1

Cybersecurity Risk Management Jobs in Kentucky (NOW HIRING)

$150 - $200/hr

This role operates at a strategic and architectural level while also ensuring operational effectiveness across cybersecurity risk management practices. The Principal Cybersecurity Analyst contributes ...

Cybersecurity Risk Analyst Experience: 5 to 10 years Employment : W2 Job locations: Dallas, TX & ... management, governance committees, and Board-level reporting, while supporting second-line ...

New

This role is ideal for a cybersecurity professional with deep expertise in cyber risk management, Business Information Security Office (BISO) operations, and emerging AI governance practices. As a ...

Senior Manager of Technical Operations Position Summary : VoltaGrid is seeking a Cybersecurity Risk & Compliance Analyst to help formalize and scale our risk governance, compliance, and policy ...

$140K - $190K/yr

Cyber & Technology Risk Management is an independent second-line risk function within Enterprise ... Demonstrated experience assessing cyber risk programs, cybersecurity controls, and information ...

$73K - $95K/yr

Leads the tracking and management of identified deficiencies, POA&Ms items, remediation activities, and risk-based exceptions * Conducts cybersecurity risk assessments for information systems ...

$112K - $236K/yr

The Director is responsible for establishing and maturing enterprise-wide cybersecurity governance processes, risk management frameworks, compliance monitoring activities, third-party risk management ...

Leading cybersecurity assurance activities throughout the product life cycle, including creating cybersecurity risk management plans, threat modeling, performing vulnerability assessments, defining ...

Leading cybersecurity assurance activities throughout the product life cycle, including creating cybersecurity risk management plans, threat modeling, performing vulnerability assessments, defining ...

Select how often (in days) to receive an alert: Sr Associate Cybersecurity Risk Analyst - Third ... Performs information security risk management activities and delivers on assigned projects while ...

As a Cybersecurity Analyst you will play a crucial role in ensuring the cyber security and ... You will be responsible for managing the Risk Management Framework (RMF) support for multiple ...

$81K - $110K/yr

This role will advance Novaspect's cybersecurity program across enterprise IT and operational technology (OT) environments, setting strategy, managing risk, establishing security standards and ...

$95K - $115K/yr

Cybersecurity Governance, Risk Management, Security Authorization (ATO), Continuous Monitoring, Security Control Assessments, POA&M Management, Vulnerability Management, Incident Response ...

... Cybersecurity Risk Management Technology Infrastructure Review & Roadmapping Control Design and Optimization. As an IT Risk Advisory Senior Associate, you will: * Perform IT risk assessments that ...

Cybersecurity & Risk Management * Implement and monitor cybersecurity controls to protect organizational systems and data. * Assist with risk assessments and security reviews to identify ...

Lead cybersecurity risk assessments by identifying, evaluating, and prioritizing threats using Cummins risk management frameworks to protect critical business assets. * Drive effective risk ...

$90K/yr

The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ...

$69K - $69K/yr

Lead cybersecurity risk identification and assessment efforts, ensuring potential threats are evaluated using Cummins risk management frameworks and prioritized appropriately. * Provide expert ...

Cybersecurity Manager

Louisville, KY · On-site

$106K - $144K/yr

Third-party and vendor risk management * Incident response, cyber resilience, and disaster recovery ... Cybersecurity operations and controls * Data protection principles * HIPAA Security and Privacy ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Kentucky salary details

$49.5K

$115.5K

$161.5K

How much do cybersecurity risk management jobs pay per year?

As of Sep 10, 2026, the average yearly pay for cybersecurity risk management in Kentucky is $115,481.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,400.00 and $130,300.00 per year, depending on experience, location, and employer.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are popular job titles related to Cybersecurity Risk Management jobs in Kentucky?

For Cybersecurity Risk Management jobs in Kentucky, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Risk Management jobs in Kentucky look for?

The top searched job categories for Cybersecurity Risk Management jobs in Kentucky are:

What cities in Kentucky are hiring for Cybersecurity Risk Management jobs?

Cities in Kentucky with the most Cybersecurity Risk Management job openings:

Infographic showing various Cybersecurity Risk Management job openings in Kentucky as of September 2026, with employment types broken down into 1% As Needed, 81% Full Time, 15% Part Time, 2% Contract, and 1% Nights. Highlights an 86% Physical, 2% Hybrid, and 12% Remote job distribution, with an average salary of $115,481 per year, or $55.5 per hour.

Principal Cybersecurity Analyst - Risk Mgmt & AI Security

On-site

University of Texas MD Anderson Cancer Center
Health Care and Social Assistance • 10K+ employees

$150 - $200/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

This job post has expired 2 days ago. Applications are no longer accepted.


MD Anderson Cancer Center rating

8.5

Company rating: 8.5 out of 10

Based on 172 frontline employees who took The Breakroom Quiz

12th of 898 rated healthcare providers


Job description

The University of Texas MD Anderson Cancer Center is seeking a highly skilled Principal Cybersecurity Analyst to serve as a technical authority within its Cybersecurity department.

The Principal Cybersecurity Analyst plays a critical role in shaping and advancing enterprise-wide governance, risk, and compliance (GRC) programs, with expanded accountability for emerging AI security and governance initiatives. This role operates at a strategic and architectural level while also ensuring operational effectiveness across cybersecurity risk management practices.

The Principal Cybersecurity Analyst contributes directly to safeguarding sensitive data, maintaining regulatory compliance, and strengthening the organization's security posture through innovative, data-driven risk management and governance strategies. The Principal Cybersecurity Analyst serves as a trusted advisor, architect, and leader within the cybersecurity function.

The ideal candidate brings advanced education in information systems or cybersecurity, extensive experience leading enterprise risk management or GRC programs, and strong knowledge of frameworks such as NIST, HIPAA, and HITRUST. Preferred candidates will also have hands‑on experience assessing AI/ML risk, strong executive communication skills, and certifications such as CISSP, CISM, or PMP.

Minimum $123,000 - Midpoint $154,000 - Maximum $185,000

Work Location: Remote 100%

Why Us?

At UT MD Anderson, the Principal Cybersecurity Analyst plays an essential role in advancing cybersecurity innovation in a mission-driven healthcare environment. This position offers the opportunity to shape enterprise risk strategy, influence executive decision‑making, and lead emerging AI governance practices, all while supporting an organization dedicated to saving lives. Employees benefit from a collaborative culture, professional development opportunities, and a strong commitment to work‑life balance.

