1

Security Risk Analyst Jobs in Kentucky (NOW HIRING)

$41.75 - $55.75/hr

The IT Governance/Risk/Compliance Analyst position offers a dynamic opportunity for an experienced ... Ensure data security and privacy compliance by providing guidance on appropriate access controls ...

Director, Security

Lexington, KY · On-site

$120 - $150/hr

Manage comprehensive security program supporting the Special Operations Forces Global Logistic ... Familiar with risk analysis process integrating intelligence, cyber posture, operational tempo, and ...

New

Familiar with risk analysis process integrating intelligence, cyber posture, operational tempo, and ... Knowledge of current security vulnerabilities and threats; Ability to collaborate with all levels ...

The Security Analyst supports customer engagements by helping to deliver business and technology ... Collaborate with the EM to develop and maintain detailed project plans, milestones, risk registers ...

Posted today

Showing results 21-40

Security Risk Analyst information

See Kentucky salary details

$8

$43

$60

How much do security risk analyst jobs pay per hour?

As of Aug 7, 2026, the average hourly pay for security risk analyst in Kentucky is $43.78, according to ZipRecruiter salary data. Most workers in this role earn between $35.48 and $52.21 per hour, depending on experience, location, and employer.

What does a security risk analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a security risk analyst?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges security risk analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.
What are popular job titles related to Security Risk Analyst jobs in Kentucky? For Security Risk Analyst jobs in Kentucky, the most frequently searched job titles are:
What job categories do people searching Security Risk Analyst jobs in Kentucky look for? The top searched job categories for Security Risk Analyst jobs in Kentucky are:
Infographic showing various Security Risk Analyst job openings in Kentucky as of August 2026, with employment types broken down into 79% Full Time, and 21% Contract. Highlights an 79% In-person, 5% Hybrid, and 16% Remote job distribution, with an average salary of $91,063 per year, or $43.8 per hour.

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 17 days ago


Job description

Job Overview
The security analyst monitors, detects, investigates, and responds to cybersecurity threats across the organization’s enterprise IT and operational technology (OT) environments, and maintains and operates
the organization’s physical access control systems. This is a converged role: the analyst works fluently across corporate networks, cloud and identity platforms, and industrial control systems, applying a
defense-in-depth approach that respects the distinct risk tolerances, availability requirements, and safety considerations of each domain. The analyst will work closely with other teams to ensure security is
designed and implemented into new and existing projects.
Company Overview

Since 1904, Southern Star has proudly served as a reliable natural gas transporter to America’s heartland. Southern Star is an innovative, customer-oriented company committed to collaboration in all parts of our business. With over a century of trusted service, we continue to prioritize what sets us apart—our people.

At Southern Star, you’ll find a workplace where your growth matters, your voice is heard, and your contributions are recognized. Whether you're just starting out or looking to take the next big step in your career, Southern Star is the employer of choice where you can make a meaningful impact.

Will you be the next talented individual to join our team?


Benefits Overview

We believe great work deserves great rewards. In exchange for your passion and expertise, we provide a benefits package that supports your well-being and growth in all aspects of life.

  • Medical
  • Vision
  • Dental
  • Supplemental Life Insurance
  • Dependent Life Insurance
  • Flexible Spending Account
  • Wellness Programs
  • Service Awards
  • Educational Reimbursement
  • Fitness Reimbursement
  • Holidays
  • Paid Time Off
  • Parental & Maternity Leave
  • 401K



  • Performing installation and maintenance of security infrastructure hardware and software
  • Monitoring security alerts and telemetry across SIEM, EDR/XDR, and OT monitoring platforms,
    and proactively reviewing internal and external-facing environments for signs of anomalous or
    malicious activity; triaging, investigating, and escalating per the incident response plan
  • Conducting threat hunting using the MITRE ATT&CK framework and MITRE ATT&CK for ICS as
    detection and investigation frameworks
  • Performing vulnerability management activities, including scanning, prioritization, remediation
    tracking, and risk acceptance documentation, across both IT and OT asset inventories
  • Maintaining and tuning access control rules, correlation logic, and alerting to reduce false
    positives and improve mean-time-to-detect and mean-time-to-respond
  • Facilitating process improvements for more effective threat detection and response
  • Maintaining knowledge of modern network security tools, technologies, and threat landscape
  • Working closely with other teams to ensure network security is designed and implemented into
    new projects
  • Supporting incident response across the full NIST lifecycle, including preparation, detection and
    analysis, containment, eradication, recovery, and post-incident review
  • Investigating alerts within cloud and identity platforms, such as Microsoft 365, Entra ID, XDR
    platforms, conditional access, and privileged access events
  • Analyzing email security verdicts, conducting phishing and business email compromise
    investigations, and managing quarantine and remediation workflows
  • Authoring and refining detection queries (e.g., KQL, SPL) and dashboards
  • Supporting endpoint, network, and firewall security operations and policy review
  • Regularly research and monitor security-related information sources to aid in the identification of
    threats
  • Contributing to security awareness initiatives, phishing simulation analysis, and reporting metrics
    for leadership
  • Develops knowledge of business processes, network protocols, and system architecture
  • Researching and testing updates to existing technology; suggest new technologies
  • Maintaining relationships with customers
  • Participating on IT related projects as well as cross-functional teams
  • Receiving general instructions and ability to work independently
  • Continuous self-improvement and willingness to learn

Minimum Qualification

  • Bachelor’s degree or equivalent experience
  • Entry-level experience in security or related area (Will also consider candidates with more experience).
  • Knowledge in IT network security
  • Knowledge of network forensics, data loss prevention, packet analysis, vulnerability management,
    and security operations
  • Familiarity with the MITRE ATT&CK framework and the cyber kill chain
  • Understanding of TCP/IP networking, segmentation, firewalls, and common attack techniques
  • Strong problem-solving skills
  • Strong communication skills
  • Ability to collaborate with other technical groups to find solutions
  • A desire to expand current knowledge and skills
  • Well organized, willing to take initiative, and work independently

Preferred Qualification

  • Advanced degree
  • Exposure to OT/ICS environments, or a demonstrated willingness to develop OT competency
  • Scripting or automation familiarity (e.g., PowerShell, Python) for SOAR or remediation workflows
  • Linux competency

License and Insurability

A valid driver’s license and insurability under company policy are required.