1

Cyber Security Risk Assessment Jobs (NOW HIRING)

Cybersecurity Risk Assessment * Conduct cybersecurity risk assessments for systems, applications, infrastructure, technologies, projects, and business initiatives. * Identify, assess, analyze, and ...

Cybersecurity Risk Assessment * Conduct cybersecurity risk assessments for systems, applications, infrastructure, technologies, projects, and business initiatives. * Identify, assess, analyze, and ...

Cybersecurity Risk Assessment * Conduct cybersecurity risk assessments for systems, applications, infrastructure, technologies, projects, and business initiatives. * Identify, assess, analyze, and ...

Cybersecurity Assessment Lead

Coronado, CA · On-site

$117K - $159K/yr

The Cybersecurity Assessment Lead serves as the senior assessor overseeing cybersecurity assessment activities supporting Risk Management Framework (RMF) authorization processes for customer networks ...

Cybersecurity Assessment Lead

Virginia Beach, VA · On-site

$98K - $133K/yr

The Cybersecurity Assessment Lead serves as the senior assessor overseeing cybersecurity assessment activities supporting Risk Management Framework (RMF) authorization processes for customer networks ...

Cybersecurity Assessment Lead

Coronado, CA · On-site

$117K - $159K/yr

The Cybersecurity Assessment Lead serves as the senior assessor overseeing cybersecurity assessment activities supporting Risk Management Framework (RMF) authorization processes for customer networks ...

The Cybersecurity Assessment Lead serves as the senior assessor overseeing cybersecurity assessment activities supporting Risk Management Framework (RMF) authorization processes for customer networks ...

Cybersecurity Risk Analyst

Evansville, IN · On-site

$36.93 - $55.40/hr

The Cybersecurity Risk Analyst will provide advice and recommendations to organizational ... Risk Assessment & Analysis * Conduct risk assessments on systems, infrastructure, software ...

Why GMF Cybersecurity? Innovation isn't just a talking point at GM Financial, it's how we operate ... Perform third party risk assessments * Partner with Application Custodians to perform application ...

next page

Showing results 1-20

Cyber Security Risk Assessment information

See salary details

$57K

$133K

$186K

How much do cyber security risk assessment jobs pay per year?

As of Jun 17, 2026, the average yearly pay for cyber security risk assessment in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

Can you make $500,000 a year in cyber security?

Cyber security professionals, especially those in senior roles such as security architects or chief information security officers, can earn $500,000 or more annually, often through a combination of base salary, bonuses, and stock options. Achieving this level typically requires extensive experience, advanced certifications like CISSP or CISM, and working in high-demand industries or organizations with complex security needs.

What are the key skills and qualifications needed to thrive in Cyber Security Risk Assessment, and why are they important?

To excel in Cyber Security Risk Assessment, you need a solid understanding of information security principles, risk management frameworks, and often a degree in cybersecurity, IT, or related fields. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM are commonly required. Analytical thinking, attention to detail, and strong communication skills help professionals effectively assess risks and convey findings to stakeholders. These skills are crucial for identifying vulnerabilities, prioritizing threats, and ensuring the organization’s data and systems are adequately protected.

What is the role of risk assessment in cyber security?

In cyber security, a risk assessment is a process that identifies, evaluates, and prioritizes potential threats and vulnerabilities to an organization's information systems. It helps security professionals, such as cyber security risk assessors, determine where to allocate resources and implement controls to reduce the likelihood and impact of cyber threats. Conducting regular risk assessments is essential for maintaining an effective security posture and complying with industry standards and regulations.

What is the difference between Cyber Security Risk Assessment vs Cyber Security Analyst?

AspectCyber Security Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating security risks and vulnerabilitiesMonitoring, analyzing, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams

While both roles require similar certifications and work within cybersecurity, a Cyber Security Risk Assessment focuses on evaluating potential vulnerabilities and risks to an organization’s assets. In contrast, a Cyber Security Analyst actively monitors and responds to security threats, ensuring ongoing protection. Understanding these differences helps organizations assign the right responsibilities to each role.

Is SOC analyst a high paying job?

SOC analysts typically earn competitive salaries that increase with experience, certifications, and the size of the organization. Entry-level positions may start at average wages, while experienced analysts with certifications like CISSP or CEH can earn higher salaries, making it a financially rewarding cybersecurity role.

What are some common challenges faced by professionals conducting cyber security risk assessments?

Professionals in cyber security risk assessment often face challenges such as keeping up with rapidly evolving threats, effectively communicating technical risks to non-technical stakeholders, and ensuring comprehensive coverage across complex IT environments. Balancing thoroughness with tight deadlines can also be demanding, as assessments must be both detailed and timely. Collaborating with various departments to gather accurate information and maintain up-to-date asset inventories is crucial for effective risk analysis and mitigation.

What is a cyber security risk assessment?

A cyber security risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities that could negatively impact an organization's information systems. By analyzing assets, threats, vulnerabilities, and impacts, organizations can determine the likelihood and consequences of cyber incidents. The goal is to implement appropriate measures to reduce risks to acceptable levels, ensuring data protection and regulatory compliance. Regular risk assessments help organizations stay ahead of evolving cyber threats and make informed security decisions.

What is the 80 20 rule in cyber security?