  • Employer‑paid medical coverage starting day one for employees working 30+ hours/week, plus optional group dental, vision, life, AD&D, and disability insurance.
  • Accruals for PTO and Extended Illness Bank, plus paid holidays, wellness, childcare, and other leave options.
  • Tuition Assistance Program after six months of service and access to extensive wellness, fitness, and employee resource groups.
  • Defined-benefit pension through the Teachers Retirement System, voluntary retirement plans, and employer‑paid life and reduced salary protection programs.
Responsibilities Governance, Risk & Compliance (GRC) Architecture & Risk Management Program Leadership
  • Serve as principal architect and subject matter expert for enterprise GRC and cybersecurity risk programs
  • Define and maintain risk assessment methodologies, control frameworks, and risk scoring models
  • Establish workflows across development, staging, and production environments
  • Develop SOPs, roles, segregation of duties, and change management processes
  • Lead design and execution of enterprise risk management strategies
Security & Risk Platform Integration and Automation
  • Architect and maintain integrations across Archer, Tenable, ServiceNow, Microsoft Configuration Manager (SCCM/MECM), and Medigate
  • Design automated workflows consolidating asset, vulnerability, and risk data
  • Enable enterprise‑wide risk visibility and reporting through data‑driven systems
  • Ensure data quality, reconciliation, and interoperability across platforms and CMDB
Regulatory & Compliance Framework Management
  • Apply frameworks including NIST CSF, NIST 800‑53, HIPAA, and HITRUST
  • Conduct control mapping, gap assessments, and compliance reportingli>
  • Advise stakeholders on remediation strategies and regulatory requirements
  • Align institutional policies with regulatory and accreditation standards
AI Security & Governance
  • Establish and mature AI security and governance programs
  • Develop AI risk assessment criteria and governance standards
  • Align controls to NIST AI Risk Management Framework and institutional policies
  • Evaluate AI/ML tools and vendors for data protection and compliance risks
  • Partner with data governance, privacy, and legal teams on AI initiatives
Strategic Risk Visioning, Assessment & Executive Advisory
  • Develop multi-year roadmaps, milestones, and resource plans
  • Lead enterprise and project-level risk assessments
  • Translate technical findings into executive-level reporting and dashboards
  • Advise leadership on risk posture and investment prioritization
  • Provide technical leadership and mentorship across teams
EDUCATION
  • Required: Bachelor's Degree Computer Information Systems, Business Information Systems, Computer Science or related field.
  • Preferred: Master's Degree Information Security, Computer Science or related field
WORK EXPERIENCE
  • Required: 7 years In information security and/or cybersecurity experience including multiple security domains, to include two years lead/supervisory experience.
  • May substitute required education degree with additional years of equivalent experience on a one to one basis.
  • Preferred: At least 7-8 years of progressive cybersecurity experience, hands-on risk management (risk assessment, risk register ownership, control evaluation, or risk quantification), led or owned a security risk management program or framework implementation (e.g., NIST RMF/CSF, ISO 27005, FAIR, or equivalent), direct hands-on experience assessing the security or risk posture of AI/ML systems or GenAI deployments, ability to translate technical risk into business-level language for executive and governance audiences (e.g., briefing a CISO, risk committee, or board), experience using Archer, excellent communication skills, risk management, and cybersecurity framework is a must.
LICENSES AND CERTIFICATIONS
  • Preferred: CISSP - Cert IS Security Professional Issued by the International Information Systems Security Certification Consortium ((ISC.
  • Preferred: CISM - Cert Info Security Manager Issued by Information Systems Audit and Control Association (ISACA).
  • Preferred: PMP - Project Mgt Professional Issued by the Project Management Institute (PMI).
  • Preferred: Other applicable security industry certifications.

The University of Texas MD Anderson Cancer Center offers excellent benefits, including medical, dental, paid time off, retirement, tuition benefits, educational opportunities, and individual and team recognition.

This position may be responsible for maintaining the security and integrity of critical infrastructure, as defined in Section 113.001(2) of the Texas Business and Commerce Code and therefore may require routine reviews and screening. The ability to satisfy and maintain all requirements necessary to ensure the continued security and integrity of such infrastructure is a condition of hire and continued employment.

It is the policy of The University of Texas MD Anderson Cancer Center to provide equal employment opportunity without regard to race, color, religion, age, national origin, sex, gender, sexual orientation, gender identity/expression, disability, protected veteran status, genetic information, or any other basis protected by institutional policy or by federal, state, or local laws unless such distinction is required by law.

http://www.mdanderson.org/about-us/legal-and-policy/legal-statements/eeo-affirmative-action.html

Additional Information
  • Requisition ID: 181706
  • Employment Status: Full-Time
  • Employee Status: Regular
  • Work Week: Days
  • Minimum Salary: US Dollar (USD) 123,000
  • Midpoint Salary: US Dollar (USD) 154,000
  • Maximum Salary : US Dollar (USD) 185,000
  • FLSA: exempt and not eligible for overtime pay
  • Fund Type: Hard
  • Work Location: Remote (within Texas only)
  • Pivotal Position: Yes
  • Referral Bonus Available?: Yes
  • Relocation Assistance Available?: Yes
#J-18808-Ljbffr

What MD Anderson Cancer Center employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom