Cybersecurity Risk and Controls Analyst Department ... Information Technology Job Status: Full Time FLSA Status: Salary Exempt Reports To: Cybersecurity ...
Cybersecurity Risk and Controls Analyst Department ... Information Technology Job Status: Full Time FLSA Status: Salary Exempt Reports To: Cybersecurity ...
Cybersecurity Risk Vulnerability III
$132K - $148K/yr
Risk/Vulnerability Analyst III Rothe Development, Inc. (RDI) is seeking a Cybersecurity Risk ... Full-time employees may participate in: * Medical Insurance * Dental Insurance * Vision Insurance
Cybersecurity Risk Vulnerability III
$132K - $148K/yr
Risk/Vulnerability Analyst III Rothe Development, Inc. (RDI) is seeking a Cybersecurity Risk ... Full-time employees may participate in: * Medical Insurance * Dental Insurance * Vision Insurance
Cybersecurity Risk
Jersey City, NJ · On-site
$104K - $134K/yr
Deep expertise in cybersecurity, regulatory compliance, and risk governance is essential to ensure robust protection and alignment with industry standards. Exceptional communication and leadership ...
Cybersecurity Risk
Jersey City, NJ · On-site
$104K - $134K/yr
Deep expertise in cybersecurity, regulatory compliance, and risk governance is essential to ensure robust protection and alignment with industry standards. Exceptional communication and leadership ...
Cyber Risk Analyst
Lemont, IL · On-site
The Companys Cyber Security Program Office promotes the safe and secure use of information ... Contract Position: Full Time, 40 hour work week Period of Performance: 1 Year Scope: The Cyber Risk ...
Quick apply
Cyber Risk Analyst
Lemont, IL · On-site
The Companys Cyber Security Program Office promotes the safe and secure use of information ... Contract Position: Full Time, 40 hour work week Period of Performance: 1 Year Scope: The Cyber Risk ...
Provide expert-level technical guidance and analysis to support cybersecurity and risk assessment initiatives, including supply chain risk management. Develop, enhance, and maintain standard ...
Provide expert-level technical guidance and analysis to support cybersecurity and risk assessment initiatives, including supply chain risk management. Develop, enhance, and maintain standard ...
Provide expert-level technical guidance and analysis to support cybersecurity and risk assessment initiatives, including supply chain risk management. Develop, enhance, and maintain standard ...
Quick apply
Provide expert-level technical guidance and analysis to support cybersecurity and risk assessment initiatives, including supply chain risk management. Develop, enhance, and maintain standard ...
Senior Analyst, Cybersecurity Risk & Compliance Risk Management & IT Compliance | Analog Devices, Inc. About Analog Devices Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that ...
Senior Analyst, Cybersecurity Risk & Compliance Risk Management & IT Compliance | Analog Devices, Inc. About Analog Devices Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that ...
Staff Cybersecurity Analyst, Risk Management
$140K - $186K/yr
Role Summary The Cybersecurity Analyst - Risk Management is a mid-career individual contributor ... Full-time employee coverage is effective on their first day of employment. Part-time employee ...
Staff Cybersecurity Analyst, Risk Management
$140K - $186K/yr
Role Summary The Cybersecurity Analyst - Risk Management is a mid-career individual contributor ... Full-time employee coverage is effective on their first day of employment. Part-time employee ...
As a Senior Analyst, Cybersecurity Risk & Compliance, you will safeguard ADI's global operations by executing risk management and compliance activities across various cybersecurity and IT frameworks ...
As a Senior Analyst, Cybersecurity Risk & Compliance, you will safeguard ADI's global operations by executing risk management and compliance activities across various cybersecurity and IT frameworks ...
Staff Cybersecurity Analyst, Risk Management
Riverdale, GA · On-site
$140K - $186K/yr
Role Summary The Cybersecurity Analyst - Risk Management is a mid-career individual contributor ... Full-time employee coverage is effective on their first day of employment. Part-time employee ...
