1

Information Security Risk Analyst Jobs in Illinois

IL · On-site

$99K - $225K/yr

Information Security Risk Specialist, Senior The Opportunity: Cyber threats are everywhere, and the ... Experience analyzing and managing software vulnerability reports * Experience with DoW RMF ...

Governance & Risk Analyst

Chicago, IL · On-site

$85K - $95K/yr

Governance & Risk Analyst in the Enterprise will... The GRC Analyst will support the organization ... Information Security * Data Privacy * Access Controls * Business Continuity & Disaster Recovery

next page

Showing results 1-20

Information Security Risk Analyst information

See Illinois salary details

$30

$56

$73

How much do information security risk analyst jobs pay per hour?

As of Jul 31, 2026, the average hourly pay for information security risk analyst in Illinois is $56.64, according to ZipRecruiter salary data. Most workers in this role earn between $44.04 and $63.61 per hour, depending on experience, location, and employer.

What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?

AspectInformation Security Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.

What are the key skills and qualifications needed to thrive as an Information Security Risk Analyst, and why are they important?

To thrive as an Information Security Risk Analyst, you need a solid understanding of cybersecurity principles, risk management frameworks, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like risk assessment platforms, vulnerability scanners, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, communication, and attention to detail help you translate complex risks into actionable recommendations and collaborate with stakeholders. These skills are crucial for effectively identifying, assessing, and mitigating security risks to protect organizational assets and ensure compliance.

What are Information Security Risk Analysts?

Information Security Risk Analysts are professionals responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze potential threats, vulnerabilities, and impacts to ensure that appropriate security measures are in place. These analysts often develop risk management strategies, conduct security assessments, and recommend security enhancements. Their goal is to help organizations protect sensitive information and comply with relevant regulations.

What Does an Information Security Risk Analyst Do?

As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.

How does an Information Security Risk Analyst typically collaborate with other departments to address security risks?

Information Security Risk Analysts work closely with various departments such as IT, compliance, legal, and business units to identify and mitigate security risks. They often facilitate risk assessments, communicate findings, and recommend solutions tailored to each department's needs. Regular meetings and cross-functional projects are common, ensuring security measures align with business objectives while maintaining compliance. This collaborative approach helps foster a culture of security awareness throughout the organization.
What are the most commonly searched types of Information Security Risk Analyst jobs in Illinois? The most popular types of Information Security Risk Analyst jobs in Illinois are:
What job categories do people searching Information Security Risk Analyst jobs in Illinois look for? The top searched job categories for Information Security Risk Analyst jobs in Illinois are:
What are popular job titles related to Information Security Risk Analyst jobs in IL? For Information Security Risk Analyst jobs in IL, the most frequently searched job titles are:
Infographic showing various Information Security Risk Analyst job openings in Illinois as of July 2026, with employment types broken down into 2% Locum Tenens, 84% Full Time, 9% Part Time, 1% Temporary, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $117,811 per year, or $56.6 per hour.

Information Security Risk Analyst - Intermediate

The University of Chicago Medicine

Darien, IL • On-site

Full-time

Posted 8 days ago


University Of Chicago Medicine rating

7.4

Company rating: 7.4 out of 10

Based on 61 frontline employees who took The Breakroom Quiz

262nd of 885 rated healthcare providers


Job description


Join a world-class academic healthcare system, UChicago Medicine, as an Information Security Risk Analyst - Intermediate in our Information Security and Privacy GRC department. This position will be primarily a work-from-home opportunity with the requirement to come onsite as needed. You will need to be based in the greater Chicagoland area.
The Information Security Risk Analyst - Intermediate plays a critical role within the Governance, Risk and Compliance (GRC) team in executing and enhancing the organization's information security risk management program. The analyst will independently conduct risk analysis on information systems, platforms, and processes in accordance with established regulatory requirements, organizational policies, and industry standards. The analyst will lead and contribute to the identification, assessment, documentation, mitigation, and communication of information security risks across the organization.
This position supports risk-driven decision-making by collaborating with stakeholders, managing risk treatment plans, and ensuring compliance with HIPAA, NIST, and other applicable healthcare cybersecurity regulations and frameworks. The analyst is expected to operate with moderate independence, assist in maturing risk workflows, and contribute to strategic improvements in governance, risk, and compliance activities.
The ideal candidate will have a strong understanding of security frameworks, risk assessment methodologies, risk assessments, risk registers, and the management of audit and penetration testing findings. The ideal candidate should be adept at monitoring regulatory developments while promoting a culture of risk awareness across the organization.
Essential Job Functions
  • Lead and conduct comprehensive information security risk analysis for IT assets, applications, processes, medical devices and third-party vendors.
  • Evaluate threats and vulnerabilities affecting the confidentiality, integrity, and availability of electronic protected health information (ePHI) and any other confidential or sensitive information, ensuring alignment with HIPAA Security Rule requirements and other applicable regulatory frameworks (e.g., NIST,).
  • Lead and manage risk management initiatives based on analysis of outcomes, including maintaining the organization's risk register and scoring methodology.
  • Oversee corrective action plans (CAPs), penetration testing results, audit findings, and risk treatment outcomes.
  • Collaborate with IT partners and key stakeholders to prioritize, implement, and track remediation efforts.
  • Monitor regulatory changes and industry threats to proactively identify emerging risks, recommend mitigation strategies, and document findings.
  • Contribute to risk reporting, including executive dashboards, and participate in risk acceptance processes and governance reviews.
  • Contribute to the development, review, and improvement of cybersecurity policies, standards, and procedures.
  • Evaluate policy exceptions and assist in documenting decisions for governance committees.
  • Enhance the organization's cybersecurity awareness and training efforts by communicating risk insights to technical and non-technical audiences.
  • Other duties as assigned

