1

Cybersecurity Risk Management Jobs in Baltimore, MD

Sr. Cybersecurity Architect

Baltimore, MD · On-site +1

$140K - $160K/yr

Serve as a senior technical advisor supporting security and privacy initiatives across emerging technology, cyber risk management, Zero Trust, and cybersecurity readiness efforts * Research, evaluate ...

Sr. Cybersecurity Architect

Baltimore, MD · On-site +1

$140K - $160K/yr

Serve as a senior technical advisor supporting security and privacy initiatives across emerging technology, cyber risk management, Zero Trust, and cybersecurity readiness efforts * Research, evaluate ...

Serve as a senior technical advisor supporting security and privacy initiatives across emerging technology, cyber risk management, Zero Trust, and cybersecurity readiness efforts * Research, evaluate ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Baltimore, MD salary details

$56.6K

$132.1K

$184.8K

How much do cybersecurity risk management jobs pay per year?

As of Jun 15, 2026, the average yearly pay for cybersecurity risk management in Baltimore, MD is $132,116.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,300.00 and $149,000.00 per year, depending on experience, location, and employer.

What is the role of a risk manager in cybersecurity?

A cybersecurity risk manager identifies, assesses, and prioritizes security risks to an organization’s information systems. They develop strategies to mitigate threats, implement security controls, and ensure compliance with industry standards, often using tools like risk assessment frameworks and security audits. Their role is essential in protecting digital assets and supporting overall cybersecurity posture.

Is security risk management a good career?

Security risk management is a valuable career in cybersecurity, focusing on identifying and mitigating threats to organizational assets. It often requires knowledge of security frameworks, risk assessment tools, and certifications like CISSP or CISM. The field offers strong job growth, competitive salaries, and opportunities across various industries.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What is risk management in cyber security?

In cybersecurity risk management, professionals identify, assess, and prioritize potential security threats to an organization’s information systems. They implement strategies and controls to mitigate or accept risks, often using frameworks like NIST or ISO 27001, and may hold certifications such as CISSP or CISM to ensure effective risk handling.

Can you make $500,000 a year in cyber security?

Cybersecurity risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working in large organizations with complex security needs.
What are popular job titles related to Cybersecurity Risk Management jobs in Baltimore, MD? For Cybersecurity Risk Management jobs in Baltimore, MD, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Baltimore, MD look for? The top searched job categories for Cybersecurity Risk Management jobs in Baltimore, MD are:
What cities near Baltimore, MD are hiring for Cybersecurity Risk Management jobs? Cities near Baltimore, MD with the most Cybersecurity Risk Management job openings:
Infographic showing various Cybersecurity Risk Management job openings in Baltimore, MD as of June 2026, with employment types broken down into 98% Full Time, 1% Part Time, and 1% Temporary. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $132,116 per year, or $63.5 per hour.

Cybersecurity & Third Party Risk Analyst

State of Maryland - DoIT Enterprise Information Systems

Anne Arundel, MD • On-site

Full-time

Posted 18 days ago


Job description

Introduction

As the state's IT leader, DoIT manages information technology and telecommunications services and provides critical support to state agencies, the Executive Office of the Governor, coordinating offices, and independent Executive Branch agencies. The agency provides cybersecurity, digital, data governance, AI enablement, infrastructure, and platform services to its partner agencies, ensuring the State of Maryland is more secure, productive, and accessible.\r\n

GRADE

STD 0023 \r\n

Main Purpose of Job

The purpose of this position is to support the development of the Department of Information\r\nTechnology's (DoIT) Third-Party Risk Management (TPRM) program while providing cross-\r\nfunctional support for enterprise cybersecurity risk assessments and the policy lifecycle.\r\nAs the primary analyst for third-party oversight, this role ensures that all vendors, contractors,\r\nand cloud service providers comply with the State of Maryland's security standards.\r\nAdditionally, this position serves as a GRC generalist, facilitating the Authority to Operate\r\n(ATO) process and ensuring that cybersecurity policies are implemented, and maintained in\r\nalignment with NIST frameworks and state legislative mandates.

POSITION DUTIES

\r\n\r\nThird-Party Risk Management Program\r\n\r\n- Support the development and implementation of a third-party/vendor risk management framework that aligns with NIST 800-161 (Supply Chain Risk Management) and State of Maryland Cybersecurity & Privacy policy suite.\r\n- Assess and manage security risks associated with cloud providers, contractors, and IT vendors.\r\n- Establish vendor security assessments, contract security requirements, and ongoing compliance monitoring.\r\n- Partner with procurement and legal teams to integrate cybersecurity requirements into contracts and vendor agreements.\r\n- Oversee vendor audits, penetration testing, and compliance assessments to mitigate third-party cybersecurity risks.\r\n\r\n\r\nCybersecurity Risk Management & ATO Support\r\n- Support execution of statewide cybersecurity risk assessments and threat modeling for Executive Branch agencies.\r\n- Facilitate the ATO (Authority to Operate) process by reviewing System Security Plans (SSPs) and assessing control implementation against NIST 800-53.\r\n- Support the development and maintenance of the the Enterprise Risk Register and assist agencies in developing Plans of Action and Milestones (POA&Ms) to remediate gaps.\r\n- Provide cross-pollination support for continuous monitoring efforts to track the state's real-time risk posture.\r\n\r\n\r\nPolicy Lifecycle & Governance Management\r\n- Manage the full lifecycle of cybersecurity and privacy policies, from initial drafting and stakeholder review to formal approval and publication.\r\n- Ensure all policies remain current with evolving federal and state regulations (e.g., IRS 1075, HIPAA, State Senate/House Bills).\r\n- Map policy requirements to technical controls to ensure measurable compliance across the enterprise.\r\n\r\n\r\n

MINIMUM QUALIFICATIONS

Experience: Four years of experience in Information security as it relates to policy creation regarding compliance, legislation, governance programs and/or supporting internal audits.\r\nNotes:\r\n1. Candidates may substitute a bachelor's degree in IT security management, IT management, information security, political science, business management, communications, or public administration with cybersecurity experience or a related field for up to two years of the required experience.\r\n

DESIRED OR PREFERRED QUALIFICATIONS

Our preferred candidate will also have one or more of the following:\r\n\r\n\r\nPublic Sector cybersecurity experience: Direct experience working within local, state, or federal government environments, with direct knowledge of the government Authority to Operate (ATO) process and specialized compliance mandates (e.g., IRS 1075, HIPAA, or State legislative frameworks).\r\n\r\n\r\nSupply Chain/Third-Party Specialization: Working experience evaluating vendor security postures using NIST 800-161 (Supply Chain Risk Management) and interpreting SOC 2 reports or vendor-provided System Security Plans (SSPs).\r\n\r\n\r\nProfessional Certifications: Possession of foundational or intermediate GRC-related certifications such as CompTIA Security+, ISACA CISA (Certified Information Systems Auditor), or CRISC (Certified in Risk and Information Systems Control).\r\n

SPECIAL REQUIREMENTS

1. Employees in this classification may be subject to call-in 24 hours a day and, therefore, may be required to provide the employing agency with a telephone number where the employee can be reached. Employees may be furnished with a pager or cell phone.\r\n2. Applicants for this classification may handle sensitive data. This will require a full-scope background investigation before the appointment. A criminal conviction may be grounds for rejection of the applicant.\r\n3. Employees may occasionally be required to travel to field locations and must have access to an automobile in the event a state vehicle cannot be provided. A standard mileage allowance will be paid for the use of a privately owned vehicle.\r\n

BENEFITS

STATE OF MARYLAND BENEFITS\r\n

FURTHER INSTRUCTIONS

Online applications are highly recommended. However, if you\r\nare unable to apply online,the paper application and supplemental\r\nquestionnaire may be submitted to:Department of Budget and Management,\r\nRecruitment andExamination Division, 301 W. Preston St., Baltimore, MD\r\n21201.Paper application materials must be received in our officeby\r\ntheclosing date for the recruitment. No postmarks will be accepted.\r\nFor questions regarding this recruitment, please contact\r\ntheDBM Recruitment andExamination Division atApplication.Help@maryland.govor\r\n410-767-4850,MD TTY Relay Service 1-800-735-2258.\r\nWe thank our Veterans for their service to our country.\r\nPeople with disabilities and bilingual candidates are\r\nencouraged to apply.\r\nAs an equal opportunity employer, Maryland is committed to\r\nrecruitment, retaining and promoting employees who are reflective of the\r\nState's diversity.\r\n

Employment Type: Full-Time