Principal, Cybersecurity Risk
Durham, NC · On-site
The candidate will quantify cyber risk and present analyses at the technical and executive level ... Demonstrated experience in cybersecurity risk management, assessment frameworks, and metrics ...
Durham, NC · On-site
The candidate will quantify cyber risk and present analyses at the technical and executive level ... Demonstrated experience in cybersecurity risk management, assessment frameworks, and metrics ...
Durham, NC · On-site
The candidate will quantify cyber risk and present analyses at the technical and executive level ... Demonstrated experience in cybersecurity risk management, assessment frameworks, and metrics ...
Durham, NC · On-site
The candidate will quantify cyber risk and present analyses at the technical and executive level ... Demonstrated experience in cybersecurity risk management, assessment frameworks, and metrics ...
Durham, NC · On-site
The candidate will quantify cyber risk and present analyses at the technical and executive level ... Demonstrated experience in cybersecurity risk management, assessment frameworks, and metrics ...
Risk Management • Risk Analysis: Analyze and assess third-party cybersecurity risks. • Compliance Monitoring: Monitor vendor compliance with security requirements. • Remediation Support:
Risk Management • Risk Analysis: Analyze and assess third-party cybersecurity risks. • Compliance Monitoring: Monitor vendor compliance with security requirements. • Remediation Support:
Ideal candidate will have a well-rounded application of cyber security risk management principles ... Review and analyze complex multi-faceted larger scale or longer-term Information Security Analysis ...
Ideal candidate will have a well-rounded application of cyber security risk management principles ... Review and analyze complex multi-faceted larger scale or longer-term Information Security Analysis ...
$97K - $126K/yr
Essential Functions Evaluate risk and control identification within key processes and perform gap ... Analyze and assess cybersecurity and AI-related risks associated with new products or services ...
$97K - $126K/yr
Essential Functions Evaluate risk and control identification within key processes and perform gap ... Analyze and assess cybersecurity and AI-related risks associated with new products or services ...
Charlotte, NC · On-site
Extensive data analytics experience in fraud analytics, fraud prevention, risk management, financial services, cybersecurity, or a related field, and experience translating findings into business ...
Charlotte, NC · On-site
Extensive data analytics experience in fraud analytics, fraud prevention, risk management, financial services, cybersecurity, or a related field, and experience translating findings into business ...
Raleigh, NC · On-site
$40K - $55K/yr
Risk Assessment: Assist with cybersecurity risk assessments, identify potential vulnerabilities ... Analytical mindset with strong problem-solving capability. * Working knowledge of Microsoft ...
Raleigh, NC · On-site
$40K - $55K/yr
Risk Assessment: Assist with cybersecurity risk assessments, identify potential vulnerabilities ... Analytical mindset with strong problem-solving capability. * Working knowledge of Microsoft ...
... Cybersecurity Risk Oversight, the Sr. Cybersecurity Risk Oversight Professional is a 2nd Line of ... Analyze and assess risks associated with new products or services including third parties.Assist ...
... Cybersecurity Risk Oversight, the Sr. Cybersecurity Risk Oversight Professional is a 2nd Line of ... Analyze and assess risks associated with new products or services including third parties.Assist ...
Charlotte, NC · On-site
Sr Cyber Security Engineer /Analyst Locations: Charlotte, NC & Chandler, AZ (Hybrid), (3 days onsite/2 wfh) Duration: 12+ Months Contract Project Scope: Support the Risk / Governance / Data Loss ...
Quick apply
Charlotte, NC · On-site
Sr Cyber Security Engineer /Analyst Locations: Charlotte, NC & Chandler, AZ (Hybrid), (3 days onsite/2 wfh) Duration: 12+ Months Contract Project Scope: Support the Risk / Governance / Data Loss ...
Routinely publishes Governance, Risk, and Compliance (GRC) metrics. * Examines design and ... Malware analysis. * Multi-task and manage demands of multiple projects, incidents, and tasks.
Routinely publishes Governance, Risk, and Compliance (GRC) metrics. * Examines design and ... Malware analysis. * Multi-task and manage demands of multiple projects, incidents, and tasks.
Raleigh, NC · On-site
Routinely publishes Governance, Risk, and Compliance (GRC) metrics. * Examines design and ... Malware analysis. * Multi-task and manage demands of multiple projects, incidents, and tasks.
Raleigh, NC · On-site
Routinely publishes Governance, Risk, and Compliance (GRC) metrics. * Examines design and ... Malware analysis. * Multi-task and manage demands of multiple projects, incidents, and tasks.
You'll work alongside cybersecurity, technology, and business partners to analyze threats, strengthen controls, and support risk-informed decision-making. Through technical capstones, hackathons, and ...
You'll work alongside cybersecurity, technology, and business partners to analyze threats, strengthen controls, and support risk-informed decision-making. Through technical capstones, hackathons, and ...
You'll work alongside cybersecurity, technology, and business partners to analyze threats, strengthen controls, and support risk-informed decision-making. Through technical capstones, hackathons, and ...
You'll work alongside cybersecurity, technology, and business partners to analyze threats, strengthen controls, and support risk-informed decision-making. Through technical capstones, hackathons, and ...
In cybersecurity we analyze and diagnose specific environments from the point of view of compliance or regulatory risks, we incorporate technological solutions, we manage the operation of ...
In cybersecurity we analyze and diagnose specific environments from the point of view of compliance or regulatory risks, we incorporate technological solutions, we manage the operation of ...
The ITRM Senior Analyst keeps abreast of external cybersecurity trends, technologies, and cyber risk management approaches, and frequently collaborates with other teams on cyber risk-related ...
The ITRM Senior Analyst keeps abreast of external cybersecurity trends, technologies, and cyber risk management approaches, and frequently collaborates with other teams on cyber risk-related ...
Salisbury, NC · On-site +1
$108K/yr
... Program Analyst to help protect the organization's information systems, sensitive data, and ... This position supports enterprise cybersecurity initiatives through risk assessment, compliance ...
Salisbury, NC · On-site +1
$108K/yr
... Program Analyst to help protect the organization's information systems, sensitive data, and ... This position supports enterprise cybersecurity initiatives through risk assessment, compliance ...
Salisbury, NC · Remote
$108K/yr
... Program Analyst to help protect the organization's information systems, sensitive data, and ... This position supports enterprise cybersecurity initiatives through risk assessment, compliance ...
Salisbury, NC · Remote
$108K/yr
... Program Analyst to help protect the organization's information systems, sensitive data, and ... This position supports enterprise cybersecurity initiatives through risk assessment, compliance ...
In cybersecurity we analyze and diagnose specific environments from the point of view of compliance or regulatory risks, we incorporate technological solutions, we manage the operation of ...
In cybersecurity we analyze and diagnose specific environments from the point of view of compliance or regulatory risks, we incorporate technological solutions, we manage the operation of ...
Charlotte, NC · On-site
$113K/yr
Strong analytical, project management, written communication, and executive presentation skills. * Ability to translate technical cybersecurity risks into clear business and risk implications.
Charlotte, NC · On-site
$113K/yr
Strong analytical, project management, written communication, and executive presentation skills. * Ability to translate technical cybersecurity risks into clear business and risk implications.
Charlotte, NC · On-site
... analyses, and remediation tracking to proactively identify and address technology risks ... cybersecurity risk, or application governance. - Demonstrated experience performing risk ...
Charlotte, NC · On-site
... analyses, and remediation tracking to proactively identify and address technology risks ... cybersecurity risk, or application governance. - Demonstrated experience performing risk ...
$13.98 - $18.15
3% of jobs
$18.15 - $22.32
7% of jobs
$22.32 - $26.49
12% of jobs
$27.31 is the 25th percentile. Wages below this are outliers.
$26.49 - $30.66
15% of jobs
$30.66 - $34.83
13% of jobs
The median wage is $34.97 / hr.
$34.83 - $39.01
16% of jobs
$39.01 - $43.18
8% of jobs
$43.70 is the 75th percentile. Wages above this are outliers.
$43.18 - $47.35
11% of jobs
$47.35 - $51.52
6% of jobs
$51.52 - $55.69
6% of jobs
$55.69 - $59.86
3% of jobs
$13
$36
$59
| Aspect | Cybersecurity Risk Analyst | Cybersecurity Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CISSP, CISA | CompTIA Security+, CEH, CISSP |
| Primary Focus | Assessing and managing security risks | Monitoring, detecting, and responding to security threats |
| Work Environment | Risk management teams, security departments | Security operations centers, IT teams |
| Industry Usage | Finance, healthcare, government | All industries with cybersecurity needs |
While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

Durham, NC • On-site
Full-time
Posted 23 days ago
8.7
Based on 274 frontline employees who took The Breakroom Quiz
Note: Fidelity will not provide immigration sponsorship for this position
The Role
The Enterprise Cybersecurity Risk (ECS Cyber Risk) team is seeking an experienced Principal-level risk professional to lead in the creation of cyber risk analysis pertaining to ECS. The candidate will understand current and emerging cybersecurity risks and determine key risk scenarios for the ECS Product Areas. The candidate will participate in risk / threat modeling sessions to prioritize top risks. The candidate will advise on both exceptions and audit finding risk levels to drive down the number of exceptions and accurately risk rate audit findings. The candidate will quantify cyber risk and present analyses at the technical and executive level that will allow senior management to make informed decisions based on resulting risk data.
The Expertise and Skills You Bring
Minimum 3-5 years of risk experience quantifying cyber risk scenarios and presenting data in a meaningful and insightful way to senior leaders.
Demonstrated experience in cybersecurity risk management, assessment frameworks, and metrics reporting.
Experience managing projects end-to-end, from initial stages of acquiring data from multiple sources and subject matter experts to the tracking, maintenance, and closure of a project, with proven ability to integrate data into risk analysis tools and communicate progress effectively across multiple lines and levels.
Use and understanding of governance, risk, and compliance tools.
Advanced understanding of NIST 800-53 Cybersecurity Framework, Cybersecurity Risk Institute (CRI), and FAIR
CRISC, CISSP, or CISM certifications are preferred.
You have effective communication and excellent presentation skills to senior leaders.
You can deep dive into metrics that will both (1) quantify the work being done and (2) quantify how cyber risk position has improved.
Critical thinking skills to ask detailed questions and fully vet answers to uncover discrepancies and gaps others may not have found is a must.
You can work across business lines to influence change and help mitigate cyber risk.
You have an intermediate understanding of risks pertaining to the following: cloud security, access controls, encryption, vendor security, data exfiltration, application security, perimeter security, customer protection, privileged access, denial of service, unpatched vulnerabilities, and end of life software.
You operate in a fast-paced environment and can complete analyses quickly and accurately integrating new cybersecurity data into risk models as it emerges.
You bring an investigator mindset to deep dive into metrics to understand and communicate actionable risk to business and technology groups.
Determining the appropriate controls for cybersecurity risks
Working with asset inventory and asset management
Evaluating multiple sources, reports, industry trends to compare risk related findings to existing ECS policies and uncover gaps and opportunities for process improvement.
Determining what, who, and where changes are warranted to close gaps, working with appropriate contacts to draft policy enhancement ensuring continued progress.
The Team
ECS Cyber Risk provides cybersecurity risk analyses pertaining to existing and emerging risk scenarios and communicates these risks to appropriate ECS technical teams and senior leadership. This team focuses on identifying, measuring, prioritizing, and reporting on cyber risk scenarios and will work both independently and across business units and technology teams to assist senior management with informed decisions and directions in strategy to either maintain the course or if needed, change direction.
Fidelity's Onsite Working Model
Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.
Please be advised that Fidelity's business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.
Get the full story on Breakroom
Sourced by ZipRecruiter
Investment management and consulting services, finance and insurance and investment advisory and financial planning services
10,000+ Employees
Boston, MA, US