Required Qualifications
  • Bachelor's degree required in Information Security, Computer Science, Engineering, Information Technology, or a related field; master's degree preferred
  • 3+ years of experience in cybersecurity, information security risk management, audit; healthcare industry experience strongly preferred
  • Demonstrated experience with risk assessment methodologies, auditing, information security practices, and familiarity with risk management platforms and risk registers
  • Strong understanding of regulatory compliance and industry best practices towards maintaining compliance with HIPAA, NIST and other relevant healthcare regulations and standards
  • One or more of the following certifications are required or must be obtained within 12 months of hire: CRISC, CISM, CISA or any other applicable certification
  • Ability to lead and structure risk assessments with limited supervision
  • Ability to manage multiple concurrent assessments and projects in a fast-paced healthcare setting
  • Experience preparing both detailed technical risk reports and executive-level summaries, tailored to varied audiences to support informed decision-making and governance oversight
  • Ability to build strong cross-functional relationships and collaboration across departments, including IT, Legal, Compliance, Clinical Operations, and Privacy, to support a collaborative approach to risk management and governance
  • Strong written and verbal communication and interpersonal skills, including ability to translate technical findings into business-relevant language for leadership audiences
  • Experience tracking audit findings, third party vendor risks, and remediation efforts
  • Familiarity with security platforms and tools
  • Ability to analyze contractual security language to identify risk exposure and recommend controls
  • Ability to learn quickly and work effectively in a team environment
  • Ability to understand and work with healthcare professionals, educators, and researchers
  • Ability to integrate cybersecurity risk management with business operations, healthcare delivery, and IT services

Position Details
  • Job Type/FTE: Full Time
  • Shift: Days
  • Location: Flexible (Hyde Park; Darien)
  • Unit/Department: Information Security Office
  • CBA Code: Non-Union

About Us
We've been at the forefront of medicine since 1899. We provide superior healthcare with compassion, always mindful that each patient is a person, an individual. To accomplish this, we need employees with passion, talent and commitment... with patients and with each other. We're in this together: working to advance medical innovation, serve the health needs of the community, and move our collective knowledge forward. If you'd like to add enriching human life to your profile, UChicago Medicine is for you. Here at the forefront, we're doing work that really matters. Join us. Bring your passion.
UChicago Medicine is growing; discover how you can be a part of this pursuit of excellence at: UChicago Medicine Career Opportunities
UChicago Medicine is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, ethnicity, ancestry, sex, sexual orientation, gender identity, marital status, civil union status, parental status, religion, national origin, age, disability, veteran status and other legally protected characteristics.
As a condition of employment, all employees are required to complete a pre-employment physical, background check, drug screening, and comply with the flu vaccination requirements prior to hire. Medical and religious exemptions will be considered for flu vaccination consistent with applicable law.
Compensation & Benefits Overview
UChicago Medicine is committed to transparency in compensation and benefits. The pay range provided reflects the anticipated wage or salary reasonably expected to be offered for the position.
The pay range is based on a full-time equivalent (1.0 FTE) and is reflective of current market data, reviewed on an annual basis. Compensation offered at the time of hire will vary based on candidate qualifications and experience and organizational considerations, such as internal equity. Pay ranges for employees subject to Collective Bargaining Agreements are negotiated by the medical center and their respective union.
Review the full complement of benefit options for eligible roles at Benefits - UChicago Medicine.

What University Of Chicago Medicine employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom