1

Cybersecurity Risk Management Jobs in Ohio (NOW HIRING)

Provide the PMO/Capability Development Manager (CDM) cybersecurity support per DoDI 8500.01. * Assessing and continuously monitoring cybersecurity risk ensuring that legacy and new capabilities ...

Senior Cybersecurity Specialist Job Location: Dayton, OH Job Type: Full-Time • Own the PG ... Risk Management Framework (RMF) process from categorization through authorization; shepherd ...

Cybersecurity SME

Dayton, OH · On-site

$90K - $140K/yr

Have knowledge of the Systems Security Engineering disciplines to include Anti-Tamper, Trusted Systems & Networks, Cybersecurity, Hardware/Software/Firmware Assurance, Supply Chain Risk Management ...

Have knowledge of the Systems Security Engineering disciplines to include Anti-Tamper, Trusted Systems & Networks, Cybersecurity, Hardware/Software/Firmware Assurance, Supply Chain Risk Management ...

The Cyber Security Architect is responsible for coordinating and architecting information security ... Translate security policies into technical, risk-managed designs-covering network, cloud, and ...

Title: Sr Cybersecurity Engineer KBR is seeking a motivated and mission-focused Cybersecurity ... Lead and support Risk Management Framework (RMF) Assessment and Authorization (A&A) efforts to ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Ohio salary details

$54.2K

$126.4K

$176.8K

How much do cybersecurity risk management jobs pay per year?

As of Jun 20, 2026, the average yearly pay for cybersecurity risk management in Ohio is $126,407.00, according to ZipRecruiter salary data. Most workers in this role earn between $105,500.00 and $142,600.00 per year, depending on experience, location, and employer.

What is the role of a risk manager in cybersecurity?

A cybersecurity risk manager identifies, assesses, and prioritizes security risks to an organization’s information systems. They develop strategies to mitigate threats, implement security controls, and ensure compliance with industry standards, often using tools like risk assessment frameworks and security audits. Their role is essential in protecting digital assets and supporting overall cybersecurity posture.

Is security risk management a good career?

Security risk management is a valuable career in cybersecurity, focusing on identifying and mitigating threats to organizational assets. It often requires knowledge of security frameworks, risk assessment tools, and certifications like CISSP or CISM. The field offers strong job growth, competitive salaries, and opportunities across various industries.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What is risk management in cyber security?

In cybersecurity risk management, professionals identify, assess, and prioritize potential security threats to an organization’s information systems. They implement strategies and controls to mitigate or accept risks, often using frameworks like NIST or ISO 27001, and may hold certifications such as CISSP or CISM to ensure effective risk handling.

Can you make $500,000 a year in cyber security?

Cybersecurity risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working in large organizations with complex security needs.
What are popular job titles related to Cybersecurity Risk Management jobs in Ohio? For Cybersecurity Risk Management jobs in Ohio, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Ohio look for? The top searched job categories for Cybersecurity Risk Management jobs in Ohio are:
What cities in Ohio are hiring for Cybersecurity Risk Management jobs? Cities in Ohio with the most Cybersecurity Risk Management job openings:
Infographic showing various Cybersecurity Risk Management job openings in Ohio as of June 2026, with employment types broken down into 98% Full Time, 1% Part Time, and 1% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $126,407 per year, or $60.8 per hour.
Manager, Product & Platform Cybersecurity Engineering

Manager, Product & Platform Cybersecurity Engineering

STERIS Corporation

Mentor, OH • Hybrid

$149K - $154K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 3 days ago


STERIS rating

8.2

Company rating: 8.2 out of 10

Based on 130 frontline employees who took The Breakroom Quiz

54th of 873 rated healthcare providers


Job description

Position Summary

The Manager, Product & Platform Cybersecurity Engineering leads the strategy, development, and implementation of a unified cybersecurity framework for medical devices, datahandling systems, and connected services across multiple business units. You will establish product security baselines, determine applicability of NIST SP 80053 controls, and oversee a team responsible for control mapping, verification, and evidence generation throughout the software development life cycle. You will operationalize NIST CSF 2.0 and embed NIST SP 800218 securebydesign practices into engineering pipelines to elevate product security maturity and improve release quality.

You will partner closely with the Product Regulatory Cybersecurity and Quality/Regulatory teams to ensure compliance with healthcare and medtech premarket and postmarket requirements, including FD&C 524B and industry standards such as IEC 8100151 and ISO/IEC 27001:2022. You will serve as both a strategic leader and handson expert-translating cybersecurity risks into backlog priorities, guiding engineering teams through secure design and verification, advising leaders on practical risk remediation and compensating controls, and defining enterprise requirements for secure development infrastructure and product operations.

*This position is located onsite in Mentor, Ohio with the opportunity for a hybrid work schedule.

