1

Cybersecurity Risk Management Jobs in Baltimore, MD

Sr Cybersecurity ISSE with Security Clearance

Hanover, MD ยท On-site

$104K - $142K/yr

Senior Cybersecurity Information Systems Security Engineer (ISSE) Razor is looking for a Senior ... Lead or support security planning, assessments, risk analysis, risk management, and authorization ...

Showing results 21-40

Cybersecurity Risk Management information

See Baltimore, MD salary details

$56.6K

$132.1K

$184.8K

How much do cybersecurity risk management jobs pay per year?

As of Aug 21, 2026, the average yearly pay for cybersecurity risk management in Baltimore, MD is $132,116.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,300.00 and $149,000.00 per year, depending on experience, location, and employer.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are popular job titles related to Cybersecurity Risk Management jobs in Baltimore, MD?

For Cybersecurity Risk Management jobs in Baltimore, MD, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Risk Management jobs in Baltimore, MD look for?

The top searched job categories for Cybersecurity Risk Management jobs in Baltimore, MD are:

What cities near Baltimore, MD are hiring for Cybersecurity Risk Management jobs?

Cities near Baltimore, MD with the most Cybersecurity Risk Management job openings:

Infographic showing various Cybersecurity Risk Management job openings in Baltimore, MD as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, and 3% Contract. Highlights an 86% Physical, 3% Hybrid, and 11% Remote job distribution, with an average salary of $132,116 per year, or $63.5 per hour.

Cybersecurity Risk & Authorization Engineer - DAOR 3 with Security Clearance

NineFX, Inc.

Fort George G Meade, MD โ€ข On-site

Contractor

This job post hasย expired today.ย Applications are no longer accepted.


Job description

The DAOR supports enterprise Cybersecurity and risk management activities by identifying security requirements, evaluating and validating security controls, and ensuring systems meet federal information assurance standards. This role works closely with technical teams, stakeholders, and senior leaders to guide secure system development, integrate legacy capabilities, and support authorization activities across complex IT environments. Responsibilities:
โ€ข Identify Cybersecurity requirements and ensure appropriate security controls are implemented to protect organizational data.
โ€ข Conduct and analyze security risk assessments, risk analyses, and risk management activities for systems and network operations.
โ€ข Support security control assessments, configuration management processes, and Cybersecurity awareness activities.
โ€ข Ensure Cybersecurity considerations are incorporated throughout development, deployment, and risk management lifecycles, with emphasis on infrastructure protection and defensive IT strategies.
โ€ข Collaborate with customers, IT staff, and executive leadership to define and achieve enterprise Cybersecurity and risk management objectives.
โ€ข Contribute to the development and enhancement of security architectures.
โ€ข Support secure integration of legacy systems into modern environments.
โ€ข Assist with acquisition, RDT&E, and system deployment by embedding Cybersecurity controls into operational system designs.
โ€ข Prepare comprehensive security authorization documentation, including risk assessments, POA&Ms, authorization recommendations, and related materials in accordance with organizational and federal guidelines. Core Capabilities:
โ€ข Analyze Cybersecurity controls within systems intended for operational deployment.
โ€ข Prepare risk assessments, POA&Ms, and authorization documentation aligned with RMF and ICD 503.
โ€ข Identify and support enterprise-wide security requirements, ensuring compliance with policies, controls, and processes.
โ€ข Facilitate collaboration among stakeholders to achieve organizational security and risk management goals.
โ€ข Support secure legacy system integration within current IT environments. Qualifications:
โ€ข Active TS/SCI with Full Scope Polygraph (must already be held)
โ€ข Eight (8) years of experience as an IT Risk Assessor, System Security Engineer, Information Systems Security Manager, or Delegated Authorizing Official (DAO) for programs of similar scope and complexity.
โ€ข Bachelorโ€™s degree in Computer Science, IT Engineering, or a related field; may substitute four (4) additional years of experience for a total of twelve (12) years.
โ€ข IAM Level III CISM, CISSP (or Associate), GSLC, CCISO. Required Knowledge:
โ€ข System security design principles
โ€ข Defense-in-depth and defense-in-breadth strategies
โ€ข Engineering lifecycle processes
โ€ข Information domains and cross-domain solutions
โ€ข Controlled interfaces
โ€ข Identification, authentication, authorization
โ€ข Systems integration
โ€ข ICD 503 and RMF
โ€ข Intrusion detection, incident handling, and contingency planning
โ€ข Configuration management and change control
โ€ข Auditing processes
โ€ข Security authorization workflows
โ€ข Core Cybersecurity principles: confidentiality, integrity, availability, non-repudiation, and access control
โ€ข Security testing methodologies