1

Risk Intelligence Jobs (NOW HIRING)

To do this, we provide enterprise risk management services and programs specifically designed for ... The Intelligence Manager, assigned to a specific client, will play a pivotal role in managing the ...

Intelligence Manager Location US-CA-Foster City ID 2026-2947 Category Intelligence Services ... To do this, we provide enterprise risk management services and programs specifically designed for ...

This position requires the Intelligence Analyst to provide continuous monitoring and assessment of global open-source information to support a large international technology company's risk management ...

You will operate at the intersection of risk intelligence, large-scale distributed systems, AI/GenAI, and financial infrastructure, shaping platforms that must be highly reliable, explainable, and ...

Concentric is a risk consultancy specializing in delivering strategic security and intelligence services. We provide holistic, intelligent security solutions for private clients and corporations ...

You will operate at the intersection of risk intelligence, large-scale distributed systems, AI/GenAI, and financial infrastructure, shaping platforms that must be highly reliable, explainable, and ...

This position requires the Intelligence Analyst to provide continuous monitoring and assessment of global open-source information to support a large international technology company's risk management ...

next page

Showing results 1-20

Risk Intelligence information

See salary details

$14

$30

$74

How much do risk intelligence jobs pay per hour?

As of Jul 22, 2026, the average hourly pay for risk intelligence in the United States is $30.34, according to ZipRecruiter salary data. Most workers in this role earn between $19.47 and $38.70 per hour, depending on experience, location, and employer.

What is the difference between Risk Intelligence vs Risk Analyst?

AspectRisk Intelligence
AspectRisk Analyst

Risk Intelligence involves analyzing and interpreting complex risk data to inform strategic decisions, often requiring advanced analytical skills and broader industry knowledge. Risk Analysts focus on identifying, assessing, and monitoring specific risks within organizations, typically performing data analysis and reporting. While both roles require risk assessment skills, Risk Intelligence professionals tend to work on higher-level strategic insights, whereas Risk Analysts handle operational risk evaluation. Both roles are common in finance, insurance, and corporate sectors, but Risk Intelligence often involves more strategic decision-making and data interpretation.

Do risk analysts make good money?

Risk analysts typically earn a competitive salary that varies by industry, experience, and location. According to industry data, the median annual wage for risk analysts is around $80,000, with higher earnings possible for those with advanced certifications or specialized skills in data analysis and risk management tools. The role often offers opportunities for advancement and additional compensation through bonuses or incentives.

What are the key skills and qualifications needed to thrive as a Risk Intelligence Analyst, and why are they important?

To thrive as a Risk Intelligence Analyst, you need a solid background in data analysis, risk assessment, and industry-specific knowledge, often supported by a degree in finance, cybersecurity, or related fields. Familiarity with risk management tools, data visualization software, and sometimes certifications like CRM or CISSP are typically required. Strong critical thinking, attention to detail, and effective communication help analysts interpret complex information and advise stakeholders. These skills are crucial for identifying potential threats and enabling informed decision-making to protect organizational assets.

What does a risk intelligence analyst do?

A risk intelligence analyst evaluates potential threats and vulnerabilities that could impact an organization by analyzing data from various sources, including open-source information, reports, and intelligence tools. They identify risks related to security, finance, or operations and provide actionable insights to support decision-making and risk mitigation strategies. Strong analytical skills, knowledge of intelligence tools, and attention to detail are essential for this role.

What qualifications do I need to be a risk analyst?

To become a risk analyst, a bachelor's degree in finance, economics, statistics, or a related field is typically required. Strong analytical skills, proficiency with data analysis tools like Excel or specialized software, and knowledge of risk management principles are also important. Certifications such as the Financial Risk Manager (FRM) or Professional Risk Manager (PRM) can enhance job prospects.

What is risk intelligence?

Risk intelligence refers to the ability to identify, assess, and manage risks that could affect an organization’s objectives. Professionals in risk intelligence gather data, analyze potential threats, and develop strategies to mitigate those risks, ensuring business continuity and compliance. This field combines elements of risk management, data analysis, and strategic planning to help businesses make informed decisions in uncertain environments. It is essential for organizations looking to proactively address threats rather than react to crises.

