Position Summary FM is seeking a Senior Information Security Analyst with deep expertise in Third-Party Risk Management (TPRM), you will play a critical role in protecting FM by assessing how ...
Position Summary FM is seeking a Senior Information Security Analyst with deep expertise in Third-Party Risk Management (TPRM), you will play a critical role in protecting FM by assessing how ...
Security/Risk Analyst
Appleton, WI · On-site
Great opportunity for a hands-on Sr. Security/Risk Analyst, an IT leader with ambition and drive to provide strategy, vision, communication, and direction regarding security risks to safeguard ...
Security/Risk Analyst
Appleton, WI · On-site
Great opportunity for a hands-on Sr. Security/Risk Analyst, an IT leader with ambition and drive to provide strategy, vision, communication, and direction regarding security risks to safeguard ...
Company Description IDEALFORCE has a Contract position available immediately for a IT Security Risk Analyst to join our customer in Phoenix Arizona. This is an ONSITE position. Please find below ...
Company Description IDEALFORCE has a Contract position available immediately for a IT Security Risk Analyst to join our customer in Phoenix Arizona. This is an ONSITE position. Please find below ...
Information Risk Analyst Other San Antonio, Texas | Contract We have an exciting opportunity for a ... The ideal candidate will possess strong cloud security, risk management, and audit experience ...
Information Risk Analyst Other San Antonio, Texas | Contract We have an exciting opportunity for a ... The ideal candidate will possess strong cloud security, risk management, and audit experience ...
Information Security Risk Analyst - Cyber Resiliency
Atlanta, GA · On-site
$120K - $130K/yr
As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and ...
Information Security Risk Analyst - Cyber Resiliency
Atlanta, GA · On-site
$120K - $130K/yr
As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and ...
Information Security Risk Analyst - Cyber Resiliency
Minneapolis, MN · On-site
$120K - $130K/yr
As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and ...
Information Security Risk Analyst - Cyber Resiliency
Minneapolis, MN · On-site
$120K - $130K/yr
As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and ...
Familiarity with vulnerability management, threat intelligence analysis, and security architecture ... Performing information security risk assessments, evaluating control effectiveness, and analyzing ...
Quick apply
Familiarity with vulnerability management, threat intelligence analysis, and security architecture ... Performing information security risk assessments, evaluating control effectiveness, and analyzing ...
EITS Security Risk Analyst B (Engagement)--Remote Job
San Francisco, CA · On-site
$60 - $70/hr
Job43 - EITS Security Risk Analyst B (Engagement) Location: 100% Remote Max Submissions: 5 Proposed ... Translate business IT risk requirements into technical control specifications. * Develop risk ...
Quick apply
EITS Security Risk Analyst B (Engagement)--Remote Job
San Francisco, CA · On-site
$60 - $70/hr
Job43 - EITS Security Risk Analyst B (Engagement) Location: 100% Remote Max Submissions: 5 Proposed ... Translate business IT risk requirements into technical control specifications. * Develop risk ...
Manager, Information Security Risk - Governance, Risk, Compliance - Audit - Hybrid, Cary, North ... As a working manager, the position is actively involved in risk analysis and problem-solving while ...
Manager, Information Security Risk - Governance, Risk, Compliance - Audit - Hybrid, Cary, North ... As a working manager, the position is actively involved in risk analysis and problem-solving while ...
Manager, Information Security Risk - Governance, Risk, Compliance - Audit - Hybrid, Cary, North ... As a working manager, the position is actively involved in risk analysis and problem-solving while ...
New
Manager, Information Security Risk - Governance, Risk, Compliance - Audit - Hybrid, Cary, North ... As a working manager, the position is actively involved in risk analysis and problem-solving while ...
New
The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery's (WBD's) third party suppliers/vendors. This role requires ...
The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery's (WBD's) third party suppliers/vendors. This role requires ...
THE JOB The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery's (WBD's) third party suppliers/vendors. This role ...
THE JOB The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery's (WBD's) third party suppliers/vendors. This role ...
Operational Risk Analyst -Security Governance & Risk Issues Management Location: Merrifield VA ... Keep current with Information Security best practices and industry trends, and communicate/apply ...