Staff Cybersecurity Analyst, Risk Management
Riverdale, GA · On-site
$140K - $186K/yr
Role Summary The Cybersecurity Analyst - Risk Management is a mid-career individual contributor ... Full-time employee coverage is effective on their first day of employment. Part-time employee ...
Senior Analyst, Cybersecurity Risk & Compliance Risk Management & IT Compliance | Analog Devices, Inc. About Analog Devices Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that ...
Senior Analyst, Cybersecurity Risk & Compliance Risk Management & IT Compliance | Analog Devices, Inc. About Analog Devices Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that ...
Cybersecurity Risk & Compliance Analyst Location: HOUSTON, TX FLSA Class: EXEMPT Responsible to: Senior Manager of Technical Operations Position Summary : VoltaGrid is seeking a Cybersecurity Risk ...
Cybersecurity Risk & Compliance Analyst Location: HOUSTON, TX FLSA Class: EXEMPT Responsible to: Senior Manager of Technical Operations Position Summary : VoltaGrid is seeking a Cybersecurity Risk ...
ETS Risk Analyst II
Johnston, RI · Hybrid
ETS Risk Analyst II - Monitoring and Testing Role Overview The Enterprise Technology & Security ... Cybersecurity Framework. You will independently assess control effectiveness, monitor key risk ...
ETS Risk Analyst II
Johnston, RI · Hybrid
ETS Risk Analyst II - Monitoring and Testing Role Overview The Enterprise Technology & Security ... Cybersecurity Framework. You will independently assess control effectiveness, monitor key risk ...
Overview: Leads risk analysis for the most complex initiatives, influencing and designing ... Influence design and delivery of training programs to strengthen the Technology and Cybersecurity ...
Overview: Leads risk analysis for the most complex initiatives, influencing and designing ... Influence design and delivery of training programs to strengthen the Technology and Cybersecurity ...
ETS Risk Analyst II
Johnston, RI · On-site
ETS Risk Analyst II - Monitoring and Testing Role Overview The Enterprise Technology & Security ... Cybersecurity Framework. You will independently assess control effectiveness, monitor key risk ...
ETS Risk Analyst II
Johnston, RI · On-site
ETS Risk Analyst II - Monitoring and Testing Role Overview The Enterprise Technology & Security ... Cybersecurity Framework. You will independently assess control effectiveness, monitor key risk ...
Principal Specialist - Technology and Cybersecurity Risk
Buffalo, NY · On-site
$148K - $247K/yr
Overview: Leads risk analysis for the most complex initiatives, influencing and designing ... Influence design and delivery of training programs to strengthen the Technology and Cybersecurity ...
Principal Specialist - Technology and Cybersecurity Risk
Buffalo, NY · On-site
$148K - $247K/yr
Overview: Leads risk analysis for the most complex initiatives, influencing and designing ... Influence design and delivery of training programs to strengthen the Technology and Cybersecurity ...
Cybersecurity Assessment Lead
Coronado, CA · On-site
$117K - $159K/yr
Analyze testing results and provide cybersecurity risk assessments to the Government SCA and Authorizing Official. * RMF Package Development and Reporting * Oversee preparation and delivery of RMF ...
Cybersecurity Assessment Lead
Coronado, CA · On-site
$117K - $159K/yr
Analyze testing results and provide cybersecurity risk assessments to the Government SCA and Authorizing Official. * RMF Package Development and Reporting * Oversee preparation and delivery of RMF ...
Lead, coach, and develop a team of cybersecurity risk analysts, principals, and managers, establishing a consistent, scalable, and value driven risk support model across the enterprise. * Define and ...
Lead, coach, and develop a team of cybersecurity risk analysts, principals, and managers, establishing a consistent, scalable, and value driven risk support model across the enterprise. * Define and ...
Lead, coach, and develop a team of cybersecurity risk analysts, principals, and managers, establishing a consistent, scalable, and value driven risk support model across the enterprise. * Define and ...
Lead, coach, and develop a team of cybersecurity risk analysts, principals, and managers, establishing a consistent, scalable, and value driven risk support model across the enterprise. * Define and ...
