1

Cyber Security Risk Assessment Jobs in New York (NOW HIRING)

They will help shape Cyber Command's approach to risk management, build new risk frameworks and processes, and assess and monitor NYC agencies' cybersecurity risks. Responsibilities will include ...

Cyber Risk Analyst

Brooklyn, NY · On-site

$90K - $100K/yr

They will help shape Cyber Command's approach to risk management, build new risk frameworks and processes, and assess and monitor NYC agencies' cybersecurity risks. Responsibilities will include:

They will help shape Cyber Command's approach to risk management, build new risk frameworks and processes, and assess and monitor NYC agencies' cybersecurity risks. Responsibilities will include:

They will help shape Cyber Command's approach to risk management, build new risk frameworks and processes, and assess and monitor NYC agencies' cybersecurity risks. Responsibilities will include:

Risk Specialist

New York, NY · On-site

$100K - $130K/yr

... assess, and mitigate cybersecurity risk. * Manage the lifecycle of vulnerabilities and third-party risks by tracking findings, driving remediation efforts, facilitating risk acceptance, and ...

This role helps clients identify cybersecurity related improvements, conduct cybersecurity risk assessments, conduct cybersecurity scans and testing, document cybersecurity related policies and ...

Cybersecurity Manager

New York, NY

$121K - $164K/yr

HIPAA Security and Privacy Rule assessments * Third-party and vendor risk management * Incident ... Cybersecurity operations and controls * Data protection principles * HIPAA Security and Privacy ...

Cybersecurity Manager

Livingston, NJ

$121K - $163K/yr

HIPAA Security and Privacy Rule assessments * Third-party and vendor risk management * Incident ... Cybersecurity operations and controls * Data protection principles * HIPAA Security and Privacy ...

Cybersecurity GRC Engineer

New York, NY · On-site

$99K - $150K/yr

Perform technical risk assessments and gap analyses for new and existing technologies, systems, applications, cloud services, vendors, and business processes. * Partner with cybersecurity engineering ...

Showing results 41-60

Cyber Security Risk Assessment information

See New York salary details

$62.4K

$145.5K

$203.5K

How much do cyber security risk assessment jobs pay per year?

As of Sep 5, 2026, the average yearly pay for cyber security risk assessment in New York is $145,465.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,400.00 and $164,100.00 per year, depending on experience, location, and employer.

What is a cyber security risk assessment?

A cyber security risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities that could negatively impact an organization's information systems. By analyzing assets, threats, vulnerabilities, and impacts, organizations can determine the likelihood and consequences of cyber incidents. The goal is to implement appropriate measures to reduce risks to acceptable levels, ensuring data protection and regulatory compliance. Regular risk assessments help organizations stay ahead of evolving cyber threats and make informed security decisions.

What are some common challenges faced by professionals conducting cyber security risk assessments?

Professionals in cyber security risk assessment often face challenges such as keeping up with rapidly evolving threats, effectively communicating technical risks to non-technical stakeholders, and ensuring comprehensive coverage across complex IT environments. Balancing thoroughness with tight deadlines can also be demanding, as assessments must be both detailed and timely. Collaborating with various departments to gather accurate information and maintain up-to-date asset inventories is crucial for effective risk analysis and mitigation.

What are the key skills and qualifications needed to thrive in cyber security risk assessment, and why are they important?

To excel in Cyber Security Risk Assessment, you need a solid understanding of information security principles, risk management frameworks, and often a degree in cybersecurity, IT, or related fields. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM are commonly required. Analytical thinking, attention to detail, and strong communication skills help professionals effectively assess risks and convey findings to stakeholders. These skills are crucial for identifying vulnerabilities, prioritizing threats, and ensuring the organization’s data and systems are adequately protected.

What is the difference between Cyber Security Risk Assessment vs Cyber Security Analyst?

AspectCyber Security Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating security risks and vulnerabilitiesMonitoring, analyzing, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams

While both roles require similar certifications and work within cybersecurity, a Cyber Security Risk Assessment focuses on evaluating potential vulnerabilities and risks to an organization’s assets. In contrast, a Cyber Security Analyst actively monitors and responds to security threats, ensuring ongoing protection. Understanding these differences helps organizations assign the right responsibilities to each role.

What are risk assessments in cybersecurity?

