Introduction As the state's IT leader, DoIT manages information technology and telecommunications ... cybersecurity risk assessments and the policy lifecycle.\r\nAs the primary analyst for third-party ...
Introduction As the state's IT leader, DoIT manages information technology and telecommunications ... cybersecurity risk assessments and the policy lifecycle.\r\nAs the primary analyst for third-party ...
GD Resources is a Veteran Women-Owned Business Management and Information Technology company ... Cybersecurity Risk Assessment Consultant Location: Hybrid (onsite work possibly at various ...
Quick apply
GD Resources is a Veteran Women-Owned Business Management and Information Technology company ... Cybersecurity Risk Assessment Consultant Location: Hybrid (onsite work possibly at various ...
AGE Solutions is seeking a highly motivated Cross Domain Solutions (CDS) CDTAB/DSAWG Support Specialist to support a critical cybersecurity risk management and assessment program for our Department ...
AGE Solutions is seeking a highly motivated Cross Domain Solutions (CDS) CDTAB/DSAWG Support Specialist to support a critical cybersecurity risk management and assessment program for our Department ...
The Lead Security, Risk and Compliance Specialist leads cross functional security initiatives and ... Support senior management in developing and executing the global cybersecurity strategy aligned to ...
The Lead Security, Risk and Compliance Specialist leads cross functional security initiatives and ... Support senior management in developing and executing the global cybersecurity strategy aligned to ...
Sr. Cyber Security Analyst - Incident Response
Owings Mills, MD · Hybrid
$95K - $123K/yr
The Senior Cyber Security Analyst will use his or her experience and expert knowledge to defend our ... Knowledgeable in Cyber risk management frameworks, web application technologies, and network and ...
Sr. Cyber Security Analyst - Incident Response
Owings Mills, MD · Hybrid
$95K - $123K/yr
The Senior Cyber Security Analyst will use his or her experience and expert knowledge to defend our ... Knowledgeable in Cyber risk management frameworks, web application technologies, and network and ...
This role requires deep expertise in multilevel security (MLS), security architecture, and risk management, with a strong foundation in NIST and CMMI-aligned cybersecurity programs. The individual ...
This role requires deep expertise in multilevel security (MLS), security architecture, and risk management, with a strong foundation in NIST and CMMI-aligned cybersecurity programs. The individual ...
The Lead Security, Risk and Compliance Specialist leads cross functional security initiatives and ... Support senior management in developing and executing the global cybersecurity strategy aligned to ...
The Lead Security, Risk and Compliance Specialist leads cross functional security initiatives and ... Support senior management in developing and executing the global cybersecurity strategy aligned to ...
Cybersecurity Strategy & Program Sr. Manager (HYBRID)
Hunt Valley, MD · Hybrid
$105K - $142K/yr
... management, governance, risk, and compliance (GRC), or a related field. * Experience conducting or facilitating assessment or audits, coordinating with auditors, and implementing audit ...
Cybersecurity Strategy & Program Sr. Manager (HYBRID)
Hunt Valley, MD · Hybrid
$105K - $142K/yr
... management, governance, risk, and compliance (GRC), or a related field. * Experience conducting or facilitating assessment or audits, coordinating with auditors, and implementing audit ...
Cybersecurity Strategy & Program Sr. Manager (HYBRID)
Hunt Valley, MD · On-site
$105K - $142K/yr
... management, governance, risk, and compliance (GRC), or a related field. * Experience conducting or facilitating assessment or audits, coordinating with auditors, and implementing audit ...
Cybersecurity Strategy & Program Sr. Manager (HYBRID)
Hunt Valley, MD · On-site
$105K - $142K/yr
... management, governance, risk, and compliance (GRC), or a related field. * Experience conducting or facilitating assessment or audits, coordinating with auditors, and implementing audit ...
Cybersecurity Strategy & Program Sr. Manager (HYBRID)
Hunt Valley, MD · Hybrid
$105K - $142K/yr
... management, governance, risk, and compliance (GRC), or a related field. * Experience conducting or facilitating assessment or audits, coordinating with auditors, and implementing audit ...
Cybersecurity Strategy & Program Sr. Manager (HYBRID)
Hunt Valley, MD · Hybrid
$105K - $142K/yr
... management, governance, risk, and compliance (GRC), or a related field. * Experience conducting or facilitating assessment or audits, coordinating with auditors, and implementing audit ...
Cyber Cloud Assessment Engineer, Sr.
Fort George G Meade, MD · On-site
$110K/yr
AGE Solutions is looking for a Senior Cyber Cloud Assessment Engineer to join our team in support of an upcoming cybersecurity risk management and assessment program with our DoD customer. As a Team ...
Cyber Cloud Assessment Engineer, Sr.
Fort George G Meade, MD · On-site
$110K/yr
AGE Solutions is looking for a Senior Cyber Cloud Assessment Engineer to join our team in support of an upcoming cybersecurity risk management and assessment program with our DoD customer. As a Team ...
Cybersecurity Strategy & Program Sr. Manager (HYBRID)
Hunt Valley, MD · Hybrid
$105K - $142K/yr
... management, governance, risk, and compliance (GRC), or a related field. * Experience conducting or facilitating assessment or audits, coordinating with auditors, and implementing audit ...
Cybersecurity Strategy & Program Sr. Manager (HYBRID)
Hunt Valley, MD · Hybrid
$105K - $142K/yr
... management, governance, risk, and compliance (GRC), or a related field. * Experience conducting or facilitating assessment or audits, coordinating with auditors, and implementing audit ...
Sr. Cybersecurity Architect
Baltimore, MD · On-site +1
$140K - $160K/yr
Serve as a senior technical advisor supporting security and privacy initiatives across emerging technology, cyber risk management, Zero Trust, and cybersecurity readiness efforts * Research, evaluate ...
Sr. Cybersecurity Architect
Baltimore, MD · On-site +1
$140K - $160K/yr
Serve as a senior technical advisor supporting security and privacy initiatives across emerging technology, cyber risk management, Zero Trust, and cybersecurity readiness efforts * Research, evaluate ...
Sr. Cybersecurity Architect
Baltimore, MD · On-site +1
$140K - $160K/yr
Serve as a senior technical advisor supporting security and privacy initiatives across emerging technology, cyber risk management, Zero Trust, and cybersecurity readiness efforts * Research, evaluate ...
Sr. Cybersecurity Architect
Baltimore, MD · On-site +1
$140K - $160K/yr
Serve as a senior technical advisor supporting security and privacy initiatives across emerging technology, cyber risk management, Zero Trust, and cybersecurity readiness efforts * Research, evaluate ...
Sr. Cybersecurity Architect
Baltimore, MD · On-site
Serve as a senior technical advisor supporting security and privacy initiatives across emerging technology, cyber risk management, Zero Trust, and cybersecurity readiness efforts * Research, evaluate ...
Sr. Cybersecurity Architect
Baltimore, MD · On-site
Serve as a senior technical advisor supporting security and privacy initiatives across emerging technology, cyber risk management, Zero Trust, and cybersecurity readiness efforts * Research, evaluate ...
Serve as a senior technical advisor supporting security and privacy initiatives across emerging technology, cyber risk management, Zero Trust, and cybersecurity readiness efforts * Research, evaluate ...
Serve as a senior technical advisor supporting security and privacy initiatives across emerging technology, cyber risk management, Zero Trust, and cybersecurity readiness efforts * Research, evaluate ...
Establish identity and access management frameworks and privileged access controls * Evaluate ... Prepare executive-level cybersecurity risk reports and board-ready briefings * Translate complex ...
Establish identity and access management frameworks and privileged access controls * Evaluate ... Prepare executive-level cybersecurity risk reports and board-ready briefings * Translate complex ...
Cybersecurity Engineer
Annapolis Junction, MD · On-site
$62K - $141K/yr
Knowledge of the cybersecurity risk management process and cybersecurity tools used in DoD environments * Knowledge of governance, risk, and compliance strategies and tools * HBSS or ACAS ...
Cybersecurity Engineer
Annapolis Junction, MD · On-site
$62K - $141K/yr
Knowledge of the cybersecurity risk management process and cybersecurity tools used in DoD environments * Knowledge of governance, risk, and compliance strategies and tools * HBSS or ACAS ...
Cybersecurity Engineer
Annapolis Junction, MD · On-site
$86K - $198K/yr
Knowledge of the cybersecurity risk management process and cybersecurity tools used in DoD environments * Knowledge of governance, risk, and compliance strategies and tools * Trelix, ENS, and Tenable ...
Cybersecurity Engineer
Annapolis Junction, MD · On-site
$86K - $198K/yr
Knowledge of the cybersecurity risk management process and cybersecurity tools used in DoD environments * Knowledge of governance, risk, and compliance strategies and tools * Trelix, ENS, and Tenable ...
ISSE, Senior with Security Clearance
$175K - $230K/yr
Expertise in the Risk Management Framework (RMF) and conducting cybersecurity risk assessments. * Expertise in network technology and systems security engineering. Experience in identifying ...
ISSE, Senior with Security Clearance
$175K - $230K/yr
Expertise in the Risk Management Framework (RMF) and conducting cybersecurity risk assessments. * Expertise in network technology and systems security engineering. Experience in identifying ...
Cybersecurity Risk Management information
See Baltimore, MD salary details
$56.6K - $68.3K
1% of jobs
$68.3K - $79.9K
4% of jobs
$79.9K - $91.6K
5% of jobs
$91.6K - $103.2K
9% of jobs
$109.7K is the 25th percentile. Wages below this are outliers.
$103.2K - $114.9K
11% of jobs
$114.9K - $126.6K
10% of jobs
The median wage is $131K / yr.
$126.6K - $138.2K
28% of jobs
$144.9K is the 75th percentile. Wages above this are outliers.
$138.2K - $149.9K
14% of jobs
$149.9K - $161.5K
11% of jobs
$161.5K - $173.2K
4% of jobs
$173.2K - $184.8K
4% of jobs
$56.6K
$132.1K
$184.8K
How much do cybersecurity risk management jobs pay per year?
What is the role of a risk manager in cybersecurity?
Is security risk management a good career?
What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?
What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?
| Aspect | Cybersecurity Risk Management | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government, large enterprises | IT departments, cybersecurity firms, corporate security teams |
Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.
What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?
What is cybersecurity risk management?
What is risk management in cyber security?
Can you make $500,000 a year in cyber security?

Cybersecurity & Third Party Risk Analyst
State of Maryland - DoIT Enterprise Information SystemsAnne Arundel, MD • On-site
Full-time
Posted 18 days ago
Job description
Introduction
As the state's IT leader, DoIT manages information technology and telecommunications services and provides critical support to state agencies, the Executive Office of the Governor, coordinating offices, and independent Executive Branch agencies. The agency provides cybersecurity, digital, data governance, AI enablement, infrastructure, and platform services to its partner agencies, ensuring the State of Maryland is more secure, productive, and accessible.\r\n
GRADE
STD 0023 \r\n
Main Purpose of Job
The purpose of this position is to support the development of the Department of Information\r\nTechnology's (DoIT) Third-Party Risk Management (TPRM) program while providing cross-\r\nfunctional support for enterprise cybersecurity risk assessments and the policy lifecycle.\r\nAs the primary analyst for third-party oversight, this role ensures that all vendors, contractors,\r\nand cloud service providers comply with the State of Maryland's security standards.\r\nAdditionally, this position serves as a GRC generalist, facilitating the Authority to Operate\r\n(ATO) process and ensuring that cybersecurity policies are implemented, and maintained in\r\nalignment with NIST frameworks and state legislative mandates.
