1

Security Risk Analyst Jobs in North Carolina (NOW HIRING)

Risk Analyst-ServiceMac

Concord, NC

$64K - $85K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

... security, compliance, customer satisfaction, and profitability. Our inclusive, people-first culture ... Conducts risk assessments to ensure compliance with federal and state regulatory requirements ...

Cloud Risk and Management Advisor - Mid Level

Charlotte, NC · On-site +1

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... analytical skills are essential for success in this role. Industry-recognized certifications, including PCCSP, CISSP, CISM, CRISC, CISA, Security+, or similar risk and security certifications, are ...

Cloud Risk and Management Advisor - Mid Level

Charlotte, NC · On-site +1

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... analytical skills are essential for success in this role. Industry-recognized certifications, including PCCSP, CISSP, CISM, CRISC, CISA, Security+, or similar risk and security certifications, are ...

Principal Risk Analyst-ServiceMac

Concord, NC · On-site

$97K - $130K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

... security, compliance, customer satisfaction, and profitability. Our inclusive, people-first culture ... Conducts risk assessments to ensure compliance with federal and state regulatory requirements ...

Risk Analysis

Raleigh, NC · On-site

$100K - $120K/yr

... security, and organizational standards. • Proven experience managing risk exceptions, including exception identification, impact analysis, approval workflows, compensating controls, periodic ...

... security, compliance, and business units to address operational, cyber, technology, and third-party risks. - Support governance, risk, and compliance (GRC) initiatives, policy reviews, audit ...

Senior Analyst, Credit Risk Strategy

Charlotte, NC · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

At USAA, our mission is to empower our members to achieve financial security through highly ... Credit Risk Analyst Seniors use quantitative methods to identify credit risk, develop and deliver ...

As a security analyst at Lucid you will be helping to protect corporate assets, including our world ... We stay abreast of evolving security, legal, and business requirements through a risk and ...

As a security analyst at Lucid you will be helping to protect corporate assets, including our world ... We stay abreast of evolving security, legal, and business requirements through a risk and ...

Lead Analyst, Credit Risk Strategy

Charlotte, NC · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

At USAA, our mission is to empower our members to achieve financial security through highly ... The Opportunity As a dedicated Bank Credit Risk Analyst Lead, you will have a strong background in ...

Risk Management Analyst

Fort Liberty, NC · Hybrid

$79K - $107K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

National Security, Risk Mitigation Strategies, Threat Analysis Certifications: None Experience: 5 + years of related experience US Citizenship Required: Yes GDIT is seeking a qualified Risk ...

next page

Showing results 1-20

Security Risk Analyst information

See North Carolina salary details

$9

$45

$63

How much do security risk analyst jobs pay per hour?

As of Aug 13, 2026, the average hourly pay for security risk analyst in North Carolina is $45.81, according to ZipRecruiter salary data. Most workers in this role earn between $37.12 and $54.62 per hour, depending on experience, location, and employer.

What does a security risk analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a security risk analyst?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges security risk analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.

What job categories do people searching Security Risk Analyst jobs in North Carolina look for?

The top searched job categories for Security Risk Analyst jobs in North Carolina are:

Infographic showing various Security Risk Analyst job openings in North Carolina as of August 2026, with employment types broken down into 84% Full Time, 14% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $95,286 per year, or $45.8 per hour.

Information Security Analyst 3 - SOC Analyst

Apex Systems

Charlotte, NC • On-site

Other

Medical, Dental, Vision, Life, Retirement

This job post has expired today. Applications are no longer accepted.


Job description

Job#: 3043803
Job Description:
Information Security Analyst 3 - SOC Analyst
Location
  • Charllotte, NC / Dallas, TX / Minneapolis, MN / Chandler, AZ / Des Moines. IA, Raleigh, NC

Job Summary
The Information Security Analyst 3 is responsible for supporting enterprise information security initiatives through risk analysis, security monitoring, incident response, compliance activities, security assessments, Identity and Access Management (IAM), and stakeholder consultation. This role serves as a key contributor in identifying, assessing, and mitigating cybersecurity risks while ensuring alignment with Enterprise Information Security policies, standards, and regulatory requirements.
The ideal candidate will possess a strong background in security operations, incident response, threat detection, security analytics, cloud security technologies, and identity security. This individual will partner with technology teams, security operations personnel, risk management partners, and business stakeholders to improve the organization's security posture, proactively address cyber threats, and support enterprise security governance initiatives.
Key Responsibilities
Information Security Risk Management
  • Provide information security consultation to improve awareness and compliance with Enterprise Information Security policies, standards, and procedures.
  • Perform remediation activities related to security assessments, audits, risk reviews, and control testing findings.
  • Provide guidance and recommendations regarding mitigating controls and information security risk reduction strategies.
  • Evaluate information security risk exposure through advanced data aggregation, analysis, and reporting.
  • Review and interpret security policies, standards, and procedures while recommending improvements and enhancements.
  • Support information asset portfolio reconciliation and certification activities.
  • Review proposed control standards for business impact and provide recommendations for modifications and clarifications.
  • Support enterprise risk, compliance, governance, audit, and security control programs.
Security Operations & Incident Response
  • Participate in security monitoring, investigation, containment, escalation, and remediation activities.
  • Support incident response processes utilizing established procedures, tools, and technologies.
  • Perform threat hunting and investigative activities utilizing endpoint, network, identity, and cloud security telemetry.
  • Analyze security events and alerts generated by security monitoring platforms.
  • Support cyber threat detection and response efforts through security analytics and log analysis.
  • Leverage offensive security concepts and adversarial thinking techniques to identify indicators of compromise, threat actor behaviors, and emerging threats.
  • Conduct vulnerability assessment reviews and support remediation planning activities.
Security Monitoring & Analytics
  • Utilize Security Information and Event Management (SIEM) platforms to identify, investigate, and respond to security events.
  • Leverage Security Orchestration, Automation, and Response (SOAR) tools to improve security operations efficiency.
  • Analyze host, endpoint, network, cloud, and identity-related logs to identify suspicious activity and potential security incidents.
  • Develop reporting, dashboards, and metrics related to security risks, incidents, and operational performance.
  • Conduct threat hunting activities utilizing security analytics, endpoint telemetry, and event data.
  • Support cybersecurity reporting, security metrics development, operational dashboards, and risk exposure analysis.
Identity & Access Management (IAM)
  • Support enterprise Identity and Access Management (IAM) programs and security controls.
  • Assist with Identity Governance processes, access reviews, certification activities, and entitlement validation.
  • Support provisioning and deprovisioning controls and related compliance initiatives.
  • Review and analyze identity security risks associated with access management processes.
  • Support Privileged Access Management (PAM) initiatives and enterprise access control programs.
  • Assist with implementation and validation of identity-related controls including authentication, authorization, and Attribute-Based Access Control (ABAC) frameworks.
Security Controls & Compliance
  • Conduct security control testing and validation activities.
  • Assess effectiveness of security controls and identify opportunities for improvement.
  • Support compliance initiatives and regulatory requirements within the enterprise environment.
  • Partner with risk, compliance, audit, and technology teams to ensure effective governance and control coverage.
  • Assist with development and delivery of Information Security Awareness and Education programs.
  • Support vulnerability management processes, remediation efforts, and enterprise security governance initiatives.
  • Participate in security assessments and control reviews to improve overall risk posture.
Cloud & Endpoint Security
  • Support security monitoring and investigative efforts across:
    • Microsoft Azure
    • Office 365
    • Google Cloud Platform (Google Cloud Platform)
    • Cloud-based environments
  • Monitor and analyze security events generated from Endpoint Detection and Response (EDR) platforms.
  • Support implementation and maintenance of security controls protecting cloud and endpoint technologies.
  • Evaluate cloud security risks and recommend appropriate mitigation strategies.
  • Assist with monitoring cloud security posture and compliance requirements across multi-cloud environments.
