1

Cybersecurity Risk Analyst Jobs in Colorado (NOW HIRING)

Analyst-Cyber GRC, Sr.

Lakewood, CO ยท On-site

$100K - $129K/yr

... cybersecurity risk and compliance program across the enterprise. This includes cyber risk ... The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy ...

Analyst-Cyber GRC, Sr.

Lakewood, CO ยท On-site

$99K - $128K/yr

The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy ... Conduct or support cybersecurity risk assessments, control evaluations, compliance assessments, and ...

Analyst-Cyber GRC, Sr.

Lakewood, CO ยท On-site

$100K - $129K/yr

The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy ... Conduct or support cybersecurity risk assessments, control evaluations, compliance assessments, and ...

CyberSecurity Senior Analyst

Centennial, CO ยท On-site

$100 - $125/hr

Lead information security initiatives that minimize risk and maximize compliance by facilitating ... Coordinate with business unit stakeholders to align cybersecurity practices and priorities across ...

Position Title: Jr. Risk Analyst Location: Amentum Downtown Building, Colorado Springs, CO ... Cybersecurity, or a related field; and/or 1 to 3 years of experience in risk management, project ...

New

Showing results 21-40

Cybersecurity Risk Analyst information

See Colorado salary details

$16

$42

$69

How much do cybersecurity risk analyst jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for cybersecurity risk analyst in Colorado is $42.57, according to ZipRecruiter salary data. Most workers in this role earn between $31.35 and $51.83 per hour, depending on experience, location, and employer.

What does a cybersecurity risk analyst do?

A Cybersecurity Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organizationโ€™s information systems and data. They evaluate potential threats and vulnerabilities, develop strategies to minimize risks, and ensure compliance with security policies and regulations. Their work helps protect sensitive data and maintain the integrity and confidentiality of digital assets. Analysts often collaborate with IT and business teams to implement security controls and respond to security incidents.

What are the key skills and qualifications needed to thrive as a cybersecurity risk analyst, and why are they important?

To thrive as a Cybersecurity Risk Analyst, you need a deep understanding of information security principles, risk management frameworks, and typically hold a degree in computer science or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, effective communication, and attention to detail help you identify risks and convey complex information to stakeholders. These skills and qualifications are vital to proactively safeguard organizational assets and ensure compliance in an evolving threat landscape.

What are some common challenges faced by cybersecurity risk analysts when working with cross-functional teams?

Cybersecurity Risk Analysts often collaborate with IT, compliance, and business units to assess and mitigate risks. A common challenge is translating complex technical risks into language that non-technical stakeholders can understand and act upon. Additionally, balancing security requirements with business objectives may require negotiation and creative problem-solving. Effective communication and relationship-building skills are key to ensuring that security recommendations are adopted across the organization.

What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Primary FocusAssessing and managing security risksMonitoring, detecting, and responding to security threats
Work EnvironmentRisk management teams, security departmentsSecurity operations centers, IT teams
Industry UsageFinance, healthcare, governmentAll industries with cybersecurity needs

While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

How much do cybersecurity risk analysts make?

Cybersecurity risk analysts typically earn a median annual salary of around $85,000 to $110,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in high-demand industries.

What cities in Colorado are hiring for Cybersecurity Risk Analyst jobs?

Cities in Colorado with the most Cybersecurity Risk Analyst job openings:

Infographic showing various Cybersecurity Risk Analyst job openings in Colorado as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 10% Part Time, and 3% Contract. Highlights an 86% Physical, 4% Hybrid, and 10% Remote job distribution, with an average salary of $88,548 per year, or $42.6 per hour.

Lead Cybersecurity Risk & Exposure Subject Matter Expert IV with Security Clearance

Colorado Springs, CO โ€ข On-site

Invictus International Consulting
Guided Missile and Space Vehicle Manufacturingย โ€ขย 11 - 50 employees

$89K - $114K/yr

Other

Posted 5 days ago


Job description

Title: Lead Cybersecurity Risk & Exposure Subject Matter Expert IV Location: Colorado Springs, CO Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details: * Serve as the senior SME for operational cyber risk, vulnerability/exposure analysis, and continuous monitoring supporting a DoD cyber defense mission
* Establish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize the exposures most likely to create operational or mission risk
* Lead complex exposure and impact assessments, including development of plausible exploitation scenarios, attack paths, affected-system analysis, compensating-control considerations, and risk-informed courses of action
* Provide expert vulnerability, asset, architecture, and security-control context to SOC leadership, Cybersecurity Operations Analysts, Threat Analysts, incident responders, and engineering teams during significant investigations and proactive defensive activity
* Lead analysis of ACAS/Tenable results, runZero asset information, STIG/configuration findings, system documentation, and other approved data to identify systemic weaknesses, exploitable conditions, and remediation priorities
* Own the SOC-side process for coordinating material cyber findings with affected system ISSOs/ISSMs, system owners, administrators, engineers, and authorization stakeholders; ensure operational findings are translated into appropriate mitigation, continuous-monitoring, POA&M, or RMF actions without duplicating system ISSO responsibilities
* Establish and maintain checklists, TTPs, guides, procedures, quality standards, and reporting methods for exposure analysis, risk prioritization, remediation validation, and SOC-to-system-security coordination
* Lead review of remediation evidence, recurring vulnerabilities, exposure trends, control weaknesses, and SOC-derived findings to identify systemic risk and recommend enterprise or site-level corrective actions
* Develop briefings, executive summaries, risk assessments, metrics, dashboards, and technical products that communicate operational exposure, remediation progress, control effectiveness, and mission impact to technical and leadership audiences
* Advise SOC leadership on vulnerability/exposure trends, high-risk assets, recurring security weaknesses, remediation priorities, and opportunities to improve the integration of vulnerability management, threat information, and cyber defense operations
* Mentor senior and developing analysts and provide technical quality review of exposure assessments, risk conclusions, remediation recommendations, and stakeholder coordination products
* Experience integrating vulnerability management, continuous monitoring, RMF/ISSO processes, and SOC or incident-response operations in a DoD/IC or similarly complex enterprise environment is highly desired Requirements: * Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree * Minimum of eight (8) years of relevant experience in addition to education level * Demonstrated expert knowledge of vulnerability/exposure management, threat-informed risk analysis, DoD continuous monitoring, RMF/security controls, network/system security, and technical risk assessment
* Experience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desired
* Demonstrated experience establishing exposure-analysis methodology, leading complex risk assessments, prioritizing remediation, and translating operational cyber findings into continuous-monitoring or RMF actions is strongly desired
* Must possess current DoD 8570 IAT II or IAM II certification * Experience working in a DoD or IC environment
* Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled