1

Information Security Risk Analyst Jobs in Maryland

$90 - $130/hr

... risk analysis. * A Master's Degree in Computer Science or IT Engineering is desired and may be substituted for 6 years of experience. * Knowledge of Federal, NSA, IC, and DoD Information Security ...

Senior Business Risk Analyst

Annapolis, MD ยท On-site

$125K - $145K/yr

More information is available at Crisis24 AiiA is seeking a Senior Business Risk Analyst with deep ... Information Security * Protect the data and systems of Crisis24 and its stakeholders by adhering to ...

$120 - $160/hr

The analyst will lead assigned cybersecurity, Information Assurance, RMF, vulnerability assessment ... Review vulnerability data, security documentation, risk assessments, andauthorizationartifacts for ...

$62K - $141K/yr

Risk Assessment Analyst The Opportunity: Cyber threats are everywhere, and the constantly evolving ... As an information security risk specialist on our team, you'll work with industry partners to ...

Showing results 21-40

Information Security Risk Analyst information

See Maryland salary details

$31

$56

$73

How much do information security risk analyst jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for information security risk analyst in Maryland is $56.73, according to ZipRecruiter salary data. Most workers in this role earn between $44.09 and $63.70 per hour, depending on experience, location, and employer.

What is an information security risk analyst?

Information Security Risk Analysts are professionals responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze potential threats, vulnerabilities, and impacts to ensure that appropriate security measures are in place. These analysts often develop risk management strategies, conduct security assessments, and recommend security enhancements. Their goal is to help organizations protect sensitive information and comply with relevant regulations.

What does an information security risk analyst do?

As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.

What are the key skills and qualifications needed to thrive as an information security risk analyst, and why are they important?

To thrive as an Information Security Risk Analyst, you need a solid understanding of cybersecurity principles, risk management frameworks, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like risk assessment platforms, vulnerability scanners, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, communication, and attention to detail help you translate complex risks into actionable recommendations and collaborate with stakeholders. These skills are crucial for effectively identifying, assessing, and mitigating security risks to protect organizational assets and ensure compliance.

How does an information security risk analyst typically collaborate with other departments to address security risks?

Information Security Risk Analysts work closely with various departments such as IT, compliance, legal, and business units to identify and mitigate security risks. They often facilitate risk assessments, communicate findings, and recommend solutions tailored to each department's needs. Regular meetings and cross-functional projects are common, ensuring security measures align with business objectives while maintaining compliance. This collaborative approach helps foster a culture of security awareness throughout the organization.

What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?

AspectInformation Security Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.

What are the most commonly searched types of Information Security Risk Analyst jobs in Maryland?

The most popular types of Information Security Risk Analyst jobs in Maryland are:

What are popular job titles related to Information Security Risk Analyst jobs in Maryland?

For Information Security Risk Analyst jobs in Maryland, the most frequently searched job titles are:

What job categories do people searching Information Security Risk Analyst jobs in Maryland look for?

The top searched job categories for Information Security Risk Analyst jobs in Maryland are:

What cities in Maryland are hiring for Information Security Risk Analyst jobs?

Cities in Maryland with the most Information Security Risk Analyst job openings:

Infographic showing various Information Security Risk Analyst job openings in Maryland as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 18% Part Time, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $117,995 per year, or $56.7 per hour.

Information Security Analyst Lead

eSimplicity

Fort George G Meade, MD โ€ข On-site

$112K - $150K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 7 days ago


Key responsibilities

  • Provide security support services to ensure systems meet security control compliance requirements.

  • Facilitate security tool and control implementation, usage, and compliance, including maintaining security documentation.

  • Coordinate and respond to security-related inquiries, monitor cybersecurity posture, and support vulnerability assessments and remediation.


Job description

Description:


About Us:
eSimplicity is modern digital services company that work across government, partnering with our clients to improve the lives and ensure the security of all Americans—from soldiers and veteran to kids and the elderly, and defend national interests on the battlefield. Our engineers, designers and strategist cut through complexity to create intuitive products and services that equip Federal agencies with solutions to courageously transform today for a better tomorrow for all Americans. 


Purpose of Scope: 

We are seeking an Information Security Analyst who is responsible for providing security support services while meeting security control compliance requirements for a portfolio of systems at various states of maturity and modernization. This role will provide support for continuously monitoring the cybersecurity posture of systems to secure against cyber threats. 


 The primary responsibility is to facilitate security tool and control implementation, security tool usage, and ensure tools and controls remain compliant and configured properly, all the while ensuring a successful program Authorization to Operate (ATO). Additionally, the expectation is to take ownership of communication and visualization of security issues, especially where coordination between product teams, information owners, engineering, and infrastructure staff is necessary for remediation. 


