1

Cyber Security Risk Management Jobs (NOW HIRING)

These teams collaborate to identify, manage and respond to threats, all while driving innovation ... The Cybersecurity Risk Analyst is responsible for executing a portion of the GM Financial (GMF ...

These teams collaborate to identify, manage and respond to threats, all while driving innovation ... Cybersecurity Governance, Risk Management, Legal Regulations, IT or Security Audit, IT or Security ...

Cybersecurity Assessment Lead

Coronado, CA · On-site

$117K - $159K/yr

The Cybersecurity Assessment Lead serves as the senior assessor overseeing cybersecurity assessment activities supporting Risk Management Framework (RMF) authorization processes for customer networks ...

Cybersecurity Assessment Lead

Virginia Beach, VA · On-site

$98K - $133K/yr

The Cybersecurity Assessment Lead serves as the senior assessor overseeing cybersecurity assessment activities supporting Risk Management Framework (RMF) authorization processes for customer networks ...

Develop and manage the Cybersecurity Risk Register and audit documentation. * Build automated compliance monitoring routines and security dashboards. * Partner across IT, operations, and leadership ...

next page

Showing results 1-20

Cyber Security Risk Management information

See salary details

$57K

$133K

$186K

How much do cyber security risk management jobs pay per year?

As of Jun 20, 2026, the average yearly pay for cyber security risk management in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cyber Security Risk Management professional, and why are they important?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

What is risk management in cyber security?

In cyber security risk management, professionals identify, assess, and prioritize potential security threats to an organization’s information systems. They implement strategies and controls to mitigate or accept risks, often using frameworks like NIST or ISO 27001, to protect data and ensure business continuity.

Is 40 too old for cyber security?

Cyber security risk management is a field open to individuals of all ages, and age is not a barrier to entering the profession. Many professionals successfully transition into cyber security later in their careers by gaining relevant certifications like CISSP or CompTIA Security+ and developing skills in areas such as threat analysis and security tools. Experience, continuous learning, and adaptability are often more important than age in this industry.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

What are some typical challenges faced by professionals in Cyber Security Risk Management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

Can you make $500,000 a year in cyber security?

Cyber security risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working for large organizations with complex security needs.

Is security risk management a good career?

Security risk management is a valuable career in cybersecurity, focusing on identifying and mitigating potential threats to an organization’s information systems. It often requires knowledge of security frameworks, risk assessment tools, and certifications like CISSP or CISM, and offers strong job growth and demand across various industries.
More about Cyber Security Risk Management jobs
What cities are hiring for Cyber Security Risk Management jobs? Cities with the most Cyber Security Risk Management job openings:
What states have the most Cyber Security Risk Management jobs? States with the most job openings for Cyber Security Risk Management jobs include:
What job categories do people searching Cyber Security Risk Management jobs look for? The top searched job categories for Cyber Security Risk Management jobs are:
Infographic showing various Cyber Security Risk Management job openings in the United States as of June 2026, with employment types broken down into 1% As Needed, 47% Full Time, 46% Part Time, 1% Temporary, and 5% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.
Mgr Cybersecurity Program & Risk

Mgr Cybersecurity Program & Risk

Blount Fine Foods

Warren, RI • On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 18 days ago


Blount Fine Foods rating

6.3

Company rating: 6.3 out of 10

Based on 23 frontline employees who took The Breakroom Quiz

264th of 385 rated food and drinks producers


Job description

Description
Bringing our love of food to families for five generations! Blount Fine Foods is a family-owned and operated manufacturer, marketer, and developer of premium fresh prepared foods. We are an engaging team, bringing restaurant-quality products to America including single-serve grab-n-go fresh soups, mac & cheese, and entrées in grocery stores across the country, as well as for hot bars and restaurants. Help us create the finest food experiences including those with specialty certifications that include organic, gluten-free, and low sodium, among others. Join a proven team for growth, success, and a satisfying career!
THIS OPPORTUNITY IS FULLY ONSITE AT OUR COROPRATE OFFICE IN WARREN, RI.
Job Summary
The Cybersecurity Program & Risk Manager is accountable for owning, integrating, and advancing the organization's enterprise cybersecurity risk posture. This role goes beyond program coordination to actively shape risk decisions, influence executive leadership, and ensure cybersecurity risks are understood, prioritized, and managed in business terms. The position serves as the single point of accountability for cybersecurity risk management across governance, third-party risk, workforce behavior, and compliance obligations.
Duties/Responsibilities
Enterprise Cybersecurity Risk & Program Ownership
  • Own the enterprise cybersecurity risk framework, including identification, assessment, prioritization, and mitigation tracking.
  • Maintain and mature the cybersecurity and technology risk register with clear risk statements, ownership, and mitigation plans.
  • Develop and execute a multi-year cybersecurity program roadmap aligned to business strategy.
  • Facilitate cybersecurity maturity assessments and pragmatic improvement planning.
Third-Party, Supply Chain & Subsidiary Risk Management
  • Own cybersecurity risk management for third parties, suppliers, logistics partners, co-manufacturers, and SaaS vendors.
  • Define and enforce cybersecurity requirements in contracts and ensure evidence-based compliance.
  • Coordinate vendor risk assessments and remediation activities with Procurement and Legal.
  • Ensure subsidiaries comply with corporate cybersecurity policies and minimum standards.
Governance, Executive Reporting & Assurance
  • Prepare cybersecurity risk materials for leadership and governance committees.
  • Translate cybersecurity risk into business, operational, and reputational impact.
  • Support audits, assessments, and external reviews with defensible documentation.
  • Develop dashboards and executive metrics to show risk posture and trend visibility.
Security Awareness, Training & Human Risk
  • Own the enterprise security awareness and phishing simulation program.
  • Analyze trends and recommend corrective actions to reduce human risk.
  • Partner with HR and Communications to embed cybersecurity into company culture.
Enterprise Coordination Across Security Domains
  • Maintain awareness across incident response, vulnerability management, IAM, and endpoint security.
  • Coordinate security initiatives without owning day-to-day technical operations.
  • Ensure clarity of ownership and risk coverage across teams and vendors.

Education and/or Experience
  • 7-10+ years of experience in cybersecurity, technology risk management, or enterprise risk roles.
  • Demonstrated ownership of cybersecurity or technology risk programs.
  • Experience with third-party risk management, risk registers, audits, and compliance documentation.
  • Ability to translate technical risk into executive-level business impact.
  • Strong judgment, stakeholder management, and ability to influence without authority.
  • Experience in manufacturing, food, CPG, or industrial environments.
  • Practical experience with NIST CSF, ISO 27001, or similar frameworks.
  • Exposure to multi-entity or subsidiary operating models.
  • Experience presenting risk to executive leadership or Boards.

Our Total Compensation Package Includes:
  • Medical, dental and vision benefits.
  • 401k with Company match.
  • Paid time off including vacation, sick time and holidays.
  • Education Assistance Program.
  • Life Insurance and Short-Term Disability.
  • Discounts on Blount products at Company retail location.
  • Discretionary Annual Bonus Program.

What Blount Fine Foods employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom