1

Information Security Risk Officer Jobs in Rochester, NY

CORPORATE COMPLIANCE OFFICER

Rochester, NY ยท On-site

$81 - $121/hr

In collaboration with the Director of Information Technology/agency Security Officer, ensures compliance with requirements for privacy and security risk assessments * Identifies and builds on ...

Posted today

Conduct physical and information security audits, facility reviews, and risk assessments; recommend ... Oversee Contract Security Force (9-Console Operators and 4-Line Officers). * Shared on-call ...

Chief Compliance Officer

Rochester, NY ยท On-site

$160K - $210K/yr

... Officer (CCO) oversees all regulatory compliance and ethics functions for Five Star Bank and its ... risk, operational risk, information security, and financial crimes risk management while ...

Security Officer (Part time) Join us in caring for the most important people on Earth. We reward ... Programs and downloads information from security patrol to include station locations and changing ...

Showing results 21-40

Information Security Risk Officer information

See Rochester, NY salary details

$29.1K

$93.7K

$168.2K

How much do information security risk officer jobs pay per year?

As of Aug 17, 2026, the average yearly pay for information security risk officer in Rochester, NY is $93,660.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,800.00 and $125,800.00 per year, depending on experience, location, and employer.

What does an Information Security Risk Officer do?

An Information Security Risk Officer is responsible for identifying, assessing, and mitigating risks that could threaten an organization's information systems and data. They develop and implement risk management strategies, conduct security assessments, and help ensure compliance with relevant laws and regulations. Their role often involves coordinating with other departments to promote security best practices and preparing reports for senior management on potential threats and risk mitigation efforts.

What are the key skills and qualifications needed to thrive as an Information Security Risk Officer?

To thrive as an Information Security Risk Officer, you need a strong background in cybersecurity principles, risk management frameworks, and typically a degree in information technology or a related field. Familiarity with technical tools such as risk assessment software, SIEM systems, and certifications like CISSP or CISM is often required. Strong analytical thinking, attention to detail, and effective communication skills are crucial for translating complex risks to stakeholders and driving organizational change. These skills are vital for identifying, assessing, and mitigating security threats, ensuring the organization's information assets remain protected and compliant.

What are some common challenges Information Security Risk Officers face when balancing security requirements with business objectives?

Information Security Risk Officers often encounter the challenge of aligning robust security controls with the organization's need for operational efficiency and innovation. Balancing compliance and risk mitigation with the urgency of business initiatives requires strong communication and negotiation skills, as well as a deep understanding of both technical risks and business goals. Successfully navigating these challenges involves collaborating closely with IT, legal, and business stakeholders to develop practical solutions that protect assets without hindering productivity or growth.

What is the difference between Information Security Risk Officer vs Cybersecurity Analyst?

AspectInformation Security Risk OfficerCybersecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk management teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsIT firms, cybersecurity service providers
Primary FocusAssessing and managing security risks, complianceDetecting and responding to security threats

The main difference is that an Information Security Risk Officer focuses on identifying, assessing, and managing security risks and ensuring compliance, while a Cybersecurity Analyst primarily detects, investigates, and responds to security threats. Both roles require relevant certifications and work in security-focused environments, but their core responsibilities differ in scope and focus.

What are popular job titles related to Information Security Risk Officer jobs in Rochester, NY?

For Information Security Risk Officer jobs in Rochester, NY, the most frequently searched job titles are:

What job categories do people searching Information Security Risk Officer jobs in Rochester, NY look for?

The top searched job categories for Information Security Risk Officer jobs in Rochester, NY are:

Infographic showing various Information Security Risk Officer job openings in Rochester, NY as of August 2026, with employment types broken down into 33% Full Time, and 67% Part Time. Highlights an 100% In-person job distribution, with an average salary of $93,660 per year, or $45 per hour.

Chief Information Security Office - Security Services & Cyber Defense - Security Operation Cent[...]

Bank of China Limited, New York Branch

Rochester, NY โ€ข On-site

$65 - $150/hr

Other

Posted 11 days ago


Job description

Introduction

Established in 1912, Bank of China is one of the largest banks in the world, with over $3 trillion in assets and a footprint that spans more than 60 countries and regions. Our long-term outlook, institutional weight and global breadth provide our clients with a stable and reliable financial partner, whether in Corporate or Personal Banking or our Trade Services, Commodities, Financial Institutions and Global Markets lines of business.

Overview

This incumbent will provide Security Operation Center services as required to fulfill the Bank's information security program requirements. This incumbent will provide real-time response and analysis to security threats across enterprise systems. In addition, this incumbent will provide support to Security Services & Cyber Defense, Governance, Compliance and Risk Management functions. This position will also manage the SOC associates and lead the team to meet expectations. This positionโ€™s schedule will rotate on a planned 8-hour shifts basis, covering 24 hours/day, 7 days/week, including overnight, weekend, and holiday.

Responsibilities

Security Operation Center

  • Execute incident response protocols for responding to and escalating incidents timely.
  • Conduct initial incident response including containment, documentation, and communication.
  • Conduct post-incident reporting and analysis. - Maintain detailed and accurate records of security events and actions taken.
  • Analyze security alerts and assess potential threats. - Stay updated on current threat landscape and emerging attack techniques.

Team Management

  • Supervise a team of SOC Associates during assigned shifts, ensuring task coverage and operational readiness.
  • Enforce adherence to SOC Policies, Standards and Procedures and enforce deviations or issues as needed.
  • Participate in the review and improvement of incident response Policies, Standards and Procedures.

Security Services & Cyber Defense, Governance, Compliance and Risk Assessment

  • Execute Security Policies and Standards.
  • Manage assigned security monitoring tools.
  • Conduct vulnerability scans, patch management, Identity & Access Management, Penetration Testing, Data Privacy, Phishing and Training, Audit affairs and Risk Assessment as needed.
Qualifications
  • Bachelorโ€™s degree in Business, Computer Science, Management Information Systems, Engineering, Mathematics, or related field is required
  • Minimum 4 years of full time work experience
  • Minimum 3 years of work experience in Information security, cybersecurity, vulnerability management, security architecture, network, security tools and computer systems administration
  • Minimum 3 years of experience in risk management
  • Good understanding of regulatory requirements including FFIEC, GLBA, NIST
  • Knowledge of Information security and cyber security best practices
  • Knowledge of systems administration such as Windows Server, Active Directory management, Firewall, UNIX system, network architectures, etc.
  • Knowledge of security tools such as SIEM, DLP, XDR, EDR, Web Filter etc
  • Good understanding of protocol behaviors, validity of identified vulnerabilities
  • CISSP/CRISC/ or IT related certifications preferred
Pay Range

Actual salary is commensurate with candidateโ€™s relevant years of experience, skillset, education and other qualifications.

USD $65,000.00 - USD $150,000.00 /Yr.

#J-18808-Ljbffr