... risk analysis into exceptionally complex problems and system architectures. The Task Lead is ... Provide expert Information Systems Security Engineering (ISSE) lifecycle alignment in strict ...
... risk analysis into exceptionally complex problems and system architectures. The Task Lead is ... Provide expert Information Systems Security Engineering (ISSE) lifecycle alignment in strict ...
The Risk & Compliance Analyst safeguards organizational assets and ensures regulatory compliance by ... Continuously monitor security operations to identify and address potential threats and verify ...
The Risk & Compliance Analyst safeguards organizational assets and ensures regulatory compliance by ... Continuously monitor security operations to identify and address potential threats and verify ...
Principal Information Security Risk Management - AI
Chicago, IL · Hybrid
$221K - $276K/yr
The Principal Information Security Risk Management, AI is responsible for ensuring enterprise-wide Generative AI (GenAI), Agentic AI, LLMs, and ML security programs are effective, risk-aligned, and ...
Principal Information Security Risk Management - AI
Chicago, IL · Hybrid
$221K - $276K/yr
The Principal Information Security Risk Management, AI is responsible for ensuring enterprise-wide Generative AI (GenAI), Agentic AI, LLMs, and ML security programs are effective, risk-aligned, and ...
Risk & Compliance Analyst (IT)
Springfield, IL · On-site
$50K - $65K/yr
The Risk & Compliance Analyst safeguards organizational assets and ensures regulatory compliance by ... Continuously monitor security operations to identify and address potential threats and verify ...
Risk & Compliance Analyst (IT)
Springfield, IL · On-site
$50K - $65K/yr
The Risk & Compliance Analyst safeguards organizational assets and ensures regulatory compliance by ... Continuously monitor security operations to identify and address potential threats and verify ...
The Risk & Compliance Analyst safeguards organizational assets and ensures regulatory compliance by ... Continuously monitor security operations to identify and address potential threats and verify ...
The Risk & Compliance Analyst safeguards organizational assets and ensures regulatory compliance by ... Continuously monitor security operations to identify and address potential threats and verify ...
IT DSS Security and Compliance JOB SUMMARY: NORC at the University of Chicago seeks Senior IT Risk and Compliance Analyst to join our DSS Security and Compliance group. The successful candidate will ...
IT DSS Security and Compliance JOB SUMMARY: NORC at the University of Chicago seeks Senior IT Risk and Compliance Analyst to join our DSS Security and Compliance group. The successful candidate will ...
Assess the adequacy of severity ratings, root cause analyses, action plans, and closure evidence ... Focus: Enterprise Technologyand Information SecurityRisk * Provide independentchallengeand ...
Assess the adequacy of severity ratings, root cause analyses, action plans, and closure evidence ... Focus: Enterprise Technologyand Information SecurityRisk * Provide independentchallengeand ...
IL · On-site
Lead teams executing Information Systems Security Engineering (ISSE), security control assessments ... Conduct advanced security analysis using validated DoD cybersecurity processes and toolsets.
IL · On-site
Lead teams executing Information Systems Security Engineering (ISSE), security control assessments ... Conduct advanced security analysis using validated DoD cybersecurity processes and toolsets.
The Security Risk and Compliance Analyst conducts third-party security risk and compliance reviews for technology and software procurements used by faculty, staff, and researchers. This includes ...
The Security Risk and Compliance Analyst conducts third-party security risk and compliance reviews for technology and software procurements used by faculty, staff, and researchers. This includes ...
Lead teams executing Information Systems Security Engineering (ISSE), security control assessments ... Conduct advanced security analysis using validated DoD cybersecurity processes and toolsets.
Quick apply
Lead teams executing Information Systems Security Engineering (ISSE), security control assessments ... Conduct advanced security analysis using validated DoD cybersecurity processes and toolsets.
The Information Security Analyst interacts with Cyber Security Team and those on contractor ... Prepares packages/risk assessments for accreditation, reaccreditation and self-assess processes of ...
The Information Security Analyst interacts with Cyber Security Team and those on contractor ... Prepares packages/risk assessments for accreditation, reaccreditation and self-assess processes of ...
Through strong partnerships with technology and risk stakeholders, the ISO will help ensure focus on the most critical information security risk priorities. Acting as a day-to-day point of contact ...
Through strong partnerships with technology and risk stakeholders, the ISO will help ensure focus on the most critical information security risk priorities. Acting as a day-to-day point of contact ...
