1

Manager Security Risk Assessment Jobs (NOW HIRING)

An information system security risk assessment should also be performed in compliance with SEC501 ... Report Manager Required: • 2+ years of experience conducting IT risk assessments • Apply strong ...

$62K - $141K/yr

As an information security risk specialist on our team, you'll work with industry partners to ... Experience in cybersecurity risk assessments and supply chain or risk management efforts

Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships * Translate ambiguous ...

next page

Showing results 1-20

Manager Security Risk Assessment information

See salary details

$51.5K

$111.6K

$170K

How much do manager security risk assessment jobs pay per year?

As of Jun 20, 2026, the average yearly pay for manager security risk assessment in the United States is $111,556.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,000.00 and $129,000.00 per year, depending on experience, location, and employer.

What is the difference between Manager Security Risk Assessment vs Security Analyst?

AspectManager Security Risk AssessmentSecurity Analyst
CertificationsCISSP, CISM, CRISCCISSP, Security+
Work EnvironmentOversees security programs, manages teamsAnalyzes security threats, monitors systems
Industry UsageCommon in organizations with complex security needsWidely used across various industries for threat detection

The Manager Security Risk Assessment focuses on leading security risk evaluations, managing teams, and developing security strategies. In contrast, a Security Analyst primarily monitors security systems, analyzes threats, and responds to incidents. Both roles require relevant certifications and work within the cybersecurity industry, but their responsibilities differ in scope and focus.

What cities are hiring for Manager Security Risk Assessment jobs? Cities with the most Manager Security Risk Assessment job openings:
What are the most commonly searched types of Security Risk Assessment jobs? The most popular types of Security Risk Assessment jobs are:
What states have the most Manager Security Risk Assessment jobs? States with the most job openings for Manager Security Risk Assessment jobs include:
GRC Analyst - IT Security Risk and Audit Manager

GRC Analyst - IT Security Risk and Audit Manager

Apex Informatics

Boca Raton, FL • On-site

Other

This job post has expired today. Applications are no longer accepted.


Job description

Job Title: IT Security Risk and Audit Manager - Governance Risk Compliance (GRC) Analyst
Location: Tolls Data Center in Boca Raton, FL. This is an onsite position, not remote.
Job Summary: The IT Security Risk and Audit Manager at the Florida Turnpike Enterprise leads the IT security risk and audit program. This role involves managing, assessing, and mitigating risks as part of the information assurance and cybersecurity program, using standards such as NIST, ISO, PCI, and ISACA. The position entails developing and implementing strategies for IT security risk and audit, conducting risk assessments, and evaluating control effectiveness.
Key Responsibilities:
  • Perform reviews to ensure compliance with PCI, SOC2, ISO, and State of Florida cybersecurity controls.
  • Plan and assess IT security controls' effectiveness and manage remediation efforts.
  • Maintain IT security risk and compliance matrices and perform management reporting.
  • Oversee the Third-Party Risk Management Program (TPRM) and analyze SOC-2 and other reports, mapping to key security controls.
  • Manage IT security vulnerabilities in alignment with PCI and NIST standards.
  • Identify and rank the criticality of operations and assets to prioritize risk mitigation.
  • Estimate potential losses and recovery costs for critical assets if threats materialize.
  • Identify and implement cost-effective risk mitigation actions, including new policies and technical controls.
  • Coordinate and verify the remediation of audit findings.
  • Document results and develop action plans for risk mitigation.
  • Produce formal audit reports based on ISACA Audit Standards.
  • Promote compliance with regulatory requirements (e.g., PCI DSS) and IT best practices.

Skills and Requirements:
  • 7-10 years of IT Audit experience (CISA certification preferred).
  • 3 years of IT Risk Management lifecycle experience.
  • 3 years of hands-on technical experience (e.g., developer, system administrator).
  • Experience with NIST 800-30 Risk Assessment Standard.
  • Extensive experience with IT General Controls evaluation and design.
  • Advanced skills in business process mapping, documentation, and policy development.
  • Up-to-date knowledge of the current threat landscape in Information Security.
  • Solid understanding of PCI DSS standards.

Education and Certifications:
  • Bachelor's Degree in Computer Science, Information Systems, Business Administration, or a related field, or equivalent work experience.
  • Preferred certifications: CISA and CISSP.