1

Cybersecurity Risk Analyst Jobs in North Carolina

Cyber and IT Risk Management Job Qualifications: Skills: Cyber Security Architecture, Risk ... Our work depends on a Cyber Security Analyst SME joining our team to support USPACOM J6 mission ...

This role requires a deep understanding of risk management practices and a proactive approach to ... Utilize quantitative and qualitative methods to analyze risk exposure * Develop and implement ...

New

Cybersecurity analyst - Responsible for protecting the organization's information systems, networks ... Conduct vulnerability assessments and risk analyses * Implement and maintain security controls ...

Information Technology and/or Cybersecurity background and/or experience, including 5-8+ years of ... analysis, identity management, access management, cloud security, or web security * Working ...

next page

Showing results 1-20

Cybersecurity Risk Analyst information

See North Carolina salary details

$13

$36

$59

How much do cybersecurity risk analyst jobs pay per hour?

As of Jul 28, 2026, the average hourly pay for cybersecurity risk analyst in North Carolina is $36.79, according to ZipRecruiter salary data. Most workers in this role earn between $27.07 and $44.81 per hour, depending on experience, location, and employer.

What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Primary FocusAssessing and managing security risksMonitoring, detecting, and responding to security threats
Work EnvironmentRisk management teams, security departmentsSecurity operations centers, IT teams
Industry UsageFinance, healthcare, governmentAll industries with cybersecurity needs

While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

What are the key skills and qualifications needed to thrive as a Cybersecurity Risk Analyst, and why are they important?

To thrive as a Cybersecurity Risk Analyst, you need a deep understanding of information security principles, risk management frameworks, and typically hold a degree in computer science or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, effective communication, and attention to detail help you identify risks and convey complex information to stakeholders. These skills and qualifications are vital to proactively safeguard organizational assets and ensure compliance in an evolving threat landscape.

Is 30 too old for cyber security?

Cybersecurity Risk Analysts can enter the field at any age, as experience, skills, and certifications like CompTIA Security+ or CISSP are often more important than age. Many professionals transition into cybersecurity later in their careers, bringing valuable perspectives and expertise. Age is generally not a barrier to starting or advancing in cybersecurity roles.

How much does a cybersecurity risk analyst make?

A cybersecurity risk analyst's average salary in the United States ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions typically start around $60,000, while experienced analysts with certifications like CISSP or CISA can earn over $130,000. The role often requires knowledge of risk assessment tools and security frameworks.

What are some common challenges faced by Cybersecurity Risk Analysts when working with cross-functional teams?

Cybersecurity Risk Analysts often collaborate with IT, compliance, and business units to assess and mitigate risks. A common challenge is translating complex technical risks into language that non-technical stakeholders can understand and act upon. Additionally, balancing security requirements with business objectives may require negotiation and creative problem-solving. Effective communication and relationship-building skills are key to ensuring that security recommendations are adopted across the organization.

What does a Cybersecurity Risk Analyst do?

A Cybersecurity Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organization’s information systems and data. They evaluate potential threats and vulnerabilities, develop strategies to minimize risks, and ensure compliance with security policies and regulations. Their work helps protect sensitive data and maintain the integrity and confidentiality of digital assets. Analysts often collaborate with IT and business teams to implement security controls and respond to security incidents.

What does a cyber security risk analyst do?

A cybersecurity risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and recommending measures to mitigate risks. They often use tools like risk assessment frameworks and require knowledge of security protocols, compliance standards, and threat intelligence. Their work helps organizations protect sensitive data and maintain secure systems.

Can you make $500,000 a year in cyber security?

Cybersecurity Risk Analysts typically earn between $70,000 and $130,000 annually, with top-tier professionals in senior or specialized roles potentially earning over $200,000. Achieving a salary of $500,000 usually requires advanced certifications, extensive experience, leadership positions, or working in high-paying industries or consulting roles.
Infographic showing various Cybersecurity Risk Analyst job openings in North Carolina as of July 2026, with employment types broken down into 85% Full Time, 11% Part Time, 1% Temporary, and 3% Contract. Highlights an 82% Physical, 8% Hybrid, and 10% Remote job distribution, with an average salary of $76,530 per year, or $36.8 per hour.
Senior Cybersecurity Governance Analyst

Senior Cybersecurity Governance Analyst

Civic Federal Credit Union

Raleigh, NC

$97K - $125K/yr

Other

Posted 5 days ago


Job description

Description

OUR CULTURE

Our organization believes we can all do well by doing good. We value the contributions of diverse minds and prioritize the success and well-being of our employees. We also believe every person in our organization plays a role in supporting a healthy environment and helping to achieve our goal of prosperity for all. To this end, we recruit bright, energetic, and talented people to be members of our team. In return, we offer a dynamic workplace that presents opportunities for professional advancement and individual growth. We strive to always display integrity, self-awareness, courage, and respect for one another while continuing to seek opportunities to learn. We really believe that when our employees succeed, our community wins. 


ABOUT THE POSITION

The Senior Cybersecurity Governance Analyst provides second-line oversight of the organization's cybersecurity risk management program by leading security architecture governance, threat-informed risk analysis, vulnerability management oversight, and independent security assurance activities. This role ensures cybersecurity risks are identified, evaluated, communicated, and managed in alignment with the organization's risk appetite, regulatory requirements, and strategic objectives. The Senior Cybersecurity Governance Analyst serves as a key advisor to technology, business, and risk stakeholders by providing independent challenge, governance oversight, and risk-informed recommendations to strengthen the organization's overall cybersecurity posture.


NORMAL DAY-TO-DAY WORK

  1. Conduct independent, risk-based reviews of system, network, application, cloud, and third-party architectures to identify cybersecurity risks and evaluate alignment with security policies, standards, and secure-by-design principles.
  2. Provide governance oversight of network segmentation, identity management, cloud security, and infrastructure security initiatives, identifying risks and recommending appropriate mitigating controls.
  3. Participate in project governance and system development lifecycle processes to ensure cybersecurity risks are identified, assessed, and addressed throughout technology initiatives.
  4. Perform cybersecurity risk assessments for technology initiatives, applications, infrastructure changes, and third-party services, evaluating threats, vulnerabilities, control effectiveness, and residual risk exposure.
  5. Facilitate risk acceptance, exception management, and remediation tracking processes, ensuring cybersecurity risks are appropriately documented, communicated, and managed in alignment with organizational risk tolerance.
  6. Support enterprise and operational risk management activities through risk analysis, reporting, and communication.
  7. Monitor and assess relevant threat intelligence sources and industry threat activity to identify emerging cyber threats and evaluate potential impacts on organizational risk exposure.
  8. Translate threat intelligence into risk informed recommendations for control enhancements, mitigation strategies, and cybersecurity planning.
  9. Provide independent oversight of the vulnerability management program, including review of prioritization methodologies and validation of remediation plans for critical and high-risk vulnerabilities.
  10. Monitor remediation performance against established service level objectives and provide reporting on vulnerability trends, exposure metrics, program effectiveness, and significant risk conditions.
  11. Coordinate and oversee penetration testing, red team assessments, and independent security reviews; evaluate results and ensure identified risks are appropriately addressed and remediated.
  12. Develop and maintain cybersecurity metrics, dashboards, risk reporting, policies, standards, and control frameworks, while contributing to cybersecurity strategy, maturity improvement initiatives, and governance committee activities as a subject matter expert on cybersecurity risk and governance matters.
  13. Display integrity, self-awareness, courage, and respect for staff while ensuring learning agility and flexibility communicating and delegating effectively. Work effectively, collaboratively, and creatively in a team-oriented environment both internally and externally.


JOB QUALIFICATIONS 

Here are a few skills you MUST have to be qualified for this position.

  1. Minimum of 7-9 years of experience in cybersecurity governance, risk management, security architecture, security assurance, vulnerability management, or related disciplines.
  2. Strong understanding of cybersecurity frameworks including NIST Cybersecurity Framework (CSF), NIST SP 800-53, FFIEC ACET, CIS Controls, and industry best practices.
  3. Experience conducting cybersecurity risk assessments and evaluating control effectiveness.
  4. Knowledge of secure architecture principles across cloud, network, application, and identity platforms.
  5. Understanding of threat intelligence, vulnerability management, and cybersecurity risk analysis methodologies.
  6. Experience supporting audits, regulatory examinations, and compliance initiatives.
  7. Strong analytical, communication, presentation, and report writing skills.
  8. Ability to function in a Consumer business office environment and utilize standard office equipment including but not limited to: PC, copier, telephone, etc.
  9. Ability to lift a minimum of 25 lbs. (file boxes, computer).
  10. Travel required on occasion.


Here are a few qualities we'd LIKE for you to have to make you more suited for this position.

  1. BA/BS degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or a related field.
  2. Experience in financial services, credit unions, or highly regulated industries.
  3. Familiarity with threat intelligence frameworks, MITRE ATT&CK, CVSS, and EPSS.
  4. Experience supporting board or executive-level cybersecurity reporting.
  5. Professional certifications such a CISSP, CRISC, CISM, CGRC, CISA, and/or GIAC (GCTI, GSEC, or equivalent).