  • General Programming - Applies a computer language to communicate with computers using a set of instructions and to automate the execution of tasks.
  • Intrusion Detection - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes.
  • Penetration Testing - The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually.
  • Relationship Management - Relationship Management is the conscious aim to develop and manage long-term and/or trusting relationships with internal or external customers, distributors, suppliers, or other parties in an environment which can include marketing, selling, servicing and other areas where a relationship is crucial to on-going success. At a senior level, it includes C-level relationships with senior management.
  • Security Controls - Manages and maintains an information system that focuses on the management of risk and the management of information systems security.
  • Security Governance - The process of developing and disseminating corporate security policies, frameworks and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats and vulnerabilities.
  • Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources.
  • Security Policy Management - The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources.
  • Threat Analysis - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics.
  • Threat Hunting - Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions.
  • Vulnerability Management - The process of defining, identifying, classifying and prioritizing vulnerabilities in computer systems, applications and network infrastructures and providing the organization with the necessary knowledge, awareness and risk background to understand the threats to its business

#TACorporate

MINIMUM QUALIFICATIONS:
Bachelor’s Degree in Information Technology, related field or equivalent experience. Professional certification, e.g. Security+, Network+, OSCP, GIAC, CEH preferred.
5+ years of relevant experience required 

As an energy industry leader, our career opportunities fuel personal and professional growth.

Location:

San Antonio, Texas

Additional locations:

Findlay, Ohio, Houston, Texas

Job Requisition ID:

00023222

Location Address:

19100 Ridgewood Pkwy

Education:

Employee Group:

Full time

Employee Subgroup:

Regular

Marathon Petroleum Company LP is an Equal Opportunity Employer and gives consideration for employment to qualified applicants without discrimination on the basis of race, color, religion, creed, sex, gender (including pregnancy, childbirth, breastfeeding or related medical conditions), sexual orientation, gender identity, gender expression, reproductive health decision-making, age, mental or physical disability, medical condition or AIDS/HIV status, ancestry, national origin, genetic information, military, veteran status, marital status, citizenship  or any other status protected by applicable federal, state, or local laws.  If you would like more information about your EEO rights as an applicant, click here.
If you need a reasonable accommodation for any part of the application process at Marathon Petroleum LP, please contact our Human Resources Department at talentacquisition@marathonpetroleum.com. Please specify the reasonable accommodation you are requesting, along with the job posting number in which you may be interested. A Human Resources representative will review your request and contact you to discuss a reasonable accommodation. Marathon Petroleum offers a total rewards program which includes, but is not limited to, access to health, vision, and dental insurance, paid time off, 401k matching program, paid parental leave, and educational reimbursement. Detailed benefit information is available at https://mympcbenefits.com.The hired candidate will also be eligible for a discretionary company-sponsored annual bonus program.
Equal Opportunity Employer: Veteran / Disability

We will consider all qualified Applicants for employment, including those with arrest or conviction records, in a manner consistent with the requirements of applicable state and local laws. In reviewing criminal history in connection with a conditional offer of employment, Marathon will consider the key responsibilities of the role.


What Marathon Petroleum employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Marathon Petroleum logo

About Marathon Petroleum

Sourced by ZipRecruiter

Marathon Petroleum Corporation, headquartered in Findlay, Ohio, US, is a leading independent petroleum refining, marketing, and transportation company. Their official website can be found at marathonpetroleum.com. The company, part of the energy sector, was established in 1887, making it one of the oldest petroleum companies in the US. It operates an integrated refining, marketing and transportation system concentrated primarily in the Midwest, Northeast, East Coast, Southeast and Gulf Coast of the United States. This includes refineries, pipelines, and terminals that process and transport crude oil and refined products.

Industry

Oil and gas extraction

Company size

10,000+ Employees

Headquarters location

Findlay, OH, US

Year founded

1887