1

Information Security Risk Analyst Jobs in Illinois

IL · On-site

Lead teams executing Information Systems Security Engineering (ISSE), security control assessments ... Conduct advanced security analysis using validated DoD cybersecurity processes and toolsets.

The Vendor Risk Management Analyst will be responsible for assessing, monitoring, and mitigating ... Bachelor's degree in Business Administration, Risk Management, Information Security, or a related ...

Showing results 21-40

Information Security Risk Analyst information

See Illinois salary details

$30

$56

$73

How much do information security risk analyst jobs pay per hour?

As of Jul 26, 2026, the average hourly pay for information security risk analyst in Illinois is $56.64, according to ZipRecruiter salary data. Most workers in this role earn between $44.04 and $63.61 per hour, depending on experience, location, and employer.

What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?

AspectInformation Security Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.

What are the key skills and qualifications needed to thrive as an Information Security Risk Analyst, and why are they important?

To thrive as an Information Security Risk Analyst, you need a solid understanding of cybersecurity principles, risk management frameworks, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like risk assessment platforms, vulnerability scanners, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, communication, and attention to detail help you translate complex risks into actionable recommendations and collaborate with stakeholders. These skills are crucial for effectively identifying, assessing, and mitigating security risks to protect organizational assets and ensure compliance.

What are Information Security Risk Analysts?

Information Security Risk Analysts are professionals responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze potential threats, vulnerabilities, and impacts to ensure that appropriate security measures are in place. These analysts often develop risk management strategies, conduct security assessments, and recommend security enhancements. Their goal is to help organizations protect sensitive information and comply with relevant regulations.

What Does an Information Security Risk Analyst Do?

As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.

How does an Information Security Risk Analyst typically collaborate with other departments to address security risks?

Information Security Risk Analysts work closely with various departments such as IT, compliance, legal, and business units to identify and mitigate security risks. They often facilitate risk assessments, communicate findings, and recommend solutions tailored to each department's needs. Regular meetings and cross-functional projects are common, ensuring security measures align with business objectives while maintaining compliance. This collaborative approach helps foster a culture of security awareness throughout the organization.
What are the most commonly searched types of Information Security Risk Analyst jobs in Illinois? The most popular types of Information Security Risk Analyst jobs in Illinois are:
What job categories do people searching Information Security Risk Analyst jobs in Illinois look for? The top searched job categories for Information Security Risk Analyst jobs in Illinois are:
What are popular job titles related to Information Security Risk Analyst jobs in IL? For Information Security Risk Analyst jobs in IL, the most frequently searched job titles are:
Infographic showing various Information Security Risk Analyst job openings in Illinois as of July 2026, with employment types broken down into 2% Locum Tenens, 84% Full Time, 9% Part Time, 1% Temporary, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $117,811 per year, or $56.6 per hour.
Risk Management Support Task Lead with Security Clearance

Risk Management Support Task Lead with Security Clearance

NexGen Data Systems, Inc.

Scott Air Force Base, IL • On-site

Other

Medical, Dental, Vision, Retirement, PTO

Posted 3 days ago


Job description

NexGen Data Systems is seeking a highly experienced Risk Management Support Task Lead to direct and execute comprehensive cybersecurity engineering and risk management operations for the United States Transportation Command (USTRANSCOM). The scope of this project is to provide comprehensive lifecycle implementation and assessment support for all phases of the DoD Risk Management Program (DoDI 8510.01) and NIST SP 800-37 Risk Management Framework (RMF) across internal enclaves, service networks, and commercial cloud environments. The Risk Management Support Task Leads functions as a top-level technical contributor and supervisor providing expert support, advanced research, and risk analysis into exceptionally complex problems and system architectures. The Task Lead is responsible for managing on-site deliverables, leading a team of specialized compliance and engineering professionals, and serving as the primary technical interface to the Cybersecurity Assessment Program to deliver highly innovative risk reduction solutions. Roles & Responsibilities:
• Manage complex on-site contract deliverables and coordinate directly with the Government functional lead to align team activities with combatant command priorities.
• Lead the technical execution of the RMF lifecycle across approximately 40 enterprise systems, independently evaluating security controls, tracking categorizations, and finalizing ATO packages.
• Reconstruct and recommend advanced cybersecurity software tools and assist in the development of tool requirements and product-specific STIGs derived from applicable DISA SRGs.
• Provide expert Information Systems Security Engineering (ISSE) lifecycle alignment in strict accordance with NIST SP 800-160 Volume I and Volume II trust and cyber resiliency models.
• Supervise the execution of weekly automated network vulnerability scanning (ACAS), continuous risk dashboard monitoring, and verification against DISA STIG/SRG baselines.
• Oversee the command’s Information Assurance Vulnerability Management (IAVM) program, managing the distribution of security alerts, tracking macro compliance trends, and processing complex POA&Ms.
• Serve as the lead technical expert for Software Assurance (SwA) code diagnostics, utilizing automated application scanning tools (such as Fortify) to evaluate source code, tune configurations to eliminate false positives, and publish annual summary analysis logs.
• Manage Security Control Assessor Representative (SCAR) workflows, performing rapid triage of all RMF-related submissions within strict 7-business-day service level thresholds.
• Coordinate across the Joint Deployment and Distribution Enterprise (JDDE) to facilitate technical data-sharing, evaluate system reciprocity, and manage DoD Ports, Protocols, and Services Management (PPSM) registries.
• Provide technical engineering oversight for the deployment of the Cybersecurity Readiness Framework (CRF), executing complex ETL data pipelines and analytics workloads using Databricks, Python, SQL, and Qlik. Other Duties: Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. Desired/Required Skills: • Active Department of Defense Top Secret/SCI (Tier 5 Investigation) required. • Travel on-site to Scott Airforce Base required one week per quarter. • Must satisfy DoD 8570.01-M / DoDM 8140.03 Information Assurance Management (IAM) Level III baseline qualification requirements (e.g., active CISSP, CISM, or GSLC) at the commencement of work.
• Must hold a validation/penetration testing credential (e.g., CEH, GPEN, LPT, or CEPT) and a Tenable Certified NESSUS Auditor (or ACAS equivalent) certification. • REQUIRED Foundational Qualification: Defense Cyber Crime Center (DC3) Cyber 101 course completion.
• Bachelor's degree or related technical training in Computer Science, Engineering, Information Management, or a related mission-area professional discipline required.
• A minimum of seven (7) years of progressive IT experience combined with at least five (5) years of direct, specialized Cybersecurity experience. • Tool Proficiency: Proven expert experience conducting CCRI-level evaluations and hands-on proficiency with tools including VULNERATOR, eMASS, ACAS/NESSUS, and HBSS (ePO, HIPS, AV).
• Technical Environment Savvy: Deep engineering knowledge of core computing environments across varying Operating Systems (Windows, Unix/Linux), Boundary Defenses (firewalls, routers), and Web/Database services (SQL Server, Oracle, Apache, IIS).
• Strong conceptual thinking and communication skills, with a documented track record of authoring high-fidelity Security Risk Assessments, standard operating procedures (SOPs), and technical analysis of alternatives (AoA) whitepapers. About the Company:
NexGen Data Systems is an emerging technologies focused company providing expert systems and network engineering solutions to the Department of Defense. NexGen Data Systems promotes a culture of knowledge and career advancement through continued learning, keeping our team current on the latest advances in systems and networking, and enabling our team to provide the best available solutions to our clients. Benefits: • Company covers 100% of premiums for the employee’s medical, dental, and vision insurance and subsidizes premiums for spouse and dependents.
• Company provides short and long term disability plans.
• 401(k) match up to 10% of the employee’s salary contributions to 401(K) plan.
• Comprehensive training and development program.
• 11 paid holidays and paid time off (PTO) accrual level starts at 15 days annually. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. NOTE: US Citizens and those authorized to work in the US are encouraged to apply. In order to be qualified for this position, you must be able to obtain and maintain a United States Department of Defense (DoD) security clearance. We are unable to sponsor Visas at this time. NexGen Data Systems provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws.