1

Information Security Risk Management Jobs in Illinois

Sr. Cybersecurity Operational Risk Officer

Chicago, IL · On-site

$103K - $132K/yr

... information security risk oversight for areas of the enterprise that manage technology, data and AI/ML systems. As part of this oversight role, experience with cybersecurity domains - including ...

... management, or third-party risk experience with network, platform, and/or application technology * One or more of the following certifications required: * Certified Information Systems Security ...

Create and manage information security and risk management awareness training programs for all employees, contractors and approved system users. * Work cross-departmentally to facilitate IT risk ...

Create and manage information security and risk management awareness training programs for all employees, contractors and approved system users. Work cross-departmentally to facilitate IT risk ...

Perform security risk mitigation planning based on the standard information security program framework, such as ISO 27001, NIST, SOC1/SOC2 * Provide a technical advisory support for both the internal ...

Showing results 21-40

Information Security Risk Management information

See Illinois salary details

$30

$56

$73

How much do information security risk management jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for information security risk management in Illinois is $56.64, according to ZipRecruiter salary data. Most workers in this role earn between $44.04 and $63.61 per hour, depending on experience, location, and employer.

What is information security risk management?

Information Security Risk Management is the process of identifying, assessing, and prioritizing risks to an organization's information assets and implementing measures to mitigate those risks. This field involves analyzing potential threats, vulnerabilities, and the impact of security breaches to ensure data protection and regulatory compliance. Professionals in this area develop policies, select security controls, and monitor systems to reduce the likelihood and consequences of cybersecurity incidents. Effective risk management helps organizations safeguard sensitive information and maintain trust with customers and stakeholders.

What are the key skills and qualifications needed to thrive in information security risk management?

To thrive in Information Security Risk Management, you need a deep understanding of cybersecurity principles, risk assessment methodologies, and relevant legal or regulatory requirements, often supported by a bachelor’s degree in IT or cybersecurity and certifications like CISSP or CISM. Familiarity with risk management frameworks (e.g., ISO 27001, NIST), vulnerability assessment tools, and governance, risk, and compliance (GRC) systems is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills set top professionals apart in this field. These competencies are crucial for identifying, evaluating, and mitigating security risks, ensuring organizational resilience and regulatory compliance.

What are some common challenges faced by professionals in information security risk management, and how are they typically addressed?

Professionals in Information Security Risk Management often face challenges such as keeping up with constantly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with various regulations. These challenges are typically addressed through continuous learning, close collaboration with IT and business teams, and implementing robust risk assessment frameworks. Proactive communication and regular updates to security policies also help manage risks effectively while supporting organizational goals.

What is the difference between Information Security Risk Management vs Cybersecurity Analyst?

AspectInformation Security Risk ManagementCybersecurity Analyst
CertificationsISO 27001, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentPolicy development, risk assessments, complianceMonitoring security systems, incident response
Industry UsageRisk management, governance, compliance teamsSecurity operations centers, IT departments

While both roles focus on protecting information assets, Information Security Risk Management emphasizes identifying and mitigating risks through policies and assessments, whereas Cybersecurity Analysts focus on monitoring security systems and responding to threats. Both roles often collaborate but serve different functions within an organization's security framework.

Infographic showing various Information Security Risk Management job openings in Illinois as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $117,811 per year, or $56.6 per hour.

IS Project Leader-Security Risk Assesor/Analyst

Glendale Heights, IL • On-site

Full-time

Re-posted 23 days ago


Job description

Company Description

Client is a leader in the healthcare industry responsible for almost 60% of all the hospitals and facilities in Illinois. Rated as one of the best healthcare companies in the country and they are revamping their IT Security department. They are looking for the best employees to help with this initiative and currently are hiring Security Risk Assessors. If you are looking to work for the best Healthcare company in the Midwest then this is the job for you!

Job Description

The Security Risk Assessor will be responsible for identifying, prioritizing, reporting, and tracking information technology and process Security risks. Applying in-depth knowledge of regulatory requirements (HIPAA, PCI, etc.) , industry trends, and Information Security best practices, this position will assess risk over a spectrum of technologies, from large and complex projects to smaller service-based initiatives. This position produces assessments with evidence and policy based descriptions of identified risks as well as recommended options for remediating them. The Security Risk Assessor ensures that identified risks are centrally recorded with sufficient detail (e.g., ownership, priority, follow-up plans and dates) to produce up-to-date profiles of enterprise risk status. The Security risk assessor will successfully articulate the risk profile and status to both technology and business leadership.

Apply proven methods of risk assessment in collaboration with business and IT stakeholders to identify, prioritize, and communicate Security risk. Provide Security requirements and guidance to business owners and Information Technology sponsors to ensure alignment to Information Security policy, process and standards

Qualifications

Bachelor's degree appropriate to Cybersecurity discipline or equivalent combination of education and experience. Related certifications (e.g., CISSP, CISM, CISA) preferred

5 - 10 years of combined IT and Security work experience with a broad range of exposure to business/systems analysis, and Security assessments

Experience in one or more of the following:

In-depth knowledge of Information Security risks one or more Security frameworks (HIPAA, PCI, etc.) and industry best practices

Working knowledge of technical areas such as data warehouses, mainframes, networks, applications, etc.

Experience in leading Information Services projects

Experience in delivering formal presentations

Excellent verbal and written communication skills

Project Management Education


Work with blueStone Recruiting, we understand Information Technology. This is our sweet spot and we're the best at finding top talent!  


Contact me immediately before you miss out on this opportunity.

Additional Information

Work with blueStone Recruiting to find the next step in your IT Recruiting career. You can find us at http://bluestonerecruiting.com. We look forward to speaking with you!

All your information will be kept confidential according to EEO guidelines.