How does a Risk Intelligence professional typically collaborate with other departments within an organization?

Risk Intelligence professionals work closely with various departments, such as compliance, IT, legal, and operations, to identify and assess potential threats to the organization. They gather and analyze data from multiple sources, then communicate their findings through reports or presentations to help inform decision-making. Collaboration is often cross-functional and may involve participating in meetings, conducting risk workshops, and developing mitigation strategies with stakeholders. This teamwork ensures that risk management is integrated into the organization's overall strategy and day-to-day operations.

How much do the CIA pay analysts?

CIA analysts typically earn salaries comparable to federal government pay scales, with entry-level positions starting around $60,000 to $80,000 annually. Experienced analysts with specialized skills or security clearances can earn over $100,000 per year, depending on experience and location. Compensation may also include benefits such as health insurance, retirement plans, and allowances for security requirements.
More about Risk Intelligence jobs
What cities are hiring for Risk Intelligence jobs? Cities with the most Risk Intelligence job openings:
What states have the most Risk Intelligence jobs? States with the most job openings for Risk Intelligence jobs include:
Infographic showing various Risk Intelligence job openings in the United States as of July 2026, with employment types broken down into 89% Full Time, 8% Part Time, and 3% Contract. Highlights an 86% Physical, 4% Hybrid, and 10% Remote job distribution, with an average salary of $63,100 per year, or $30.3 per hour.
Senior Manager - Security Risk Engineering

Senior Manager - Security Risk Engineering

Klaviyo

Boston, MA

Other

Re-posted 5 days ago


Job description

About the team:

An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and security of our customers, partners and Klaviyos as well as deliver best in class technology solutions, infrastructure and services. This is achieved by providing a robust and secure technology foundation to do great work. We solve problems using technology, embrace automation and AI, and support Klaviyo's continued scalability and sustainable employee growth in a rapidly evolving environment.

The STAR team assists the Global Security Services (GSS) organization in developing and refining information security policies, standards and strategy, enterprise risk management, creating metrics and reporting, coordinating cross-functional projects, and strategically aligning global information security initiatives with the broader CISO vision amongst other governance, risk and compliance efforts. The STAR team is highly collaborative and cross-functional, working closely with various functions within the GSS team (namely Security Product and Development and Security Intelligence Operations), Global Technology Solutions (GTS) team and the broader Klaviyo organization.

About the role:

The Senior Manager, Security Risk Engineering is a senior information security and risk leader responsible for evolving risk management at Klaviyo from a traditional, cyber-centric, compliance-driven model into a real-time, business-aligned, engineering-led risk intelligence capability. Reporting into the Director of Security Trust and Risk, you will lead the Security Risk Engineering team as a second line of defense - owning technology risk management, third-party risk, risk quantification, and the risk intelligence and automation capability that turns disparate security signals into a single, decision-enabling view of risk.

You will operate as a credible, hands-on risk authority who can challenge and partner with engineering and security teams while maintaining independence from first-line delivery. You will build a team that thinks like risk engineers rather than traditional analysts - automating repeatable assessment, instrumenting controls, and applying AI as foundational infrastructure. You will partner with Engineering, Product, GTS, Legal, Audit, Finance, and the wider GSS organization to make risk legible across the business and to move Klaviyo's risk posture measurably forward.

How you'll have an impact:
  • Lead the transition of risk management from a cyber-centric model to an enterprise-wide framework - expanding scope beyond cybersecurity to operational, financial, regulatory, and third-party risk, with integrated remediation tracking and clear ownership of outcomes
  • Own the risk register and taxonomy, establishing a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that aggregation, prioritisation, and reporting become meaningful
  • Quantify risk in financial terms - expected loss, probability, and cost of remediation versus acceptance - so leadership can make rational investment and risk-acceptance decisions rather than relying on qualitative severity labels
  • Set and continuously refine the risk cadence: weekly risk huddles with business functions, monthly risk reviews, and a quarterly Enterprise Risk Committee, connecting day-to-day execution to GSS and Klaviyo-level objectives
  • Build the risk intelligence and automation capability - partnering closely with the team's risk intelligence lead, whose remit is risk intelligence and building automations using AI - to surface a continuously updated, quantified view of risk posture drawn from the live security tool estate (vulnerability, endpoint, third-party, data movement, and cyber risk quantification sources)
  • Drive the risk scoring programme: integrate third-party risk, application inventory, and cyber risk quantification platforms so that applications and vendors carry a composite, evidence-based risk score that drives tiered, automated decision-making
  • Unlock third-party risk automation through a tiered vendor model - fast-tracking low-risk vendors while ensuring high-risk vendors receive deep due diligence, business reviews, and continuous monitoring
  • Evaluate and govern risks associated with AI/ML deployments, LLM integrations, and cloud data pipelines, embedding AI risk assessment into the internal and third-party risk programs
  • Operate as a second line of defense - providing independent oversight, challenge, and guidance to first-line teams, applying consistent risk taxonomies and reporting standards, and escalating risks that exceed established tolerance
  • Act as custodian of the relevant security risk policies and standards, owning the review and update cycle and ensuring each policy connects to a specific risk it reduces
  • Partner with Legal and Internal Audit on regulatory horizon scanning and on audit findings affecting systems and processes, tracking findings through to closure
  • Maintain authoritative risk materials for GSS leadership, monthly KPI updates, and quarterly Board contributions - accurate, succinct, and decision-ready - translating high-severity findings into clear business impact
  • Lead, mentor, and grow the team, developing risk engineers and specialists and building a culture of adversarial thinking, business empathy, and technical rigour
Who you are:
  • 10+ years of experience in information security, cybersecurity, technology risk, or operational risk within a large, complex, or high-growth organization, with demonstrable depth of information security expertise and a track record of operating at a senior level
  • Proven experience operating in or alongside a second line of defense function within a Three (or Four) Lines of Defense model, able to engage credibly with senior engineers, architects, and security teams while maintaining independence from first-line delivery ownership
  • Demonstrated leadership of a risk or security team, with a track record of mentoring and developing people, and the ability to manage conflicting priorities and multiple concurrent initiatives
  • Strong command of risk quantification - able to express risk in financial and business terms, not just qualitative severity ratings - and of enterprise risk management beyond cybersecurity alone
  • Working knowledge of security frameworks - NIST, ISO 27001, SOC 2, ISO 42001, PCI DSS, CIS Controls - and how they translate into credible control requirements and delivery plans
  • Hands-on familiarity with modern risk and security tooling: third-party risk platforms, cyber risk quantification, vulnerability management, endpoint, and data-security telemetry, with a clear point of view on where AI augments versus replaces human judgement
  • Experience building and tracking security KPIs and metrics to measure success and drive continuous improvement
  • A strong communicator and problem-solver who balances persuasion with active listening, with exceptional stakeholder management skills to engage engineering leaders and executives and translate complex, technical risk into clear business impact
Nice to have:
  • Experience leading an evolution from a traditional GRC / compliance model toward an automated, engineering-led, or AI-enabled risk capability
  • Experience in a regulated or high-trust environment (e.g. SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR) and familiarity with the regulatory expectations affecting technology and cybersecurity risk
  • Exposure to AI governance, model risk, or responsible-AI program work
  • Familiarity with operational resilience and third-party risk beyond cybersecurity alone
  • Experience with Python, SQL, and REST APIs to build automated data ingestion pipelines, query security telemetry, and programmatically orchestrate risk reporting
  • Hands-on experience in SecOps, AppSec, or Security Architecture - with a focus on threat modeling, Zero Trust architecture, and data governance
  • Experience working with security and risk tooling in cloud infrastructure, hosting, and platform contexts
  • Relevant professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or ISO 27001 Lead Auditor / Lead Implementer