Cybersecurity Assessment Lead
Virginia Beach, VA · On-site
$98K - $133K/yr
Analyze testing results and provide cybersecurity risk assessments to the Government SCA and Authorizing Official. * RMF Package Development and Reporting * Oversee preparation and delivery of RMF ...
Cybersecurity Assessment Lead
Virginia Beach, VA · On-site
$98K - $133K/yr
Analyze testing results and provide cybersecurity risk assessments to the Government SCA and Authorizing Official. * RMF Package Development and Reporting * Oversee preparation and delivery of RMF ...
Full Time Cyber Security Risk Analyst information
See salary details
$43K - $52.7K
1% of jobs
$52.7K - $62.5K
6% of jobs
$62.5K - $72.2K
10% of jobs
$78.8K is the 25th percentile. Wages below this are outliers.
$72.2K - $81.9K
12% of jobs
$81.9K - $91.6K
15% of jobs
The median wage is $95.8K / yr.
$91.6K - $101.4K
15% of jobs
$101.4K - $111.1K
10% of jobs
$115.3K is the 75th percentile. Wages above this are outliers.
$111.1K - $120.8K
16% of jobs
$120.8K - $130.5K
7% of jobs
$130.5K - $140.3K
5% of jobs
$140.3K - $150K
3% of jobs
$43K
$99.4K
$150K
How much do full time cyber security risk analyst jobs pay per year?
What is the difference between Full Time Cyber Security Risk Analyst vs Cyber Security Analyst?
| Aspect | Full Time Cyber Security Risk Analyst | Cyber Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CISSP, CISA | CompTIA Security+, CEH, CISSP (preferred) |
| Work Environment | Risk assessment teams, security compliance, policy development | Security monitoring, incident response, vulnerability assessment |
| Employer & Industry Usage | Financial, healthcare, government sectors focusing on risk management | IT firms, tech companies, cybersecurity service providers |
Full Time Cyber Security Risk Analysts focus on identifying, assessing, and mitigating security risks within organizations, often working on compliance and policy. Cyber Security Analysts primarily monitor security systems, respond to incidents, and perform vulnerability assessments. While both roles require similar certifications and work in cybersecurity, their core responsibilities differ: risk analysis versus security monitoring.
Full-time
Posted 11 days ago
Job description
Cybersecurity Risk and Controls Analyst
Job Description
Department: Information Technology         Â
Job Status: Full Time
FLSA Status: Salary Exempt
Reports To: Cybersecurity Manager
Location: The Woodlands, TX
Amount of Travel Required: Less than 5%
Work Schedule: Monday Friday, 8am – 5pm                          Â
Positions Supervised: n/a
AIP: Level 7
POSITION SUMMARY:
Beusa Energy is seeking a Cybersecurity Risk & Controls Analyst to help build and scale our cybersecurity governance, risk, and compliance (GRC) program across both enterprise IT and operational technology (OT) environments.
This role is responsible for defining, implementing, and continuously improving the controls that protect Beusa Energy’s systems, infrastructure, and operations. You will translate cybersecurity risks and regulatory expectations into practical, enforceable controls that align with real world operating conditions in the energy sector.
As Beusa Energy continues to grow, this role will be central to ensuring cybersecurity is embedded into how we operate. You will help establish consistency, accountability, and visibility in how cybersecurity risk is identified, mitigated, and communicated across the organization.
ESSENTIAL FUNCTIONS: (The following duties and responsibilities are all essential job functions, as
defined by the ADA, except for those that begin with the word "may")
- Identify, assess, and manage cybersecurity risks across IT and OT environments, maintaining a clear and actionable risk register.
- Develop, implement, and maintain cybersecurity policies, standards, and procedures aligned with Beusa Energy’s risk profile and operational environment.
- Design, document, and manage a centralized control framework that maps to industry standards (e.g., NIST CSF, ISO 27001) and regulatory requirements.
- Lead and support enterprise risk assessments across IT and OT environments, including risk identification, analysis, tracking, and reporting.
- Partner with IT, engineering, and field operations teams to ensure security controls are practical, implemented effectively, and embedded into daily workflows.
