1

Cyber Security Risk Assessment Jobs in New York (NOW HIRING)

Senior Cybersecurity GRC

Manhattan, NY · On-site

$110K - $142K/yr

Senior Cybersecurity GRC & Third Party Risk Consultant Location: New York, NY (Onsite/Hybrid ... Design and maintain risk taxonomy, risk assessment methodologies, and risk scoring models.

As a Cyber & AI Risk Analyst, you will play a critical role in strengthening Alpaca's security ... assessment, and documentation of cybersecurity and AI-related risks that impact our infrastructure ...

Act as the primary technical consultant on all aspects of cybersecurity, including threat modeling, risk assessment, secure coding practices, and compliance. Conduct research on emerging threats and ...

... risk assessment, secure coding practices, and compliance. • Conduct research on emerging threats and vulnerabilities, and translate this research into actionable requirements for the AI models and ...

Conduct structured assessments, data analysis, control evaluations, and risk reviews to identify opportunities for improving cybersecurity maturity and operational effectiveness. * Lead client ...

Managing and overseeing assessment teams, project timelines, and client deliverables across ... Information Technology and/or Cybersecurity background and/or experience, including 5-8+ years of ...

Managing and overseeing assessment teams, project timelines, and client deliverables across ... Information Technology and/or Cybersecurity background and/or experience, including 5-8+ years of ...

Showing results 41-60

Cyber Security Risk Assessment information

See New York salary details

$62.4K

$145.5K

$203.5K

How much do cyber security risk assessment jobs pay per year?

As of Aug 11, 2026, the average yearly pay for cyber security risk assessment in New York is $145,465.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,400.00 and $164,100.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in cyber security risk assessment, and why are they important?

To excel in Cyber Security Risk Assessment, you need a solid understanding of information security principles, risk management frameworks, and often a degree in cybersecurity, IT, or related fields. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM are commonly required. Analytical thinking, attention to detail, and strong communication skills help professionals effectively assess risks and convey findings to stakeholders. These skills are crucial for identifying vulnerabilities, prioritizing threats, and ensuring the organization’s data and systems are adequately protected.

What is the difference between Cyber Security Risk Assessment vs Cyber Security Analyst?

AspectCyber Security Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating security risks and vulnerabilitiesMonitoring, analyzing, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams

While both roles require similar certifications and work within cybersecurity, a Cyber Security Risk Assessment focuses on evaluating potential vulnerabilities and risks to an organization’s assets. In contrast, a Cyber Security Analyst actively monitors and responds to security threats, ensuring ongoing protection. Understanding these differences helps organizations assign the right responsibilities to each role.

What are some common challenges faced by professionals conducting cyber security risk assessments?

Professionals in cyber security risk assessment often face challenges such as keeping up with rapidly evolving threats, effectively communicating technical risks to non-technical stakeholders, and ensuring comprehensive coverage across complex IT environments. Balancing thoroughness with tight deadlines can also be demanding, as assessments must be both detailed and timely. Collaborating with various departments to gather accurate information and maintain up-to-date asset inventories is crucial for effective risk analysis and mitigation.

What is a cyber security risk assessment?

A cyber security risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities that could negatively impact an organization's information systems. By analyzing assets, threats, vulnerabilities, and impacts, organizations can determine the likelihood and consequences of cyber incidents. The goal is to implement appropriate measures to reduce risks to acceptable levels, ensuring data protection and regulatory compliance. Regular risk assessments help organizations stay ahead of evolving cyber threats and make informed security decisions.
What are popular job titles related to Cyber Security Risk Assessment jobs in New York? For Cyber Security Risk Assessment jobs in New York, the most frequently searched job titles are:
What job categories do people searching Cyber Security Risk Assessment jobs in New York look for? The top searched job categories for Cyber Security Risk Assessment jobs in New York are:
What cities in New York are hiring for Cyber Security Risk Assessment jobs? Cities in New York with the most Cyber Security Risk Assessment job openings:
Infographic showing various Cyber Security Risk Assessment job openings in New York as of August 2026, with employment types broken down into 82% Full Time, 15% Part Time, 1% Temporary, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $145,465 per year, or $69.9 per hour.

Senior Cybersecurity GRC

BIGDATAAPPTECH LLC

Manhattan, NY • On-site

$110K - $142K/yr

Other

Posted 28 days ago


Job description

Job Title: Senior Cybersecurity GRC & Third Party Risk Consultant
Location: New York, NY (Onsite/Hybrid)
Duration: Long-Term Contract(W2)

Job Description
We are seeking an experienced Senior Cybersecurity GRC & Third Party Risk Consultant to support the implementation and enhancement of Third Party and Fourth Party Risk Management programs. The ideal candidate will have strong expertise in vendor risk management, information security governance, regulatory compliance, and Archer GRC solutions within the banking or financial services industry.

Key Responsibilities
Gather and define business requirements for Third Party and Fourth Party Risk Management initiatives.
Lead the implementation and alignment of SIG 2027 questionnaires, risk domains, and assessment frameworks.
Design and maintain risk taxonomy, risk assessment methodologies, and risk scoring models.
Configure and support RSA Archer TPRM workflows and related GRC processes.
Collaborate with business and technical teams to implement vendor risk workflows, questionnaires, and data models.
Support vendor onboarding, security due diligence, risk assessments, continuous monitoring, and remediation activities.
Ensure compliance with regulatory, governance, audit, and information security requirements.
Participate in User Acceptance Testing (UAT), data validation, issue resolution, and governance approvals.
Develop executive dashboards, KPIs, and risk analytics for vendor risk reporting.
Recommend improvements to Third Party Risk Management processes and governance practices.
Required Skills
10+ years of experience in Third Party Risk Management (TPRM), Vendor Risk Management (VRM), Information Security Risk, or Governance, Risk & Compliance (GRC).
Strong expertise in Third Party and Fourth Party Risk Management frameworks and operating models.
Deep understanding of SIG (Standardized Information Gathering) questionnaires, including SIG 2027.
Experience defining risk taxonomy, risk assessment methodologies, and risk scoring models.
Hands-on experience with RSA Archer TPRM or similar GRC platforms.
Strong knowledge of the vendor lifecycle, including onboarding, due diligence, continuous monitoring, and offboarding.
Experience working with cybersecurity governance, regulatory compliance, and audit frameworks.
Excellent communication, stakeholder management, and documentation skills.