1

Cyber Security Risk Assessment Jobs (NOW HIRING)

Cybersecurity Governance, Risk Management, Legal Regulations, IT or Security Audit, IT or Security Compliance preferred * 3+ years of experience performing risk assessments and/or cybersecurity ...

Cybersecurity Risk & Resilience Manager

Concord, CA · Hybrid

$121K - $164K/yr

Conduct cybersecurity risk assessments to identify control gaps, prioritize remediation, and support continuous improvement of the company's security posture. * Develop and maintain cybersecurity ...

next page

Showing results 1-20

Cyber Security Risk Assessment information

See salary details

$57K

$133K

$186K

How much do cyber security risk assessment jobs pay per year?

As of Jun 17, 2026, the average yearly pay for cyber security risk assessment in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

Can you make $500,000 a year in cyber security?

Cyber security professionals, especially those in senior roles such as security architects or chief information security officers, can earn $500,000 or more annually, often through a combination of base salary, bonuses, and stock options. Achieving this level typically requires extensive experience, advanced certifications like CISSP or CISM, and working in high-demand industries or organizations with complex security needs.

What are the key skills and qualifications needed to thrive in Cyber Security Risk Assessment, and why are they important?

To excel in Cyber Security Risk Assessment, you need a solid understanding of information security principles, risk management frameworks, and often a degree in cybersecurity, IT, or related fields. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM are commonly required. Analytical thinking, attention to detail, and strong communication skills help professionals effectively assess risks and convey findings to stakeholders. These skills are crucial for identifying vulnerabilities, prioritizing threats, and ensuring the organization’s data and systems are adequately protected.

What is the role of risk assessment in cyber security?

In cyber security, a risk assessment is a process that identifies, evaluates, and prioritizes potential threats and vulnerabilities to an organization's information systems. It helps security professionals, such as cyber security risk assessors, determine where to allocate resources and implement controls to reduce the likelihood and impact of cyber threats. Conducting regular risk assessments is essential for maintaining an effective security posture and complying with industry standards and regulations.

What is the difference between Cyber Security Risk Assessment vs Cyber Security Analyst?

AspectCyber Security Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating security risks and vulnerabilitiesMonitoring, analyzing, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams

While both roles require similar certifications and work within cybersecurity, a Cyber Security Risk Assessment focuses on evaluating potential vulnerabilities and risks to an organization’s assets. In contrast, a Cyber Security Analyst actively monitors and responds to security threats, ensuring ongoing protection. Understanding these differences helps organizations assign the right responsibilities to each role.

Is SOC analyst a high paying job?

SOC analysts typically earn competitive salaries that increase with experience, certifications, and the size of the organization. Entry-level positions may start at average wages, while experienced analysts with certifications like CISSP or CEH can earn higher salaries, making it a financially rewarding cybersecurity role.

What are some common challenges faced by professionals conducting cyber security risk assessments?

Professionals in cyber security risk assessment often face challenges such as keeping up with rapidly evolving threats, effectively communicating technical risks to non-technical stakeholders, and ensuring comprehensive coverage across complex IT environments. Balancing thoroughness with tight deadlines can also be demanding, as assessments must be both detailed and timely. Collaborating with various departments to gather accurate information and maintain up-to-date asset inventories is crucial for effective risk analysis and mitigation.

What is a cyber security risk assessment?

A cyber security risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities that could negatively impact an organization's information systems. By analyzing assets, threats, vulnerabilities, and impacts, organizations can determine the likelihood and consequences of cyber incidents. The goal is to implement appropriate measures to reduce risks to acceptable levels, ensuring data protection and regulatory compliance. Regular risk assessments help organizations stay ahead of evolving cyber threats and make informed security decisions.

What is the 80 20 rule in cyber security?

In cyber security risk assessment, the 80/20 rule suggests that approximately 80% of security issues are caused by 20% of vulnerabilities or threats. Security professionals focus on identifying and mitigating the most critical risks to efficiently improve overall security posture.
More about Cyber Security Risk Assessment jobs
What cities are hiring for Cyber Security Risk Assessment jobs? Cities with the most Cyber Security Risk Assessment job openings:
What states have the most Cyber Security Risk Assessment jobs? States with the most job openings for Cyber Security Risk Assessment jobs include:
Infographic showing various Cyber Security Risk Assessment job openings in the United States as of June 2026, with employment types broken down into 1% As Needed, 85% Full Time, 10% Part Time, and 4% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.
Cybersecurity Risk Analyst

Cybersecurity Risk Analyst

GM Financial

Irving, TX • Hybrid

Full-time

Retirement

Posted 27 days ago


GM Financial rating

7.7

Company rating: 7.7 out of 10

Based on 38 frontline employees who took The Breakroom Quiz

73rd of 142 rated vehicle equipment hire


Job description

Why GMF Cybersecurity?

Innovation isn't just a talking point at GM Financial, it's how we operate. By joining our team, you'll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.

Cybersecurity is central to our strategic vision, so you'll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies.

Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive. 


This position will be posted until filled.

What makes You an ideal candidate?

  • High level understanding of technology infrastructure, security concepts and platforms
  • Advanced knowledge of the OSI model and security that is associated with each layer
  • Knowledge of information security standards/frameworks (ie, NIST Cybersecurity Framework, ISO 27001) skillsDemonstrated success in project management
  • Ability to think strategically and make collaborative decisions
  • Ability to apply structured analysis methods to various types of data to establish trends, determine variability and business impact
  • Communicates quickly, clearly, concisely, appropriately and intelligently
  • Ability to effectively negotiate with vendors on upgrades and acquisitions
  • Foster open communication, speaks with impact, listens to others and writes effectively
  • Effective planning, time management, negotiation and delegation skills
  • Ability to approach problems with an open-mind and create new and innovative ideas and methods
  • Creative, Innovative, problem-solving and maximizing your potential to solve problems and improve methods

Experience and Education

  • 3+ years of experience in a large and complex business environment with a successful track record working directly with senior level management in Financial Services or Banking strongly preferred
  • 3+ years of experience in one or more of the following domains: Cybersecurity Governance, Risk Management, Legal Regulations, IT or Security Audit, IT or Security Compliance preferred
  • 3+ years of experience performing risk assessments and/or cybersecurity vendor risk assessments preferred
  • Experience with technical writing preferred
  • Bachelor's Degree in related field or equivalent work experience strongly strongly preferred

What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.

Our Culture: Our team members define and shape our culture - an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work - we thrive.

Compensation: Competitive pay and bonus eligibility.

Work Life Balance: Hybrid work environment, 4-days a week in office.

NOTE: We are unable to consider candidates who require visa sponsorship for this position

This position is not open to agency submissions

#GMFJobs #LI-Hybrid #LI-KA1

About the role:

The Cybersecurity Risk Analyst is responsible for executing a portion of the GM Financial (GMF) Cybersecurity Program designed to advise the organization on its management of Cybersecurity risk by organizing information, enabling risk management decisions and addressing threats to ensure the security of company systems and information assets. The Cybersecurity Risk Analyst is responsible for contributing to the success of comprehensive security initiatives, work with internal and external groups to ensure the program is operating effectively and efficiently and develop strong partnerships with business partners across the enterprise to ensure company information assets are protected at the appropriate level.

In this role you will:

  • Develop and update Cybersecurity policies, standards, and procedures referencing NIST 800-53 controls and the NIST Cybersecurity Framework, including implementing revisions in accordance with updates in relevant regulatory or industry Cybersecurity practices
  • Track remediation items and/or findings to completion as part of the risk assessment process
  • Collaborate with business partners to manage Cybersecurity needs
  • Initiate, facilitate, and promote Cybersecurity within the organization and monitor adherence to Cybersecurity policies, standards and controls
  • Perform third party risk assessments
  • Partner with Application Custodians to perform application risk assessments
  • Possess and continue building knowledge of GRC tooling, processes, and the global regulatory environment relating to the management of risk
  • Drive maturation of the Cybersecurity Risk Program through continuous process improvement
     

What GM Financial employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom