1

Cyber Security Risk Management Jobs in New York (NOW HIRING)

The role involves shaping risk management strategies, building risk frameworks, and assessing cybersecurity risks across NYC agencies. Responsibilities : • Build new risk processes and implement ...

Director of Cybersecurity - GRC

Newark, NJ · On-site

$116K - $156K/yr

NRC, SOX, DoE, NERC CIP, TSA, Internal Audits, etc.), Cybersecurity Risk, Cybersecurity Policy, Cybersecurity Awareness, and Nth Party Risk Management and Assurance. (S)he coordinates across all ...

Director of Cybersecurity - GRC

Newark, NJ · On-site

$116K - $156K/yr

NRC, SOX, DoE, NERC CIP, TSA, Internal Audits, etc.), Cybersecurity Risk, Cybersecurity Policy, Cybersecurity Awareness, and Nth Party Risk Management and Assurance. (S)he coordinates across all ...

next page

Showing results 1-20

Cyber Security Risk Management information

See New York salary details

$62.4K

$145.5K

$203.5K

How much do cyber security risk management jobs pay per year?

As of Aug 28, 2026, the average yearly pay for cyber security risk management in New York is $145,465.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,400.00 and $164,100.00 per year, depending on experience, location, and employer.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

What are the key skills and qualifications needed to thrive in cyber security risk management?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What are some typical challenges faced in cyber security risk management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

What does a cyber security risk management do?

A cyber security risk management professional identifies, assesses, and prioritizes potential security threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, often using frameworks like NIST or ISO, and may conduct regular audits to ensure security measures are effective.

What job categories do people searching Cyber Security Risk Management jobs in New York look for?

The top searched job categories for Cyber Security Risk Management jobs in New York are:

What cities in New York are hiring for Cyber Security Risk Management jobs?

Cities in New York with the most Cyber Security Risk Management job openings:

Infographic showing various Cyber Security Risk Management job openings in New York as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 15% Part Time, and 2% Contract. Highlights an 84% Physical, 2% Hybrid, and 14% Remote job distribution, with an average salary of $145,465 per year, or $69.9 per hour.

Technology Operational Risk Management Lead (Cybersecurity) - Vice President

JPMorgan Chase & Co.

Jersey City, NJ • On-site

$150 - $200/hr

Other

Re-posted 9 days ago


JPMorgan Chase & Co. rating

8.0

Company rating: 8.0 out of 10

Based on 497 frontline employees who took The Breakroom Quiz

72nd of 172 rated banks


Job description

Bring your expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient. You help the firm grow its business in a responsible way by anticipating new and emerging risks, and using your expert judgement to solve real-world challenges that impact our company, customers and communities. Our culture in Risk Management and Compliance is all about thinking outside the box, challenging the status quo and striving to be best-in-class.

As a Technology Risk Management Vice President within the Commercial & Investment Bank (CIB), you will be responsible for analyzing and identifying technology and cyber operational risks. Additionally to cybersecurity risk assessment activities, you will work closely with CIB Business Operational Risk teams, CIB Technology leadership, and Technology Risk Control teams to drive execution of operational risk management framework procedures. You will need to be an experienced technologist that understands Cybersecurity Risks, controls, and assessment methodologies. You will also participate in efforts to develop data-driven and automated testing approaches to risk identification and control assessment. To be successful in this role, you will need to possess significant technology and business facing activities in this role.

Job Responsibilities
  • Understand key processes and controls performed within CIB Technology
  • Perform independent assessment of Cybersecurity risks on CIB Technology through CCOR’s monitoring program.
  • Manage identified risks using firm’s Operational Risk Management Framework
  • Participate and challenge first line control designers and operators.
  • Conduct Testing and Monitoring and identify operational risk control gaps.
  • Develop and/or challenge KPIs / KRIs related to these risks through effective monitoring activities.
  • Participate in firm-wide global initiatives to analyze impact to the firm.
  • Partner and advise internal 2LoD teams of thematic monitoring and testing deficiencies.
  • Manage book of work assessments impacting CIB and produce weekly status updates.
Required qualifications, capabilities and skills
  • 7+ years of experience with infrastructure/application architecture.
  • 5+ years in a senior technology role (engineering, operations, or strategic planning)
  • 5+ years of Cybersecurity risk working experience.
  • Ability to understand complex technical systems, the business processes they support and synthesize the corresponding risks and controls.
  • Proven leadership skills and ability to influence decisions at senior levels
  • Ability to seamlessly transition between business and technical discussion.
  • Strong organizational and multi-tasking skills with demonstrated ability to manage expectations.
  • Excellent verbal and written communication skills, including the ability to present concise findings in a persuasive manner to a senior audience.
  • Deadline driven; delivering results with limited supervision.
#J-18808-Ljbffr

What JPMorgan Chase & Co. employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom