1

Cybersecurity Risk Management Jobs in Appleton, WI

... our cybersecurity capabilities. If you're passionate about security, problem-solving, and staying ... Knowledge of information security principles, security controls, and risk management practices.

Senior Engineer, Systems

Menasha, WI

$106K - $146K/yr

Background in Power Electronic Reliability, Safety & Cybersecurity WORK SCHEDULE This position ... Lead development of risk registry, risk management and risk mitigation plan * Assess TRL level for ...

Senior Engineer, Systems

Menasha, WI · On-site

$106K - $146K/yr

Background in Power Electronic Reliability, Safety & Cybersecurity WORK SCHEDULE This position ... Lead development of risk registry, risk management and risk mitigation plan * Assess TRL level for ...

Showing results 21-40

Cybersecurity Risk Management information

See Appleton, WI salary details

$55.6K

$129.7K

$181.5K

How much do cybersecurity risk management jobs pay per year?

As of Aug 15, 2026, the average yearly pay for cybersecurity risk management in Appleton, WI is $129,735.00, according to ZipRecruiter salary data. Most workers in this role earn between $108,300.00 and $146,400.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What are popular job titles related to Cybersecurity Risk Management jobs in Appleton, WI?

For Cybersecurity Risk Management jobs in Appleton, WI, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Risk Management jobs in Appleton, WI look for?

The top searched job categories for Cybersecurity Risk Management jobs in Appleton, WI are:

What cities near Appleton, WI are hiring for Cybersecurity Risk Management jobs?

Cities near Appleton, WI with the most Cybersecurity Risk Management job openings:

Infographic showing various Cybersecurity Risk Management job openings in Appleton, WI as of August 2026, with employment types broken down into 1% As Needed, 80% Full Time, 16% Part Time, and 3% Contract. Highlights an 91% Physical, 4% Hybrid, and 5% Remote job distribution, with an average salary of $129,735 per year, or $62.4 per hour.

Senior Product Security Engineer

Faith Technologies Incorporated (FTI)

Menasha, WI • On-site

$117K - $160K/yr

Full-time

Posted 25 days ago


Faith Technologies rating

8.0

Company rating: 8.0 out of 10

Based on 54 frontline employees who took The Breakroom Quiz

208th of 449 rated engineering


Job description

You've discovered something special. A company that cares. Cares about leading the way in construction, engineering, manufacturing and renewable energy. Cares about redefining how energy is designed, applied and consumed. Cares about thoughtfully growing to meet market demands. And - as "one of the Healthiest 100 Workplaces in America" - is focused on the mind/body/soul of team members through our Culture of Care
The Senior Product Security Engineer leads the security design and governance of our Industrial Internet of Things (IIoT) and Grid connected product portfolio. Reporting to the Cybersecurity Manager, this role is the primary technical authority for IIoT product security across the entire device lifecycle - from early design through field deployment and ongoing operation.
This is a deeply technical role focused on hardware and embedded systems security, OT/IT convergence, and the application of industrial security standards. Day-to-day development and DevSecOps execution (code scanning, firmware management, CI/CD pipeline tooling) is owned by the Product Security Engineer II; the Senior Engineer operates at the architectural, standards, and cross-functional leadership level.
MINIMUM REQUIREMENTS
Education: Bachelor's degree or equivalent experience in Information Security, Electrical Engineering, Computer Engineering, or a related technical field.
Experience: 5+ years of dedicated experience in product security, embedded/IIoT security,
or
Education: Industry-recognized security certifications preferred but not required (e.g., GICSP, CISSP, ISA/IEC 62443 Cybersecurity Certificate Program, CSSA).
Experience: OT/ICS security, with at least 2 years in a senior or lead capacity and
Travel: 5-10%
Work Schedule: Typical work hours are between 7:00 a.m. and 5:00 p.m. Monday - Friday. However, work may be performed at any time on any day of the week to meet business needs.
KEY RESPONSIBILITIES
IIoT Security Architecture and Standards
  • Security Architecture: Define and own the security architecture for connected IIoT products, including device identity frameworks (PKI/certificate management), secure boot chains, cryptographic key management, and hardware root of trust.
  • Industrial Standards Leadership: Establish and enforce security design requirements based on applicable standards and frameworks (e.g., IEC 62443, UL 2900, NERC CIP, NIST SP 800-82, NIST CSF) across product lines.
  • OT/IT Convergence: Design security boundaries and communication controls for environments where operational technology (OT) interfaces with enterprise IT systems, ensuring defense-in-depth across both layers.
  • Protocol and Interface Security: Evaluate and provide security guidance on industrial communication protocols used in energy and grid applications (e.g., IEC 61850, DNP3, Modbus, CAN bus, GOOSE/Sampled Values).

Threat Modeling and Risk Management
  • Lead Threat Modeling: Conduct and lead structured threat modeling exercises (e.g., STRIDE, PASTA) for new IIoT product initiatives and significant feature changes, translating identified risks into actionable design controls.
  • Risk Prioritization: Assess and prioritize security risks across fielded and in-development device portfolios based on exploitability, potential impact to grid operations or physical safety, and business criticality.
  • Vulnerability Coordination: Serve as the technical lead for coordinating responses to security vulnerabilities identified in fielded IIoT products, including working with Product, Engineering, and customers on disclosure and remediation timelines.
  • Supply Chain Security: Evaluate hardware component and third-party software supply chain risks, providing security requirements for procurement and vendor selection of embedded components.

Governance, Consultation, and Leadership
  • Security SME: Act as the primary subject matter expert for IIoT and OT product security, providing high-context technical consultation to product architects, engineering leads, and executive leadership.
  • Security Standards Ownership: Own the product security standards, policies, and design review processes applicable to IIoT devices, ensuring teams have clear, actionable requirements before development begins.
  • Cross-Functional Collaboration: Partner with Hardware, Firmware, Systems Engineering, and Product Management teams to embed security requirements early in the product development process without creating unnecessary friction.
  • Incident Leadership: Serve as the senior technical contributor during high-severity security incidents involving fielded IIoT products, leading root cause analysis and driving architectural improvements to prevent recurrence.
  • Public Disclosure and Advisory: Coordinate with Threat Intelligence and engineering teams to document identified vulnerabilities and assist in drafting CVEs and public security advisories following successful remediation.

Technical Components
  • IIoT and Embedded Security: Demonstrated expertise in securing embedded and IIoT devices, including secure boot, hardware security modules (HSMs), trusted execution environments (TEEs), and firmware security architecture.
  • Industrial Protocols: Working knowledge of industrial communication protocols common in energy and grid applications (IEC 61850, DNP3, Modbus, CAN bus) and their associated security considerations.
  • OT/ICS Security: Strong understanding of OT and ICS security principles, network segmentation strategies (e.g., Purdue Model, IEC 62443 zones and conduits), and the unique threat landscape of connected energy infrastructure.
  • PKI and Cryptography: Solid understanding of public key infrastructure, certificate lifecycle management for device identity, and applied cryptography as it relates to constrained embedded environments.
  • Security Standards: Deep familiarity with IEC 62443, UL 2900, NERC CIP, and NIST SP 800-82; ability to translate standards requirements into concrete, enforceable product security controls.
  • Threat Modeling: Proven experience leading structured threat modeling sessions for hardware/firmware products in OT or energy environments.
  • Performs other related duties as required and assigned.

The job description and responsibilities described are intended to provide guidelines for job expectations and the employee's ability to perform the position described. It is not intended to be construed as an exhaustive list of all functions, responsibilities, skills, and abilities. Additional functions and requirements may be assigned by supervisors as deemed appropriate.
How Does FTI Give YOU the Chance to Thrive?
If you're energized by new challenges, FTI provides you with many opportunities. Joining FTI opens doors to redefine what's possible for your future.
Once you're a team member, you're supported and provided with the knowledge and resources to achieve your career goals with FTI. You're officially in the driver's seat of your career, and FTI's career development and continued education programs give you opportunities to position yourself for success.
FTI is a "merit to the core" organization. We recognize and reward top performers, offering competitive, merit-based compensation, career path development and a flexible and robust benefits package.
Benefits are the Game-Changer
We provide industry-leading benefits as an investment in the lives of team members and their families. You're invited to review the full list of FTI benefits available to regular/full-time team members. Start here. Grow here. Succeed here. If you're ready to learn more about your career with FTI, apply today!
Faith Technologies, Inc. is an Equal Opportunity Employer - veterans/disabled.
Employment is contingent upon successfully passing a background and drug test

What Faith Technologies employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom