... risk management in an OT / SCADA environment in two or more areas such as: * Cyber security * Secure Supply Chain * Security Analytics * Security Operations Centers * Vulnerability and Threat ...
... risk management in an OT / SCADA environment in two or more areas such as: * Cyber security * Secure Supply Chain * Security Analytics * Security Operations Centers * Vulnerability and Threat ...
... cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever ... Develop and execute strategies for integrated risk management (IRM), governance, risk, and ...
... cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever ... Develop and execute strategies for integrated risk management (IRM), governance, risk, and ...
Risk Management * Agile Program Management * Digital Engineering * DevSecOps * Cloud Technologies * Cybersecurity and RMF * Foreign Military Sales (FMS) Knowledge, Skills & Abilities * Defense ...
Risk Management * Agile Program Management * Digital Engineering * DevSecOps * Cloud Technologies * Cybersecurity and RMF * Foreign Military Sales (FMS) Knowledge, Skills & Abilities * Defense ...
... in cybersecurity. Join our team to deliver powerful solutions that help clients navigate an ... manage cyber, risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you ...
... in cybersecurity. Join our team to deliver powerful solutions that help clients navigate an ... manage cyber, risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you ...
... risk management in an OT / SCADA environment in two or more areas such as: * Cyber security * Secure Supply Chain * Security Analytics * Security Operations Centers * Vulnerability and Threat ...
... risk management in an OT / SCADA environment in two or more areas such as: * Cyber security * Secure Supply Chain * Security Analytics * Security Operations Centers * Vulnerability and Threat ...
Cyber Sales Executive Associate Director
Cincinnati, OH · On-site
$200 - $385/hr
Serve as a thought partner to clients on cybersecurity strategy, risk management, transformation, and operational resilience. * Understand industry-specific cyber risks, trends, regulatory ...
Posted today
Cyber Sales Executive Associate Director
Cincinnati, OH · On-site
$200 - $385/hr
Serve as a thought partner to clients on cybersecurity strategy, risk management, transformation, and operational resilience. * Understand industry-specific cyber risks, trends, regulatory ...
Posted today
Risk Management & Compliance * Implement and maintain Risk Management Framework (RMF) processes ... VPC design, firewalls, intrusion detection What you'll need: * 5 years cybersecurity experience ...
Risk Management & Compliance * Implement and maintain Risk Management Framework (RMF) processes ... VPC design, firewalls, intrusion detection What you'll need: * 5 years cybersecurity experience ...
... cybersecurity/RMF policies * Maintain awareness and knowledge of evolving security and risk management standards and communicate and apply relevant changes to existing processes * Lead and/or attend ...
... cybersecurity/RMF policies * Maintain awareness and knowledge of evolving security and risk management standards and communicate and apply relevant changes to existing processes * Lead and/or attend ...
Principal Information Systems Security Engineer (ISSE) with Security Clearance
Beavercreek, OH · On-site
... cybersecurity/RMF policies * Maintain awareness and knowledge of evolving security and risk management standards and communicate and apply relevant changes to existing processes * Lead and/or attend ...
Principal Information Systems Security Engineer (ISSE) with Security Clearance
Beavercreek, OH · On-site
... cybersecurity/RMF policies * Maintain awareness and knowledge of evolving security and risk management standards and communicate and apply relevant changes to existing processes * Lead and/or attend ...
... cybersecurity/RMF policies * Maintain awareness and knowledge of evolving security and risk management standards and communicate and apply relevant changes to existing processes * Lead and/or attend ...
... cybersecurity/RMF policies * Maintain awareness and knowledge of evolving security and risk management standards and communicate and apply relevant changes to existing processes * Lead and/or attend ...
IS Senior Manager, Technology Procurement & Sourcing HQ
Cincinnati, OH · On-site +1
$92K - $125K/yr
Coordinate supplier due diligence and ongoing third-party risk management covering cybersecurity, privacy, financial viability, regulatory compliance, business continuity, concentration risk, and ...
New
IS Senior Manager, Technology Procurement & Sourcing HQ
Cincinnati, OH · On-site +1
$92K - $125K/yr
Coordinate supplier due diligence and ongoing third-party risk management covering cybersecurity, privacy, financial viability, regulatory compliance, business continuity, concentration risk, and ...