In cyber security risk assessment, the 80/20 rule suggests that approximately 80% of security issues are caused by 20% of vulnerabilities or threats. Security professionals focus on identifying and mitigating the most critical risks to efficiently improve overall security posture.
More about Cyber Security Risk Assessment jobs
What cities are hiring for Cyber Security Risk Assessment jobs? Cities with the most Cyber Security Risk Assessment job openings:
What states have the most Cyber Security Risk Assessment jobs? States with the most job openings for Cyber Security Risk Assessment jobs include:
Infographic showing various Cyber Security Risk Assessment job openings in the United States as of June 2026, with employment types broken down into 1% As Needed, 85% Full Time, 10% Part Time, and 4% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

Cybersecurity Risk Assessment Consultant

GDR Defense

Annapolis, MD • On-site

Contractor

Posted 25 days ago


Job description

“Join GD Resources for dynamic opportunities in business management and IT, where innovation meets excellence.”

 About the Company:

GD Resources is a Veteran Women-Owned Business Management and Information Technology company committed to excellence. GD Resources provides dynamic opportunities for veterans and professionals alike to contribute to innovative projects and drive success in a collaborative and supportive environment. Join us to make a difference, advance your career, and grow with a company that values integrity, diversity, and continuous improvement.

Job Title: Cybersecurity Risk Assessment Consultant
Location: Hybrid (onsite work possibly at various locations throughout Maryland)
Rate: Competitive, DOE (W2 or 1099)

Position Overview

We are seeking a Cybersecurity GRC Data & Dashboard Consultant to support follow-on work from approximately 90 completed cybersecurity assessments for a client. The consultant will transform assessment results into structured data, dashboards, and reports that align with NIST CSF, CMMI maturity scoring, and the client’s Governance, Risk, and Compliance (GRC) platform (e.g., ServiceNow GRC). This role is ideal for someone with strong cybersecurity domain knowledge, GRC platform experience, and hands-on skills in data analytics and dashboard development. The consultant will help build real-time, interactive views of client-wide and agency-level cybersecurity maturity, risks, issues, and remediation progress to support executive decision-making and continuous improvement.

Responsibilities

  • Convert all assessment results into a format compatible with the client’s GRC platform import requirements.
  • Prepare and manage key data outputs, including assessment scope, maturity scores (CMMI 0–5 by NIST CSF function/category/control), findings, risks, issues, and recommended remediation actions.
  • Provide data files and reports in Client-specified formats and offer reasonable technical assistance to support successful import into the Client’s GRC platform.
  • Incorporate agency issue response status data from the Client’s GRC platform into reporting and analysis, as needed.
  • Design, develop, and maintain real-time reporting dashboards using cybersecurity assessment data at both client-wide (aggregated) and agency (disaggregated) levels.
  • Build dashboards that show:
    • Top control categories by maturity
    • Most common constraints
    • Top recommended areas of improvement
    • CMMI-based maturity levels (0–5) across Identify, Protect, Detect, Respond, and Recover
    • Top findings, risks, issues, and issue response by agency
  • Ensure all dashboards are interactive, allowing users to drill down into underlying assessment data behind summary metrics.
  • Implement robust filters in dashboards to support targeted analysis, including filters for: Executive Branch designation, enterprise agency, agency size tier, IT complexity tier, and overall Maturity Group.
  • Build agency-level dashboards that:
    • Display average maturity scores by NIST CSF area compared against client-wide averages using side-by-side bar charts
    • Show maturity averages by CSF categories (e.g., Communications, Maintenance, Access Control) compared to client-wide averages
    • Highlight recommended areas of improvement, top 10 findings, and percent completion of identified issues
  • Create comparison dashboards that allow users to select one or more agencies and compare ratings and metrics across NIST CSF areas and categories.
  • Integrate historical NIST CSF assessment data from prior years into dashboards to show year-over-year trends at both agency and client-wide levels.
  • Ensure all required data entry is completed before final project close-out unless an exception is approved by the client.
  • Provide reasonable technical assistance to support ongoing imports and integration into the Client’s GRC platform.
  • Participate in weekly status meetings with client stakeholders.
  • Prepare concise written status updates on a bi-weekly basis and join additional meetings/discussions as needed.
  • Maintain and follow quality procedures, methodologies, and standards relevant to this contract, including those associated with Client platforms such as ServiceNow GRC.

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Data Analytics, or related field (or equivalent experience).
  • 5+ years of experience in cybersecurity, GRC, or risk management roles supporting government or large enterprise environments.
  • Hands-on experience working with NIST Cybersecurity Framework (NIST CSF) and familiarity with NIST 800-53 and/or NIST 800-171 controls.
  • Experience with CMMI-style maturity scoring (0–5) and translating assessment results into structured data and reports.
  • Practical experience with Governance, Risk, and Compliance (GRC) platforms, preferably ServiceNow GRC or similar Client/enterprise platforms.
  • Strong skills in data analysis and dashboard/report development using tools such as Power BI, Tableau, or similar visualization platforms.
  • Proven ability to design interactive dashboards with drill-down and filter capabilities for different organizational tiers (e.g., client-wide vs. agency-level).
  • Experience integrating and analyzing historical assessment data to present trends and performance changes over time.
  • Strong attention to detail and ability to ensure data quality, consistency, and completeness prior to project close-out.
  • Excellent written and verbal communication skills, including experience preparing status reports and presenting findings to technical and non-technical stakeholders.
  • Demonstrated commitment to ongoing training and staying current with cybersecurity standards, tools, and assessment methodologies.
  • Ability to participate in weekly calls and other meetings during standard business hours and collaborate effectively with a remote, multi-organization team.

GDR is an Equal Opportunity Employer. We consider all qualified applicants without regard to race, color, religion, sex, gender identity, national origin, age, disability, veteran status, or any other protected status under applicable law. We are committed to equal opportunity in all aspects of employment, including hiring, promotion, compensation, and benefits.