1

Cyber Security Risk Assessment Jobs in New York (NOW HIRING)

... cybersecurity risk assessment procedures and control testing methodologies based on established frameworks and guidelines; • Assess NYC agencies' documented information security and technology ...

Director of Cybersecurity - GRC

Newark, NJ

$116K - $156K/yr

Implementing the risk assessment framework, which identifies critical cybersecurity and privacy impacting business process and/or systems. * Maintaining the global Cybersecurity and IT risk registers ...

Director of Cybersecurity - GRC

Newark, NJ · On-site

$116K - $156K/yr

Implementing the risk assessment framework, which identifies critical cybersecurity and privacy impacting business process and/or systems. * Maintaining the global Cybersecurity and IT risk registers ...

next page

Showing results 1-20

Cyber Security Risk Assessment information

See New York salary details

$62.4K

$145.5K

$203.5K

How much do cyber security risk assessment jobs pay per year?

As of Aug 27, 2026, the average yearly pay for cyber security risk assessment in New York is $145,465.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,400.00 and $164,100.00 per year, depending on experience, location, and employer.

What is a cyber security risk assessment?

A cyber security risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities that could negatively impact an organization's information systems. By analyzing assets, threats, vulnerabilities, and impacts, organizations can determine the likelihood and consequences of cyber incidents. The goal is to implement appropriate measures to reduce risks to acceptable levels, ensuring data protection and regulatory compliance. Regular risk assessments help organizations stay ahead of evolving cyber threats and make informed security decisions.

What are some common challenges faced by professionals conducting cyber security risk assessments?

Professionals in cyber security risk assessment often face challenges such as keeping up with rapidly evolving threats, effectively communicating technical risks to non-technical stakeholders, and ensuring comprehensive coverage across complex IT environments. Balancing thoroughness with tight deadlines can also be demanding, as assessments must be both detailed and timely. Collaborating with various departments to gather accurate information and maintain up-to-date asset inventories is crucial for effective risk analysis and mitigation.

What are the key skills and qualifications needed to thrive in cyber security risk assessment, and why are they important?

To excel in Cyber Security Risk Assessment, you need a solid understanding of information security principles, risk management frameworks, and often a degree in cybersecurity, IT, or related fields. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM are commonly required. Analytical thinking, attention to detail, and strong communication skills help professionals effectively assess risks and convey findings to stakeholders. These skills are crucial for identifying vulnerabilities, prioritizing threats, and ensuring the organization’s data and systems are adequately protected.

What is the difference between Cyber Security Risk Assessment vs Cyber Security Analyst?

AspectCyber Security Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating security risks and vulnerabilitiesMonitoring, analyzing, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams

While both roles require similar certifications and work within cybersecurity, a Cyber Security Risk Assessment focuses on evaluating potential vulnerabilities and risks to an organization’s assets. In contrast, a Cyber Security Analyst actively monitors and responds to security threats, ensuring ongoing protection. Understanding these differences helps organizations assign the right responsibilities to each role.

What are risk assessments in cybersecurity?

In cybersecurity, a risk assessment is a process that a Cyber Security Risk Assessment professional uses to identify, evaluate, and prioritize potential security threats and vulnerabilities within an organization's information systems. It involves analyzing assets, threats, and existing controls to determine the level of risk, helping organizations implement appropriate security measures and comply with standards like ISO 27001 or NIST. Regular risk assessments are essential for maintaining a strong security posture and managing evolving cyber threats.

What are popular job titles related to Cyber Security Risk Assessment jobs in New York?

For Cyber Security Risk Assessment jobs in New York, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Assessment jobs in New York look for?

The top searched job categories for Cyber Security Risk Assessment jobs in New York are:

What cities in New York are hiring for Cyber Security Risk Assessment jobs?

Cities in New York with the most Cyber Security Risk Assessment job openings:

Infographic showing various Cyber Security Risk Assessment job openings in New York as of August 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $145,465 per year, or $69.9 per hour.

Cyber Security Analyst (GRC)

Glint Tech Solutions

New York, NY • Remote

Full-time

This job post has expired 2 days ago. Applications are no longer accepted.


Job description

Job Title: Cyber Security Analyst (GRC)

Location: 100% Remote (EST/CST/MST)

Company Overview:
Glint Tech Solutions is a women-owned, global IT staffing and recruiting firm serving enterprise clients across the USA and Canada. We are currently hiring on behalf of a leading healthcare insurance client.

Project Description:
Our client is seeking a Cyber Security Risk Analyst to ensure organizational data remains protected from inappropriate access, disclosure, and damage by assessing, documenting, and socializing risk. This role reports to the Manager, Cybersecurity Risk and Compliance.

Key Responsibilities:

  • Support the Cybersecurity Risk Management program, guiding a diverse technical team and collaborating across risk-related teams
  • Partner with TPRM, Procurement, Legal, and business stakeholders on continuous monitoring efforts
  • Assess cybersecurity controls, identify gaps, and manage mitigation strategies to closure
  • Conduct risk assessments evaluating security practices, data handling procedures, and regulatory compliance (HIPAA, PCI, GDPR)
  • Prepare detailed risk assessment reports and maintain a comprehensive repository of documentation
  • Design, implement, and integrate security solutions to address enterprise risks
  • Develop Information Security Risk Metrics (KPIs/KRIs) to support the analytics team
  • Support NIST, FedRAMP, and HIPAA compliance efforts including assessment readiness, POA&M management, and continuous monitoring

Mandatory Skills:

  • One or more certifications: CISSP, CEH, CTIA, CAP, or EnCase Certified Examiner
  • Bachelor's Degree in Computer Science, Cyber Security, IT, or related field (or 4 additional years of experience in lieu of degree)
  • 5+ years of cybersecurity experience, specifically in Risk Management, with 3rd party/supplier risk assessment knowledge
  • Experience with eGRC platforms (HyperProof, Archer, or ServiceNow GRC)
  • Strong understanding of NIST Risk Management Framework and FAIR quantitative model
  • Ability to develop and socialize security policies, standards, and procedures
  • Knowledge of HIPAA/PHI security standards and network/firewall architecture

Nice-to-Have Skills:

  • SOC Reporting / HITRUST knowledge
  • Diverse background in cloud (off-prem) platforms
  • Experience within the healthcare insurance/payor industry