New
Cyber Security Engineer [Must 10+ yrs Network Security, threat Dete]- Franklin or Madison County, OH
Franklin, OH · On-site
Requirement Description: • Planning, implementing, managing, monitoring, and upgrading security ... based on risk and exploitability • Partner with IT team and application teams tocoordinate ...
Cyber Security Engineer [Must 10+ yrs Network Security, threat Dete]- Franklin or Madison County, OH
Franklin, OH · On-site
Requirement Description: • Planning, implementing, managing, monitoring, and upgrading security ... based on risk and exploitability • Partner with IT team and application teams tocoordinate ...
Cybersecurity Client Relationship & Sales Support Specialist
Cincinnati, OH · On-site
$70K - $154K/yr
Build trusted client relationships that transform how clients experience cybersecurity response partnership and long-term risk management * Design, set up, and refine the sales cycle process and post ...
Cybersecurity Client Relationship & Sales Support Specialist
Cincinnati, OH · On-site
$70K - $154K/yr
Build trusted client relationships that transform how clients experience cybersecurity response partnership and long-term risk management * Design, set up, and refine the sales cycle process and post ...
Cyber - AWS Cloud Security - Senior Manager
$106K - $143K/yr
Experience advising clients on AI/ML security risk management, model and data protection, and ... Bachelor's degree * 8+ years of experience in cybersecurity, information security, or cloud ...
Cyber - AWS Cloud Security - Senior Manager
$106K - $143K/yr
Experience advising clients on AI/ML security risk management, model and data protection, and ... Bachelor's degree * 8+ years of experience in cybersecurity, information security, or cloud ...
Cybersecurity Client Relationship & Sales Support Specialist
Saint Bernard, OH · On-site
$70K - $154K/yr
Build trusted client relationships that transform how clients experience cybersecurity response partnership and long-term risk management * Design, set up, and refine the sales cycle process and post ...
New
Cybersecurity Client Relationship & Sales Support Specialist
Saint Bernard, OH · On-site
$70K - $154K/yr
Build trusted client relationships that transform how clients experience cybersecurity response partnership and long-term risk management * Design, set up, and refine the sales cycle process and post ...
New
Cyber - AWS Cloud Security - Manager
Cincinnati, OH · On-site
$106K - $143K/yr
... cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever ... Advising clients on AWS identity and access management, network security, logging and monitoring ...
Cyber - AWS Cloud Security - Manager
Cincinnati, OH · On-site
$106K - $143K/yr
... cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever ... Advising clients on AWS identity and access management, network security, logging and monitoring ...
Leads the Information Security Risk Management and Identity & Access Management (IAM) teams ... Cybersecurity regulation, NAIC Data Security Model Law, and Health Insurance Portability and ...
Leads the Information Security Risk Management and Identity & Access Management (IAM) teams ... Cybersecurity regulation, NAIC Data Security Model Law, and Health Insurance Portability and ...
Leads the Information Security Risk Management and Identity & Access Management (IAM) teams ... Cybersecurity regulation, NAIC Data Security Model Law, and Health Insurance Portability and ...
Leads the Information Security Risk Management and Identity & Access Management (IAM) teams ... Cybersecurity regulation, NAIC Data Security Model Law, and Health Insurance Portability and ...
Leads the Information Security Risk Management and Identity & Access Management (IAM) teams ... Cybersecurity regulation, NAIC Data Security Model Law, and Health Insurance Portability and ...
Leads the Information Security Risk Management and Identity & Access Management (IAM) teams ... Cybersecurity regulation, NAIC Data Security Model Law, and Health Insurance Portability and ...
Vigilant is on a mission to protect and defend our customers, enable better risk-informed business ... Skilled with data collection, log analysis tools, pattern recognition, and managing ...
Quick apply
Vigilant is on a mission to protect and defend our customers, enable better risk-informed business ... Skilled with data collection, log analysis tools, pattern recognition, and managing ...
Cybersecurity Risk Management information
See Mason, OH salary details
$53.6K - $64.6K
1% of jobs
$64.6K - $75.7K
4% of jobs
$75.7K - $86.7K
5% of jobs
$86.7K - $97.7K
9% of jobs
$103.8K is the 25th percentile. Wages below this are outliers.
$97.7K - $108.7K
11% of jobs
$108.7K - $119.8K
10% of jobs
The median wage is $124K / yr.
$119.8K - $130.8K
28% of jobs
$137.2K is the 75th percentile. Wages above this are outliers.
$130.8K - $141.8K
14% of jobs
$141.8K - $152.9K
11% of jobs
$152.9K - $163.9K
4% of jobs
$163.9K - $174.9K
4% of jobs
$53.6K
$125K
$174.9K
How much do cybersecurity risk management jobs pay per year?
What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?
What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?
| Aspect | Cybersecurity Risk Management | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government, large enterprises | IT departments, cybersecurity firms, corporate security teams |
Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.
What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?
What is cybersecurity risk management?

Part-time
Re-posted 13 days ago
Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
45th of 150 rated financial services
Job description
Power and Utilities OT (Operational Technology) - Manager
Position Summary
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cyber team and become a member of the largest group of cybersecurity professionals worldwide.
Recruiting for this role ends on 12/21/2026
Work you'll do
Responsibilities:
- Identify and evaluate complex business and technology risks
- Develop remediation methods to mitigate risks
- Demonstrate problem solving, critical thinking and logical structuring skills
- Assist in the selection and tailoring of approaches, methods and tools to support service offering or industry projects
- Actively participate in decision making with engagement management and seek to understand the broader impact of current decisions
- Facilitate use of technology-based tools or methodologies to review, design and/or implement products and services
- Identify opportunities to improve engagement profitability and manage engagement economics
- Demonstrate ability to with identify and address client needs: building solid relationships with clients; developing an awareness of Firm services; communicating with the client in an organized and knowledgeable manner; delivering clear requests for information; demonstrating flexibility in prioritizing and completing tasks; and communicating potential conflicts to the manager
- Demonstrate a general knowledge of market trends, competitor activities, Deloitte Advisory products and service lines
Required Skills:
- 7+ years of demonstrate advanced understanding and experience governing and implementing power and utility regulations and standards including:
- North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP)
- NERC Operations and Planning (O&P)
- Federal Energy Regulatory Commission
- Transportation Security Administration (TSA) Cybersecurity
- IEC 62443 standard - Securing Industrial Automation and Control Systems (IACS)
- Nuclear Energy Institute (NEI) - NEI 08-09, 10 CFR 73.54
- 7+ years of demonstrate advanced understanding and cyber risk management in at least two of the following areas:
- SCADA with experience in securing ICS (Industrial Control Systems) security
- Internet of Things (IOT) architecture and security
- OT (Operational Technology) security
- NERC CIP-015 - Internal Network Security Monitoring (INMS)
- Embedded systems security
- OT network segmentation (zones/conduits), jump hosts, secure remote access
- Passive OT discovery/asset inventory, OT IDS, SIEM integration/use cases
- Incident response in OT (containment with availability/safety constraints)
- Vendor/OEM risk management, SBOM/patch constraints, compensating controls
- Security experience in the field environment within the Power, Utilities & Renewables, Oil & Gas, or Industrial Products & Construction industry sectors
- 7+ years of demonstrate advanced understanding of business processes and cyber risk management in an OT / SCADA environment in two or more areas such as:
- Cyber security
- Secure Supply Chain
- Security Analytics
- Security Operations Centers
- Vulnerability and Threat Management
- Data Security
- Secure Dev Ops
- Business continuity management
- Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF)
- Limited sponsorship opportunities may be available
Additional Requirements:
- Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve
- Locations include: Houston, Dallas, Cleveland, Detroit, St. Louis, Pittsburgh, Boston, Charlotte, Atlanta, Miami, Memphis, Denver, Phoenix, Salt Lake City, Los Angeles, San Diego, San Franciso, Seattle. Must be within a reasonable commute and willing to work part-time in the Deloitte and/or client offices.
Preferred:
- Minimum of 4 years working in an OT environment (e.g. OT security, ICS security, IOT security, SCADA, etc.)
