1

Information Security Risk Analyst Jobs in Baltimore, MD

Physical Security & Risk Analyst

Owings Mills, MD

$105K - $125K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you ...

Compliance & Risk Analyst

Owings Mills, MD · On-site

$30 - $34/hr

  • Medical

  • Dental

  • Vision

  • Retirement

Compliance & Risk Analyst (Audit & Controls) Location-Type: Hybrid (Owings Mills, MD - 2 Days ... Certified Information Security Manager (CISM)

Cybersecurity GRC * IT Risk Management * Information Security Compliance * Security Governance ... Cybersecurity GRC Analyst * Information Security Analyst (Governance/Risk) * IT Risk Analyst

New

1640 - Information Security Analyst

Belcamp, MD

$85K - $101K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army ... Conduct vulnerability assessments, risk analysis, and incident responses. * Actively monitor ...

1640 - Information Security Analyst

Belcamp, MD · On-site

$85K - $101K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army ... Conduct vulnerability assessments, risk analysis, and incident responses. * Actively monitor ...

1640 - Information Security Analyst

Belcamp, MD · On-site

$85K - $101K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army ... Conduct vulnerability assessments, risk analysis, and incident responses. * Actively monitor ...

The ideal candidate is a seasoned analyst with deep expertise in both corporate risk and financial ... Information Security Protect the data and systems of Crisis24 and its stakeholders by adhering to ...

next page

Showing results 1-20

Information Security Risk Analyst information

See Baltimore, MD salary details

$31

$58

$75

How much do information security risk analyst jobs pay per hour?

As of Aug 14, 2026, the average hourly pay for information security risk analyst in Baltimore, MD is $58.08, according to ZipRecruiter salary data. Most workers in this role earn between $45.14 and $65.19 per hour, depending on experience, location, and employer.

What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?

AspectInformation Security Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.

What are the key skills and qualifications needed to thrive as an information security risk analyst, and why are they important?

To thrive as an Information Security Risk Analyst, you need a solid understanding of cybersecurity principles, risk management frameworks, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like risk assessment platforms, vulnerability scanners, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, communication, and attention to detail help you translate complex risks into actionable recommendations and collaborate with stakeholders. These skills are crucial for effectively identifying, assessing, and mitigating security risks to protect organizational assets and ensure compliance.

What is an information security risk analyst?

Information Security Risk Analysts are professionals responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze potential threats, vulnerabilities, and impacts to ensure that appropriate security measures are in place. These analysts often develop risk management strategies, conduct security assessments, and recommend security enhancements. Their goal is to help organizations protect sensitive information and comply with relevant regulations.

What does an information security risk analyst do?

As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.

How does an information security risk analyst typically collaborate with other departments to address security risks?

Information Security Risk Analysts work closely with various departments such as IT, compliance, legal, and business units to identify and mitigate security risks. They often facilitate risk assessments, communicate findings, and recommend solutions tailored to each department's needs. Regular meetings and cross-functional projects are common, ensuring security measures align with business objectives while maintaining compliance. This collaborative approach helps foster a culture of security awareness throughout the organization.

What are popular job titles related to Information Security Risk Analyst jobs in Baltimore, MD?

For Information Security Risk Analyst jobs in Baltimore, MD, the most frequently searched job titles are:

What job categories do people searching Information Security Risk Analyst jobs in Baltimore, MD look for?

The top searched job categories for Information Security Risk Analyst jobs in Baltimore, MD are:

What cities near Baltimore, MD are hiring for Information Security Risk Analyst jobs?

Cities near Baltimore, MD with the most Information Security Risk Analyst job openings:

Infographic showing various Information Security Risk Analyst job openings in Baltimore, MD as of August 2026, with employment types broken down into 1% As Needed, 78% Full Time, 19% Part Time, and 2% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $120,803 per year, or $58.1 per hour.

Physical Security & Risk Analyst

GFT.

Owings Mills, MD

$105K - $125K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 7 days ago


Job description

GFT is seeking a Physical Security & Risk Analyst to join our Security and Safety Team in Mechanicsburg, PA or Baltimore, MD! This role follows a hybrid work model, requiring regular attendance at the office.

What you'll be challenged to do:As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you will combine security expertise, risk analysis, systems thinking, and project leadership to assess vulnerabilities, integrate protective solutions, and develop strategies that ensure mission continuity in an evolving threat environment.This position is ideal for professionals who enjoy solving complex challenges at the intersection of physical security, operational resilience, emergency preparedness, and integrated risk management.

In this capacity, the successful candidate will be responsible for the following: 

  • Conduct physical security assessments, threat and vulnerability analyses, and risk evaluations for facilities, infrastructure, and critical operations.
  • Support mission assurance initiatives by identifying risks that could impact organizational objectives, operational continuity, and critical functions.
  • Evaluate and integrate physical security, safety, operational, cyber-physical, and emergency preparedness considerations into comprehensive risk management strategies.
  • Perform site visits, facility walkdowns, stakeholder interviews, and field assessments to validate conditions and identify vulnerabilities.
  • Develop practical, risk-informed recommendations that improve protection, resilience, and operational effectiveness.
  • Support systems integration efforts, ensuring that security technologies, operational processes, personnel, and protective measures work together effectively to achieve mission objectives.
  • Research emerging threats and industry best practices to strengthen infrastructure protection and resilience programs.
  • Prepare technical reports, risk assessments, presentations, and client-facing deliverables.
  • Collaborate with multidisciplinary teams, clients, and stakeholders to develop integrated security and resilience solutions.
  • Assist with or lead projects, including scope development, scheduling, budgeting, resource coordination, and delivery management.
What you will bring to our firm: 
  • Bachelor's degree in Security Management, Risk Management, Emergency Management, Criminal Justice, Engineering, Homeland Security, Public Administration, Infrastructure Protection, or a related field.
  • 10+ years of experience in physical security, infrastructure protection, mission assurance, emergency management, resilience planning, risk assessment, cyber-physical security, or related disciplines.
  • Strong understanding of physical security principles, threat and vulnerability assessment methodologies, risk management frameworks, and continuity planning.
  • Experience supporting mission assurance, business continuity, operational resilience, or critical infrastructure protection programs.
  • Knowledge of integrated security systems and the ability to evaluate how people, processes, technology, and facilities work together to mitigate risk and support organizational objectives.
  • Experience conducting facility assessments, field observations, stakeholder engagement, and developing actionable risk-based recommendations.
  • Excellent written and verbal communication skills, including technical writing, presentations, and client engagement.
  • Strong organizational, analytical, and project management capabilities.
  • Proficiency with Microsoft Office, including Word, Excel, PowerPoint, and Outlook.
 What we prefer you bring: 
  • Professional certifications such as PSP, CPP, APP, CPTED, CEM, PMP, PE, or other relevant security, emergency management, resilience, or project management credentials.
  • Experience supporting critical infrastructure, utilities, government, defense, transportation, or other mission-critical environments.
  • Experience integrating security, safety, emergency management, and operational risk management programs.
  • Experience leading multidisciplinary teams and managing complex projects.
 Compensation:The salary range for this role is $105,000 - $125,000. Salary is dependent upon experience and geographic location. Featured Benefits:  Hybrid (in-person and remote) work environment. Comprehensive benefits package including wellness programs, parental leave, and pet insurance, in addition to medical, dental, vision, disability, and life insurance. Tax-deferred 401(k) savings plan. Competitive paid-time-off (PTO) accrual. Tuition reimbursement for continued education. Commitment to professional development, access to internal and external training programs, and support of active participation in professional organizations Incentive compensation for eligible positions.

At GFT, a privately held AEC firm, we innovate where transportation, water, power, and buildings converge. We call this the Infrastructure of Life. We measure our success by the strength of our relationships - that's why we're the employer of choice for 5,000+ of the industry's brightest engineers, planners, architects, inspectors, designers, and more.

Our clients choose us for our expertise and prefer us for our nimble approach, creativity, and personal touch. Backed by over a century's experience, together we're building a lasting legacy for future generations: stronger communities, a healthier planet, and better lives.GFT: Ingenuity That Shapes Lives is an Equal Opportunity Employer. All qualified candidates will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veterans' status or other characteristics protected by law.

Unsolicited resumes from third party agencies will be considered the property GFT.

GFT does require the successful completion of a criminal background check for all advertised positions. 

Location: Mechanicsburg, PA, Owings Mills, MDCore Business Hours: 8:00 AM - 5:00 PMEmployment Status: Full-Time

#LI-KV1

#LI-hybrid

Employment Type: FULL_TIME