Operational Risk Analyst -Security Governance & Risk Issues Management Location: Merrifield VA ... Keep current with Information Security best practices and industry trends, and communicate/apply ...
The VP, Information Security & Risk is accountable for fulfilling the program's protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and ...
The VP, Information Security & Risk is accountable for fulfilling the program's protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and ...
The VP, Information Security & Risk is accountable for fulfilling the program's protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and ...
The VP, Information Security & Risk is accountable for fulfilling the program's protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and ...
The VP, Information Security & Risk is accountable for fulfilling the program's protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and ...
The VP, Information Security & Risk is accountable for fulfilling the program's protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and ...
The VP, Information Security & Risk is accountable for fulfilling the program's protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and ...
Quick apply
The VP, Information Security & Risk is accountable for fulfilling the program's protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and ...
Vice President, Information Security & Risk
Chicago, IL · On-site
$155K - $175K/yr
The VP, Information Security & Risk is accountable for fulfilling the program's protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and ...
Vice President, Information Security & Risk
Chicago, IL · On-site
$155K - $175K/yr
The VP, Information Security & Risk is accountable for fulfilling the program's protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU's IT Security Risk team. Core responsibilities include third-party risk management (TPRM) and security ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU's IT Security Risk team. Core responsibilities include third-party risk management (TPRM) and security ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU's IT Security Risk team. Core responsibilities include third-party risk management (TPRM) and security ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU's IT Security Risk team. Core responsibilities include third-party risk management (TPRM) and security ...
Information Security RISK Analyst information
See salary details
$31.97 - $35.93
6% of jobs
$35.93 - $39.88
5% of jobs
$39.88 - $43.84
8% of jobs
$45.72 is the 25th percentile. Wages below this are outliers.
$43.84 - $47.79
11% of jobs
$47.79 - $51.75
12% of jobs
The median wage is $55.46 / hr.
$51.75 - $55.70
8% of jobs
$55.70 - $59.66
7% of jobs
$59.66 - $63.61
9% of jobs
$65.41 is the 75th percentile. Wages above this are outliers.
$63.61 - $67.57
17% of jobs
$67.57 - $71.53
8% of jobs
$71.53 - $75.48
7% of jobs
$31
$58
$75
How much do information security risk analyst jobs pay per hour?
What is an information security risk analyst?
What does an information security risk analyst do?
As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.
What are the key skills and qualifications needed to thrive as an information security risk analyst, and why are they important?
How does an information security risk analyst typically collaborate with other departments to address security risks?
What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?
| Aspect | Information Security Risk Analyst | Cybersecurity Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment teams, compliance departments | Security operations centers, incident response teams |
| Employer & Industry Usage | Financial, healthcare, government sectors | Tech companies, cybersecurity firms, enterprises |
While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.
What cities are hiring for Information Security Risk Analyst jobs?
Cities with the most Information Security Risk Analyst job openings:
What are the most commonly searched types of Information Security Risk Analyst jobs?
The most popular types of Information Security Risk Analyst jobs are:
Who are the top companies hiring for Information Security Risk Analyst jobs?
The top employers for Information Security Risk Analyst jobs are:
What states have the most Information Security Risk Analyst jobs?
States with the most job openings for Information Security Risk Analyst jobs include:
What are popular job titles related to Information Security Risk Analyst jobs?
For Information Security Risk Analyst jobs, the most frequently searched job titles are:

Senior Information Security Risk Analyst
Johnston, RI • On-site
Other
Medical, Dental, Vision, Life, Retirement, PTO
This job post has expired 2 days ago. Applications are no longer accepted.
Job description
Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk management and the resilience of its policyholder-owners. These owners, who share the belief that the majority of property loss is preventable, represent many of the world’s largest organizations, including one of every four Fortune 500 companies. They work with FM to better understand the hazards that can impact their business continuity to make cost-effective risk management decisions, combining property loss prevention with insurance protection.
Work Schedule
This position requires on-site work one day per week at our Corporate Headquarters and flexibility to be on-site when needed based on the demands of the business
Relocation is not offered for this position.
Position Summary
FM is seeking a Senior Information Security Analyst with deep expertise in Third-Party Risk Management (TPRM), you will play a critical role in protecting FM by assessing how external vendors, SaaS platforms, and cloud solutions interact with our systems and data. This high-impact role where your expertise in cyber risk, vendor security, and cloud architecture will help shape business decisions, strengthen our security posture, and support innovation in a secure way. This includes reviewing both the vendor’s security control environment and the specific solution being implemented, with a focus on data handling, storage, and integration with internal systems.
You will partner closely with business, technology, and procurement teams to identify risks and recommend practical, business-aligned mitigation strategies.
You will lead end-to-end cybersecurity risk assessments of third-party vendors and solutions—going beyond standard due diligence to evaluate real-world risk across systems, data, and integrations.
Key Responsibilities
- Lead end-to-end third-party solution risk assessments and vendor security reviews across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, and reassessments.
- Evaluate vendor security programs, control effectiveness, and governance, along with deep-dive assessment of the specific product being implemented including solution architecture, data flows, and integration points.
- Identify and communicate inherent and residual cyber risks related to data protection, privacy, IAM, privileged access, system connectivity, and external attack surface exposure.
- Review and interpret security documentation, including SOC 1/SOC 2 reports, ISO 27001 certifications, audit reports, architecture diagrams, data flow diagrams, and technical configurations.
- Recommend practical risk mitigation strategies, including compensating controls, secure design changes, and contractual safeguards to support risk-informed decisions.
- Partner with business, technology, procurement, and legal teams to support risk acceptance, exception management, and third-party risk governance.
- Contribute to the evolution of FM’s third-party risk management framework, methodology, and standards in alignment with NIST, ISO 27001, NYDFS, and other applicable regulatory expectations.
- 5+ years of experience in cybersecurity, information security, or cyber risk, with a background in third-party risk management (TPRM), IT risk, audit, incident response, or access management.
- Experience assessing vendor security posture in cloud (SaaS/PaaS)and enterprise environments.
Technical Expertise
- Strong understanding of systems, networks, application architecture, cloud security, and secure system design across AWS, Azure, SaaS, PaaS, APIs, and enterprise integrations.
- Experience evaluating data flows, data classification, data protection, data governance, and secure data handling practices.
- Knowledge of IAM, SSO, federation, privileged access, cyber threats, vulnerabilities, and attack methodologies.
- Ability to interpret SOC 1, SOC 2, ISO certifications, and other third-party assurance artifacts to identify control gaps and residual risk.
Risk & Analysis:
- Ability to identify, assess, and clearly communicate complex cyber risks, trade-offs, and residual risk.
- Experience recommending practical, business-aligned risk based mitigation strategies, including compensating controls and secure design changes.
- Strong analytical judgment, attention to detail, and risk-based decision-making.
Collaboration & Communication
- Ability to translate technical findings into clear, business-relevant insights and recommendations.
- Strong stakeholder management and partnership across business, technology, procurement, and legal teams.
- Collaborative, solutions-focused mindset with strong influencing skills in a fast-paced assessment environment.
- High degree of professional skepticism and curiosity when evaluating vendor claims and evidence
- Ability to manage multiple priorities independently while maintaining quality and consistency of assessments
Tools & Certifications:
- Proficiency with Microsoft Office tools.
- Relevant certifications such as CISSP, CISA, CSA, CISM, Security+, GIAC, CEH, or similar are strongly desired.
Education
Bachelor's degree in information security, Computer Science, Information Technology, or a related field required. An equivalent of relevant work experience will also be considered.
The hiring range for this position is $106,000- $152,000. The final salary offer will vary based on geographic location, individual education, skills, and experience. The position is eligible to participate in FM’s comprehensive Total Rewards program that includes an incentive plan, medical, dental and vision insurance, life and disability insurance, well-being programs, a 401(k) and pension plan, career development opportunities, tuition reimbursement, flexible work, and time off, including vacation and sick time.
FM is an Equal Opportunity Employer and is committed to attracting, developing, and retaining a diverse workforce.
#LI-NL1
#FMG
About FM
Sourced by ZipRecruiter
Industry
Plastics product manufacturing
Company size
51 - 200 Employees
Headquarters location
Rogers, AR, US
Year founded
1980