POSITION DUTIES
\r\n\r\nThird-Party Risk Management Program\r\n\r\n- Support the development and implementation of a third-party/vendor risk management framework that aligns with NIST 800-161 (Supply Chain Risk Management) and State of Maryland Cybersecurity & Privacy policy suite.\r\n- Assess and manage security risks associated with cloud providers, contractors, and IT vendors.\r\n- Establish vendor security assessments, contract security requirements, and ongoing compliance monitoring.\r\n- Partner with procurement and legal teams to integrate cybersecurity requirements into contracts and vendor agreements.\r\n- Oversee vendor audits, penetration testing, and compliance assessments to mitigate third-party cybersecurity risks.\r\n\r\n\r\nCybersecurity Risk Management & ATO Support\r\n- Support execution of statewide cybersecurity risk assessments and threat modeling for Executive Branch agencies.\r\n- Facilitate the ATO (Authority to Operate) process by reviewing System Security Plans (SSPs) and assessing control implementation against NIST 800-53.\r\n- Support the development and maintenance of the the Enterprise Risk Register and assist agencies in developing Plans of Action and Milestones (POA&Ms) to remediate gaps.\r\n- Provide cross-pollination support for continuous monitoring efforts to track the state's real-time risk posture.\r\n\r\n\r\nPolicy Lifecycle & Governance Management\r\n- Manage the full lifecycle of cybersecurity and privacy policies, from initial drafting and stakeholder review to formal approval and publication.\r\n- Ensure all policies remain current with evolving federal and state regulations (e.g., IRS 1075, HIPAA, State Senate/House Bills).\r\n- Map policy requirements to technical controls to ensure measurable compliance across the enterprise.\r\n\r\n\r\n
MINIMUM QUALIFICATIONS
Experience: Four years of experience in Information security as it relates to policy creation regarding compliance, legislation, governance programs and/or supporting internal audits.\r\nNotes:\r\n1. Candidates may substitute a bachelor's degree in IT security management, IT management, information security, political science, business management, communications, or public administration with cybersecurity experience or a related field for up to two years of the required experience.\r\n
DESIRED OR PREFERRED QUALIFICATIONS
Our preferred candidate will also have one or more of the following:\r\n\r\n\r\nPublic Sector cybersecurity experience: Direct experience working within local, state, or federal government environments, with direct knowledge of the government Authority to Operate (ATO) process and specialized compliance mandates (e.g., IRS 1075, HIPAA, or State legislative frameworks).\r\n\r\n\r\nSupply Chain/Third-Party Specialization: Working experience evaluating vendor security postures using NIST 800-161 (Supply Chain Risk Management) and interpreting SOC 2 reports or vendor-provided System Security Plans (SSPs).\r\n\r\n\r\nProfessional Certifications: Possession of foundational or intermediate GRC-related certifications such as CompTIA Security+, ISACA CISA (Certified Information Systems Auditor), or CRISC (Certified in Risk and Information Systems Control).\r\n
SPECIAL REQUIREMENTS
1. Employees in this classification may be subject to call-in 24 hours a day and, therefore, may be required to provide the employing agency with a telephone number where the employee can be reached. Employees may be furnished with a pager or cell phone.\r\n2. Applicants for this classification may handle sensitive data. This will require a full-scope background investigation before the appointment. A criminal conviction may be grounds for rejection of the applicant.\r\n3. Employees may occasionally be required to travel to field locations and must have access to an automobile in the event a state vehicle cannot be provided. A standard mileage allowance will be paid for the use of a privately owned vehicle.\r\n
BENEFITS
STATE OF MARYLAND BENEFITS\r\n
FURTHER INSTRUCTIONS
Online applications are highly recommended. However, if you\r\nare unable to apply online,the paper application and supplemental\r\nquestionnaire may be submitted to:Department of Budget and Management,\r\nRecruitment andExamination Division, 301 W. Preston St., Baltimore, MD\r\n21201.Paper application materials must be received in our officeby\r\ntheclosing date for the recruitment. No postmarks will be accepted.\r\nFor questions regarding this recruitment, please contact\r\ntheDBM Recruitment andExamination Division atApplication.Help@maryland.govor\r\n410-767-4850,MD TTY Relay Service 1-800-735-2258.\r\nWe thank our Veterans for their service to our country.\r\nPeople with disabilities and bilingual candidates are\r\nencouraged to apply.\r\nAs an equal opportunity employer, Maryland is committed to\r\nrecruitment, retaining and promoting employees who are reflective of the\r\nState's diversity.\r\n
Employment Type: Full-Time