Additionally, this role provides independent oversight of firstline technology and information security activities, leveraging strong analytical expertise and sound risk judgment to assess, challenge ...
Additionally, this role provides independent oversight of firstline technology and information security activities, leveraging strong analytical expertise and sound risk judgment to assess, challenge ...
Risk Analyst
Chicago, IL · On-site
The Enterprise Risk Analyst supports the development, implementation, and continuous enhancement of ... Engage with underwriting, claims, actuarial, finance, IT, and legal & compliance teams to embed ...
Risk Analyst
Chicago, IL · On-site
The Enterprise Risk Analyst supports the development, implementation, and continuous enhancement of ... Engage with underwriting, claims, actuarial, finance, IT, and legal & compliance teams to embed ...
Information Security & Technology Mgr, Sr
Chicago, IL · On-site
$199K/yr
Additionally, this role provides independent oversight of firstline technology and information security activities, leveraging strong analytical expertise and sound risk judgment to assess, challenge ...
Information Security & Technology Mgr, Sr
Chicago, IL · On-site
$199K/yr
Additionally, this role provides independent oversight of firstline technology and information security activities, leveraging strong analytical expertise and sound risk judgment to assess, challenge ...
The Security Engineer - Risk & Vulnerability Management is a key member of the Information Security ... Analyze business impact, threat landscape, and vulnerability data to determine overall risk posture.
The Security Engineer - Risk & Vulnerability Management is a key member of the Information Security ... Analyze business impact, threat landscape, and vulnerability data to determine overall risk posture.
... risk posture of CPS. This role leads the information security and operations teams. This is a ... gap analysis and other comprehensive internal assessments of existing systems to improve the ...
... risk posture of CPS. This role leads the information security and operations teams. This is a ... gap analysis and other comprehensive internal assessments of existing systems to improve the ...
Executive Director, Information Security
Chicago, IL · On-site
$150K - $179K/yr
... risk posture of CPS. This role leads the information security and operations teams. This is a ... gap analysis and other comprehensive internal assessments of existing systems to improve the ...
Executive Director, Information Security
Chicago, IL · On-site
$150K - $179K/yr
... risk posture of CPS. This role leads the information security and operations teams. This is a ... gap analysis and other comprehensive internal assessments of existing systems to improve the ...
... • Analyze business impact, threat landscape, and vulnerability data to determine overall risk ... Required : • Bachelor's degree in Computer Science, Information Security, or a related field. • ...
... • Analyze business impact, threat landscape, and vulnerability data to determine overall risk ... Required : • Bachelor's degree in Computer Science, Information Security, or a related field. • ...
Vendor Risk Analyst
Chicago, IL · On-site +1
The Vendor Risk Management Analyst will be responsible for assessing, monitoring, and mitigating ... Bachelor's degree in Business Administration, Risk Management, Information Security, or a related ...
Vendor Risk Analyst
Chicago, IL · On-site +1
The Vendor Risk Management Analyst will be responsible for assessing, monitoring, and mitigating ... Bachelor's degree in Business Administration, Risk Management, Information Security, or a related ...
Information Security Risk Analyst information
See Illinois salary details
$30.98 - $34.81
6% of jobs
$34.81 - $38.65
5% of jobs
$38.65 - $42.48
8% of jobs
$44.30 is the 25th percentile. Wages below this are outliers.
$42.48 - $46.31
11% of jobs
$46.31 - $50.15
12% of jobs
The median wage is $53.74 / hr.
$50.15 - $53.98
8% of jobs
$53.98 - $57.81
7% of jobs
$57.81 - $61.64
9% of jobs
$63.38 is the 75th percentile. Wages above this are outliers.
$61.64 - $65.48
17% of jobs
$65.48 - $69.31
8% of jobs
$69.31 - $73.14
7% of jobs
$30
$56
$73
How much do information security risk analyst jobs pay per hour?
What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?
| Aspect | Information Security Risk Analyst | Cybersecurity Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment teams, compliance departments | Security operations centers, incident response teams |
| Employer & Industry Usage | Financial, healthcare, government sectors | Tech companies, cybersecurity firms, enterprises |
While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.
What are the key skills and qualifications needed to thrive as an Information Security Risk Analyst, and why are they important?
What are Information Security Risk Analysts?
What Does an Information Security Risk Analyst Do?
As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.
How does an Information Security Risk Analyst typically collaborate with other departments to address security risks?

Risk Management Support Task Lead with Security Clearance
Scott Air Force Base, IL • On-site
Other
Medical, Dental, Vision, Retirement, PTO
Posted 3 days ago
Job description
• Manage complex on-site contract deliverables and coordinate directly with the Government functional lead to align team activities with combatant command priorities.
• Lead the technical execution of the RMF lifecycle across approximately 40 enterprise systems, independently evaluating security controls, tracking categorizations, and finalizing ATO packages.
• Reconstruct and recommend advanced cybersecurity software tools and assist in the development of tool requirements and product-specific STIGs derived from applicable DISA SRGs.
• Provide expert Information Systems Security Engineering (ISSE) lifecycle alignment in strict accordance with NIST SP 800-160 Volume I and Volume II trust and cyber resiliency models.
• Supervise the execution of weekly automated network vulnerability scanning (ACAS), continuous risk dashboard monitoring, and verification against DISA STIG/SRG baselines.
• Oversee the command’s Information Assurance Vulnerability Management (IAVM) program, managing the distribution of security alerts, tracking macro compliance trends, and processing complex POA&Ms.
• Serve as the lead technical expert for Software Assurance (SwA) code diagnostics, utilizing automated application scanning tools (such as Fortify) to evaluate source code, tune configurations to eliminate false positives, and publish annual summary analysis logs.
• Manage Security Control Assessor Representative (SCAR) workflows, performing rapid triage of all RMF-related submissions within strict 7-business-day service level thresholds.
• Coordinate across the Joint Deployment and Distribution Enterprise (JDDE) to facilitate technical data-sharing, evaluate system reciprocity, and manage DoD Ports, Protocols, and Services Management (PPSM) registries.
• Provide technical engineering oversight for the deployment of the Cybersecurity Readiness Framework (CRF), executing complex ETL data pipelines and analytics workloads using Databricks, Python, SQL, and Qlik. Other Duties: Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. Desired/Required Skills: • Active Department of Defense Top Secret/SCI (Tier 5 Investigation) required. • Travel on-site to Scott Airforce Base required one week per quarter. • Must satisfy DoD 8570.01-M / DoDM 8140.03 Information Assurance Management (IAM) Level III baseline qualification requirements (e.g., active CISSP, CISM, or GSLC) at the commencement of work.
• Must hold a validation/penetration testing credential (e.g., CEH, GPEN, LPT, or CEPT) and a Tenable Certified NESSUS Auditor (or ACAS equivalent) certification. • REQUIRED Foundational Qualification: Defense Cyber Crime Center (DC3) Cyber 101 course completion.
• Bachelor's degree or related technical training in Computer Science, Engineering, Information Management, or a related mission-area professional discipline required.
• A minimum of seven (7) years of progressive IT experience combined with at least five (5) years of direct, specialized Cybersecurity experience. • Tool Proficiency: Proven expert experience conducting CCRI-level evaluations and hands-on proficiency with tools including VULNERATOR, eMASS, ACAS/NESSUS, and HBSS (ePO, HIPS, AV).
• Technical Environment Savvy: Deep engineering knowledge of core computing environments across varying Operating Systems (Windows, Unix/Linux), Boundary Defenses (firewalls, routers), and Web/Database services (SQL Server, Oracle, Apache, IIS).
• Strong conceptual thinking and communication skills, with a documented track record of authoring high-fidelity Security Risk Assessments, standard operating procedures (SOPs), and technical analysis of alternatives (AoA) whitepapers. About the Company:
NexGen Data Systems is an emerging technologies focused company providing expert systems and network engineering solutions to the Department of Defense. NexGen Data Systems promotes a culture of knowledge and career advancement through continued learning, keeping our team current on the latest advances in systems and networking, and enabling our team to provide the best available solutions to our clients. Benefits: • Company covers 100% of premiums for the employee’s medical, dental, and vision insurance and subsidizes premiums for spouse and dependents.
• Company provides short and long term disability plans.
• 401(k) match up to 10% of the employee’s salary contributions to 401(K) plan.
• Comprehensive training and development program.
• 11 paid holidays and paid time off (PTO) accrual level starts at 15 days annually. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. NOTE: US Citizens and those authorized to work in the US are encouraged to apply. In order to be qualified for this position, you must be able to obtain and maintain a United States Department of Defense (DoD) security clearance. We are unable to sponsor Visas at this time. NexGen Data Systems provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws.
About NexGen Data Systems
Sourced by ZipRecruiter
Industry
It services
Company size
11 - 50 Employees
Headquarters location
Goose Creek, SC, US
Year founded
2005