1

Information Security Risk Analyst Jobs (NOW HIRING)

Great opportunity for a hands-on Sr. Security/Risk Analyst, an IT leader with ambition and drive to provide strategy, vision, communication, and direction regarding security risks to safeguard ...

next page

Showing results 1-20

Information Security Risk Analyst information

See salary details

$31

$58

$75

How much do information security risk analyst jobs pay per hour?

As of Aug 26, 2026, the average hourly pay for information security risk analyst in the United States is $58.45, according to ZipRecruiter salary data. Most workers in this role earn between $45.43 and $65.62 per hour, depending on experience, location, and employer.

What is an information security risk analyst?

Information Security Risk Analysts are professionals responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze potential threats, vulnerabilities, and impacts to ensure that appropriate security measures are in place. These analysts often develop risk management strategies, conduct security assessments, and recommend security enhancements. Their goal is to help organizations protect sensitive information and comply with relevant regulations.

What does an information security risk analyst do?

As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.

What are the key skills and qualifications needed to thrive as an information security risk analyst, and why are they important?

To thrive as an Information Security Risk Analyst, you need a solid understanding of cybersecurity principles, risk management frameworks, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like risk assessment platforms, vulnerability scanners, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, communication, and attention to detail help you translate complex risks into actionable recommendations and collaborate with stakeholders. These skills are crucial for effectively identifying, assessing, and mitigating security risks to protect organizational assets and ensure compliance.

How does an information security risk analyst typically collaborate with other departments to address security risks?

Information Security Risk Analysts work closely with various departments such as IT, compliance, legal, and business units to identify and mitigate security risks. They often facilitate risk assessments, communicate findings, and recommend solutions tailored to each department's needs. Regular meetings and cross-functional projects are common, ensuring security measures align with business objectives while maintaining compliance. This collaborative approach helps foster a culture of security awareness throughout the organization.

What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?

AspectInformation Security Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.

What cities are hiring for Information Security Risk Analyst jobs?

Cities with the most Information Security Risk Analyst job openings:

What are the most commonly searched types of Information Security Risk Analyst jobs?

The most popular types of Information Security Risk Analyst jobs are:

Who are the top companies hiring for Information Security Risk Analyst jobs?

The top employers for Information Security Risk Analyst jobs are:

What states have the most Information Security Risk Analyst jobs?

States with the most job openings for Information Security Risk Analyst jobs include:

What job categories do people searching Information Security Risk Analyst jobs look for?

The top searched job categories for Information Security Risk Analyst jobs are:

Infographic showing various Information Security Risk Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 73% Full Time, 23% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $121,577 per year, or $58.5 per hour.

Information Security Risk Analyst 2

University of Minnesota

Minneapolis, MN • Hybrid

$85K - $95K/mo

Full-time

Medical, Dental, Life, Retirement, PTO

Re-posted 17 days ago


Job description

About the Job
 

Please note that this position is not eligible for H-1B or Green Card sponsorship. This position does not offer a STEM OPT training program.
The University of Minnesota is committed to fostering local talent through employment opportunities.
While this position utilizes a hybrid work modality, prospective applicants must be located either in the state of Minnesota or near the Wisconsin border OR otherwise open to relocation.
Position Overview:
The University of Minnesota's University Information Security seeks an Information Security Risk Analyst who will improve the information security of the University through information security risk assessments, security standards development, and exception management.
The Information Security Risk Analyst will assess the information security posture of collegiate and administrative units by conducting information security risk assessments, including analyzing security controls and processes, interviewing subject matter experts, and helping to shape a risk-based approach to security across the entire University system.
Why Join Our Team?
As a Risk Analyst at the University of Minnesota, you wont just be checking boxes on a spreadsheet. You will act as a trusted consultant across a massive ecosystem ranging from cutting-edge research labs and medical clinics to athletics and student services. Your work directly protects the privacy of our 50,000+ students and safeguards groundbreaking academic research.
Job Responsibilities:

Security Analysis - 80%

  • Conduct information security assessments utilizing ISO 27001 / 27002, NIST 800-171 or other appropriate information security control structures; develop risk remediation plans, and facilitate risk remediation efforts.
  • Facilitate the information security risk management program by identifying areas most in need of risk assessment, coordinating risk assessments with other information security risk analysts, and consulting with information security architects. 
  • Monitor and advise on information security needs for systems and processes at the University of Minnesota to ensure the information security controls for the campuses are consistent and appropriate.
  • Consult with administrative and collegiate units to address policy and process-related information security risks identified through the information security risk and exception management programs.
  • Collaborate with stakeholders by translating complex technical vulnerabilities and control deficiencies into clear, business-risk language for non-technical academic and administrative leaders.
  • Assist with development and maintenance of information security policies, standards, guidelines and procedures, based on industry best practices and compliance requirements.
  • Maintain a strong working knowledge of regulatory frameworks impacting higher education, including GLBA, PCI and FERPA while building knowledge of applicable security standards (SANS, OWASP, NIST).

Procedural Support - 20%

  • Facilitate the exception management process by tracking exceptions to information security policies and standards, evaluating associated risks by working with the other information security staff, and coordinating communication with the risk owner.
  • Assist with information security reviews of vendors and suppliers.
  • We Offer:
    • University paid contribution (10% of your salary) to your retirement account - vested immediately.
    • 22 paid vacation days per year, in addition to sick leave and 11 paid holidays.
    • Reduced tuition opportunities covering 75% - 100% of eligible tuition.
    • Excellent and affordable health care benefits.
    • Wellness program with opportunity to earn lower health care rates.
    • Free disability insurance.
    • Annual merit increase program.
Qualifications
 

Required Qualifications:

  • Bachelors degree in a related field and 2 years of relevant work experience or a Master's degree.
  • 1 year experience in information security risk assessment, audit, quality assurance,or similar.
  • Excellent communication (oral, written, presentation), interpersonal and consultative skills.

Preferred Qualifications:

  • Relevant work experience in a technical role, such as enterprise system management, or working within an IT-role in higher education
  • Knowledge of information security standards (e.g., ISO 27001/27002, NIST 800-171.), rules and regulations related to information security and data confidentiality (e.g., FERPA, GLBA, PCI DSS, HIPAA)
  • CISSP, CISA, or other security certifications are desirable.
  • Strong capability to analyze complex, ambiguous situations and synthesize conflicting information into clear, data-driven risk recommendations.
  • Demonstrated ability to look beyond surface-level technical symptoms to identify underlying root causes of systemic risk.
Pay and Benefits
 

Pay Range: $85,000 - $95,000; depending on education/qualifications/experience 

Time Appointment: 100% Appointment

Position Type: Faculty and P&A Staff 

Please visit the Office of Human Resources website for more information regarding benefit eligibility.

The University offers a comprehensive benefits package that includes:

  • Competitive wages, paid holidays, and generous time off
  • Continuous learning opportunities through professional training and degree-seeking programs supported by the Regents Tuition Benefit Program
  • Low-cost medical, dental, and pharmacy plans
  • Healthcare and dependent care flexible spending accounts
  • University HSA contributions
  • Disability and employer-paid life insurance
  • Employee wellbeing program
  • Excellent retirement plans with employer contribution
  • Public Service Loan Forgiveness (PSLF) opportunity
  • Financial counseling services 
  • Employee Assistance Program with eight sessions of counseling at no cost
  • Employee Transit Pass with free or reduced rates in the Twin Cities metro area

While our salary ranges provide a framework, it is important to note that most of the time, the initial pay may not reach the maximum of the range. This approach ensures that compensation reflects the value and unique contributions of each candidate while maintaining equity within our organization. As part of our commitment to fair and equitable compensation, please be aware that the salary offered to incoming candidates will be based on their individual credentials and experience.

How To Apply
 

Applications must be submitted online. To be considered for this position, please click the Apply button and follow the instructions. You will have the opportunity to complete an online application for the position and attach a cover letter and resume or CV.

Required Application Materials:

  • Resume
  • Cover Letter

This position will remain open until filled.

To request an accommodation during the application process, please e-mail employ@umn.edu or call (612) 624-8647.

Diversity
 

The University recognizes and values the importance of diversity and inclusion in enriching the employment experience of its employees and in supporting the academic mission.  The University is committed to attracting and retaining employees with varying identities and backgrounds.

The University of Minnesota provides equal access to and opportunity in its programs, facilities, and employment without regard to race, color, creed, religion, national origin, gender, age, marital status, disability, public assistance status, veteran status, sexual orientation, gender identity, or gender expression.  To learn more about diversity at the U:  http://diversity.umn.edu

Employment Requirements
 

Any offer of employment is contingent upon the successful completion of a background check. Our presumption is that prospective employees are eligible to work here. Criminal convictions do not automatically disqualify finalists from employment.

About University of Minnesota
 

The University of Minnesota, Twin Cities (UMTC)

The University of Minnesota, Twin Cities (UMTC), is among the largest public research universities in the country, offering undergraduate, graduate, and professional students a multitude of opportunities for study and research. Located at the heart of one of the nation's most vibrant, diverse metropolitan communities, students on the campuses in Minneapolis and St. Paul benefit from extensive partnerships with world-renowned health centers, international corporations, government agencies, and arts, nonprofit, and public service organizations.

At the University of Minnesota, we are proud to be recognized by Forbes as a Best Employer for Company Culture (2026), Best Employer for Women (2023), and Best Employer by State (2022-2026). In 2026, we also received Culture Excellence & Industry Awards recognition for employee appreciation and work-life flexibility.