 The candidate will own coordination and response to the agency’s security-related inquiries, compliance with agency policy, security controls, and the maintenance of security documentation and artifacts. You will function as the primary liaison to provide timely and accurate responses to security-related data calls (System Security & Compliance Status, Vulnerability, and Compliance scanning issues) and provide security guidance throughout the system development lifecycle. This role requires interfacing with multiple stakeholders through multiple touchpoints weekly. 


Responsibilities: 

  • Work closely with the Product Owners, ISSOs, engineering and infrastructure staff to provide guidance on implementation if security policies, standards, and procedures 
  • Analyze new or updated security requirements, collaborate with stakeholders, and develop responses that are clear and accurate. 
  • Support the review and update of ATO artifacts such as System Security Plans, Information System Contingency Plans, Configuration and Change Management Plans, Incident Response Plans, Privacy Impact Analysis, and more. 
  • Interpret security risk assessment, review security scan results, assess security vulnerabilities and support the development and remediation of vulnerability and compliance issues via Plan of Action and Milestones (POA&Ms). 
  • Support the development of implementation and design documentation relating to security feature implementation. 
  • Work with engineering and infrastructure personnel to document remediation for vulnerabilities and non-compliance issues. 
  • Analyze and interpret agency security requirements and provide governance communication to non-security personnel. 
  • Collaborate with product teams, ISSOs and other stakeholders in support of continuous monitoring and ATO efforts. 
  • Conducts vulnerability assessments and monitors systems, networks, databases and Web-based assets for potential system breaches. Recommends and takes the lead on implementing changes to enhance security systems, prevent unauthorized access, and help mitigate security vulnerabilities. 
  • Responds to alerts from information security tools. Reports, investigates, and resolves higher level security incidents. 
  • Responds to security tool outages, degradations in service, tune security rules and alerts, and setup/maintain security tool dashboards and reporting. 
  • Research security trends, new methods, and techniques used in unauthorized access of data to preemptively eliminate the possibility of system breach. Ensures compliance with regulations and privacy laws. Conducts research to identify new attack vectors. 
  • Educates and communicates security requirements and procedures to all users and new employees. 
  • Recommend process improvements to the information system for risk mitigation. 
  • Applies iterative security automation to all program aspects increasing overall security posture iteratively and never accepts the status quo. 
  • Provide audit log review in Splunk, present any findings to ISSO, and plan for any investigation or remediation activities. 
  • Periodic user and privileged access reviews. 


Requirements:

Requirements 

Required Qualifications: 

  • Minimum of eight years of experience in cybersecurity architecture, cloud security, DevSecOps, security engineering, or a related technical field. Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related field preferred but not required. 
  • Must hold a current Security+ certification.
  • Experience designing security "baked-in" to architectures including Cloud and IaC, applications, web applications, data processing, data-centric applications, AI/ML, and CI/CD pipelines. 
  • A proven track record 
  • Familiarity with Agile methodologies. 
  • Working knowledge of AWS or Azure security tools, their functionality, and their purpose. 
  • Ability to assist customers with defining appropriate management processes (responsible for documenting application criticality, privacy, and security impact analysis). 
  • Knowledge of hardening standards (DISA STIG, CIS). 
  • Experience with the NIST Risk Management Framework, NIST 800-53 rev5, and NIST 800-171. 
  • Active secret clearance. 

Desired Qualifications: 

  • Federal Government contracting work experience. 
  • Experience as an ISSO for the DoD. 
  • Highly preferred industry certifications such as CISSP, CEH, GIAC, etc. 
  • Experience with Security Information and Event Management (SIEM) systems (e.g., Splunk). 

Location and Hours 

Location: This role is primarily remote; however, the employee must be able to report on-site to Fort Meade, MD when requested due to customer or business needs. The frequency and timing of on-site support may vary and cannot be guaranteed in advance. 


Hours: Expected hours are 9:00 AM to 5:00 PM Eastern Time unless otherwise directed by your manager. 

Travel: Occasional travel for training and project meetings, estimated to be less than 5% per year. 


Benefits:

eSimplicity offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k) retirement benefits, paid time off, paid holidays, life and disability insurance, and additional wellness and employee support programs. Eligibility may vary based on employment status and applicable plan terms.

Reasonable Accommodation:

eSimplicity is committed to providing reasonable accommodations to qualified individuals with disabilities during the application and hiring process. Applicants who need assistance or an accommodation should contact Human Resources.

Equal Employment Opportunity:
eSimplicity is an Equal Opportunity Employer, including disability and protected veteran status. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other legally protected status.