1

Information Security Risk Analyst Jobs in Raleigh, NC

Principally works, under limited supervision, with Corporate Information Security (CIS) personnel ... Analysts, Systems Engineers, other Solutions Architects, and application development teams. 2.

Principally works, under limited supervision, with Corporate Information Security (CIS) personnel ... Analysts, Systems Engineers, other Solutions Architects, and application development teams. 2.

Our direct client has a new opening for a Lead Security Analyst 141809 This job is 14 months to ... Top 3 Skills: 5 to 7 years of experience in a leadership role, information security, relationship ...

... Indicators and UHS Risk Management reporting requirements. • Maintains current knowledge of ... information (e.g., Social Security Number, credit card or bank information, etc.) from you via ...

... Risk Management reporting requirements. · Maintains current knowledge of federal updates for CORE ... information (e.g., Social Security Number, credit card or bank information, etc.) from you via ...

You will report to the IT Security & Governance Manager and will have an onsite work structure in ... Experience in risk management and compliance * In-depth experience with Microsoft 365 suite of ...

next page

Showing results 1-20

People also search for

Information Security Risk Analyst information

See Raleigh, NC salary details

$31

$56

$73

How much do information security risk analyst jobs pay per hour?

As of May 29, 2026, the average hourly pay for information security risk analyst in Raleigh, NC is $56.82, according to ZipRecruiter salary data. Most workers in this role earn between $44.18 and $63.80 per hour, depending on experience, location, and employer.

What Does an Information Security Risk Analyst Do?

As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.

What are the key skills and qualifications needed to thrive as an Information Security Risk Analyst, and why are they important?

To thrive as an Information Security Risk Analyst, you need a solid understanding of cybersecurity principles, risk management frameworks, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like risk assessment platforms, vulnerability scanners, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, communication, and attention to detail help you translate complex risks into actionable recommendations and collaborate with stakeholders. These skills are crucial for effectively identifying, assessing, and mitigating security risks to protect organizational assets and ensure compliance.

How does an Information Security Risk Analyst typically collaborate with other departments to address security risks?

Information Security Risk Analysts work closely with various departments such as IT, compliance, legal, and business units to identify and mitigate security risks. They often facilitate risk assessments, communicate findings, and recommend solutions tailored to each department's needs. Regular meetings and cross-functional projects are common, ensuring security measures align with business objectives while maintaining compliance. This collaborative approach helps foster a culture of security awareness throughout the organization.

What are Information Security Risk Analysts?

Information Security Risk Analysts are professionals responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze potential threats, vulnerabilities, and impacts to ensure that appropriate security measures are in place. These analysts often develop risk management strategies, conduct security assessments, and recommend security enhancements. Their goal is to help organizations protect sensitive information and comply with relevant regulations.

What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?

AspectInformation Security Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.

What are popular job titles related to Information Security Risk Analyst jobs in Raleigh, NC? For Information Security Risk Analyst jobs in Raleigh, NC, the most frequently searched job titles are:
What job categories do people searching Information Security Risk Analyst jobs in Raleigh, NC look for? The top searched job categories for Information Security Risk Analyst jobs in Raleigh, NC are:
Cybersecurity Senior Architect

Cybersecurity Senior Architect

Truist

Raleigh, NC

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 25 days ago


Truist rating

8.3

Company rating: 8.3 out of 10

Based on 109 frontline employees who took The Breakroom Quiz

33rd of 141 rated banks


Job description

The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.

Need Help?

If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).

Regular or Temporary:

Regular

Language Fluency: English (Required)

Work Shift:

1st shift (United States of America)Please review the following job description:Derive security specifications from business requirements, and design security solutions that support core organizational functions, and assure their confidentiality, integrity and high availability. Gain organizational commitment for security infrastructure systems and software plans, as well as assist to evaluate and select security technologies required to complete those plans. Provide integrated infrastructure-related technical expertise across the organization, from conceptualization and project planning to the post-implementation support level. Principally works, under limited supervision, with Corporate Information Security (CIS) personnel, Line of Business (LOB) personnel, external vendors, and internal IT Services personnel including Enterprise Architects, Application & Data Services personnel and other IT Operations Services teams. Security Solution Architects develop security specifications, requirements and architecture artifacts in compliance with corporate standards, laws and regulations for architecture adherence and performance guidelines.

Essential Duties and Responsibilities

Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.

1. Provide security infrastructure solution expertise, requirements, and assistance to Systems Analysts, Systems Engineers, other Solutions Architects, and application development teams.

2.Confer with end-users, clients, or senior management to define security infrastructure requirements for complex systems and infrastructure development.

3. Design and oversee development and implementation of end-to-end integrated security infrastructure solutions and communicate needs for investing in infrastructure evolution, including analysis of cost reduction opportunities.

4. Make recommendations for improvements and/or alternatives for the company's existing solution architecture and technology portfolio.

5. Create and maintain system security context and preliminary system security concept of operations and define baseline system security requirements in accordance with applicable regulations and standards.

6. Liaison with Enterprise Architects to conduct research on emerging technologies, and recommend technologies that will provide right-sized security posture, operational efficiency, infrastructure flexibility and operational stability.

7. Mentors less experienced teammates to build their own technical expertise.

8. Demonstrate deep specialization or comprehensive knowledge in Information Security (InfoSec) technology and practices necessary to negotiate and persuade technology direction on security principals and tenets such as confidentiality, integrity, availability, authentication and non-repudiation.

9. Perform security reviews, identify gaps in security architecture and develop security risk management plans.

Qualifications

Required Qualifications:

The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

1. Bachelor's degree in a technical or business field, or equivalent education and related training

2. Eight years of demonstrated experience of systems engineering and/or architecture in at least one of the information security areas: network security, access management, end point protection, data loss prevention, vulnerability management, application security, forensics, web security, mainframe, incident response and/or cyber threat management in a medium to large corporation

3. Highly experienced in network security architecture, including design tools, methods, and techniques and the application of Defense-in-Depth principles; knowledge of network design processes, including understanding of security objectives

4. Specialized depth and thorough Knowledge of The Open Group Architecture Framework (TOGAF), including infrastructure, data, information security, applications, architectural concepts, and associated disciplines

5. Deep knowledge of:

  • Mainframe security, including access control, monitoring, integration with non-mainframe technologies, and virtualization;

  • Authentication and authorization technologies including remote access;

  • Application security and the security development lifecycle and ability to apply to client-server and web-based application development environments;

  • Enterprise databases and database security, including database activity monitoring and database access control technologies;

  • Encryption methods and technologies for data-in-transit and data-at-rest scenarios;

  • Incident response processes;

  • Denial of Service prevention mechanisms;

  • Firewall technologies and intrusion prevention methods;

  • Cloud technologies and hosting;

  • Operating system hardening;

  • Virtualization technologies;

  • Mobile technologies;

  • Encryption and key management technologies;

  • Endpoint Protection (includes malware);

  • Data Loss Protection technologies

6. Experience with peripheral component interconnect and other security audit processes, evidence gathering and development/management of remediation plans used in resolution of finding

Preferred Qualifications:

1. Degree in a related field from an accredited program or equivalent experience

2. Industry certifications in cyber security and forensics, such as CISSP, CFCE, GCFE, GCFA, GCIH and other related credentials preferred

3. Industry certifications in general technology (MCP, MCSE, Network+, etc)

4. Industry certifications in networking, such as CCNA, CWNA, and/or Net+ preferred

Other Job Requirements / Working Conditions

Sitting

Constantly (More than 50% of the time)

Visual / Audio / Speaking

Able to access and interpret client information received from the computer and able to hear and speak with individuals in person and on the phone.

Manual Dexterity / Keyboarding

Able to work standard office equipment, including PC keyboard and mouse, copy/fax machines, and printers.

Availability

Able to work all hours scheduled, including overtime as directed by manager/supervisor and required by business need.

Travel

Minimal and up to 10%

General Description of Available Benefits for Eligible Employees of Truist Financial Corporation: All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position.Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist's generous benefit plans, please visit our Benefits site. Depending on the position and division, this job may also be eligible for Truist's defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.

Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace.

EEO is the Law E-Verify IER Right to Work


What Truist employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Truist logo

About Truist

Sourced by ZipRecruiter

Truist is combining distinctive personal service with investments in innovation to create transformational client experiences. We believe the unique blend of human touch and innovative technology will set us apart, instill confidence, and build deeper levels of trust with our clients

Industry

Finance and insurance

Company size

10,000+ Employees

Headquarters location

Charlotte, NC, US

Year founded

2019