This role offers significant exposure to cybersecurity governance, risk management, cloud security, third-party risk, customer assurance activities, executive reporting, and industry-standard ...
This role offers significant exposure to cybersecurity governance, risk management, cloud security, third-party risk, customer assurance activities, executive reporting, and industry-standard ...
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Cyber Security Risk Analyst
Belleville, IL ยท On-site
$115K - $125K/yr
... Cyber Security Risk Analyst Work Location: Required onsite work at the client location at Scott ... Management Framework (RMF) and Vulnerability Management to on-premises and Cloud networks.
Cyber Security Risk Analyst
Belleville, IL ยท On-site
$115K - $125K/yr
... Cyber Security Risk Analyst Work Location: Required onsite work at the client location at Scott ... Management Framework (RMF) and Vulnerability Management to on-premises and Cloud networks.
Manager, Cybersecurity Governance, Risk & Compliance (GRC)
Omaha, NE ยท On-site
$106K - $143K/yr
Key Responsibilities Leadership & People Management * Lead and develop a team responsible for Cybersecurity GRC, IT Compliance, Third-Party Risk Management, ERP Security, and Security Awareness.
Manager, Cybersecurity Governance, Risk & Compliance (GRC)
Omaha, NE ยท On-site
$106K - $143K/yr
Key Responsibilities Leadership & People Management * Lead and develop a team responsible for Cybersecurity GRC, IT Compliance, Third-Party Risk Management, ERP Security, and Security Awareness.
Manager, Cybersecurity Governance, Risk & Compliance (GRC)
Omaha, NE ยท On-site
$106K - $143K/yr
Key Responsibilities Leadership & People Management * Lead and develop a team responsible for Cybersecurity GRC, IT Compliance, Third-Party Risk Management, ERP Security, and Security Awareness.
Manager, Cybersecurity Governance, Risk & Compliance (GRC)
Omaha, NE ยท On-site
$106K - $143K/yr
Key Responsibilities Leadership & People Management * Lead and develop a team responsible for Cybersecurity GRC, IT Compliance, Third-Party Risk Management, ERP Security, and Security Awareness.
Senior Third-Party Cyber Security Risk Analyst
$95K - $123K/yr
... cybersecurity controls ... The role also consolidates and communicates risk findings and metrics to operational management and ...
Senior Third-Party Cyber Security Risk Analyst
$95K - $123K/yr
... cybersecurity controls ... The role also consolidates and communicates risk findings and metrics to operational management and ...
Chief Cybersecurity Risk Officer
Atlanta, GA ยท On-site
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Chief Cybersecurity Risk Officer
Atlanta, GA ยท On-site
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Senior Third-Party Cyber Security Risk Analyst
Plano, TX ยท On-site
$95K - $123K/yr
... cybersecurity controls ... The role also consolidates and communicates risk findings and metrics to operational management and ...
Senior Third-Party Cyber Security Risk Analyst
Plano, TX ยท On-site
$95K - $123K/yr
... cybersecurity controls ... The role also consolidates and communicates risk findings and metrics to operational management and ...
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Chief Cybersecurity Risk Officer
Atlanta, GA ยท On-site
$300 - $400/hr
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Chief Cybersecurity Risk Officer
Atlanta, GA ยท On-site
$300 - $400/hr
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Cybersecurity Risk and Compliance Manager
Saint Charles, MO ยท On-site
$110 - $150/hr
Lead the organization's cybersecurity strategy, governance, and risk management program * Manage all CMMC readiness, implementation, certification, and continuous compliance activities * Develop and ...
Cybersecurity Risk and Compliance Manager
Saint Charles, MO ยท On-site
$110 - $150/hr
Lead the organization's cybersecurity strategy, governance, and risk management program * Manage all CMMC readiness, implementation, certification, and continuous compliance activities * Develop and ...
Cybersecurity Risk Assessor
Tallahassee, FL ยท On-site
JOB TITLE : Cybersecurity Risk Assessor LOCATION : Florida (Central/South Florida preferred ... Support development of Plans of Action and Milestones (POA&M) and vulnerability management ...
Quick apply
Cybersecurity Risk Assessor
Tallahassee, FL ยท On-site
JOB TITLE : Cybersecurity Risk Assessor LOCATION : Florida (Central/South Florida preferred ... Support development of Plans of Action and Milestones (POA&M) and vulnerability management ...
Leads cybersecurity risk identification utilizing identified Cummins risk management frameworks while providing guidance to the team to evaluate severity and mitigation plans. Coaches and develops ...
Leads cybersecurity risk identification utilizing identified Cummins risk management frameworks while providing guidance to the team to evaluate severity and mitigation plans. Coaches and develops ...
Leads cybersecurity risk identification utilizing identified Cummins risk management frameworks while providing guidance to the team to evaluate severity and mitigation plans. Coaches and develops ...
Leads cybersecurity risk identification utilizing identified Cummins risk management frameworks while providing guidance to the team to evaluate severity and mitigation plans. Coaches and develops ...
Chief Cybersecurity Risk Officer
Raleigh, NC ยท On-site
$300 - $400/hr
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Chief Cybersecurity Risk Officer
Raleigh, NC ยท On-site
$300 - $400/hr
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Chief Cybersecurity Risk Officer
Richmond, VA ยท On-site
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Chief Cybersecurity Risk Officer
Richmond, VA ยท On-site
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Chief Cybersecurity Risk Officer
Raleigh, NC ยท On-site
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Chief Cybersecurity Risk Officer
Raleigh, NC ยท On-site
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Reporting to the Chief Risk Information Officer (CIRO), this role serves as a critical second line of defense function, ensuring effective risk management across cybersecurity, while supporting the ...
Senior Manager - Security Risk, Tech and Cyber Risk, Compliance
Washington, DC ยท On-site
$120 - $160/hr
Advanced cybersecurity risk management skills * Experience utilizing ISO/IEC 27001 and NIST Cybersecurity Framework (CSF) * Analytical thinking for complex regulatory challenges * Experience leading ...
Senior Manager - Security Risk, Tech and Cyber Risk, Compliance
Washington, DC ยท On-site
$120 - $160/hr
Advanced cybersecurity risk management skills * Experience utilizing ISO/IEC 27001 and NIST Cybersecurity Framework (CSF) * Analytical thinking for complex regulatory challenges * Experience leading ...
Leads cybersecurity risk identification utilizing identified Cummins risk management frameworks while providing guidance to the team to evaluate severity and mitigation plans. Coaches and develops ...
Leads cybersecurity risk identification utilizing identified Cummins risk management frameworks while providing guidance to the team to evaluate severity and mitigation plans. Coaches and develops ...
Cybersecurity Risk Management information
See salary details
$57K - $68.7K
1% of jobs
$68.7K - $80.5K
4% of jobs
$80.5K - $92.2K
5% of jobs
$92.2K - $103.9K
9% of jobs
$110.4K is the 25th percentile. Wages below this are outliers.
$103.9K - $115.6K
11% of jobs
$115.6K - $127.4K
10% of jobs
The median wage is $131.9K / yr.
$127.4K - $139.1K
28% of jobs
$145.9K is the 75th percentile. Wages above this are outliers.
$139.1K - $150.8K
14% of jobs
$150.8K - $162.5K
11% of jobs
$162.5K - $174.3K
4% of jobs
$174.3K - $186K
4% of jobs
$57K
$133K
$186K
How much do cybersecurity risk management jobs pay per year?
What is cybersecurity risk management?
What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?
What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?
What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?
| Aspect | Cybersecurity Risk Management | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government, large enterprises | IT departments, cybersecurity firms, corporate security teams |
Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.
What cities are hiring for Cybersecurity Risk Management jobs?
Cities with the most Cybersecurity Risk Management job openings:
What states have the most Cybersecurity Risk Management jobs?
States with the most job openings for Cybersecurity Risk Management jobs include:
What job categories do people searching Cybersecurity Risk Management jobs look for?
The top searched job categories for Cybersecurity Risk Management jobs are:

Full-time
Posted 20 days ago
Job description
This position reports into the Information Security organization and works closely with the Chief Information Security Officer (CISO), Technology, Compliance, Legal, Internal Audit, and business stakeholders. The successful candidate will contribute to strengthening the organization's cybersecurity posture, operational resilience, regulatory compliance, and customer trust programs.
This role offers significant exposure to cybersecurity governance, risk management, cloud security, third-party risk, customer assurance activities, executive reporting, and industry-standard security frameworks. It provides a growth path into senior cybersecurity governance, risk, compliance, and security leadership roles.
Key Responsibilities
Cybersecurity Governance & Risk Management:
- Maintain and enhance the organization's cybersecurity governance, risk, and compliance program.
- Conduct cyber and technology risk assessments for systems, business processes, cloud services, and strategic initiatives.
- Maintain the enterprise risk register, ensuring risks, owners, mitigation plans, and status updates remain current.
- Track key risk indicators (KRIs), emerging cyber threats, and remediation activities.
- Assist technology and business teams with risk identification, treatment planning, and control implementation.
- Support development and maintenance of information security policies, standards, procedures, and governance documentation.
- Assist with cybersecurity risk reporting for executive leadership and governance committees.
Third-Party Risk Management:
- Conduct vendor cybersecurity assessments and due diligence reviews for new and existing third-party relationships.
- Evaluate vendor security documentation, including SOC reports, penetration test summaries, security assessments, audit reports, and compliance certifications.
- Assess risks associated with cloud-hosted services, SaaS platforms, and strategic technology providers.
- Track remediation activities resulting from third-party assessments and risk reviews.
- Partner with Procurement, Legal, Compliance, Technology, and business stakeholders throughout the vendor lifecycle.
- Maintain accurate third-party risk records and reporting within the organization's GRC platform.
Customer Security Assurance & Due Diligence:
- Coordinate responses to customer security questionnaires, risk assessments, and due diligence requests.
- Support customer audits and security review meetings.
- Collaborate with Information Security, Technology, Privacy, Legal, Compliance, and business teams to gather accurate responses.
- Maintain a centralized repository of approved security, compliance, risk, and privacy responses.
- Support development and maintenance of customer assurance materials, including SOC reports, policy summaries, security overviews, and compliance documentation.
- Identify opportunities to improve response quality, consistency, and efficiency through automation and AI-enabled tools.
Audit, Compliance & Control Assurance:
- Support internal and external audits, including SOC examinations and customer audits.
- Coordinate evidence collection, documentation, and stakeholder responses.
- Assist with remediation tracking and validation of audit findings.
- Monitor compliance with internal policies, regulatory requirements, and security frameworks.
- Support control testing, assessment activities, and continuous improvement initiatives.
Metrics, Reporting & Governance:
- Develop cybersecurity metrics, dashboards, and executive reporting materials.
- Prepare risk summaries and presentations for management and governance committees.
- Analyze risk trends and provide actionable recommendations to leadership.
- Identify opportunities to enhance governance processes through data analytics, workflow automation, and AI-enabled technologies.
- Support ongoing maturation of the cybersecurity program.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Systems, Information Security, Risk Management, Business, Finance, Accounting, or a related field.
- 5+ years of experience in cybersecurity risk management, IT risk, governance, compliance, internal audit, third-party risk management, operational risk, or related disciplines.
- Experience working within financial services, fintech, banking, regulated technology, healthcare, insurance, or another regulated industry.
- Experience conducting risk assessments and maintaining risk registers.
- Experience responding to customer security questionnaires, due diligence requests, and audit inquiries.
- Experience reviewing SOC 1 and SOC 2 reports, security assessments, and vendor due diligence materials.
- Experience supporting SOC examinations, regulatory assessments, customer audits, or customer security reviews.
- Demonstrated experience applying at least one recognized cybersecurity, risk, or control framework, such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, SOC 2, FFIEC, or PCI DSS.
- Working familiarity with Microsoft Azure, Microsoft 365, cloud governance, and cloud security concepts.
- Strong understanding of cybersecurity risk management concepts, governance practices, and internal controls.
- Excellent written and verbal communication skills, including the ability to communicate effectively with senior leadership, auditors, regulators, customers, and technical teams.
- Strong analytical, organizational, and problem-solving skills.
- Ability to manage multiple priorities and work independently in a fast-paced environment.
Preferred Qualifications
- Experience with GRC platforms such as ServiceNow GRC, Archer, LogicGate, AuditBoard, ProcessUnity, or similar solutions.
- Experience leveraging AI-enabled technologies, workflow automation, Microsoft Copilot, Microsoft Power Platform, Microsoft Purview, or analytics platforms to improve security and risk processes.
- One or more relevant professional certifications, such as CRISC, CISA, CISM, CISSP, CIA, or CRCM.
- Experience supporting process improvement, risk reporting automation, or executive-level cybersecurity metrics and dashboards.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
About mTrade
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
51 - 200 Employees
Headquarters location
Oxford, MS, US
Year founded
2016