1

Cybersecurity Risk Management Jobs in New York (NOW HIRING)

Director of Cybersecurity - GRC

Newark, NJ

$116K - $156K/yr

NRC, SOX, DoE, NERC CIP, TSA, Internal Audits, etc.), Cybersecurity Risk, Cybersecurity Policy, Cybersecurity Awareness, and Nth Party Risk Management and Assurance. (S)he coordinates across all ...

Serve as the primary cybersecurity and risk advisor to EIT, aligning security strategies with the ... Ensure security and risk management practices are embedded in business processes, digital ...

... Risk Management, Cybersecurity, and Managed Services. Vistrada provides deep expertise and flexible ... team structures ensuring agility and responsiveness to support our client's evolving needs. We ...

Showing results 21-40

Cybersecurity Risk Management information

See New York salary details

$62.4K

$145.5K

$203.5K

How much do cybersecurity risk management jobs pay per year?

As of Aug 17, 2026, the average yearly pay for cybersecurity risk management in New York is $145,465.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,400.00 and $164,100.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What are popular job titles related to Cybersecurity Risk Management jobs in New York?

For Cybersecurity Risk Management jobs in New York, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Risk Management jobs in New York look for?

The top searched job categories for Cybersecurity Risk Management jobs in New York are:

What cities in New York are hiring for Cybersecurity Risk Management jobs?

Cities in New York with the most Cybersecurity Risk Management job openings:

Infographic showing various Cybersecurity Risk Management job openings in New York as of August 2026, with employment types broken down into 1% As Needed, 80% Full Time, 16% Part Time, 1% Temporary, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $145,465 per year, or $69.9 per hour.

Director of Cybersecurity - GRC

PSEG

Newark, NJ

$116K - $156K/yr

Full-time

Re-posted 6 days ago


PSEG rating

8.8

Company rating: 8.8 out of 10

Based on 79 frontline employees who took The Breakroom Quiz

6th of 53 rated energy and utility


Job description

Job Summary

The Director, Cybersecurity Governance, Risk, and Compliance leads the development, implementation, and ongoing coordination of enterprise-wide Cybersecurity Governance, Risk, and Compliance, including Regulatory Assurance (e.g. NRC, SOX, DoE, NERC CIP, TSA, Internal Audits, etc.), Cybersecurity Risk, Cybersecurity Policy, Cybersecurity Awareness, and Nth Party Risk Management and Assurance. (S)he coordinates across all business lines, service departments, external risk organizations (e.g. cross-sector cyber industry trade organizations), and peer energy companies. As PSEG's senior leader responsible for Cybersecurity Governance, Risk, and Compliance, (s)he will also be responsible for defining and aligning cybersecurity policies, strategy, and standards. (S)he will be responsible for multiple discrete projects/enhancements to build, maintain, and mature capabilities, including people, processes, and technologies. (S)he will engage across the entire IT, OT, and managed services landscapes, including leading a team across these environments.

(S)he will spend his/her time
* Serving as the Subject Matter Expert for Cybersecurity governance, risk, and compliance issues/concerns/audits.
* Conducting cybersecurity assessments, identifying risks, and tracking/reporting on remediations.
* Providing cybersecurity insight and expertise in assessing new business opportunities.
* Identifying opportunities for process improvements to deliver increasing efficiency within the Risk and Control framework.
* Interacting with auditors on cybersecurity management oversight.
* Coordinating with outside vendors/third-parties to protect client information, to secure data transmission protocols, and to complete/remediate Information/cybersecurity assessments.
* Collaborating closely with developers and infrastructure teams to implement the Cybersecurity policies required to protect the integrity, confidentiality, and availability of the information on an end-to-end basis.
* Implementing the risk assessment framework, which identifies critical cybersecurity and privacy impacting business process and/or systems.
* Maintaining the global Cybersecurity and IT risk registers, tracking remediations, and creating status reports/metrics.
* Completing risk assessments of new/existing infrastructure, systems, Industrial Control Systems, and other components.
* Conducting risk assessments of third-party vendors to evaluate cybersecurity controls for protecting company-specific data.
* Leading and/or contributing to the creation and maintenance of the enterprise's cybersecurity documents (policies, standards, guidelines and procedures). Ensuring enforcement of these enterprise cybersecurity documents.
* Preparing for, supporting, and potentially presenting at, Cybersecurity Council, Senior Executive Team, and Board of Directors meetings.
* Preparing senior-level technical reports for executive management.
* Providing support and risk guidance for enterprise infrastructure, the wireless environment, Cloud software/infrastructure security, secure software development, and data protection.
* Collaborating closely with Digital Workplace, Infrastructure, Enterprise Resource Planning, and Application Development Teams to identify and remediate cybersecurity issues.
* Identifying/overseeing remediation of open cybersecurity issues and validating closure.
* Maintaining up-to-date cybersecurity knowledge, including awareness of innovative solutions/processes, emerging standards, and new threat vectors by reading professional publications, maintaining personal networks, and participating in professional organizations.

Job Responsibilities
  • Directs, coaches, and counsels internal/external cyber resources on Cybersecurity technologies, including Regulatory Assurance (e.g. NRC, SOX, DoE, NERC CIP, TSA, Internal Audits, etc.), Cybersecurity Risk, Cybersecurity Policy, Cybersecurity Awareness, and Nth Party Risk Management and Assurance for all lines of business and service departments for both IT and OT landscapes. Ensure that Cybersecurity Governance, Risk, and Compliance service delivery aligns with the corporate IT strategy, including development of Cybersecurity operations standards, capacity planning, lifecycle management plans, solution selection, and partner management. Ensure scalability of Cybersecurity Governance, Risk, and Compliance capabilities, including hardware and software, to meet business needs and risk tolerances.
  • Develops and implements best practices for PSEG Cybersecurity Governance, Risk, and Compliance capabilities. Participate in external risk organizations (including with peer groups) to learn from other organizations and to benchmark our program. Partner with professional Cybersecurity Governance, Risk, and Compliance associations, service providers, and to identify and implement best practices.
  • Partners with and advises various IT teams. Operationalizes Policies, Practices, and Instructions to protect against existing and emerging threats.
  • Builds relationships across PSEG business and technology teams. Interacts routinely with vendors, service providers, consultants/advisors, law enforcement agencies, and cross-sector cyber industry trade organizations. Ensures that cyber governance, risk, and compliance requirements are identified, well defined, properly documented, and approved by appropriate stakeholders.
  • Develops, manages, and pre-prioritizes Cybersecurity CAPEX and OPEX budgets based on business needs and cyber threats. Lead the identification of optimal OPEX and CAPEX allocations, including opportunities to reduce expenditures while transforming PSEG Cybersecurity Governance, Risk, and Compliance. Lead and advise on business case development.
  • Leads team, including performance evaluations, career development guidance, and other aspects to grow the talent pipeline and to mature our program.
Job Specific Qualifications
  • Bachelors degree and 10 years of relevant cybersecurity experience, including leadership experience
  • Demonstrated strong leadership and influence skills
  • Demonstrated strong presentation skills with the ability to present to all levels of management and executive leadership
  • Experience leading a Cybersecurity Governance, Risk, and Compliance organization
  • Executive teamwork, facilitation, relationship building, and negotiation skills
  • Ability to maintain positive working relationships both as a leader and as a team member
  • Effective time management and multitasking skills
  • Ability to communicate effectively with both technical and non-technical individuals
  • Strong interpersonal communication skills, analytical abilities, detail focused, quality focused, and problem-solving skills, as well as broad knowledge of business functions, information technologies, and cybersecurity and compliance practice on a global level
  • A demonstrated ability to develop and maintain policy that integrates various cybersecurity, network and data protection technologies and controls into a cohesive solution that sufficiently mitigates risk
  • Extensive relevant experience in Cybersecurity, Information Risk Management, Nth-Party Risk Management, Cybersecurity Policies/Procedures, and Cybersecurity Compliance/Audit
  • Strong analytical skills, problem solving skills, writing skills, attention to detail, and conceptual thinking, including the ability to work with technical and non-technical business owners
  • Broad knowledge of cybersecurity principles (e.g. access control, data protection, security architecture, infrastructure/application security design principles, policies) and privacy (i.e. GDPR)
  • Working knowledge of cybersecurity and control frameworks (ISO27001, NIST, CobIT)
  • Effective communication skills, including the ability to build relationships with technical and non-technical individuals
  • Be able to identify, analyze, and address problems in order to resolve issues in ways that minimize negative impact and risk to the company
  • Experience evaluating security controls, conducting risks assessments, and providing guidance to platform architects/developers
  • Demonstrated experience in delivering comprehensive solutions to complex security issues on a global scale
  • Confidence in leading diverse matrix teams independently, making decisions daily as it relates to the successful delivery of the program
  • Ability and insight to know when critical decisions must be raised to senior level and/or business unit management quickly to ensure that the program remains on track
  • Department of Energy's regulation 10 CFR 810 is required

Desired

  • Industry Cybersecurity certifications (e.g. CISSP, CEH, etc....)
  • Masters in Information Security, Computer Science, Business, Engineering, or related fields
  • Experience in Electric or Gas Utility or Power Generation industry, and/or experience in manufacturing
  • Broad knowledge of IT and related control environments

What PSEG employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


PSEG logo

About PSEG

Sourced by ZipRecruiter

This is an exciting time to be joining PSEG. Our commitments, which include safety, integrity, customer focus, and diversity & inclusion, are the fabric of our culture and help drive the success of our business. We are fortunate to have an outstanding workforce of diverse and highly skilled talent who move us forward in our operational excellence journey. PSEG has more than 12,000 employees who are dedicated to the communities we serve and embody our vision: People providing Safe, Reliable, Economic and Greener Energy.

Industry

Clean energy services

Company size

10,000+ Employees

Headquarters location

Newark, NJ, US

Year founded

1903