1

Information Security Risk Management Jobs (NOW HIRING)

Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships * Translate ambiguous ...

Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...

$99K - $225K/yr

As an information security risk specialist on our team, you'll assist military leaders with ... You Have * 7+ years of experience leading and executing Navy Risk Management Framework (RMF ...

next page

Showing results 1-20

Information Security Risk Management information

See salary details

$31

$58

$75

How much do information security risk management jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for information security risk management in the United States is $58.45, according to ZipRecruiter salary data. Most workers in this role earn between $45.43 and $65.62 per hour, depending on experience, location, and employer.

What is information security risk management?

Information Security Risk Management is the process of identifying, assessing, and prioritizing risks to an organization's information assets and implementing measures to mitigate those risks. This field involves analyzing potential threats, vulnerabilities, and the impact of security breaches to ensure data protection and regulatory compliance. Professionals in this area develop policies, select security controls, and monitor systems to reduce the likelihood and consequences of cybersecurity incidents. Effective risk management helps organizations safeguard sensitive information and maintain trust with customers and stakeholders.

What are the key skills and qualifications needed to thrive in information security risk management?

To thrive in Information Security Risk Management, you need a deep understanding of cybersecurity principles, risk assessment methodologies, and relevant legal or regulatory requirements, often supported by a bachelor’s degree in IT or cybersecurity and certifications like CISSP or CISM. Familiarity with risk management frameworks (e.g., ISO 27001, NIST), vulnerability assessment tools, and governance, risk, and compliance (GRC) systems is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills set top professionals apart in this field. These competencies are crucial for identifying, evaluating, and mitigating security risks, ensuring organizational resilience and regulatory compliance.

What are some common challenges faced by professionals in information security risk management, and how are they typically addressed?

Professionals in Information Security Risk Management often face challenges such as keeping up with constantly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with various regulations. These challenges are typically addressed through continuous learning, close collaboration with IT and business teams, and implementing robust risk assessment frameworks. Proactive communication and regular updates to security policies also help manage risks effectively while supporting organizational goals.

What is the difference between Information Security Risk Management vs Cybersecurity Analyst?

AspectInformation Security Risk ManagementCybersecurity Analyst
CertificationsISO 27001, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentPolicy development, risk assessments, complianceMonitoring security systems, incident response
Industry UsageRisk management, governance, compliance teamsSecurity operations centers, IT departments

While both roles focus on protecting information assets, Information Security Risk Management emphasizes identifying and mitigating risks through policies and assessments, whereas Cybersecurity Analysts focus on monitoring security systems and responding to threats. Both roles often collaborate but serve different functions within an organization's security framework.

More about Information Security Risk Management jobs

What states have the most Information Security Risk Management jobs?

States with the most job openings for Information Security Risk Management jobs include:

Infographic showing various Information Security Risk Management job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $121,577 per year, or $58.5 per hour.

Information Security Risk - Risk Management - Advisor

Plano, TX • On-site

Full-time

Medical, Life

Re-posted yesterday


Job description

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home.

Job Description

In this first-line risk role, you will provide risk management expertise with a particular focus on Identity and Access Management (IAM). You will partner with stakeholders across the enterprise to assess potential risks, evaluate processes and controls, and provide thoughtful, data-informed guidance that supports sound business decisions. Your ability to connect risk considerations with business objectives will help strengthen how the organization manages information security risk in a highly regulated environment.

The Way You Will Make a Difference
  • Advise on methods, models, and analytical approaches used to identify, assess, and evaluate information security risks, with an emphasis on risks related to Identity and Access Management.
  • Partner with business and risk stakeholders to evaluate potential risks and understand their impact on the enterprise.
  • Review processes and controls to identify opportunities to reduce risk and strengthen risk management practices through rigorous analysis.
  • Provide informed guidance and feedback to management on risk resolutions, control guidelines, and related risk management decisions.
  • Collaborate with stakeholders across the enterprise to communicate risk considerations clearly and support effective decision-making.
  • Apply sound judgment to assess risk within the context of business objectives, priorities, and the broader operating environment.
  • Contribute to the development and evaluation of business strategies by incorporating relevant information security and risk considerations.
  • Help the organization respond effectively to evolving business conditions, risk considerations, and regulatory expectations.

Minimum Required Experience

  • 6 years of relevant professional experience in risk management, information security risk, or a related discipline.
  • Demonstrated experience assessing risk, evaluating processes or controls, and using analysis to inform risk management decisions.
  • Experience collaborating with stakeholders and communicating risk considerations to support business decisions.
  • Ability to understand business objectives and apply sound judgment when evaluating risk.
  • Shows curiosity and adaptability in learning and responsibly applying new technologies, including artificial intelligence, to reimagine how we work.
Desired Experiences
  • Bachelor's degree or equivalent.
  • Experience working with information security risk in a complex organizational environment.
  • Experience supporting or partnering with Identity and Access Management functions.
  • Experience providing advisory guidance to business, risk, or management stakeholders.
  • Experience operating in an environment where business decisions must account for evolving risk and regulatory considerations.

#LI - TW1 - Hybrid

Qualifications

Education:

Bachelor's Level Degree (Required)

The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers.

For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote.


Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form.

The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here.

Requisition compensation:

141000

to

184000