1

Cyber Security Risk Management Jobs (NOW HIRING)

Cybersecurity Assessment Lead

Coronado, CA · On-site

$117.70K - $159.10K/yr

The Cybersecurity Assessment Lead serves as the senior assessor overseeing cybersecurity assessment activities supporting Risk Management Framework (RMF) authorization processes for customer networks ...

Cybersecurity Assessment Lead

Virginia Beach, VA · On-site

$98.70K - $133.40K/yr

The Cybersecurity Assessment Lead serves as the senior assessor overseeing cybersecurity assessment activities supporting Risk Management Framework (RMF) authorization processes for customer networks ...

next page

Showing results 1-20

Cyber Security Risk Management information

See salary details

$57K

$133K

$186K

How much do cyber security risk management jobs pay per year?

As of May 29, 2026, the average yearly pay for cyber security risk management in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cyber Security Risk Management professional, and why are they important?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What are some typical challenges faced by professionals in Cyber Security Risk Management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

Can you make $500,000 a year in cyber security?

Cyber security risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with specialized skills such as threat intelligence or security architecture. Achieving this income typically requires extensive experience, advanced certifications like CISSP or CISM, and working in high-demand industries or organizations with complex security needs.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

More about Cyber Security Risk Management jobs
What cities are hiring for Cyber Security Risk Management jobs? Cities with the most Cyber Security Risk Management job openings:
What states have the most Cyber Security Risk Management jobs? States with the most job openings for Cyber Security Risk Management jobs include:
Infographic showing various Cyber Security Risk Management job openings in the United States as of May 2026, with employment types broken down into 59% Full Time, 35% Part Time, and 6% Contract. Highlights an 67% Physical, and 33% Hybrid job distribution, with an average salary of $132,962 per year, or $63.9 per hour.
Cybersecurity Risk Manager

Cybersecurity Risk Manager

City of Cleveland

Cleveland, OH

$90K - $95K/yr

Full-time

Medical, Dental, Vision, Life

Posted 4 days ago


City Of Cleveland (Ohio) rating

7.6

Company rating: 7.6 out of 10

Based on 29 frontline employees who took The Breakroom Quiz

368th of 638 rated public administrative organizations


Job description

Description Cybersecurity Risk Manager The Cybersecurity Specialist has a strategic role within the Division of Risk Management, acting as the bridge between technical IT vulnerabilities and organizational risk strategy. We are seeking an abstract thinker capable of linking emerging external threats with current internal IT protocols and software. This position focuses on proactive risk analysis, risk transference, and the continuous monitoring of the City's cyber-risk landscape.

Examples of Duties Typical duties performed, include, but are not limited to oversight of daily operations to ensure alignment with departmental objectives and organizational priorities. Dependent upon service area, may manage and direct staff to maintain efficient workflows, ensuring productivity and high-quality outcomes. Develop, implement, and evaluate operational strategies, procedures, and best practices to improve efficiency and effectiveness.

Monitor performance metrics and identify opportunities for process improvement. Collaborate with leadership and cross-functional teams to support departmental initiatives. Perform other job-related duties as required.

Minimum Qualifications Bachelor's degree required. Substitution: Two (2) years of any equivalent combination of education, training, and experience may substitute for each year of college education lacking. Six (6) years of full-time management experience required.

Four (4) years of demonstrated leadership experience. Strong critical thinking and analytical skills, with the ability to identify process inefficiencies and implement effective solutions. Excellent written and verbal communication skills.

Valid State of Ohio Driver's License required. Supplemental Information Key Responsibilities Vulnerability & Threat Analysis: Identify potential cyber-related compromises, points of entry, and system vulnerabilities. Link external global threats to the City's specific IT risk protocols.

Control Implementation: Establish, maintain, and test robust cybersecurity controls to safeguard municipal data. KPI & KRI Management: Maintain rigorous tracking and reporting of Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs). Supply Chain Risk: Identify and mitigate third-party supply chain risk vulnerabilities.

Risk Transference: Assist in the analysis and execution of risk transference strategies, including cyber insurance management and coverage alignment. Qualifications Education: Bachelor's degree in information technology, Enterprise Risk Management, Accounting, Finance, or Business (with a specific emphasis on IT and Cybersecurity). Driver's License: Must possess a valid State of Ohio Driver's License.

Preferred Qualifications & Requirements Experience: 3-5 years of professional experience in cybersecurity, risk analysis, or insurance. Government Expertise: Prior experience working within a government or public sector environment is highly preferred. Certifications: Possession of (or progress toward) relevant industry certifications such as CISSP, CISM, CISA, COSA, or CRISC.

Systems Knowledge: Familiarity with ERP systems and their integration into organizational workflows. Interpersonal Skills: Exceptional ability to build and maintain interdepartmental relationships, translating complex technical risks into actionable insights for non-technical stakeholders Strategic Thinking: Proven ability to manage complex projects with a "Finisher-style" approach to execution and tracking. Physical & Mental Requirements Ability to think abstractly and solve non-linear problems.

High level of attention to detail for tracking and documentation. The City's guiding principles are as follows: Placing Clevelanders at the Center, Empowering Employees to Do Purposeful Work, Defining Clear and Pragmatic Objectives, Leading with Trust and Transparency, Striving for Equity in All We Do, and Embracing Change. All City employees are responsible for embracing and carrying out these principles in all that they do.

The City of Cleveland makes available a variety of benefit options depending upon your employment status and any applicable union membership. In general, benefit options include comprehensive medical, dental, vision, prescription medical and life insurance. Specific information regarding benefit eligibility will be discussed and reviewed at the time of hire.


What City Of Cleveland (Ohio) employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom