1

Information Security Risk Officer Jobs (NOW HIRING)

next page

Showing results 1-20

Information Security Risk Officer information

See salary details

$29.5K

$94.9K

$170.5K

How much do information security risk officer jobs pay per year?

As of Jun 6, 2026, the average yearly pay for information security risk officer in the United States is $94,926.00, according to ZipRecruiter salary data. Most workers in this role earn between $49,500.00 and $127,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an Information Security Risk Officer, and why are they important?

To thrive as an Information Security Risk Officer, you need a strong background in cybersecurity principles, risk management frameworks, and typically a degree in information technology or a related field. Familiarity with technical tools such as risk assessment software, SIEM systems, and certifications like CISSP or CISM is often required. Strong analytical thinking, attention to detail, and effective communication skills are crucial for translating complex risks to stakeholders and driving organizational change. These skills are vital for identifying, assessing, and mitigating security threats, ensuring the organization's information assets remain protected and compliant.

What does an Information Security Risk Officer do?

An Information Security Risk Officer is responsible for identifying, assessing, and mitigating risks that could threaten an organization's information systems and data. They develop and implement risk management strategies, conduct security assessments, and help ensure compliance with relevant laws and regulations. Their role often involves coordinating with other departments to promote security best practices and preparing reports for senior management on potential threats and risk mitigation efforts.

What is the difference between Information Security Risk Officer vs Cybersecurity Analyst?

AspectInformation Security Risk OfficerCybersecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk management teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsIT firms, cybersecurity service providers
Primary FocusAssessing and managing security risks, complianceDetecting and responding to security threats

The main difference is that an Information Security Risk Officer focuses on identifying, assessing, and managing security risks and ensuring compliance, while a Cybersecurity Analyst primarily detects, investigates, and responds to security threats. Both roles require relevant certifications and work in security-focused environments, but their core responsibilities differ in scope and focus.

What are some common challenges Information Security Risk Officers face when balancing security requirements with business objectives?

Information Security Risk Officers often encounter the challenge of aligning robust security controls with the organization's need for operational efficiency and innovation. Balancing compliance and risk mitigation with the urgency of business initiatives requires strong communication and negotiation skills, as well as a deep understanding of both technical risks and business goals. Successfully navigating these challenges involves collaborating closely with IT, legal, and business stakeholders to develop practical solutions that protect assets without hindering productivity or growth.
More about Information Security Risk Officer jobs
What cities are hiring for Information Security Risk Officer jobs? Cities with the most Information Security Risk Officer job openings:
Infographic showing various Information Security Risk Officer job openings in the United States as of May 2026, with employment types broken down into 43% Full Time, and 57% Part Time. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $94,926 per year, or $45.6 per hour.
Information Security Risk Analyst

Information Security Risk Analyst

AllSTEM Connections

San Francisco, CA • On-site

$153K/yr

Temporary

Medical, Dental, Vision, Retirement

Posted 24 days ago


Job description

JOB SUMMARY
Are you passionate about strengthening security through risk insight and strategic partnership? We are seeking an experienced Information Security Risk Analyst to help identify, assess, and reduce cybersecurity risk across cloud and on-prem environments.
In this role, you will partner closely with application development teams, technical stakeholders, and leadership to evaluate security controls, advise on secure cloud and DevSecOps practices, and translate complex technical risks into actionable business guidance. This is an opportunity to play a highly visible role in improving enterprise security posture while influencing modern development practices, third-party risk management, and emerging AI/GenAI governance considerations.
If you thrive in collaborative environments and enjoy combining technical depth with risk strategy and communication, this role offers meaningful impact and professional growth.
KEY RESPONSIBILITIES
• Support enterprise risk strategies by identifying security risks in processes and technologies and leading initiatives to reduce exposure.
• Apply and interpret security policies and contribute insights to ongoing policy and control improvements.
• Partner with business and technical teams to help them understand and implement security controls, policies, and procedures.
• Establish trusted relationships across assigned business areas to understand operational and technical requirements and enable secure outcomes.
• Advise application development teams on Secure Cloud Development and DevSecOps best practices to mature security practices.
• Assess technical implementations in both cloud and on-prem environments to evaluate security risk and recommend control enhancements or compensating controls.
• Perform complex security analyses and provide clear, practical mitigation recommendations.
• Evaluate third-party service providers, identify associated risks, and clarify shared security responsibilities.
• Conduct formal security control assessments and prepare detailed assessment reports documenting scope, methodology, findings, risk impact, and remediation recommendations.
• Communicate security risks and business implications to stakeholders at all levels, including executive leadership.
• Collaborate cross-functionally, manage multiple initiatives simultaneously, and navigate ambiguity in a fast-paced, results-driven environment.
REQUIRED QUALIFICATIONS
• Experience performing security control assessments aligned to NIST 800-37 (SCA and CMCA).
• Hands-on experience conducting assessments using NIST 800-53 controls.
• Experience reviewing and evaluating FedRAMP authorization packages.
• Experience mapping OWASP Top Ten risks within DevSecOps environments to strengthen security operations.
• Strong understanding of cloud security principles and secure development practices.
• Ability to analyze complex technical security issues and translate them into clear, actionable risk narratives.
PREFERRED QUALIFICATIONS
• Experience in DevSecOps environments, including governance and security automation.
• Exposure to AI / GenAI-related cybersecurity governance and risk considerations.
• Experience working in regulated or compliance-driven environments.
KEY COMPETENCIES
• Strong verbal and written communication skills with the ability to convey risk to both technical and non-technical stakeholders.
• Excellent relationship-building and stakeholder partnership skills.
• Strategic thinking with practical, solutions-oriented execution.
• Ability to manage competing priorities while maintaining accountability and delivering results.
Equal Opportunity Employer / Disabled / Protected Veterans
The Know Your Rights poster is available here:
https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12.pdf
The pay transparency policy is available here:
https://www.dol.gov/sites/dolgov/files/ofccp/pdf/pay-transp_%20English_formattedESQA508c.pdf
For temporary assignments lasting 13 weeks or longer, AllSTEM Connections is pleased to offer major medical, dental, vision, 401k and any statutory sick pay where required.
We are committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please contact your staffing representative who will reach out to our HR team.
AllSTEM Connections participates in the E-Verify program in certain locations as required by law. Learn more about the E-Verify program.
https://e-verify.uscis.gov/web/media/resourcesContents/E-Verify_Participation_Poster_ES.pdf
We also consider for employment qualified applicants regardless of criminal histories, consistent with legal requirements, including, if applicable, the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance. Pursuant to applicable state and municipal Fair Chance Laws and Ordinances, we will consider for employment-qualified applicants with arrest and conviction records, including, if applicable, the San Francisco Fair Chance Ordinance. For Los Angeles, CA applicants: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Additional Skills
(none specified)
AllSTEM Representative Contact Info
Account Executive:
IN HOUSE
Branch Phone:
(909) 244-1777
Location:
Ontario, CA