What You'll Do as a Manager, Product and Platform Cybersecurity Engineering
  • Coordinate with the product development, implementation and CPE teams in the specification, development, verification, and deployment of security measures in new, currently marketed, and legacy products, which run Linux, Windows, or embedded operating systems.
  • Propose solutions and defines the technical direction for product security development efforts. Shares responsibility for ensuring secure architecture designs.
  • Own the development and execution of security plans and product security specifications for new and legacy products.
  • Lead cybersecurity risk management activities, including threat modeling and vulnerability assessments.
  • Work with the product team to perform vulnerability scans, assessments, and specify risk controls on software prior to release.
  • Participate in design and code reviews to identify security-related issues and recommends design changes as appropriate.
  • Coordinate with development teams in penetration and fuzz testing and third-party attestations of cyber devices.
  • Implement secure code and server configuration practices within products and supporting infrastructure.
  • Responsible for customer facing product security documents such as MDS2 forms (Manufacturer Disclosure Statement for Medical Device Security) and medical device security labelling.
  • Provide level 3 support on product security issues and questions that are escalated to Engineering.
  • Facilitate product security incident response and coordinated vulnerability disclosure.
  • Develop awareness of security concerns, shares best engineering practices, and creates/updates procedures to ensure compliance.
  • Continuously expands broader team knowledge and expertise in cybersecurity.
The Experience, Skills and Abilities Needed

Required:

  • Bachelors Degree in Software Engineering, Computer Engineering, Electrical Engineering or related technical degree required.
  • 10+ years of product software development experience.
  • 5+ years new product development cybersecurity experience.
  • 2+ years managing a team in a new product development (NPD) or Cybersecurity capacity.
  • Experience working in a highly regulated industry, ie: Medical Device, Automotive, Aerospace, etc.
  • Experience in the following:
    • Working knowledge and understanding of security engineering, system and network security, authentication, network and web-related protocols, cryptography, or application security
    • Software development processes and secure coding
    • Developing security procedures and product security specifications
    • Vulnerability/penetration testing
    • TCP/IP, UDP, HTTP, HTTPS, routing protocols
    • Experience with secure design, configuration, and installation of networked devices such as servers, client PCs, NAS drives, and mobile devices, preferably on a hospital network.
    • Use of development tools to facilitate and automate the analysis of software systems and code for security deficiencies.

Preferred:

  • Medical device industry experience.
  • Secure web and server-side application development; REST or GraphQL web services.
  • Identity management, authentication, DDKG, cryptography, and encryption, including data encryption in transfer and at rest.
  • Experience with system administration and network security, including firewalls, VPNs, SSH, Site-to-Site tunnels, and network certificates.
  • Hardening Linux systems to DoD RMF standards.
What STERIS Offers

We value our employees and are committed to providing a comprehensive benefits package that supports your health, well-being and financial future.


Here is a brief overview of what we offer:


Market Competitive Pay
Extensive Paid Time Off and (9) added Holidays
Excellent Healthcare, Dental and Vision Benefits
Long/Short Term Disability Coverage
401(k) with a company match
Maternity and Paternity Leave
Additional add-on benefits/discounts for programs such as Pet Insurance
Tuition Reimbursement and continued education programs
Excellent opportunities for advancement in a stable long-term career

#LI-KK1

Pay range for this opportunity is $143,750 - $158,125.00. This position is bonus and LTI eligible.

Minimum pay rates offered will comply with county/city minimums, if higher than range listed. Pay rates are based on a number of factors, including but not limited to local labor market costs, years of relevant experience, education, professional certifications, foreign language fluency, etc.

STERIS offers a comprehensive and competitive benefits portfolio. Click here for a complete list of benefits: STERIS Benefits

Open until position is filled.

STERIS is a leading global provider of products and services that support patient care with an emphasis on infection prevention. WE HELP OUR CUSTOMERS CREATE A HEALTHIER AND SAFER WORLD by providing innovative healthcare and life sciences products and services around the globe. For more information, visit www.steris.com.

If you need assistance completing the application process, please call 1 (440) 392.7047. This contact information is for accommodation inquiries only and cannot be used to check application status.

STERIS is an Equal Opportunity Employer. We are committed to equal employment opportunity to ensure that persons are recruited, hired, trained, transferred and promoted in all job groups regardless of race, color, religion, age, disability, national origin, citizenship status, military or veteran status, sex (including pregnancy, childbirth and related medical conditions), sexual orientation, gender identity, genetic information, and any other category protected by federal, state or local law. We are not only committed to this policy by our status as a federal government contractor, but also we are strongly bound by the principle of equal employment opportunity.

The full affirmative action program, absent the data metrics required by 60-741.44(k), shall be available to all employees and applicants for employment for inspection upon request. The program may be obtained at your location's HR Office during normal business hours.

Employment Type: FULL_TIME

What STERIS employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom