1

Cybersecurity Risk Management Analyst Jobs (NOW HIRING)

The Cybersecurity Risk Manager will identify, assess, and mitigate risks affecting the company ... management Analytical skills Research skills Risk assessment Policy development Incident response ...

NY · On-site

Partner with metric owners and managers on data submission, interpretation, evidence standards, and ... cybersecurity risk, technology risk, GRC, risk analytics, metrics reporting, or data governance

next page

Showing results 1-20

Cybersecurity Risk Management Analyst information

See salary details

$15

$40

$65

How much do cybersecurity risk management analyst jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for cybersecurity risk management analyst in the United States is $40.49, according to ZipRecruiter salary data. Most workers in this role earn between $29.81 and $49.28 per hour, depending on experience, location, and employer.

What does a Cybersecurity Risk Management Analyst do?

A Cybersecurity Risk Management Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security policies, conduct risk assessments, and recommend controls to minimize potential threats. Their work involves monitoring security measures, ensuring compliance with regulations, and helping develop strategies to protect the organization from cyberattacks. Ultimately, they play a crucial role in safeguarding sensitive information and supporting overall cybersecurity posture.

What are some typical challenges a Cybersecurity Risk Management Analyst faces when working with cross-functional teams?

Cybersecurity Risk Management Analysts often collaborate with IT, legal, compliance, and business units to identify and mitigate risks. A common challenge is bridging the communication gap between technical and non-technical stakeholders, ensuring that risk recommendations are understood and actionable. Additionally, balancing business objectives with security requirements can be complex, requiring strong negotiation and diplomacy skills. Analysts must also stay updated on evolving threats while tailoring solutions to each department’s unique needs.

What are the key skills and qualifications needed to thrive as a Cybersecurity Risk Management Analyst, and why are they important?

To thrive as a Cybersecurity Risk Management Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and regulatory frameworks, typically backed by a degree in cybersecurity or a related field. Familiarity with tools such as risk management software, vulnerability scanners, and certifications like CISSP, CISM, or CRISC is highly valued. Strong analytical thinking, attention to detail, and effective communication skills help in translating technical risks into actionable insights for stakeholders. These skills ensure organizations can proactively identify, assess, and mitigate cyber risks to protect sensitive information and maintain regulatory compliance.

What is the difference between Cybersecurity Risk Management Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk Management AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentFocus on risk assessment, policy development, and complianceFocus on threat detection, incident response, and system monitoring
Employer & Industry UsageUsed in organizations prioritizing risk mitigation and complianceUsed across various sectors for security operations and monitoring

While both roles involve cybersecurity, the Cybersecurity Risk Management Analyst primarily assesses and manages risks, ensuring compliance and policy adherence. In contrast, the Cybersecurity Analyst concentrates on identifying threats, monitoring security systems, and responding to incidents. Both roles are essential but focus on different aspects of cybersecurity defense.

More about Cybersecurity Risk Management Analyst jobs

What cities are hiring for Cybersecurity Risk Management Analyst jobs?

Cities with the most Cybersecurity Risk Management Analyst job openings:

What states have the most Cybersecurity Risk Management Analyst jobs?

States with the most job openings for Cybersecurity Risk Management Analyst jobs include:

What are popular job titles related to Cybersecurity Risk Management Analyst jobs?

For Cybersecurity Risk Management Analyst jobs, the most frequently searched job titles are:

Infographic showing various Cybersecurity Risk Management Analyst job openings in the United States as of September 2026, with employment types broken down into 95% Full Time, and 5% Contract. Highlights an 79% In-person, 13% Hybrid, and 8% Remote job distribution, with an average salary of $84,210 per year, or $40.5 per hour.

Cybersecurity Risk Management Analyst

Plano, TX • On-site

PROLIM Global Corporation
IT Services • 201 - 500 employees

Other

This job post has expired 1 day ago. Applications are no longer accepted.


Key responsibilities

  • Conduct risk intake, assessments, triage sessions, and stakeholder risk discussions.

  • Assess technology and cybersecurity risks using NIST, COBIT, and ISO frameworks.

  • Develop risk treatment recommendations and track remediation activities through closure.


Job description

Looking for Technology & Cybersecurity Risk Management Analyst

Location: Plano, Texas (Hybrid)

Description

The Technology & Cybersecurity Risk Management (T&CRM) Engineer supports the T&CRM program by analyzing technology and cybersecurity risks, conducting risk assessments, leading risk-related initiatives, and enhancing risk management processes. This role helps identify, visualize, and reduce technology and cybersecurity risks while guiding stakeholders through risk-based decision-making.

Core Responsibilities

  • Conduct risk intake, assessments, triage sessions, and stakeholder risk discussions.
  • Assess technology and cybersecurity risks using NIST, COBIT, and ISO frameworks.
  • Identify, document, and evaluate inherent, residual, and emerging technology risks.
  • Review controls and evaluate their effectiveness in mitigating identified risks.
  • Map risks to controls and applicable framework and policy requirements.
  • Facilitate control walkthroughs and risk discussions with control owners and stakeholders.
  • Document risk statements, controls, evidence, and assessment results in governance tools and Word/Excel/PPT.
  • Develop risk treatment recommendations and track remediation activities through closure.
  • Escalate overdue actions, unresolved risks, and significant control or compliance concerns.
  • Prepare executive-ready risk reports, dashboards, and governance presentation materials.

Required Knowledge and Skills

  • Technology and Cybersecurity Fundamentals: Demonstrates a solid understanding of security controls, threats, and risk concepts. NIST, COBIT, and ISO 27001 framework knowledge.
  • Risk Assessment & Analysis: Ability to identify, assess, and document technology and cybersecurity risks and control gaps. Understanding of control design, control effectiveness, and risk mitigation concepts.
  • Project Management: Effectively plans, tracks, and executes work across multiple concurrent initiatives.
  • Process Improvement: Identifies opportunities to streamline workflows and improve operational efficiency.
  • Stakeholder Collaboration: Works effectively with crossfunctional teams and external partners.
  • Communication: Clearly communicates technical risk information to both technical and nontechnical audiences.
  • Attention to Detail: Produces accurate, welldocumented assessments and maintains reliable risk records.
  • Tool proficiency: Microsoft Word, Excel, PowerPoint, and CoPilot. ServiceNow.

Requirements

  • Bachelor s degree in Information Technology, Cybersecurity, Computer Science, Business, or a related field (or equivalent experience).
  • 1 3 years of experience in cybersecurity or technology risk management, IT risk, cybersecurity, compliance, or related discipline.
  • Foundational understanding of cybersecurity principles, risk assessment methodologies, and common security control frameworks.
  • Experience supporting projects or initiatives that require coordination across multiple stakeholders.
  • Strong written and verbal communication skills, with the ability to clearly document risks and recommendations.

Key Success Factors

  • Comfortable navigating conversations with Control Owners and stakeholders.
  • Clear and structured articulation of technology risks and controls.
  • Strong attention to detail and documentation quality.
  • Willingness to learn and grow within a Technology & Cybersecurity Risk Management function.
  • Collaborative mindset across technical and non-technical teams.