The Security Risk & Compliance Analyst supports the organizations global information security program by assisting in the identification, assessment, and management of information security risks and ...
The Security Risk & Compliance Analyst supports the organizations global information security program by assisting in the identification, assessment, and management of information security risks and ...
Information Security Risk Analyst - Cyber Resiliency
Atlanta, GA · On-site
$120K - $130K/yr
As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and ...
Information Security Risk Analyst - Cyber Resiliency
Atlanta, GA · On-site
$120K - $130K/yr
As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and ...
Information Security Risk Analyst - Cyber Resiliency
Atlanta, GA · On-site
$120K - $130K/yr
As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and ...
Information Security Risk Analyst - Cyber Resiliency
Atlanta, GA · On-site
$120K - $130K/yr
As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and ...
Information Security Risk Analyst - Cyber Resiliency
Minneapolis, MN · On-site
$120K - $130K/yr
As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and ...
Information Security Risk Analyst - Cyber Resiliency
Minneapolis, MN · On-site
$120K - $130K/yr
As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization's cybersecurity governance, risk, and compliance initiatives. This role drives the design ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization's cybersecurity governance, risk, and compliance initiatives. This role drives the design ...
The Security Risk & Compliance Analyst supports the organizations global information security program by assisting in the identification, assessment, and management of information security risks and ...
The Security Risk & Compliance Analyst supports the organizations global information security program by assisting in the identification, assessment, and management of information security risks and ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization's cybersecurity governance, risk, and compliance initiatives. This role drives the design ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization's cybersecurity governance, risk, and compliance initiatives. This role drives the design ...
Familiarity with vulnerability management, threat intelligence analysis, and security architecture ... Performing information security risk assessments, evaluating control effectiveness, and analyzing ...
Quick apply
Familiarity with vulnerability management, threat intelligence analysis, and security architecture ... Performing information security risk assessments, evaluating control effectiveness, and analyzing ...
EITS Security Risk Analyst B (Engagement)--Remote Job
San Francisco, CA · On-site
$60 - $70/hr
Job43 - EITS Security Risk Analyst B (Engagement) Location: 100% Remote Max Submissions: 5 Proposed ... Translate business IT risk requirements into technical control specifications. * Develop risk ...
Quick apply
EITS Security Risk Analyst B (Engagement)--Remote Job
San Francisco, CA · On-site
$60 - $70/hr
Job43 - EITS Security Risk Analyst B (Engagement) Location: 100% Remote Max Submissions: 5 Proposed ... Translate business IT risk requirements into technical control specifications. * Develop risk ...
Job43 - EITS Security Risk Analyst B (Engagement) Location: 100% Remote Max Submissions: 5 Proposed ... Translate business IT risk requirements into technical control specifications. * Develop risk ...
Job43 - EITS Security Risk Analyst B (Engagement) Location: 100% Remote Max Submissions: 5 Proposed ... Translate business IT risk requirements into technical control specifications. * Develop risk ...
The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery's (WBD's) third party suppliers/vendors. This role requires ...
The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery's (WBD's) third party suppliers/vendors. This role requires ...
Operational Risk Analyst -Security Governance & Risk Issues Management Location: Merrifield VA ... Keep current with Information Security best practices and industry trends, and communicate/apply ...
Operational Risk Analyst -Security Governance & Risk Issues Management Location: Merrifield VA ... Keep current with Information Security best practices and industry trends, and communicate/apply ...
The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery's (WBD's) third party suppliers/vendors. This role requires ...
The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery's (WBD's) third party suppliers/vendors. This role requires ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU's IT Security Risk team. Core responsibilities include third-party risk management (TPRM) and security ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU's IT Security Risk team. Core responsibilities include third-party risk management (TPRM) and security ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU's IT Security Risk team. Core responsibilities include third-party risk management (TPRM) and security ...
IT Risk Analyst II
Salt Lake City, UT · On-site
$108K - $162K/yr
Technical 407 Pay Range: $108,200.00 - $162,400.00 The IT Risk Analyst II is a member of WGU's IT Security Risk team. Core responsibilities include third-party risk management (TPRM) and security ...
Role overview The information security risk and compliance analyst supports the organization's governance, risk, and compliance program by managing security risk, ensuring regulatory compliance and ...
New
Role overview The information security risk and compliance analyst supports the organization's governance, risk, and compliance program by managing security risk, ensuring regulatory compliance and ...
New
Information Security Risk and Compliance Analyst
Denver, CO · Hybrid
$65K - $75K/yr
The Information Security Risk and Compliance Analyst performs recurring and ad hoc assessments such as user access reviews, vendor due diligence and monitoring, and other control validation tasks to ...
Information Security Risk and Compliance Analyst
Denver, CO · Hybrid
$65K - $75K/yr
The Information Security Risk and Compliance Analyst performs recurring and ad hoc assessments such as user access reviews, vendor due diligence and monitoring, and other control validation tasks to ...
The Information Security Risk and Compliance Analyst performs recurring and ad hoc assessments such as user access reviews, vendor due diligence and monitoring, and other control validation tasks to ...
Quick apply
The Information Security Risk and Compliance Analyst performs recurring and ad hoc assessments such as user access reviews, vendor due diligence and monitoring, and other control validation tasks to ...
The Information Security Risk and Compliance Analyst performs recurring and ad hoc assessments such as user access reviews, vendor due diligence and monitoring, and other control validation tasks to ...
The Information Security Risk and Compliance Analyst performs recurring and ad hoc assessments such as user access reviews, vendor due diligence and monitoring, and other control validation tasks to ...
Technology and Information Security Risk Specialist
Manhattan, NY · On-site
$160K - $180K/yr
Technology and Information Security Risk Specialist Vice President | Second Line of Defense ... Communication and Judgment - Strong analytical, writing, documentation, executive communication ...
Technology and Information Security Risk Specialist
Manhattan, NY · On-site
$160K - $180K/yr
Technology and Information Security Risk Specialist Vice President | Second Line of Defense ... Communication and Judgment - Strong analytical, writing, documentation, executive communication ...
Information Security Risk Analyst information
See salary details
$31.97 - $35.93
6% of jobs
$35.93 - $39.88
5% of jobs
$39.88 - $43.84
8% of jobs
$45.72 is the 25th percentile. Wages below this are outliers.
$43.84 - $47.79
11% of jobs
$47.79 - $51.75
12% of jobs
The median wage is $55.46 / hr.
$51.75 - $55.70
8% of jobs
$55.70 - $59.66
7% of jobs
$59.66 - $63.61
9% of jobs
$65.41 is the 75th percentile. Wages above this are outliers.
$63.61 - $67.57
17% of jobs
$67.57 - $71.53
8% of jobs
$71.53 - $75.48
7% of jobs
$31
$58
$75
How much do information security risk analyst jobs pay per hour?
What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?
| Aspect | Information Security Risk Analyst | Cybersecurity Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment teams, compliance departments | Security operations centers, incident response teams |
| Employer & Industry Usage | Financial, healthcare, government sectors | Tech companies, cybersecurity firms, enterprises |
While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.
What are the key skills and qualifications needed to thrive as an information security risk analyst, and why are they important?
What is an information security risk analyst?
What does an information security risk analyst do?
As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.
How does an information security risk analyst typically collaborate with other departments to address security risks?

Full-time
This job post has expired today. Applications are no longer accepted.
Victaulic rating
7.2
Based on 35 frontline employees who took The Breakroom Quiz
352nd of 536 rated manufacturers
Job description
The Security Risk & Compliance Analyst supports the organizations global information security program by assisting in the identification, assessment, and management of information security risks and compliance demands across Victaulic's entire organization. This position plays an integral role in ensuring the company meets its obligations under domestic and international regulatory frameworks, including but not limited to, NIST CSF, ISO27001, CMMC and the EU's NIS2 Directive. The analyst will work closely with internal stakeholders, external auditors, and third-party vendors to support a culture of security awareness and continuous compliance improvement.
The ideal candidate for this role will have knowledge of, if not actual experience, in the processes of obtaining and maintaining compliance with security frameworks as well as an understanding of industry standard Information Technology auditing.
Responsibilities
Risk Assessment & Management
• Assist in conducting information security risk assessments across business units, systems, and processes in accordance with established methodologies.
• Document risk findings, assign risk ratings, and track remediation activities through the risk register.
• Support the development and maintenance of risk treatment plans in coordination with system owners and IT teams.
• Participate in annual and ad hoc enterprise risk reviews, contributing analysis and supporting materials.
Compliance & Framework Management
• Support compliance activities related to NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CMMC (Cybersecurity Maturity Model Certification), and the EU NIS2 Directive.
• Conduct gap analyses against applicable frameworks and assist in developing remediation roadmaps.
• Maintain compliance documentation, including policies, procedures, control evidence, and assessment reports.
• Monitor regulatory changes and emerging framework updates; summarize implications for the security program.
Third-Party & Audit Management
• Coordinate and support third-party security audits and assessments, including scheduling, evidence collection, and stakeholder communication.
• Assist in managing vendor risk assessments for new and existing third-party vendors and suppliers.
• Track audit findings and corrective action plans, ensuring timely remediation and closure.
• Serve as a liaison between internal teams and external auditors during certification audits.
Policy, Documentation & Awareness
• Assist in drafting, reviewing, and updating information security policies, standards, and procedures.
• Support the delivery of security awareness training and phishing simulation programs.
• Maintain organized records of all compliance and risk management activities in the Governance, Risk & Compliance platform.
Collaboration & Reporting
• Collaborate with IT, Legal, Operations, and other business functions to integrate security requirements into business processes.
• Prepare regular status reports and metrics dashboards for management review.
• Contribute to the continuous improvement of the information security program by identifying process gaps and recommending enhancements.
Qualifications
Technical Experience
• Foundational understanding of information security principles, including confidentiality, integrity, and availability (CIA).
• Basic understanding of risk assessment methodologies and risk management concepts.
• Familiarity with third-party risk management and audit processes.
• Strong analytical and problem-solving skills with attention to detail.
• Capacity to understand legacy and progressive technology and security controls along with respective risk.
• Working knowledge of technologies such as cloud computing, DevOps, and application security is required.
General Requirements
• Analytical Thinking - applies structured reasoning to evaluate risk and compliance data objectively
• Integrity & Accountability - Handles sensitive security information with discretion and professionalism.
• Communication - Clearly translates security requirements and findings for varied audiences across the organization
• Continuous Learning - Proactively keeps pace with evolving security frameworks, threats, and regulatory requirements
• Collaboration - Builds effective working relationships across IT, operations, and business functions globablly
• Detail Orientation - Produces thorough, accurate documentation and maintains meticulous records of compliance activities
Education & Certifications
• 0 - 2 years' experience in information security, IT audit, risk management, or a related field.
• Bachelor's degree, cybersecurity certification, or equivalent experience in an information security or related field.
• A minimum of an entry-level certification such as the CompTIA Security+ certification
• Additional Risk & Compliance certification(s), such as CISA, a plus
Work Environment & Physical Requirements
This position is primarily office-based with hybrid flexibility. The role may require occasional visits to manufacturing facilities domestically and internationally. Ability to work across global time zones may be required for coordination with European and Asian teams.
Victaulic is an Equal Employment Opportunity (EOE/M/F/Vets/Disabled) employer and welcomes all qualified applicants. Applicants will receive fair and impartial consideration without regard to race, gender, color, religion, national origin, age, disability, veteran status, sexual orientation, genetic data, or other legally protected status. (Background checks may be required as part of our pre-employment process).
What Victaulic employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Victaulic
Sourced by ZipRecruiter
Industry
Industrial machinery manufacturing
Company size
1,001 - 5,000 Employees
Headquarters location
Easton, PA, US
Year founded
1919