1

Cyber Security Risk Management Analyst Jobs (NOW HIRING)

The Cybersecurity Risk Manager will identify, assess, and mitigate risks affecting the company ... management Analytical skills Research skills Risk assessment Policy development Incident response ...

NY · On-site

Partner with metric owners and managers on data submission, interpretation, evidence standards, and ... cybersecurity risk, technology risk, GRC, risk analytics, metrics reporting, or data governance

next page

Showing results 1-20

Cyber Security Risk Management Analyst information

See salary details

$43K

$99.4K

$150K

How much do cyber security risk management analyst jobs pay per year?

As of Sep 13, 2026, the average yearly pay for cyber security risk management analyst in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What is the difference between Cyber Security Risk Management Analyst vs Cyber Security Analyst?

AspectCyber Security Risk Management AnalystCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, complianceMonitoring, threat detection, incident response
Primary FocusIdentifying and managing security risksDetecting and mitigating security threats

The Cyber Security Risk Management Analyst focuses on assessing and managing security risks within an organization, ensuring compliance and developing policies. In contrast, a Cyber Security Analyst primarily monitors systems for threats and responds to security incidents. Both roles require similar certifications but differ in their core responsibilities and daily activities.

What does a cybersecurity risk management analyst do?

A cybersecurity risk management analyst assesses an organization’s security posture by identifying vulnerabilities, analyzing potential threats, and implementing strategies to mitigate risks. They often use tools like risk assessment frameworks and may hold certifications such as CISSP or CISM to evaluate and improve security controls. Their work helps protect sensitive data and ensure compliance with security standards.

What cities are hiring for Cyber Security Risk Management Analyst jobs?

Cities with the most Cyber Security Risk Management Analyst job openings:

What states have the most Cyber Security Risk Management Analyst jobs?

States with the most job openings for Cyber Security Risk Management Analyst jobs include:

What are popular job titles related to Cyber Security Risk Management Analyst jobs?

For Cyber Security Risk Management Analyst jobs, the most frequently searched job titles are:

Infographic showing various Cyber Security Risk Management Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 83% Physical, 2% Hybrid, and 15% Remote job distribution, with an average salary of $99,400 per year, or $47.8 per hour.

Cybersecurity Risk Management Analyst

Plano, TX • On-site

PROLIM Global Corporation
IT Services • 201 - 500 employees

Other

This job post has expired 2 days ago. Applications are no longer accepted.


Key responsibilities

  • Conduct risk intake, assessments, triage sessions, and stakeholder risk discussions.

  • Assess technology and cybersecurity risks using NIST, COBIT, and ISO frameworks.

  • Develop risk treatment recommendations and track remediation activities through closure.


Job description

Looking for Technology & Cybersecurity Risk Management Analyst

Location: Plano, Texas (Hybrid)

Description

The Technology & Cybersecurity Risk Management (T&CRM) Engineer supports the T&CRM program by analyzing technology and cybersecurity risks, conducting risk assessments, leading risk-related initiatives, and enhancing risk management processes. This role helps identify, visualize, and reduce technology and cybersecurity risks while guiding stakeholders through risk-based decision-making.

Core Responsibilities

  • Conduct risk intake, assessments, triage sessions, and stakeholder risk discussions.
  • Assess technology and cybersecurity risks using NIST, COBIT, and ISO frameworks.
  • Identify, document, and evaluate inherent, residual, and emerging technology risks.
  • Review controls and evaluate their effectiveness in mitigating identified risks.
  • Map risks to controls and applicable framework and policy requirements.
  • Facilitate control walkthroughs and risk discussions with control owners and stakeholders.
  • Document risk statements, controls, evidence, and assessment results in governance tools and Word/Excel/PPT.
  • Develop risk treatment recommendations and track remediation activities through closure.
  • Escalate overdue actions, unresolved risks, and significant control or compliance concerns.
  • Prepare executive-ready risk reports, dashboards, and governance presentation materials.

Required Knowledge and Skills

  • Technology and Cybersecurity Fundamentals: Demonstrates a solid understanding of security controls, threats, and risk concepts. NIST, COBIT, and ISO 27001 framework knowledge.
  • Risk Assessment & Analysis: Ability to identify, assess, and document technology and cybersecurity risks and control gaps. Understanding of control design, control effectiveness, and risk mitigation concepts.
  • Project Management: Effectively plans, tracks, and executes work across multiple concurrent initiatives.
  • Process Improvement: Identifies opportunities to streamline workflows and improve operational efficiency.
  • Stakeholder Collaboration: Works effectively with crossfunctional teams and external partners.
  • Communication: Clearly communicates technical risk information to both technical and nontechnical audiences.
  • Attention to Detail: Produces accurate, welldocumented assessments and maintains reliable risk records.
  • Tool proficiency: Microsoft Word, Excel, PowerPoint, and CoPilot. ServiceNow.

Requirements

  • Bachelor s degree in Information Technology, Cybersecurity, Computer Science, Business, or a related field (or equivalent experience).
  • 1 3 years of experience in cybersecurity or technology risk management, IT risk, cybersecurity, compliance, or related discipline.
  • Foundational understanding of cybersecurity principles, risk assessment methodologies, and common security control frameworks.
  • Experience supporting projects or initiatives that require coordination across multiple stakeholders.
  • Strong written and verbal communication skills, with the ability to clearly document risks and recommendations.

Key Success Factors

  • Comfortable navigating conversations with Control Owners and stakeholders.
  • Clear and structured articulation of technology risks and controls.
  • Strong attention to detail and documentation quality.
  • Willingness to learn and grow within a Technology & Cybersecurity Risk Management function.
  • Collaborative mindset across technical and non-technical teams.