1

Cybersecurity Risk Management Jobs (NOW HIRING)

These teams collaborate to identify, manage and respond to threats, all while driving innovation ... The Cybersecurity Risk Analyst is responsible for executing a portion of the GM Financial (GMF ...

These teams collaborate to identify, manage and respond to threats, all while driving innovation ... Cybersecurity Governance, Risk Management, Legal Regulations, IT or Security Audit, IT or Security ...

Cybersecurity Assessment Lead

Coronado, CA · On-site

$117K - $159K/yr

The Cybersecurity Assessment Lead serves as the senior assessor overseeing cybersecurity assessment activities supporting Risk Management Framework (RMF) authorization processes for customer networks ...

Cybersecurity Assessment Lead

Virginia Beach, VA · On-site

$98K - $133K/yr

The Cybersecurity Assessment Lead serves as the senior assessor overseeing cybersecurity assessment activities supporting Risk Management Framework (RMF) authorization processes for customer networks ...

Develop and manage the Cybersecurity Risk Register and audit documentation. * Build automated compliance monitoring routines and security dashboards. * Partner across IT, operations, and leadership ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See salary details

$57K

$133K

$186K

How much do cybersecurity risk management jobs pay per year?

As of Jun 20, 2026, the average yearly pay for cybersecurity risk management in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What is the role of a risk manager in cybersecurity?

A cybersecurity risk manager identifies, assesses, and prioritizes security risks to an organization’s information systems. They develop strategies to mitigate threats, implement security controls, and ensure compliance with industry standards, often using tools like risk assessment frameworks and security audits. Their role is essential in protecting digital assets and supporting overall cybersecurity posture.

Is security risk management a good career?

Security risk management is a valuable career in cybersecurity, focusing on identifying and mitigating threats to organizational assets. It often requires knowledge of security frameworks, risk assessment tools, and certifications like CISSP or CISM. The field offers strong job growth, competitive salaries, and opportunities across various industries.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What is risk management in cyber security?

In cybersecurity risk management, professionals identify, assess, and prioritize potential security threats to an organization’s information systems. They implement strategies and controls to mitigate or accept risks, often using frameworks like NIST or ISO 27001, and may hold certifications such as CISSP or CISM to ensure effective risk handling.

Can you make $500,000 a year in cyber security?

Cybersecurity risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working in large organizations with complex security needs.
More about Cybersecurity Risk Management jobs
What cities are hiring for Cybersecurity Risk Management jobs? Cities with the most Cybersecurity Risk Management job openings:
What states have the most Cybersecurity Risk Management jobs? States with the most job openings for Cybersecurity Risk Management jobs include:
Infographic showing various Cybersecurity Risk Management job openings in the United States as of June 2026, with employment types broken down into 99% Full Time, and 1% Temporary. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.
Mgr Cybersecurity Program & Risk

Mgr Cybersecurity Program & Risk

Blount Fine Foods

Warren, RI • On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 18 days ago


Blount Fine Foods rating

6.3

Company rating: 6.3 out of 10

Based on 23 frontline employees who took The Breakroom Quiz

264th of 385 rated food and drinks producers


Job description

Description
Bringing our love of food to families for five generations! Blount Fine Foods is a family-owned and operated manufacturer, marketer, and developer of premium fresh prepared foods. We are an engaging team, bringing restaurant-quality products to America including single-serve grab-n-go fresh soups, mac & cheese, and entrées in grocery stores across the country, as well as for hot bars and restaurants. Help us create the finest food experiences including those with specialty certifications that include organic, gluten-free, and low sodium, among others. Join a proven team for growth, success, and a satisfying career!
THIS OPPORTUNITY IS FULLY ONSITE AT OUR COROPRATE OFFICE IN WARREN, RI.
Job Summary
The Cybersecurity Program & Risk Manager is accountable for owning, integrating, and advancing the organization's enterprise cybersecurity risk posture. This role goes beyond program coordination to actively shape risk decisions, influence executive leadership, and ensure cybersecurity risks are understood, prioritized, and managed in business terms. The position serves as the single point of accountability for cybersecurity risk management across governance, third-party risk, workforce behavior, and compliance obligations.
Duties/Responsibilities
Enterprise Cybersecurity Risk & Program Ownership
  • Own the enterprise cybersecurity risk framework, including identification, assessment, prioritization, and mitigation tracking.
  • Maintain and mature the cybersecurity and technology risk register with clear risk statements, ownership, and mitigation plans.
  • Develop and execute a multi-year cybersecurity program roadmap aligned to business strategy.
  • Facilitate cybersecurity maturity assessments and pragmatic improvement planning.
Third-Party, Supply Chain & Subsidiary Risk Management
  • Own cybersecurity risk management for third parties, suppliers, logistics partners, co-manufacturers, and SaaS vendors.
  • Define and enforce cybersecurity requirements in contracts and ensure evidence-based compliance.
  • Coordinate vendor risk assessments and remediation activities with Procurement and Legal.
  • Ensure subsidiaries comply with corporate cybersecurity policies and minimum standards.
Governance, Executive Reporting & Assurance
  • Prepare cybersecurity risk materials for leadership and governance committees.
  • Translate cybersecurity risk into business, operational, and reputational impact.
  • Support audits, assessments, and external reviews with defensible documentation.
  • Develop dashboards and executive metrics to show risk posture and trend visibility.
Security Awareness, Training & Human Risk
  • Own the enterprise security awareness and phishing simulation program.
  • Analyze trends and recommend corrective actions to reduce human risk.
  • Partner with HR and Communications to embed cybersecurity into company culture.
Enterprise Coordination Across Security Domains
  • Maintain awareness across incident response, vulnerability management, IAM, and endpoint security.
  • Coordinate security initiatives without owning day-to-day technical operations.
  • Ensure clarity of ownership and risk coverage across teams and vendors.

Education and/or Experience
  • 7-10+ years of experience in cybersecurity, technology risk management, or enterprise risk roles.
  • Demonstrated ownership of cybersecurity or technology risk programs.
  • Experience with third-party risk management, risk registers, audits, and compliance documentation.
  • Ability to translate technical risk into executive-level business impact.
  • Strong judgment, stakeholder management, and ability to influence without authority.
  • Experience in manufacturing, food, CPG, or industrial environments.
  • Practical experience with NIST CSF, ISO 27001, or similar frameworks.
  • Exposure to multi-entity or subsidiary operating models.
  • Experience presenting risk to executive leadership or Boards.

Our Total Compensation Package Includes:
  • Medical, dental and vision benefits.
  • 401k with Company match.
  • Paid time off including vacation, sick time and holidays.
  • Education Assistance Program.
  • Life Insurance and Short-Term Disability.
  • Discounts on Blount products at Company retail location.
  • Discretionary Annual Bonus Program.

What Blount Fine Foods employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom