1

Cybersecurity Risk Management Jobs in Draper, UT

Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or a related field * 3+ years of experience in cybersecurity, risk, compliance, or audit-related roles * Experience ...

Cyber Security Tutor

Provo, UT · Remote

$18 - $40/hr

Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk management, compliance requirements, and ethical computing practices. * Curriculum Awareness ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Draper, UT salary details

$53.3K

$124.3K

$173.9K

How much do cybersecurity risk management jobs pay per year?

As of Jul 29, 2026, the average yearly pay for cybersecurity risk management in Draper, UT is $124,299.00, according to ZipRecruiter salary data. Most workers in this role earn between $103,800.00 and $140,200.00 per year, depending on experience, location, and employer.

Can I make $200,000 a year in cyber security?

Cybersecurity risk management professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and roles in senior management or specialized fields. Salary levels vary based on industry, location, and the complexity of the organization's security needs.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

How much does a cybersecurity risk analyst make?

A cybersecurity risk analyst typically earns between $70,000 and $120,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in high-demand industries.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What does a cyber risk manager do?

A cyber risk manager assesses and prioritizes cybersecurity threats to an organization, develops strategies to mitigate risks, and implements security policies. They often use tools like risk assessment frameworks and require certifications such as CISSP or CISM to effectively manage security risks and ensure compliance.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

Can you make $500,000 a year in cyber security?

Cybersecurity risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working for large organizations with complex security needs.
What job categories do people searching Cybersecurity Risk Management jobs in Draper, UT look for? The top searched job categories for Cybersecurity Risk Management jobs in Draper, UT are:
What cities near Draper, UT are hiring for Cybersecurity Risk Management jobs? Cities near Draper, UT with the most Cybersecurity Risk Management job openings:
Infographic showing various Cybersecurity Risk Management job openings in Draper, UT as of July 2026, with employment types broken down into 3% Locum Tenens, 86% Full Time, 8% Part Time, and 3% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution, with an average salary of $124,299 per year, or $59.8 per hour.

Cybersecurity Engineer

KēSTA I.T.

Draper, UT

$90K - $114K/yr

Full-time

Re-posted 13 days ago


Job description

Come build, innovate, disrupt, and thrive!


KēSTA I.T. is actively seeking a Cybersecurity Engineer for an immediate full-time opportunity with our industry leading client.


Are you on the lookout for a unique career opportunity that offers the chance to make a significant impact? If you're eager to contribute to a thriving and stable organization while maintaining your confidentiality, continue reading...


A Cybersecurity / GRC Engineer supports the execution and continuous improvement of an organization’s governance, risk, and compliance (GRC) program. This role operates under the direction of GRC leadership and is responsible for day-to-day risk, compliance, and audit activities to ensure cybersecurity practices align with regulatory, contractual, and business requirements.


This position plays a key role in operationalizing cybersecurity governance by conducting risk assessments, supporting audits, maintaining control frameworks, and partnering across IT and business teams to track and remediate findings. The ideal candidate is detail-oriented and analytical, with the ability to translate technical risks and controls into clear documentation and actionable insights.


Responsibilities

  • Conduct cybersecurity risk assessments for systems, applications, and business processes
  • Support third-party and vendor risk assessments, including due diligence reviews
  • Identify control gaps, document risks, and assist in developing remediation plans
  • Maintain and update the enterprise risk register, including risk scoring and tracking
  • Partner with control owners to validate mitigation efforts and assess risk status
  • Support internal and external audits by coordinating evidence collection and responses
  • Track audit findings and remediation activities, ensuring proper validation and closure
  • Assist with security questionnaires, RFP responses, and due diligence requests
  • Support compliance with regulatory and contractual requirements
  • Maintain and update cybersecurity policies, standards, and procedures
  • Map controls to industry frameworks such as NIST CSF, ISO 27001, and CIS
  • Support the development and maintenance of a unified control framework
  • Assist with control testing activities and documentation of effectiveness
  • Develop and maintain GRC metrics, dashboards, and reporting artifacts
  • Track key risk indicators (KRIs), audit trends, and remediation progress
  • Prepare reports and summaries for leadership and stakeholders
  • Maintain organized documentation and evidence repositories
  • Collaborate with cross-functional teams to drive risk awareness and remediation efforts
  • Support process improvements to enhance GRC efficiency and scalability
  • Assist in the implementation and optimization of GRC tools and automation
  • Stay current on evolving cybersecurity risks and compliance requirements
  • Perform additional related duties as needed


Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field
  • 3+ years of experience in cybersecurity, risk, compliance, or audit-related roles
  • Experience supporting audits, risk assessments, and compliance initiatives
  • Experience collaborating across IT and business teams
  • Working knowledge of cybersecurity frameworks such as NIST CSF, ISO 27001, and CIS


Preferred Qualifications:

  • Relevant certifications such as Security+, CISA, CRISC, or similar
  • Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, Drata, Vanta or similar tools)


Core Skills:

  • Strong analytical, documentation, and organizational capabilities
  • Ability to communicate technical concepts clearly to non-technical stakeholders
  • Attention to detail and ability to manage multiple priorities effectively



About KēSTA I.T.:


Our name says it all; KēSTA I.T. (Keys-to-I.T.) AND our people are our keys to our success!


KēSTA I.T. is a premier Utah-based technical staffing and consulting services firm. We specialize in temporary and permanent placement of Software, Hardware, Network, Cloud, CRM/ERP, Data, End-User support, Web and Executive / leadership-based positions on a full time and consulting basis. If you're interested in a role where top performance is rewarded, personal time is valued, and excellence is demanded at every level we want to talk to you today!


Where do you want to go? We've got the keys! ~ KēSTA I.T.


WWW.KeSTAIT.COM