1

Cybersecurity Risk Management Jobs (NOW HIRING)

... Risk Management governance/process, and leverage the broader teams for execution of risk ... cybersecurity risk management, and related compliance initiatives Develop and maintain a ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See salary details

$57K

$133K

$186K

How much do cybersecurity risk management jobs pay per year?

As of Sep 10, 2026, the average yearly pay for cybersecurity risk management in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

More about Cybersecurity Risk Management jobs

What cities are hiring for Cybersecurity Risk Management jobs?

Cities with the most Cybersecurity Risk Management job openings:

What states have the most Cybersecurity Risk Management jobs?

States with the most job openings for Cybersecurity Risk Management jobs include:

What other helpful pages are available for Cybersecurity Risk Management?

Other pages related to Cybersecurity Risk Management:

Infographic showing various Cybersecurity Risk Management job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 86% Physical, 2% Hybrid, and 12% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

Cybersecurity Risk Management Analyst

Plano, TX • On-site

PROLIM Global Corporation
IT Services • 201 - 500 employees

Other

Posted 8 days ago


Key responsibilities

  • Conduct risk intake, assessments, triage sessions, and stakeholder risk discussions.

  • Assess technology and cybersecurity risks using NIST, COBIT, and ISO frameworks.

  • Develop risk treatment recommendations and track remediation activities through closure.


Job description

Looking for Technology & Cybersecurity Risk Management Analyst

Location: Plano, Texas (Hybrid)

Description

The Technology & Cybersecurity Risk Management (T&CRM) Engineer supports the T&CRM program by analyzing technology and cybersecurity risks, conducting risk assessments, leading risk-related initiatives, and enhancing risk management processes. This role helps identify, visualize, and reduce technology and cybersecurity risks while guiding stakeholders through risk-based decision-making.

Core Responsibilities

  • Conduct risk intake, assessments, triage sessions, and stakeholder risk discussions.
  • Assess technology and cybersecurity risks using NIST, COBIT, and ISO frameworks.
  • Identify, document, and evaluate inherent, residual, and emerging technology risks.
  • Review controls and evaluate their effectiveness in mitigating identified risks.
  • Map risks to controls and applicable framework and policy requirements.
  • Facilitate control walkthroughs and risk discussions with control owners and stakeholders.
  • Document risk statements, controls, evidence, and assessment results in governance tools and Word/Excel/PPT.
  • Develop risk treatment recommendations and track remediation activities through closure.
  • Escalate overdue actions, unresolved risks, and significant control or compliance concerns.
  • Prepare executive-ready risk reports, dashboards, and governance presentation materials.

Required Knowledge and Skills

  • Technology and Cybersecurity Fundamentals: Demonstrates a solid understanding of security controls, threats, and risk concepts. NIST, COBIT, and ISO 27001 framework knowledge.
  • Risk Assessment & Analysis: Ability to identify, assess, and document technology and cybersecurity risks and control gaps. Understanding of control design, control effectiveness, and risk mitigation concepts.
  • Project Management: Effectively plans, tracks, and executes work across multiple concurrent initiatives.
  • Process Improvement: Identifies opportunities to streamline workflows and improve operational efficiency.
  • Stakeholder Collaboration: Works effectively with crossfunctional teams and external partners.
  • Communication: Clearly communicates technical risk information to both technical and nontechnical audiences.
  • Attention to Detail: Produces accurate, welldocumented assessments and maintains reliable risk records.
  • Tool proficiency: Microsoft Word, Excel, PowerPoint, and CoPilot. ServiceNow.

Requirements

  • Bachelor s degree in Information Technology, Cybersecurity, Computer Science, Business, or a related field (or equivalent experience).
  • 1 3 years of experience in cybersecurity or technology risk management, IT risk, cybersecurity, compliance, or related discipline.
  • Foundational understanding of cybersecurity principles, risk assessment methodologies, and common security control frameworks.
  • Experience supporting projects or initiatives that require coordination across multiple stakeholders.
  • Strong written and verbal communication skills, with the ability to clearly document risks and recommendations.

Key Success Factors

  • Comfortable navigating conversations with Control Owners and stakeholders.
  • Clear and structured articulation of technology risks and controls.
  • Strong attention to detail and documentation quality.
  • Willingness to learn and grow within a Technology & Cybersecurity Risk Management function.
  • Collaborative mindset across technical and non-technical teams.