In cybersecurity, a risk assessment is a process that a Cyber Security Risk Assessment professional uses to identify, evaluate, and prioritize potential security threats and vulnerabilities within an organization's information systems. It involves analyzing assets, threats, and existing controls to determine the level of risk, helping organizations implement appropriate security measures and comply with standards like ISO 27001 or NIST. Regular risk assessments are essential for maintaining a strong security posture and managing evolving cyber threats.

What are popular job titles related to Cyber Security Risk Assessment jobs in New York?

For Cyber Security Risk Assessment jobs in New York, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Assessment jobs in New York look for?

The top searched job categories for Cyber Security Risk Assessment jobs in New York are:

What cities in New York are hiring for Cyber Security Risk Assessment jobs?

Cities in New York with the most Cyber Security Risk Assessment job openings:

Infographic showing various Cyber Security Risk Assessment job openings in New York as of August 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $145,465 per year, or $69.9 per hour.

Operational Risk and Control Analyst

Network Temp Inc

New York, NY • On-site

$75K - $110K/yr

Full-time

Re-posted 16 days ago


Key responsibilities

  • Coordinate and conduct Risk and Control Self-Assessment (RCSA), including Control Testing and maintaining Risk Registers.

  • Perform analyses of risk data, conduct deep dives on controls, and identify remediation for gaps to mitigate operational risks.

  • Prepare operational risk reports, facilitate reporting to senior management, and contribute to risk assessments and risk culture initiatives.


Job description

Description:

Your Role Overview:

Risk and Control Analyst is accountable for engaging in the proactive identification, escalation, and timely mitigation of operational risks. Responsible for administering Operational Risk and Control Self-Assessment (RCSA) including Control Testing and Risk Register. Participates in the design, supervision, and implementation of an RCSA program to provide support in identifying, assessing, monitoring, and escalating the risk assessments performed by the First Line of the Bank.

The analyst is given broad exposure to all functions and business lines within the Americas Division and is expected to execute all aspects of the Operational Risk Management Framework through the 2nd line of defense oversight activities.
 

Your Duties and Responsibilities:

  1. Coordinate and conduct Risk and Control Self-Assessment (“RCSA”).
  2. Coordinate and conduct Vendor Risk Assessment, Model Risk Assessment, and Operational Risk Event (Business Continuity) Assessment.
  3. Conduct analyses of risk data to identify trends and potential areas of concern.
  4. Perform deep dives to assess the design and operational effectiveness of controls surrounding key technology and operations processes, and to identify remediation for gaps to mitigate risks.
  5. Challenge risks within scenario analysis.
  6. Maintain Risk Registers.
  7. Contribute to the New Product Approval process. 
  8. Research regulatory changes and/or risk trends applicable to area(s) of coverage.
  9. Assist in various Operational Risk related projects and initiatives.
  10. Proactively contribute to the risk culture and overall awareness of operational risk and contribute to the creation and delivery of operational risk management training and/or workshop sessions.
  11. Prepare operational risk reports, schedule meetings, takes notes, prepare minutes, and maintain files for ORM department.
  12. Provide analysis and coordination for the ORM department.
  13. Provide challenges on key indicators and material operational risks.
  14. Identify emerging operational risks in the context of the regulatory and business operation environment and assure that measures are being taken to mitigate these risks.
  15. Serve as a subject matter expert for operational risk and control assessments, and independently prepare a comprehensive report.
  16. Facilitate accurate and appropriate reporting of operational risks to senior management. 
  17. Analyze operational risk data (losses, metrics, or assessment results) to identify areas of excessive risk and to ensure that mitigation efforts are having the desired effect(s).
  18. Perform other duties and responsibilities as assigned by management.

Work schedule: 3 days onsite (Midtown Manhattan), 2 days remote

Requirements:

 Your Qualifications:

  1. Bachelor’s degree or equivalent. 
  2. A minimum of 4-5 years of prior operational risk management experience with a financial institution, including exposure to technology risk, information/cyber security risk, vendor risk and/or model risk management.
  3. Integrative thinking skills, basic risk management knowledge, good organizational, communication and influencing skills.
  4. Analytical and thorough approach to form defensible conclusions from risk assessments.
  5. Able to present to and respond effectively to internal and external stakeholders.
  6. Team-oriented with strong interpersonal skills, able to calmly manage conflict and pressure in a demanding, high-volume environment.
  7. Able to be flexible and capable of prioritizing based on changing internal or external demands.
  8. Good computer skills in Microsoft Office including Excel, Word, and PowerPoint.