1

Information Security Risk Officer Jobs (NOW HIRING)

Security Risk Officer As a Security Risk Officer within Global Information security (GIS) team, you will focus on security risks across the organization. This will be done in collaboration with ...

Security Risk Officer As a Security Risk Officer within Global Information security (GIS) team, you will focus on security risks across the organization. This will be done in collaboration with ...

This role will collaborate and interact with the Chief Risk Officer (CRO) and the Office of Enterprise Risk Management (OERM) on information security risk related topics. Responsibilities

Description The Information Security Risk Manager is responsible for managing the Global Information Security risk program across eBay. This individual will work directly with business leaders to ...

Title: Sr. Information Security Risk Analyst Location: Kansas City ,MO Position Type : Full Time Compensation Pay Range:$120,000 Per Year Description Join our team as a Senior Information Security ...

Sr. Information Security Risk Analyst As part of UMB's Corporate Information Security and Privacy (CISP) team, the mission is to identify threats, vulnerabilities, and risks and to help protect the ...

next page

Showing results 1-20

Information Security Risk Officer information

See salary details

$29.5K

$94.9K

$170.5K

How much do information security risk officer jobs pay per year?

As of Jun 26, 2026, the average yearly pay for information security risk officer in the United States is $94,926.00, according to ZipRecruiter salary data. Most workers in this role earn between $49,500.00 and $127,500.00 per year, depending on experience, location, and employer.

How much does a CISO get paid?

Chief Information Security Officers (CISOs) typically earn between $150,000 and $300,000 annually, depending on the size of the organization, industry, and location. Experienced CISOs with certifications like CISSP or CISM and strong leadership skills can earn higher salaries, often supplemented with bonuses and stock options.

Can you make $500,000 a year in cyber security?

Information Security Risk Officers typically earn salaries ranging from $100,000 to $200,000 annually, depending on experience, certifications, and location. Reaching a $500,000 annual salary usually requires senior roles such as Chief Information Security Officer (CISO) or executive-level positions, which involve strategic leadership, extensive experience, and often additional compensation like bonuses or stock options.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is typically not entry-level and usually requires some experience in cybersecurity, network monitoring, or related fields. Entry-level positions in cybersecurity may include roles like SOC analyst I or security technician, but higher-tier SOC roles often demand certifications such as CompTIA Security+ or Certified SOC Analyst (CSA) and familiarity with security tools and incident response processes.

What are the key skills and qualifications needed to thrive as an Information Security Risk Officer, and why are they important?

To thrive as an Information Security Risk Officer, you need a strong background in cybersecurity principles, risk management frameworks, and typically a degree in information technology or a related field. Familiarity with technical tools such as risk assessment software, SIEM systems, and certifications like CISSP or CISM is often required. Strong analytical thinking, attention to detail, and effective communication skills are crucial for translating complex risks to stakeholders and driving organizational change. These skills are vital for identifying, assessing, and mitigating security threats, ensuring the organization's information assets remain protected and compliant.

What does an Information Security Risk Officer do?

An Information Security Risk Officer is responsible for identifying, assessing, and mitigating risks that could threaten an organization's information systems and data. They develop and implement risk management strategies, conduct security assessments, and help ensure compliance with relevant laws and regulations. Their role often involves coordinating with other departments to promote security best practices and preparing reports for senior management on potential threats and risk mitigation efforts.

What is the difference between Information Security Risk Officer vs Cybersecurity Analyst?

AspectInformation Security Risk OfficerCybersecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk management teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsIT firms, cybersecurity service providers
Primary FocusAssessing and managing security risks, complianceDetecting and responding to security threats

The main difference is that an Information Security Risk Officer focuses on identifying, assessing, and managing security risks and ensuring compliance, while a Cybersecurity Analyst primarily detects, investigates, and responds to security threats. Both roles require relevant certifications and work in security-focused environments, but their core responsibilities differ in scope and focus.

What are some common challenges Information Security Risk Officers face when balancing security requirements with business objectives?

Information Security Risk Officers often encounter the challenge of aligning robust security controls with the organization's need for operational efficiency and innovation. Balancing compliance and risk mitigation with the urgency of business initiatives requires strong communication and negotiation skills, as well as a deep understanding of both technical risks and business goals. Successfully navigating these challenges involves collaborating closely with IT, legal, and business stakeholders to develop practical solutions that protect assets without hindering productivity or growth.

Is CISO a high paying job?

A Chief Information Security Officer (CISO) is typically a high-paying executive role in cybersecurity, with salaries often exceeding six figures depending on the organization size and industry. The role requires extensive experience, leadership skills, and often relevant certifications like CISSP or CISM.
More about Information Security Risk Officer jobs
What cities are hiring for Information Security Risk Officer jobs? Cities with the most Information Security Risk Officer job openings:
What job categories do people searching Information Security Risk Officer jobs look for? The top searched job categories for Information Security Risk Officer jobs are:
Infographic showing various Information Security Risk Officer job openings in the United States as of June 2026, with employment types broken down into 93% Full Time, and 7% Part Time. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $94,926 per year, or $45.6 per hour.

Information Security Risk Officer

Texas State Library and Archives Commision

Houston, TX • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 24 days ago


Job description

Our client is one of the largest private, independent, full-service trust companies in the state of Texas. Since its founding, the company has grown to serve hundreds of relationships worldwide and currently manages over $10 billion in client assets. With a state-of-the-art trust accounting system, the firm is seeking an experienced Information Security Risk Officer (ISRO) to lead its overall technology and information security strategy.
This role carries accountability for the organization's technology roadmap, vendor ecosystem, cybersecurity posture, IT compliance, and digital transformation initiatives. Serving as the subject matter expert on regulatory technology requirements, the ISRO is also responsible for technology policies and procedures and acts as the primary contact for IT and Information Security exams and audits.
Responsibilities of the VP, Information Security Risk Officer:
Strategic Leadership and Technology Vision
• Lead the IT Steering Committee, conducting quarterly meetings and serving as a voting member
• Maintain oversight of the MSP relationship (Integris) and the information security program
• Partner with leadership to align technology with business goals, oversee enterprise infrastructure and information security, and drive innovation to enhance client and employee experience
• Oversee the IT Officer, fostering a culture of accountability, innovation, and continuous learning
• Present technology strategy and risk updates to the board and leadership as needed
• Develop and lead staff technology and information security training
• Lead the cross-functional business continuity team through disasters and other incidents
• Lead the key vendor review process, including due diligence and contract renewals
• Proactively assess new company initiatives and provide guidance on inherent security risks
Policy Development and Maintenance
• Author, maintain, and version-control all enterprise IT policies and procedures
• Review, update, and present information security and business continuity plans
• Develop a formal policy review calendar and lead all reviews of technology governance documents
• Create and maintain IT operational procedures, standards, and control documentation
• Translate regulatory guidance, examination findings, and industry frameworks (NIST, FFIEC, ISO 27001, GLBA, SOC 2) into actionable internal policy requirements
• Update and document processes using flowcharts, narratives, and risk and control matrices
Regulatory Compliance, Risk Management, and Audit Coordination
• Serve as the primary point of contact for all IT-related regulatory examinations, internal and external audits, and manage responses, tracking all findings to resolution
• Stay current on cybersecurity standards, including NIST CSF updates, FFIEC guidance, and relevant CISA advisories
• Monitor evolving federal and state banking regulations (GLBA, FFIEC IT Examination Handbook, Texas Department of Banking, etc.) and communicate changes
• Ensure timely updates to internal policies and procedures in response to regulatory guidance
• Design and test IT general controls and ensure proper documentation for SOC reports and other attestation requirements
• Coordinate periodic testing, including user access, clean desk, disaster recovery, and incident response
• Understand and comply with the Bank Secrecy Act and Know Your Customer procedures
• Develop and maintain knowledge of fiduciary tax laws and the Texas Trust Code
Qualifications of the VP, Information Security Risk Officer:
• 10+ years of experience in information security risk management, compliance, or IT leadership within financial services or banking
• Bachelor's degree in Management Information Systems, Computer Science, Cybersecurity, Business Administration, or related field preferred
• Knowledge of FFIEC with CCISO, CISM, or CISSP designations preferred
• Willingness to learn GWES trust accounting system and other firm technologies
• Proficiency in Microsoft Office products including Word, Excel, and Outlook
• Self-starter with strong initiative, sound judgment, and problem-solving skills
• Team-oriented with a positive attitude and collaborative mindset
• Discreet and reliable, with the ability to handle highly confidential financial and personal information
Why is This a Great Opportunity
What Our Amazing Client Offers:
• Competitive compensation with a discretionary annual bonus based on performance
• Long-term incentive program including employee tracking stock grants that vest over five years and provide dividend participation during the vesting period
• Comprehensive benefits including medical, dental, and vision insurance, with the company covering a significant portion of employee coverage
• 401(k) plan with company contribution based on total cash compensation after one year of service
• Generous vacation policy
• Long-term disability and life insurance coverage with company contributions
• Free parking at the office location and access to the building fitness center, with optional training sessions during the work week
• Opportunity to work within an exceptional team and join a highly respected organization known for its long-tenured team, collaborative culture, and commitment to professional development
Keywords: Information Security Risk Officer, ISRO, Cybersecurity, IT Risk, Financial Services, Trust Company, FFIEC, GLBA, NIST, SOC 2, ISO 27001, IT Governance, Risk Management, Compliance, Audit, Cyber Risk, Vendor Management, Digital Transformation, Business Continuity, CISO, CISSP, CISM, CCISO