1

Security Risk Jobs (NOW HIRING)

Security Risk Manager

San Francisco, CA · Hybrid

$194K - $220K/yr

As the Security Risk Manager, you will own Asana's internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists - you will ...

Security Risk Manager

San Francisco, CA · On-site

$194K - $220K/yr

As the Security Risk Manager, you will own Asana's internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists - you will ...

Great opportunity for a hands-on Sr. Security/Risk Analyst, an IT leader with ambition and drive to provide strategy, vision, communication, and direction regarding security risks to safeguard ...

Description We are seeking a Senior AI Security Risk Assessment Consultant to help establish and operationalize our client's organization's enterprise AI Security Risk Assessment Methodology. This ...

The Security Risk & Compliance Analyst (Analyst) is responsible for ensuring that Jamf 's security controls, policies, and procedures are implemented in accordance with applicable laws, regulations ...

As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you ...

As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you ...

As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you ...

As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you ...

The Security Risk & Compliance Analyst (Analyst) is responsible for ensuring that Jamf 's security controls, policies, and procedures are implemented in accordance with applicable laws, regulations ...

As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you ...

As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you ...

As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you ...

next page

Showing results 1-20

Security Risk information

See salary details

$10

$50

$69

How much do security risk jobs pay per hour?

As of Aug 31, 2026, the average hourly pay for security risk in the United States is $50.41, according to ZipRecruiter salary data. Most workers in this role earn between $40.87 and $60.10 per hour, depending on experience, location, and employer.

What is a security risk professional?

Security risk professionals are experts who identify, assess, and mitigate potential threats to an organization's physical and digital assets. Their responsibilities include conducting risk assessments, developing security policies, and ensuring compliance with regulations. They work to minimize vulnerabilities that could lead to data breaches, theft, or other security incidents. These professionals may also train staff on security best practices and respond to security incidents as they arise.

What are the key skills and qualifications needed to thrive as a security risk analyst, and why are they important?

To thrive as a Security Risk Analyst, you need a strong understanding of information security principles, risk assessment methodologies, and relevant regulations, typically supported by a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), vulnerability assessment tools, and certifications like CISSP or CISM are highly valued. Analytical thinking, attention to detail, and effective communication skills help convey risk findings and collaborate with diverse stakeholders. These competencies are crucial for identifying threats, minimizing vulnerabilities, and ensuring organizational resilience against security risks.

What are some common challenges faced by security risk professionals, and how can they overcome them?

Security Risk professionals often face challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and gaining buy-in from stakeholders for risk mitigation strategies. To overcome these, it’s essential to engage in continuous learning, build strong cross-functional relationships, and communicate the value of security initiatives in business terms. Developing robust reporting and assessment processes can also help identify risks early and ensure effective collaboration across departments.

What is the difference between Security Risk vs Security Analyst?

AspectSecurity RiskSecurity Analyst
Required CredentialsKnowledge of security principles, risk assessment skillsCertifications like CompTIA Security+, CISSP, or CISA
Work EnvironmentIdentifying potential threats, assessing vulnerabilitiesMonitoring security systems, analyzing security data
Employer & Industry UsageUsed across industries to identify threatsCommonly employed in cybersecurity teams
Search & Comparison IntentUnderstanding risk factors and mitigationAnalyzing security incidents and improving defenses

Security Risk involves identifying and assessing potential threats to an organization, focusing on risk management strategies. Security Analysts, on the other hand, monitor and analyze security systems to detect and respond to threats. While both roles require security knowledge and certifications, Security Risk professionals focus on risk assessment, whereas Security Analysts are more involved in operational security monitoring.

What is a security risk officer?

A security risk officer is a professional responsible for identifying, assessing, and mitigating security risks within an organization. They develop security policies, conduct risk assessments, and implement measures to protect assets, often requiring knowledge of cybersecurity, physical security, and relevant regulations. Certifications like CISSP or CISM can enhance their qualifications.
More about Security Risk jobs

What cities are hiring for Security Risk jobs?

Cities with the most Security Risk job openings:

What states have the most Security Risk jobs?

States with the most job openings for Security Risk jobs include:

Infographic showing various Security Risk job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $104,848 per year, or $50.4 per hour.

Security Risk Manager

Asana

San Francisco, CA • Hybrid

$194K - $220K/yr

Full-time

Retirement

Re-posted 2 days ago


Job description

At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance, and fostering a culture of security throughout our product and operations.

As the Security Risk Manager, you will own Asana's internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists - you will engineer the quantitative and automated foundations that let Asana continuously measure and make confident decisions about security risk. You'll build the systems and processes that make risk scalable, not just the policies that describe it, and serve as a trusted advisor to senior leadership.

This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements

What you'll achieve

  • Own Asana's security risk management program: Design and continuously mature a quantitative risk framework - including risk scoring methodologies, likelihood and impact modeling, and risk appetite thresholds - that enables consistent, data-driven risk decisions across the organization.
  • Build and maintain a living risk register: Own Asana's central security risk register, developing KRIs, tracking trends over time, and driving accountability for risk treatment and remediation with business and technical owners.
  • Automate risk identification and monitoring: Design and implement automated data pipelines and integrations that continuously surface security risks - pulling signals from vulnerability scanners, cloud security tooling, SIEMs, and third-party risk sources - so Asana's risk posture is always current and not dependent on manual review cycles.
  • Deliver quantitative risk reporting: Develop executive-level dashboards that communicate security risk in business terms - probability, potential impact, cost of control vs. cost of breach, and residual risk exposure - to inform investment and prioritization decisions.
  • Partner cross-functionally on risk: Act as the primary security risk partner to Legal, Privacy, Finance, and Engineering. Influence security investment decisions and build a culture of risk awareness across the company.

About you

  • 7+ years of experience in information security with a strong focus on security risk management and GRC.
  • Demonstrated experience building or leading a security risk management program - not just contributing to one.
  • Hands-on experience with quantitative risk methodologies such as FAIR, risk scoring models, or statistical risk analysis. You back up risk ratings with numbers, not just color codes.
  • Hands-on experience scripting or building automation to integrate security tooling, build data pipelines, or automate risk monitoring - you've built things, not just directed others to build them.Deep knowledge of security frameworks including NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, and FedRAMP.
  • Proven ability to develop risk metrics, KRIs, and executive-level reporting that drives decision-making.
  • Strong understanding of cloud environments and SaaS architecture - enough to have credible risk conversations with technical teams.
  • Excellent communicator who can translate technical risk findings for both engineering teams and C-suite stakeholders.
  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity and decision-making.

At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills. If you're interested in this role and don't meet every listed requirement, we still encourage you to apply.

What we'll offer

For this role, the estimated base salary range is between $194,000-$220,000. The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process.

In addition to base salary, your compensation package may include equity and benefits. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more.

We strive to provide equitable and competitive benefits packages that support our employees worldwide and include:

  • Mental health, wellness & fitness benefits
  • Career coaching & support
  • Inclusive family building benefits
  • Long-term savings or retirement plans
  • In-office culinary options to cater to your dietary preferences

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

#LI-Hybrid