1

Cybersecurity Risk Management Jobs in Tennessee (NOW HIRING)

Cybersecurity Lead

Oak Ridge, TN · On-site

$96K - $130K/yr

NIST 800-53 Rev 5, Risk Management Framework, NIST Cybersecurity Framework (CSF), FedRAMP ... Authorization, Tenable Nessus (ACAS), and DISA STIGs. Desired Skills * Strategic thinker with ...

Cyber Manager - ServiceNow

Nashville, TN · On-site

$16 - $18.50/hr

... Risk Management workstreams in partnership with architects and product owners • Managing ... Required : • Bachelor's degree in Computer Science, Cyber Security, Information Security ...

Cyber Manager - ServiceNow

Memphis, TN · On-site

$16 - $18.75/hr

... Risk Management workstreams in partnership with architects and product owners • Managing ... Required : • Bachelor's degree in Computer Science, Cyber Security, Information Security ...

Director - Product Security

Nashville, TN · On-site +1

$225K - $235K/yr

Ensure all required cybersecurity documentation, including risk assessments and SBOMs, is prepared and submitted for premarket applications (510(k), PMA). * Manage the generation and maintenance of ...

Risk Management: Oversee the assessment and management of cybersecurity risks associated with third-party vendors, partners, and bio-medical devices. Policy Development and Enforcement * Policy ...

Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk management, compliance requirements, and ethical computing practices. * Curriculum Awareness ...

Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk management, compliance requirements, and ethical computing practices. * Curriculum Awareness ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Tennessee salary details

$51.7K

$120.7K

$168.8K

How much do cybersecurity risk management jobs pay per year?

As of Jun 20, 2026, the average yearly pay for cybersecurity risk management in Tennessee is $120,679.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,700.00 and $136,100.00 per year, depending on experience, location, and employer.

What is the role of a risk manager in cybersecurity?

A cybersecurity risk manager identifies, assesses, and prioritizes security risks to an organization’s information systems. They develop strategies to mitigate threats, implement security controls, and ensure compliance with industry standards, often using tools like risk assessment frameworks and security audits. Their role is essential in protecting digital assets and supporting overall cybersecurity posture.

Is security risk management a good career?

Security risk management is a valuable career in cybersecurity, focusing on identifying and mitigating threats to organizational assets. It often requires knowledge of security frameworks, risk assessment tools, and certifications like CISSP or CISM. The field offers strong job growth, competitive salaries, and opportunities across various industries.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What is risk management in cyber security?

In cybersecurity risk management, professionals identify, assess, and prioritize potential security threats to an organization’s information systems. They implement strategies and controls to mitigate or accept risks, often using frameworks like NIST or ISO 27001, and may hold certifications such as CISSP or CISM to ensure effective risk handling.

Can you make $500,000 a year in cyber security?

Cybersecurity risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working in large organizations with complex security needs.
What are popular job titles related to Cybersecurity Risk Management jobs in Tennessee? For Cybersecurity Risk Management jobs in Tennessee, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Tennessee look for? The top searched job categories for Cybersecurity Risk Management jobs in Tennessee are:
What cities in Tennessee are hiring for Cybersecurity Risk Management jobs? Cities in Tennessee with the most Cybersecurity Risk Management job openings:
Infographic showing various Cybersecurity Risk Management job openings in Tennessee as of June 2026, with employment types broken down into 98% Full Time, 1% Temporary, and 1% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $120,679 per year, or $58 per hour.
NIST Risk Management Framework SME

NIST Risk Management Framework SME

Boston Government Services, LLC

Oak Ridge, TN • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 29 days ago


Job description

Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to NIST Risk Management Framework (RMF) Subject Matter Expert (SME) to support our clients. The RMF SME will provide expert guidance and support for implementing and maintaining compliance with NIST SP 800-53 security controls across federal systems. This role ensures adherence to the RMF lifecycle, including categorization, selection, implementation, assessment, authorization, and continuous monitoring of security controls.

BGS is an engineering, technology, and security firm helping to advance missions of national importance for government programs, national laboratories, national security facilities, nuclear operations, and complex projects. We support clients at every stage, from strategic planning and program management to the execution of engineering and technical activities. We work to attract and retain the best talent because the best talent delivers the best results for our clients. Our capabilities are based on our experience in complex, secure, and highly regulated environments. We leverage our experience and capabilities to provide mission-driven solutions tuned to our client's mission needs and strategic direction.

Work that Matters. People that Matter More. At BGS, we believe meaningful work starts with great people. We foster a culture built on respect, collaboration, and accountability—where employees are empowered to contribute ideas, grow professionally, and make an impact. We care about our employees’ well-being through competitive benefits, clear expectations, and an environment that values both excellence and connection.


If you align with BGS’ company values and culture, we would love for you to explore opportunities to join our growing team by checking out the job description below!

Responsibilities:

  • Lead RMF activities for federal systems, ensuring compliance with NIST SP 800-53 and related standards.
  • Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms).
  • Conduct gap analyses and risk assessments to identify compliance deficiencies and recommend remediation strategies.
  • Provide expert guidance on security control implementation and documentation for Authorization to Operate (ATO) packages.
  • Support security audits and assessments, including preparation for FISMA and FedRAMP requirements.
  • Deliver training and workshops on RMF processes and NIST SP 800-53 controls.
  • Collaborate with system owners, ISSOs, and other stakeholders to ensure continuous monitoring and risk mitigation.

Requirements:

  • Bachelor’s degree in Cybersecurity, Information Systems, or related field (or equivalent experience).
  • Minimum 5 years of experience in cybersecurity compliance, with at least 3 years focused on RMF and NIST SP 800-53.
  • Demonstrated experience developing SSPs, POA&Ms, and conducting security assessments.
  • Strong understanding of NIST SP 800 series (800-53, 800-37, 800-171) and FISMA requirements.
  • Professional certifications such as CISSP, CISM, CISA, or equivalent are required.
  • Excellent technical writing and communication skills for compliance documentation.

Preferred Qualifications:

  • ISSEP (formerly CISSP-ISSEP) certification.
  • Experience with cloud security and FedRAMP controls.
  • Ability to lead compliance workshops and mentor junior staff.

Location/Work Arrangement:

  • This position is a Remote Work Arrangement with some travel/onsite requirements.

Benefits:

BGS offers a competitive total compensation package to eligible employees. Benefits include Health, Dental, Vision, Life Insurance, Paid Vacation, 401K, Long and Short-Term Disability.

EEO:

BGS is an Equal Opportunity/Affirmative Action employer. All qualified applicants are encouraged to apply and will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.

Exclusive Agreement Disclaimer:

BGS has standing contracts with federal agencies throughout the United States. We require an affirmative exclusive agreement to represent all candidates to our clients. By submitting this application, you are consenting to allow BGS to represent you as a candidate for the role in which you are applying.


Schedule is full-time, Monday – Friday 40-hour week.