1

Information Security Risk Analyst Jobs in Raleigh, NC

Enterprise Risk Analyst

Durham, NC ยท On-site

$62K - $141K/yr

Enterprise Risk Analyst The Opportunity : As an experienced Risk Analyst, you will execute the VA ... CompTIA Security+, Risk Management Professional (CRISC), or Risk and Information Systems Control ...

Information security analyst experience performing risk analysis, documenting results and guiding best practice implementations * Information security analyst experience performing business ...

Information Security Officer

Durham, NC ยท Hybrid

$109.62K - $165K/yr

Direct risk assessments, security audits, penetration testing, and vulnerability management ... Analyzing complex risks and prioritizing investments in security. * Ability to: * Lead an ...

Network Security Engineer

Durham, NC ยท On-site

$101K - $138.20K/yr

... Information Security standards and practices - Internet security - LAN and or WAN routers and switches - Network security - Risk analysis - Routing protocols - BGP - OSPF - STP - IPV6 - MPLS ...

212406 Network Security Engineer

Durham, NC ยท On-site

$101K - $138.20K/yr

Information Security standards and practices * Internet security * LAN and or WAN routers and switches * Network security * Risk analysis * Routing protocols - BGP - OSPF - STP - IPV6 - MPLS

next page

Showing results 1-20

People also search for

Information Security Risk Analyst information

See Raleigh, NC salary details

$31

$56

$73

How much do information security risk analyst jobs pay per hour?

As of May 28, 2026, the average hourly pay for information security risk analyst in Raleigh, NC is $56.82, according to ZipRecruiter salary data. Most workers in this role earn between $44.18 and $63.80 per hour, depending on experience, location, and employer.

What Does an Information Security Risk Analyst Do?

As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.

What are the key skills and qualifications needed to thrive as an Information Security Risk Analyst, and why are they important?

To thrive as an Information Security Risk Analyst, you need a solid understanding of cybersecurity principles, risk management frameworks, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like risk assessment platforms, vulnerability scanners, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, communication, and attention to detail help you translate complex risks into actionable recommendations and collaborate with stakeholders. These skills are crucial for effectively identifying, assessing, and mitigating security risks to protect organizational assets and ensure compliance.

How does an Information Security Risk Analyst typically collaborate with other departments to address security risks?

Information Security Risk Analysts work closely with various departments such as IT, compliance, legal, and business units to identify and mitigate security risks. They often facilitate risk assessments, communicate findings, and recommend solutions tailored to each department's needs. Regular meetings and cross-functional projects are common, ensuring security measures align with business objectives while maintaining compliance. This collaborative approach helps foster a culture of security awareness throughout the organization.

What are Information Security Risk Analysts?

Information Security Risk Analysts are professionals responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze potential threats, vulnerabilities, and impacts to ensure that appropriate security measures are in place. These analysts often develop risk management strategies, conduct security assessments, and recommend security enhancements. Their goal is to help organizations protect sensitive information and comply with relevant regulations.

What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?

AspectInformation Security Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.

What are popular job titles related to Information Security Risk Analyst jobs in Raleigh, NC? For Information Security Risk Analyst jobs in Raleigh, NC, the most frequently searched job titles are:
What job categories do people searching Information Security Risk Analyst jobs in Raleigh, NC look for? The top searched job categories for Information Security Risk Analyst jobs in Raleigh, NC are:
Technical Specialist, Information Security Risk Analyst

Technical Specialist, Information Security Risk Analyst

InstantServe LLC

Raleigh, NC โ€ข On-site

Full-time

This job post hasย expired 1 day ago.ย Applications are no longer accepted.


Job description

Skills:
Experience in IT risk management, cybersecurity, or information security assessment. Highly desired 5 Years
Demonstrated knowledge of NIST SP 800-30, NIST SP 800-53 Rev. 5, and NIST Privacy Framework. Highly desired 5 Years
Experience performing security and privacy risk assessments with documentation aligned to federal and state standards. Highly desired 5 Years
Familiarity with HIPAA Security and Privacy Rules, and healthcare-specific risk domains. Highly desired 5 Years
Experience with HITRUST CSF alignment or certification preparation. Highly desired 5 Years
Strong written and verbal communication skills for technical and executive audiences. Highly desired 5 Years
Description:
This engagement ensures compliance with industry-standard frameworks, supports proactive risk mitigation, & positions NC HIEA for future HITRUST certification.Plan and conduct NC HIEA's annual enterprise security risk assessment using NIST SP 800-30, ISO 27005, or FAIR methodologies.
2. Ensure full alignment with NIST SP 800-53 Revision 5, including: RA (Risk Assessment), AC (Access Control), SC (System Communications Protection), IR (Incident Response), and more.
3. Incorporate NIST Privacy Framework and NIST SP 800-53 Rev. 5 privacy control families (AP, AR, DI, DM, IP, SE, TR, UL).
4. Build and maintain a comprehensive risk register, with treatment plans for mitigation, transfer, acceptance, or avoidance.
5. Map risks and mitigation efforts to HITRUST CSF control domains to support future certification
6. Develop and deliver documentation, dashboards, and executive summaries.
7. Collaborate with internal stakeholders to validate findings and support security governance efforts.

InstantServe logo

About InstantServe

Sourced by ZipRecruiter

InstantServe provides a one-stop solution to all Healthcare, IT/Non-IT Staffing needs. Established in 2016, InstantServe is a strong workforce of over 100+ go-getters with a demonstrated background in IT/Non-IT service. We are a nationally certified SBE from the Department of Administration (State of PA). As a proud Minority Woman Owned Small Business Enterprise (M/WBE), InstantServe boasts of a strong team of professionals who have extensive experience catering to several Federal, Public, Commercial, and Healthcare Clients which includes 26 States and 46 government agencies. InstantServe is a client-centric organization that offers cost-effective and reliable solutions. Client satisfaction is sacrosanct! Our team strives to provide the best staffing and IT solutions to take your business to the next level.

Industry

Recruiting and staffing services

Company size

11 - 50 Employees

Headquarters location

Wayne, PA, US

Year founded

2016

Social media