1

Cybersecurity Risk Management Jobs in Alabama (NOW HIRING)

Senior Information Systems Security Engineer

Huntsville, AL ยท On-site

$99.20K - $134.60K/yr

The Senior ISSE SME will support cybersecurity, risk management, and security authorization activities for law enforcement and national security organizations. This role will provide technical ...

Utilizes eMASS to manage Risk Management Framework implementation for DoD Information systems * Ensures timely A&A submissions for DoD information systems * Uses cybersecurity knowledge to assess the ...

The Mid-Level DoW Cybersecurity Engineer is responsible for supporting the implementation ... Support the Risk Management Framework (RMF) process for system accreditation and continuous ...

Implements Risk Management Framework (RMF) processes. * Develops and maintains RMF artifacts and ... Manages cybersecurity incident reporting (DFARS 252.204-7012). * Implements NIST 800-53 security ...

Classified Cyber Security

Huntsville, AL

$109.40K - $147.80K/yr

Lockheed Martin is a cybersecurity pioneer, partner, innovator and builder. Our amazing employees ... Risk Management Framework (RMF) to include Continuous Monitoring, Plan of Action and Milestones ...

The Mid-Level DoW Cybersecurity Engineer is responsible for supporting the implementation ... Support the Risk Management Framework (RMF) process for system accreditation and continuous ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Alabama salary details

$51.7K

$120.5K

$168.6K

How much do cybersecurity risk management jobs pay per year?

As of May 30, 2026, the average yearly pay for cybersecurity risk management in Alabama is $120,515.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,600.00 and $136,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are popular job titles related to Cybersecurity Risk Management jobs in Alabama? For Cybersecurity Risk Management jobs in Alabama, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Alabama look for? The top searched job categories for Cybersecurity Risk Management jobs in Alabama are:
What cities in Alabama are hiring for Cybersecurity Risk Management jobs? Cities in Alabama with the most Cybersecurity Risk Management job openings:
ISSM/Cybersecurity Engineer

ISSM/Cybersecurity Engineer

Strata-G Solutions

Huntsville, AL โ€ข On-site

$54.50 - $67/hr

Full-time

Posted 11 days ago


Job description

This is a full-time, onsite position located in Huntsville, AL.
At Strata-G, we know it takes talented and dedicated people to deliver solutions for a greater cause, and we consider our employees to be our greatest asset. We are a growing, dynamic organization offering diverse challenges to innovative professionals.
We're looking for a seasoned Cybersecurity Engineer / ISSM to lead and execute the full cybersecurity program for a complex Army weapon system. This is a high-impact role supporting mission-critical hardware and software across development, integration, testing, fielding, and long-term sustainment.
You'll serve as the contractor's primary cybersecurity authority, partnering directly with Government stakeholders, engineering teams, and program leadership to drive RMF execution, achieve and maintain ATO, and ensure lifecycle cybersecurity compliance.
What You'll Do
You'll own the cybersecurity program end-to-end, ensuring the system meets DoD, Army, CNSS, NIST, DISA, and export control requirements. From early system design through operational fielding, you'll embed cybersecurity into every engineering phase-hardware, firmware, software, testing, training, and sustainment.
You'll lead all RMF Assess & Authorize (A&A) activities, producing and maintaining Government-ready artifacts including the System Security Plan (SSP), POA&Ms, COOP/DRP documentation, and baseline inventories. You'll guide the program through CT&E, IATT, and ATO/ATC approvals, while providing continuous monitoring and risk management support throughout the lifecycle.
As the program's ISSM, you'll act as the primary cybersecurity liaison to the Program Office, Authorizing Official, SCA/SCA-V teams, DISA, DCSA, and engineering IPTs. You'll assess system changes, manage vulnerabilities, apply DISA STIGs, and ensure the system is audit-ready and Government-review-ready at all times.
What You Bring
You have deep expertise in DoD RMF, cybersecurity engineering, and A&A documentation, with hands-on experience applying NIST, CNSS, FIPS, and DISA requirements to complex systems. You're comfortable navigating ambiguity, interpreting overlapping guidance, and applying the most stringent requirements when needed.
You've supported CT&E, vulnerability remediation, and continuous risk management, and you understand how cybersecurity decisions impact mission performance, interoperability, and fielded systems. You communicate confidently with both engineers and Government customers-and you're trusted as the cybersecurity voice in the room.
Required Experience
  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Assurance, or related field (or equivalent experience)
  • 5+ years supporting DoD cybersecurity engineering, ISSM/ISSO, or RMF programs
  • Strong working knowledge of RMF, A&A artifacts, and DoD cybersecurity controls
  • Experience applying NIST SP 800-53, 800-37, 800-30, 800-39, 800-160, CNSSI 1253, and DISA STIGs
  • Background supporting CT&E, vulnerability mitigation, and lifecycle cybersecurity
  • Ability to obtain and maintain a DoD Secret clearance (or higher)

Preferred Experience
  • DoD 8140 / 8570 certifications (CISSP, CISM, CASP+, CCISO, IAM/IAT/IASAE)
  • Army cybersecurity experience (AR 25-1, AR 25-2, AR 380-5)
  • Experience with weapon systems, tactical or embedded systems
  • Prior ISSM, ISSE, or senior ISSO experience on ATO/ATC acquisition programs
  • Experience developing complex cybersecurity CDRLs for DoD contracts