- Support compliance initiatives and audits (e.g., SOC 2, ISO 27001), including control design, evidence collection, and audit coordination.
- Maintain risk registers, control inventories, and remediation plans, providing clear visibility and reporting to leadership.
- Support third-party risk management processes, including vendor risk assessments and ongoing monitoring.
- Collaborate with cybersecurity and technology teams to align security tooling, monitoring, and detection capabilities with defined controls and compliance objectives.
- Assist in developing and delivering security awareness, policy training, and control adoption initiatives.
- Produce clear, executive-level reporting on risk posture, control effectiveness, and program maturity.
- Continuously evaluate and improve governance processes, documentation, and control effectiveness to support a scalable cybersecurity program.
- Performs other related duties as assigned to assist with successful operations and business continuity.
POSITION REQUIREMENTS:
- Successfully passes all applicable general pre-employment testing, including but not limited to: background check, pre-employment drug screening, pre-employment fit tests, pre-employment aptitude and/or competency assessment(s).
- Possesses a valid U.S. Driver’s License. Employment is contingent upon meeting the company's driving standards, including an acceptable Motor Vehicle Record (MVR) in accordance with the company's policy.
- Daily overtime required and in-person, predictable attendance.
- Must be legally authorized to work in the United States without the need for sponsorship.
- Must be at least 18 years of age or older.
EDUCATION/EXPERIENCE LEVEL
- Bachelor’s degree in Cybersecurity, Information Technology, or related field.  An equivalent combination of education, specialized training, and relevant professional experience may be considered in lieu of a formal degree.
- 3 to 6 years of experience in cybersecurity GRC, risk management, controls, or related roles.
- Strong understanding of cybersecurity frameworks and control standards, such as:
- NIST Cybersecurity Framework (CSF).
- ISO 27001.
- SOC 2.
- Experience designing, implementing, and assessing security controls in real-world environments.
- Familiarity with risk assessment methodologies and control testing practices.
- Experience supporting audits and managing evidence for compliance initiatives.
- Ability to translate technical and regulatory requirements into clear, actionable controls.
- Strong analytical, organizational, and communication skills with the ability to work cross-functionally.
QUALIFICATIONS, SKILLS, COMPETENCIES, AND ABILITIES
- Experience in energy, critical infrastructure, or industrial environments.
- Familiarity with OT/ICS cybersecurity risks and control considerations.
- Experience with GRC or compliance automation tools (e.g., Drata or similar platforms).
- Understanding of third-party risk management practices and frameworks.
- Relevant certifications such as CISA, CRISC, CISSP, or ISO 27001 Lead Implementer.
PHYSICAL REQUIREMENTS/WORK ENVIRONMENT
The physical demands and work environment described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Employee works indoors in an office setting, primarily sitting for extended periods at a desk station. The role requires keyboarding and repetitive motions with wrists, hands, and fingers. Vision abilities required include close vision and the ability to adjust focus while reading and staring at a computer monitor. The Employee must speak clearly and audibly, and have the ability to hear, understand, and distinguish speech and other sounds (e.g., building alarms) from in-person speech, telephone, or remote communication. While in the office, the Employee may be called upon to stand, kneel, push, pull, reach overhead, stoop, crouch, climb, and lift; therefore, the Employee should be able to independently lift 25 lbs. No adverse environmental conditions are expected.
Work hours may include early morning, late evenings, and weekends, depending on business necessity.
AAP/EEO STATEMENT
The Company is committed to the cause of equal employment opportunity for all employees and applicants, thus abiding by all applicable state and federal laws. Our practices regarding employment, job promotion, compensation, training, and termination do not discriminate on the basis of race, color, religious creed, age, sex, national origin, veteran's status, disability, pregnancy, genetic information, or any other legally protected status. It is expected that all employees, both management and staff, will fully support these nondiscriminatory policies.
The company has reviewed this job description to ensure essential functions and duties have been included. It is not intended to be an exhaustive list of all functions, responsibilities, skills, and abilities.
Last Revised (05/2026)