- Minimum 4 years designing security for infrastructure, network and application architectures
- Experience in the Power Utilities & Renewables, Oil & Gas, or Industrial Products & Construction sector
- Demonstrated experience working with cloud platforms (AWS, Azure)
- 5+ years implementing security solutions
- BA/BS in cyber security, information security, engineering, computer science, information technology, information management, information sciences, business administration, or related field preferred
- CISSP, CISM, or CISA certification a plus
- Excellent verbal and written communication
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberES26
Power and Utilities OT (Operational Technology) - Manager
Position Summary
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Cyber team and become a member of the largest group of cybersecurity professionals worldwide.
Recruiting for this role ends on 12/21/2026
Work you'll do
Responsibilities:
- Identify and evaluate complex business and technology risks
- Develop remediation methods to mitigate risks
- Demonstrate problem solving, critical thinking and logical structuring skills
- Assist in the selection and tailoring of approaches, methods and tools to support service offering or industry projects
- Actively participate in decision making with engagement management and seek to understand the broader impact of current decisions
- Facilitate use of technology-based tools or methodologies to review, design and/or implement products and services
- Identify opportunities to improve engagement profitability and manage engagement economics
- Demonstrate ability to with identify and address client needs: building solid relationships with clients; developing an awareness of Firm services; communicating with the client in an organized and knowledgeable manner; delivering clear requests for information; demonstrating flexibility in prioritizing and completing tasks; and communicating potential conflicts to the manager
- Demonstrate a general knowledge of market trends, competitor activities, Deloitte Advisory products and service lines
Required Skills:
- 7+ years of demonstrate advanced understanding and experience governing and implementing power and utility regulations and standards including:
- North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP)
- NERC Operations and Planning (O&P)
- Federal Energy Regulatory Commission
- Transportation Security Administration (TSA) Cybersecurity
- IEC 62443 standard - Securing Industrial Automation and Control Systems (IACS)
- Nuclear Energy Institute (NEI) - NEI 08-09, 10 CFR 73.54
- 7+ years of demonstrate advanced understanding and cyber risk management in at least two of the following areas:
- SCADA with experience in securing ICS (Industrial Control Systems) security
- Internet of Things (IOT) architecture and security
- OT (Operational Technology) security
- NERC CIP-015 - Internal Network Security Monitoring (INMS)
- Embedded systems security
- OT network segmentation (zones/conduits), jump hosts, secure remote access
- Passive OT discovery/asset inventory, OT IDS, SIEM integration/use cases
- Incident response in OT (containment with availability/safety constraints)
- Vendor/OEM risk management, SBOM/patch constraints, compensating controls
- Security experience in the field environment within the Power, Utilities & Renewables, Oil & Gas, or Industrial Products & Construction industry sectors
- 7+ years of demonstrate advanced understanding of business processes and cyber risk management in an OT / SCADA environment in two or more areas such as:
- Cyber security
- Secure Supply Chain
- Security Analytics
- Security Operations Centers
- Vulnerability and Threat Management
- Data Security
- Secure Dev Ops
- Business continuity management
- Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF)
- Limited sponsorship opportunities may be available
Additional Requirements:
- Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve
- Locations include: Houston, Dallas, Cleveland, Detroit, St. Louis, Pittsburgh, Boston, Charlotte, Atlanta, Miami, Memphis, Denver, Phoenix, Salt Lake City, Los Angeles, San Diego, San Franciso, Seattle. Must be within a reasonable commute and willing to work part-time in the Deloitte and/or client offices.
Preferred:
- Minimum of 4 years working in an OT environment (e.g. OT security, ICS security, IOT security, SCADA, etc.)
- Minimum 4 years designing security for infrastructure, network and application architectures
- Experience in the Power Utilities & Renewables, Oil & Gas, or Industrial Products & Construction sector
- Demonstrated experience working with cloud platforms (AWS, Azure)
- 5+ years implementing security solutions
- BA/BS in cyber security, information security, engineering, computer science, information technology, information management, information sciences, business administration, or related field preferred
- CISSP, CISM, or CISA certification a plus
- Excellent verbal and written communication
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberES26