1

Information Security Risk Management Consultant Jobs

The IT Security Risk Manager will lead the identification, assessment, monitoring, and mitigation ... Risk Management, Legal, IT, Compliance, and other key partners. • Provides guidance in the ...

Job Summary : 1872 Consulting is a company focused on IT security, and they are seeking an IT Security Manager (GRC) to oversee the security risk management program. The role involves managing risk ...

Senior Risk Management Specialist

Austin, TX · On-site

$97K/yr

The client is looking for Risk Management Specialist with experience in information security or cyber risk to lead the design, implementation, and optimization of enterprise and third-party risk ...

Showing results 21-40

Information Security Risk Management Consultant information

See salary details

$19

$56

$78

How much do information security risk management consultant jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for information security risk management consultant in the United States is $56.82, according to ZipRecruiter salary data. Most workers in this role earn between $48.08 and $69.95 per hour, depending on experience, location, and employer.

What does an information security risk management consultant do?

An Information Security Risk Management Consultant helps organizations identify, assess, and mitigate risks related to their information systems and data. They analyze potential threats and vulnerabilities, develop strategies to protect sensitive information, and ensure compliance with relevant regulations and standards. Their work often includes conducting risk assessments, recommending security controls, and advising on best practices to minimize security incidents and data breaches.

What are some typical challenges faced by information security risk management consultants when working with diverse clients?

Information Security Risk Management Consultants often encounter challenges such as adapting to varying levels of security maturity across clients, managing conflicting stakeholder priorities, and ensuring compliance with different regulatory frameworks. Navigating these complexities requires strong communication skills, flexibility, and the ability to tailor risk mitigation strategies for each unique environment. Successful consultants are adept at building trust and educating clients on the importance of proactive risk management, often acting as both advisors and change agents within organizations.

What are the key skills and qualifications needed to thrive as an information security risk management consultant, and why are they important?

To thrive as an Information Security Risk Management Consultant, you need a solid background in cybersecurity principles, risk assessment methodologies, and regulatory compliance, typically supported by a relevant degree and certifications like CISSP or CISM. Familiarity with risk management frameworks (such as NIST or ISO 27001), vulnerability assessment tools, and governance, risk, and compliance (GRC) platforms is essential. Strong analytical thinking, communication, and stakeholder management skills help consultants effectively identify risks and articulate recommendations to diverse audiences. These skills ensure organizations can proactively manage security risks, comply with regulations, and safeguard critical assets.

What is the difference between Information Security Risk Management Consultant vs Cybersecurity Analyst?

AspectInformation Security Risk Management ConsultantCybersecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISACISSP, CompTIA Security+, CEH
Work EnvironmentAdvisory roles, risk assessments, policy developmentMonitoring security systems, incident response, threat analysis
Employer & IndustryConsulting firms, large corporations, government agenciesIT departments, security operations centers, tech companies

While both roles focus on cybersecurity, the Information Security Risk Management Consultant primarily assesses and manages risks through policies and frameworks, whereas the Cybersecurity Analyst actively monitors and responds to security threats. The consultant provides strategic guidance, while the analyst handles day-to-day security operations.

What cities are hiring for Information Security Risk Management Consultant jobs?

Cities with the most Information Security Risk Management Consultant job openings:

What states have the most Information Security Risk Management Consultant jobs?

States with the most job openings for Information Security Risk Management Consultant jobs include:

What are popular job titles related to Information Security Risk Management Consultant jobs?

For Information Security Risk Management Consultant jobs, the most frequently searched job titles are:

Infographic showing various Information Security Risk Management Consultant job openings in the United States as of August 2026, with employment types broken down into 83% Full Time, 13% Part Time, 1% Temporary, and 3% Contract. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $118,187 per year, or $56.8 per hour.

Information Security Risk Specialist

Mclean, VA • On-site

Booz Allen Hamilton
IT Services • 10K+ employees

$99K - $225K/yr

Other

Medical, Life, Retirement, PTO

Posted 29 days ago


Booz Allen Hamilton rating

8.9

Company rating: 8.9 out of 10

Based on 49 frontline employees who took The Breakroom Quiz

11th of 72 rated business consultants


Job description

Join a culture of emplowerment and connectivity.

Develop your craft

Learn the skills you need to accelerate your career.

Discover benefits that your life and work.

Innovate with intention

Build mission-ready tech that protects the nation.

As an Information Security Risk Spe cia list on our team, you will leverage your expertise to collaborate closely with contractor and DoD government system owners, as well as system administrators and developers, to identify cyber risks, analyze applicable policies , and develop comprehensive mitigation strategies. Utilizing insights from subject matter experts ( SMEs ) and engineers, you will evaluate technical infrastructure and personnel dynamics to assess the full threat landscape. From there, you will guide clients through actionable remediation plans, delivering clear and impactful solutions through presentations, detailed white papers, and well-defined milestones to ensure effective risk management and cybersecurity resilience.

You’ll work with your client to translate security concepts so they can make the best decisions to secure critical DoD systems. This is your opportunity to act as an information security SME while broadening your skills in DevSecOps and cloud security.

Join us. The world can’t wait.

You Have:

5+ years of experience working in a professional IT environment

3+ years of experience in cybersecurity and Assessment and Authorization ( A & A ) supporting DoD environments

Experience supporting federal government or DoD ATO packages, performing A & A and RMF, and c ond ucting risk assessments for federal government or DoD systems hosted in AWS, Azure, or hybrid cloud environments

Experience performing technical evaluations and security control assessments in cloud-native and containerized environments

Experience interfacing with engineering teams to align DevSecOps pipelines with cybersecurity policies

Knowledge of compliance testing tools such as ACAS, SCAP, STIGs or SRGs, eMASS, or Xacta

Experience with NIST SP 800-53, CNSSI 1253, artifact generation, SSPs, POA & Ms, SAPs, risk assessments, and continuous monitoring

TS/SCI clearance

HS diploma or GED

DoD 8570 Level II Security+ Certification or higher

Nice If You Have:

Experience with DevSecOps, Path-to-Production, and CI / CD

Experience administering Red Hat Enterprise Linux 8 or Windows Server 2012 or higher

Experience with cloud tools and container orchestration security

Knowledge of STIG and compliance scans

Ability to advise stakeholders on cloud security strategies, container orchestration security such as Kubernetes and Rancher, and platform hardening

Possession of excellent verbal and written communication skills

Bachelor's degree in IT or Cybersecurity

Clearance:

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information ; TS/SCI clearance is required.

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.

Information Security Risk Specialist

The Opportunity :

As an Information Security Risk Spe cia list on our team, you will leverage your expertise to collaborate closely with contractor and DoD government system owners, as well as system administrators and developers, to identify cyber risks, analyze applicable policies , and develop comprehensive mitigation strategies. Utilizing insights from subject matter experts ( SMEs ) and engineers, you will evaluate technical infrastructure and personnel dynamics to assess the full threat landscape. From there, you will guide clients through actionable remediation plans, delivering clear and impactful solutions through presentations, detailed white papers, and well-defined milestones to ensure effective risk management and cybersecurity resilience.

You’ll work with your client to translate security concepts so they can make the best decisions to secure critical DoD systems. This is your opportunity to act as an information security SME while broadening your skills in DevSecOps and cloud security.

Join us. The world can’t wait.

You Have:

  • 5+ years of experience working in a professional IT environment

  • 3+ years of experience in cybersecurity and Assessment and Authorization ( A & A ) supporting DoD environments

  • Experience supporting federal government or DoD ATO packages, performing A & A and RMF, and c ond ucting risk assessments for federal government or DoD systems hosted in AWS, Azure, or hybrid cloud environments

  • Experience performing technical evaluations and security control assessments in cloud-native and containerized environments

  • Experience interfacing with engineering teams to align DevSecOps pipelines with cybersecurity policies

  • Knowledge of compliance testing tools such as ACAS, SCAP, STIGs or SRGs, eMASS, or Xacta

  • Experience with NIST SP 800-53, CNSSI 1253, artifact generation, SSPs, POA & Ms, SAPs, risk assessments, and continuous monitoring

  • TS/SCI clearance

  • HS diploma or GED

  • DoD 8570 Level II Security+ Certification or higher

Nice If You Have:

  • Experience with DevSecOps, Path-to-Production, and CI / CD

  • Experience administering Red Hat Enterprise Linux 8 or Windows Server 2012 or higher

  • Experience with cloud tools and container orchestration security

  • Knowledge of STIG and compliance scans

  • Ability to advise stakeholders on cloud security strategies, container orchestration security such as Kubernetes and Rancher, and platform hardening

  • Possession of excellent verbal and written communication skills

  • Bachelor's degree in IT or Cybersecurity

Clearance:

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information ; TS/SCI clearance is required.

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy

AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.

Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.

  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.

  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.

  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

#J-18808-Ljbffr

What Booz Allen Hamilton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Booz Allen Hamilton logo

About Booz Allen Hamilton

Sourced by ZipRecruiter

Booz Allen Hamilton is a leading provider of management and technology consulting services to the US government in defense, intelligence, and civil markets. Headquartered in McLean, Virginia, the firm also serves major corporations, institutions, and not-for-profit organizations. Founded in 1914 by Edwin G. Booz, the company has a long-standing tradition of helping clients achieve success by delivering a wide range of consulting services that include strategic planning, human capital and learning, communication, systems development, and others. The company's mission is to empower people to change the world, and it has a reputation for maintaining the highest standards of integrity and-excellence.

Industry

It services

Company size

10,000+ Employees

Headquarters location

McLean, VA, US

Year founded

1914