Professional certification or designation in risk management, business continuity, audit, information security, compliance, or a related discipline is preferred. * Bachelor's degree in business or a ...
Professional certification or designation in risk management, business continuity, audit, information security, compliance, or a related discipline is preferred. * Bachelor's degree in business or a ...
Bachelor's degree in Cybersecurity, Information Security, Information Technology, Risk Management, Business Administration, or a related field. * 3+ years of experience in cybersecurity governance ...
Bachelor's degree in Cybersecurity, Information Security, Information Technology, Risk Management, Business Administration, or a related field. * 3+ years of experience in cybersecurity governance ...
WI Β· On-site
$118K - $143K/yr
Project Management * Information Security * IT Auditing * Security Risk Mitigation * Technology Implementation * Endpoint Security * Network Security * Cloud Security * Application Security
Principal IT Security Architect - REMOTE from any EST or CST US-based location
Milwaukee, WI Β· Remote
Developing formal management reporting dashboards aligned to widely accepted standards, including appropriate metrics that inform senior leadership as to the state of information security risk and ...
Principal IT Security Architect - REMOTE from any EST or CST US-based location
Milwaukee, WI Β· Remote
Developing formal management reporting dashboards aligned to widely accepted standards, including appropriate metrics that inform senior leadership as to the state of information security risk and ...
... security risk management, compliance and controls, AI product risk, model risk management, or ... Certifications such as Certified Information Privacy Professional/United States, Certified ...
... security risk management, compliance and controls, AI product risk, model risk management, or ... Certifications such as Certified Information Privacy Professional/United States, Certified ...
Job Title- LEAD IT SYSTEMS ADMINISTRATOR Project Location - PLEASANT PRAIRIE, WI or WAUKEGAN, IL ... Operations to the support staff, focusing on security, risk management and controls that go along ...
Quick apply
Job Title- LEAD IT SYSTEMS ADMINISTRATOR Project Location - PLEASANT PRAIRIE, WI or WAUKEGAN, IL ... Operations to the support staff, focusing on security, risk management and controls that go along ...
WI Β· On-site
Acting as a trusted advisor to senior management, you will collaborate closely with technology ... complex risk scenarios to senior stakeholders. * Good knowledge of NIS2 requirements and ...
New
Analyst II, Information Security
Madison, WI Β· On-site
$80K - $100K/yr
... reduce risk and improve the security posture. Responsibilities * Create secure endpoint ... Conditional Access, MFA, device compliance gates, role-based access, Privileged Identity Management ...
Analyst II, Information Security
Madison, WI Β· On-site
$80K - $100K/yr
... reduce risk and improve the security posture. Responsibilities * Create secure endpoint ... Conditional Access, MFA, device compliance gates, role-based access, Privileged Identity Management ...
Information Security Engineer
Neenah, WI Β· On-site
The Information Security Engineer is responsible for designing, implementing, and maintaining the ... Risk Investigations, Incident Response and Documentation, DNS, Registrar Management, etc * Assist ...
Information Security Engineer
Neenah, WI Β· On-site
The Information Security Engineer is responsible for designing, implementing, and maintaining the ... Risk Investigations, Incident Response and Documentation, DNS, Registrar Management, etc * Assist ...
Information Security Engineer
Neenah, WI Β· On-site
The Information Security Engineer is responsible for designing, implementing, and maintaining the ... Risk Investigations, Incident Response and Documentation, DNS, Registrar Management, etc * Assist ...
Information Security Engineer
Neenah, WI Β· On-site
The Information Security Engineer is responsible for designing, implementing, and maintaining the ... Risk Investigations, Incident Response and Documentation, DNS, Registrar Management, etc * Assist ...
WI Β· On-site
Manage and triage the Information Security ticket queue, providing timely and effective technical support to SpaceX employees and stakeholders. * Perform operational tasks required to keep security ...
Responsible for presenting reports based on risk analysis of the information sharing network ... Understanding of patch management with the ability to deploy patches in a timely manner while ...
Responsible for presenting reports based on risk analysis of the information sharing network ... Understanding of patch management with the ability to deploy patches in a timely manner while ...
Responsible for presenting reports based on risk analysis of the information sharing network ... Understanding of patch management with the ability to deploy patches in a timely manner while ...
Responsible for presenting reports based on risk analysis of the information sharing network ... Understanding of patch management with the ability to deploy patches in a timely manner while ...
Minimum of 3 years of security risk identification, mitigation, and remediation, and policy ... Experience managing Active Directory. Special Knowledge, Skills and Abilities : * Comprehensive ...
Quick apply
Minimum of 3 years of security risk identification, mitigation, and remediation, and policy ... Experience managing Active Directory. Special Knowledge, Skills and Abilities : * Comprehensive ...
Minimum of 3 years of security risk identification, mitigation, and remediation, and policy ... Experience managing Active Directory. Special Knowledge, Skills and Abilities: * Comprehensive ...
Minimum of 3 years of security risk identification, mitigation, and remediation, and policy ... Experience managing Active Directory. Special Knowledge, Skills and Abilities: * Comprehensive ...
Minimum of 3 years of security risk identification, mitigation, and remediation, and policy ... Experience managing Active Directory. Special Knowledge, Skills and Abilities: * Comprehensive ...
Minimum of 3 years of security risk identification, mitigation, and remediation, and policy ... Experience managing Active Directory. Special Knowledge, Skills and Abilities: * Comprehensive ...
Minimum of 3 years of security risk identification, mitigation, and remediation, and policy ... Experience managing Active Directory. Special Knowledge, Skills and Abilities * Comprehensive ...
Minimum of 3 years of security risk identification, mitigation, and remediation, and policy ... Experience managing Active Directory. Special Knowledge, Skills and Abilities * Comprehensive ...
Senior Information Security Engineer
Madison, WI Β· Hybrid
$107K - $145K/yr
The State of Wisconsin Investment Board (SWIB) manages more than $178 billion in assets, including ... As a senior member of the Information Security team, you will help reduce organizational risk ...
Senior Information Security Engineer
Madison, WI Β· Hybrid
$107K - $145K/yr
The State of Wisconsin Investment Board (SWIB) manages more than $178 billion in assets, including ... As a senior member of the Information Security team, you will help reduce organizational risk ...
Analyst II, Information Security
$80K - $100K/yr
... reduce risk and improve our security posture. This role is ideal for someone who has worked ... Identity Management (PIM). * Use PowerShell and/or Intune remediation scripts to automate ...
Quick apply
Analyst II, Information Security
$80K - $100K/yr
... reduce risk and improve our security posture. This role is ideal for someone who has worked ... Identity Management (PIM). * Use PowerShell and/or Intune remediation scripts to automate ...
Senior Information Security Engineer
Madison, WI Β· On-site
$107K - $145K/yr
The State of Wisconsin Investment Board (SWIB) manages more than $178 billion in assets, including ... As a senior member of the Information Security team, you will help reduce organizational risk ...
Senior Information Security Engineer
Madison, WI Β· On-site
$107K - $145K/yr
The State of Wisconsin Investment Board (SWIB) manages more than $178 billion in assets, including ... As a senior member of the Information Security team, you will help reduce organizational risk ...
Information Security Risk Management information
See Wisconsin salary details
$32.27 - $36.26
6% of jobs
$36.26 - $40.26
5% of jobs
$40.26 - $44.25
8% of jobs
$46.14 is the 25th percentile. Wages below this are outliers.
$44.25 - $48.24
11% of jobs
$48.24 - $52.23
12% of jobs
The median wage is $55.98 / hr.
$52.23 - $56.22
8% of jobs
$56.22 - $60.22
7% of jobs
$60.22 - $64.21
9% of jobs
$66.02 is the 75th percentile. Wages above this are outliers.
$64.21 - $68.20
17% of jobs
$68.20 - $72.19
8% of jobs
$72.19 - $76.19
7% of jobs
$32
$58
$76
How much do information security risk management jobs pay per hour?
What is information security risk management?
What are the key skills and qualifications needed to thrive in information security risk management?
What are some common challenges faced by professionals in information security risk management, and how are they typically addressed?
What is the difference between Information Security Risk Management vs Cybersecurity Analyst?
| Aspect | Information Security Risk Management | Cybersecurity Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISM | CompTIA Security+, CEH, CISSP |
| Work Environment | Policy development, risk assessments, compliance | Monitoring security systems, incident response |
| Industry Usage | Risk management, governance, compliance teams | Security operations centers, IT departments |
While both roles focus on protecting information assets, Information Security Risk Management emphasizes identifying and mitigating risks through policies and assessments, whereas Cybersecurity Analysts focus on monitoring security systems and responding to threats. Both roles often collaborate but serve different functions within an organization's security framework.

Director - Enterprise Risk Management
Madison, WI β’ On-site
Full-time
Re-posted 14 days ago
Job description
Responsible for the leadership, innovation, governance, and management necessary to identify, evaluate, mitigate, and monitor the company's enterprise risks. Evaluate emerging risks and trends that may impact the company's risk appetite and present mitigation strategies. Prioritize risks within the company's ERM framework, enterprise risk register, and risk profile to ensure risks are managed to minimize negative financial and operational impact. Manage tools, practices, and policies to analyze and report enterprise risks; evaluate new methodologies and risk technologies for continuous improvement. Responsible for creating organizational awareness of risk management through training and education. Develop, maintain, and administer the Business Continuity Program. Supervisor responsibilities to include staffing, training and development, performance management, and workforce planning.
PRIMARY JOB RESPONSIBILITIES:
- Supervisor/Manager responsibilities may include all of the following:
- Staffing needs, to include interviewing and onboarding for new employees.
- Training and development, as well as coaching and motivation, for staff.
- Performance management, goal setting, employee engagement, and salary administration.
- Workforce management to include: unit equipment, software, and space needs; approving time off and overtime usage; and budget recommendations.
- Lead or coordinate the development, maintenance, and governance of Own Risk and Solvency Assessment materials, ensuring alignment with regulatory expectations, capital adequacy considerations, the ERM framework, and enterprise risk appetite.
- Monitor emerging strategic, operations, financial, regulatory, cyber, technology, third-party data, and AI-related risks and recommend practical mitigation strategies that support risk-informed business decisions.
- Lead the design, development, implementation, and ongoing enhancement of CM Group's ERM framework. Responsible for the leadership, innovation, governance, and management necessary to identify, evaluate, mitigate, monitor, and report the company's enterprise risks.
- Facilitate the determination of the company's risk appetite, tolerances, and limits. Identify and report key regulatory changes, external factors, emerging risks, and trends that might impact the company's risk profile and present mitigation strategies for management's review.
- Develop, analyze, quantify, and prioritize risks within the company's risk universe, enterprise risk register, and risk profile. Develop and maintain Key Risk Indicators (KRIs), risk appetite metrics, and related reporting to actively monitor risk exposures and trends. Ensure risks are recognized and managed in a manner the minimizes negative financial and operational impact while supporting efficient, cost-effective mitigation strategies.
- Ensure the ERM framework is appropriate to the nature, scale, and complexity of the business. Work with cross-functional business leaders to regularly identify key risks across all types and categories. Assess risks based on likelihood, impact, and level of mitigation.
- Prepare and present ERM reporting, risk assessments, emerging risk updates, risk appetite results, ERI trends, and mitigation plans for senior leadership, management committees, the Risk Management Committee, Board-level audiences, regulators, and auditors, as appropriate.
- Lead the Business Continuity Program. Complete risk analysis, business impact analysis, assessment, and evaluation for all CM Group internal departments and critical outsourced partners. Identify comprehensive strategic solutions to satisfy the various business, regulatory, and technology requirements.
- Manage the development and delivery of training that facilitates corporate ERM and Business Continuity awareness.
- Manage the development and implementation of tools, practices, policies, and risk technology solutions to analyze, monitor, and report enterprise risks.
- Leverage internal and external relationships of the ERM Department to deliver projects on time. Exerts influence appropriately on outside teams to meet project deliverables while creating positive impact within the organization.
- Professionally represent the company's position with regulators, auditors, rating agencies, external vendors, and other key stakeholders.
QUALIFICATIONS:
- Professional certification or designation in risk management, business continuity, audit, information security, compliance, or a related discipline is preferred.
- Bachelor's degree in business or a related field is required.
- 12-15 years' risk management experience developing and implementing enterprise risk management programs, including writing policies and procedures, producing executive materials, supporting risk committees/meetings, and instituting industry best practice risk management principles and practices.
- Experience supporting insurance regulatory reporting, ORSA-related activities, risk appetite development, KRI reporting, enterprise risk assessments, and management or Board-level risk governance forums is preferred.
- Demonstrated management experience.
- Proficient in current ERM tools, risk reporting processes, and, where applicable, governance, risk, and compliance technology platforms. Able to add to and/or build complex models, tools, dashboards, or reporting solutions and monitor their effectiveness. .
- Excellent oral communication and writing skills to produce clear and concise materials.
- High-level critical thinking skills, including strategic thinking, effective analysis of data, and the ability to aggregate information.
- Strong project management discipline and demonstrated success overseeing multiple projects to completion.
- Proven ability to foster productive relationships with diverse staff, including senior leadership.
- Strong ability to influence and lead a successful team.
- Detail oriented, with a hands-on approach.
- Ability to travel as necessary.
WORK ENVIRONMENT:
Professional office environment.
NOTE: This job description in no way states or implies that these are the only duties performed by this employee. Employees may be requested to perform job-related tasks other than those specifically presented in this job description. The employer reserves the right to change or assign other duties to this position.
The CM Group is made up of Church Mutual Insurance Company, S.I., CM Regent Insurance Company, and CM Vantage Specialty Insurance Company.