1

Cybersecurity Risk Management Jobs in Madison, WI

Support leadership with all aspects of the cybersecurity enterprise-wide risk management program, with minimal supervision. Responsibilities include facilitating the identification of risks ...

Cyber Security Tutor

Madison, WI · Remote

$18 - $40/hr

Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk management, compliance requirements, and ethical computing practices. * Curriculum Awareness ...

Associate's or Bachelor's degree in enterprise risk management, information technology, cybersecurity, business administration, finance, accounting, or related field. * 0-3 years of relevant ...

Associate's or Bachelor's degree in enterprise risk management, information technology, cybersecurity, business administration, finance, accounting, or related field. * 0-3 years of relevant ...

Support access management, change management, and asset-completeness evidence in preparation for ... Our FusionDirect development program pursues the lowest-risk, shortest-schedule path to a fusion ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Madison, WI salary details

$57.4K

$134K

$187.4K

How much do cybersecurity risk management jobs pay per year?

As of Aug 27, 2026, the average yearly pay for cybersecurity risk management in Madison, WI is $133,996.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,900.00 and $151,200.00 per year, depending on experience, location, and employer.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are popular job titles related to Cybersecurity Risk Management jobs in Madison, WI?

For Cybersecurity Risk Management jobs in Madison, WI, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Risk Management jobs in Madison, WI look for?

The top searched job categories for Cybersecurity Risk Management jobs in Madison, WI are:

What cities near Madison, WI are hiring for Cybersecurity Risk Management jobs?

Cities near Madison, WI with the most Cybersecurity Risk Management job openings:

Infographic showing various Cybersecurity Risk Management job openings in Madison, WI as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 16% Part Time, 2% Temporary, and 2% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $133,996 per year, or $64.4 per hour.

Senior Manager, Information Security

Socket.dev

Janesville, WI • On-site

$140 - $175/hr

Other

Posted 17 days ago


Job description

Description

SHINE Technologies is seeking a Senior Manager, Information Security who will be responsible for leading SHINE’s enterprise information security program, with a balanced focus on cybersecurity governance, risk management, compliance, and oversight of operational security activities. The Senior Manager, Information Security provides strategic direction for SHINE’s security posture, ensures alignment with regulatory and contractual obligations, and manages day to day security operations performed by IT staff.

This leader owns SHINE’s security policies, the risk management framework, and the overall maturity of the information security program while partnering across IT, Engineering, Operations, Supply Chain, and other departments to embed security into organizational processes and technical decisions.

The base salary range for this position is $140,000 - $175,000 plus a comprehensive compensation package. Our salary ranges are determined by role, level, and location.

Information Security Program Leadership
  • Lead SHINE’s information security program, ensuring policies, controls, and processes are implemented and continuously improved.
  • Provide oversight and direction to Cybersecurity staff for operational tasks including monitoring, analysis, vulnerability scanning, and control implementation.
  • Maintain SHINE’s Information Security Plan and ensure alignment with NIST 800 171, CMMC, ISO 27001/27002, NRC requirements, and internal standards.
  • Ensure proper integration of security requirements into IT systems, cloud platforms, and applicable OT/ICS environments.
2. Governance, Risk, & Compliance (Primary Focus)
  • Own the governance framework for information security, including policy management, standards, procedures, and control mappings.
  • Manage SHINE’s cybersecurity risk management process, including maintaining the risk register and presenting treatment recommendations to leadership.
  • Lead compliance activities for NIST 800 171, CMMC, ISO, and other regulatory frameworks.
  • Coordinate internal and external audits, ensuring evidence is complete, accurate, and audit ready.
  • Conduct periodic assessments and internal reviews to validate ongoing compliance.
3. Strategic Planning & Program Maturity
  • Develop annual security improvement plans and budget recommendations based on business priorities and risk.
  • Identify gaps in security posture and propose operational, technical, and procedural enhancements.
  • Participate in cross functional project reviews and ensure security is integrated into new technologies, system changes, and enterprise initiatives.
4. Incident Response Leadership
  • Serve as a senior member of the Security Incident Response Team (SIRT).
  • Lead incident governance: escalation, communication, documentation, decision making, and after action reviews.
  • Direct technical incident response tasks performed by relevant IT Staff.
  • Maintain and improve incident response plans, communication models, and readiness processes.
5. OT/ICS Security Participation (Limited Scope)
  • Provide consultative security guidance for OT/ICS environments where cybersecurity risk, regulatory requirements, or system criticality justify involvement.
  • Support reviews of high risk OT changes to assess potential security impacts.
  • Partner with Engineering teams to apply appropriate security expectations to critical systems without imposing unnecessary operational burden.
6. Third Party & Customer Cybersecurity Requirements
  • Lead vendor security assessments and drive ongoing third party cybersecurity monitoring.
  • Serve as the primary responder for customer cybersecurity questionnaires, attestation requests, and contract driven security obligations.
  • Collaborate with Legal, Supply Chain, and Business Development to ensure cybersecurity terms are understood, feasible, and enforced.
7. Security Awareness & Workforce Engagement
  • Oversee the enterprise security awareness program.
  • Ensure workforce compliance with annual cybersecurity training and role specific requirements.
  • Coordinate with HR and Communications to deliver effective campaigns and reinforce a culture of security.
8. Reporting & Executive Communication
  • Produce and present information security metrics, risk summaries, and program updates for IT leadership and executive stakeholders.
  • Communicate security issues in clear, actionable terms tailored to both technical and non technical audiences.
RequirementsRequired Experience
  • 7+ years of experience in information security, cybersecurity, risk management, or GRC.
  • Experience with NIST 800 171, CMMC, ISO 27001/27002, or similar frameworks.
  • Broad technical knowledge across networks, systems, cloud environments, and identity management.
  • Demonstrated experience leading audits, assessments, or governance programs.
Preferred Experience
  • Experience in regulated industries (nuclear, defense, medical, engineering, or manufacturing).
  • Familiarity with OT/ICS cybersecurity.
  • Experience maturing security programs in small or growing organizations.
Knowledge, Skills, and Abilities
  • Solid understanding of information security governance, risk management, and compliance frameworks.
  • Strong communication skills with the ability to translate complex risks into business relevant terms.
  • Excellent organizational and documentation skills.
  • Demonstrated leadership and ability to collaborate across diverse technical and business functions.
  • Ability to make informed decisions based on risk, business needs, and technical considerations.
Education & Certifications
  • Bachelor’s degree in Information Security, Computer Science, IT, Engineering, or related field (or equivalent experience).
  • Preferred certifications: CISSP, CISM, CISA, CRISC, Security+, ISO 27001 Lead Implementer/Auditor.
Work Environment
  • Primarily office based with hybrid flexibility as appropriate.
  • Occasional work within secure or regulated environments.
  • May require after hours support during security incidents or operational needs.

Eligibility for employment is conditioned on the applicant’s ability to qualify for access to information subject to U.S. Export Controls. Additionally, applicant’s eligibility may be conditioned based upon meeting the Nuclear Regulatory Commission requirements for access to Safeguards Information, which typically requires a pre-employment drug screen, fingerprinting and criminal background check.

SHINE values diversity in all its forms as a critical component of innovation, which is fundamental to our success. Every member of the SHINE community benefits from the talents and experiences of our peers, from the mutual respect we exercise, and from the responsibility we take for our actions.

SHINE Technologies, LLC maintains affirmative action plans for individuals with disabilities and protected veterans. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Pay Transparency Policy

Employee Rights Under the NLRA

Equal Opportunity Employment

E-Verify

#J-18808-Ljbffr