Security Engineering & Automation
  • Support security tool integrations and automation initiatives that improve detection and response capabilities.
  • Partner with security engineering teams to enhance monitoring, workflow automation, and operational effectiveness.
  • Support SOAR implementation efforts and security automation activities.
  • Contribute to DevSecOps and security operations modernization initiatives.
  • Assist with security analytics and advanced detection engineering efforts.
Collaboration & Leadership
  • Collaborate with peers, technology teams, security engineers, compliance partners, and business stakeholders.
  • Provide consultation and security guidance to internal customers.
  • Support cross-functional security initiatives and projects.
  • Mentor junior analysts and provide knowledge sharing across the team.
  • Participate in continuous improvement efforts to strengthen security operations and risk management programs.
  • Serve as a trusted advisor on information security risks, controls, and incident response activities.
Required Qualifications
  • 4+ years of Information Security Analysis experience or equivalent demonstrated through work experience, military experience, education, or training.
  • 2+ years of Information Security Engineering experience.
  • 1+ year of Incident Response experience utilizing security monitoring tools and response methodologies.
  • 1+ year of experience with:
    • Security Information and Event Management (SIEM) platforms
    • Security Orchestration, Automation, and Response (SOAR) solutions
  • 1+ year of experience supporting:
    • Microsoft Azure
    • Office 365
    • Cloud security technologies
  • Experience conducting security investigations and responding to security incidents.
  • Knowledge of security analytics, incident response, and digital forensics disciplines.
  • Experience developing security reports, dashboards, and risk analysis deliverables.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent verbal and written communication skills.
Preferred Qualifications
  • 2+ years of experience supporting Endpoint Detection and Response (EDR) solutions.
  • Experience with:
    • Threat Hunting
    • Security Operations
    • Incident Response
    • Digital Forensics
    • Security Analytics
  • Experience supporting Identity and Access Management (IAM), Identity Governance, Access Reviews, Provisioning and Deprovisioning, Privileged Access Management (PAM), and enterprise access control programs.
  • Experience developing cybersecurity metrics, dashboards, reporting, and operational security analytics.
  • Knowledge of offensive security concepts including penetration testing methodologies, adversary tactics, exploitation techniques, and vulnerability research.
  • Experience performing host and network log analysis in support of threat investigations and incident response activities.
  • Experience supporting vulnerability management, remediation planning, security assessments, and enterprise security governance initiatives.
  • Experience securing and monitoring cloud environments including Microsoft Azure and Google Cloud Platform (Google Cloud Platform).
  • Experience supporting security automation, security tool integrations, SOAR initiatives, and DevSecOps-driven security operations.
  • Experience working in banking, financial services, or other highly regulated environments.
  • Experience working within a 24x7x365 Security Operations Center (SOC) environment.
Technical Skills
Security Operations
  • Incident Response
  • Threat Hunting
  • Security Monitoring
  • Digital Forensics
  • Security Investigations
  • Security Analytics
  • Threat Detection
  • Cyber Threat Analysis
Security Platforms
  • SIEM
  • SOAR
  • Endpoint Detection & Response (EDR)
  • Log Management Solutions
  • Security Monitoring Platforms
  • Security Automation Tools
Cloud Security
  • Microsoft Azure
  • Office 365
  • Google Cloud Platform (Google Cloud Platform)
  • AWS
  • Cloud Security Monitoring
  • Cloud Security Controls
  • Cloud Risk Management
Identity & Access Management
  • Identity Governance
  • Access Reviews
  • Privileged Access Management (PAM)
  • Authentication & Authorization
  • IAM Administration
  • Provisioning & Deprovisioning
  • Attribute-Based Access Control (ABAC)
Security Controls & Governance
  • Security Assessments
  • Security Risk Management
  • Security Control Testing
  • Information Security Governance
  • Regulatory Compliance
  • Audit Management
  • Vulnerability Management
  • Remediation Planning
Security Technologies
  • Firewalls
  • Intrusion Detection Systems (IDS)
  • Intrusion Prevention Systems (IPS)
  • Malware Protection
  • Encryption Controls
  • Content Filtering
  • Internet Proxies
  • Endpoint Security Controls
Preferred Certifications
One or more of the following certifications are highly desired:
  • GIAC (Global Information Assurance Certification)
  • OSCP (Offensive Security Certified Professional)
  • OSWP (Offensive Security Wireless Professional)
  • OSCE (Offensive Security Certified Expert)
  • OSEE (Offensive Security Exploitation Expert)
  • OSWE (Offensive Security Web Expert)
Cloud Certifications
  • AWS Certified Security Specialty
  • Microsoft Azure Security Engineer Associate
  • Google Professional Cloud Security Engineer
  • Other relevant cloud security certifications
Desired Candidate Profile
The ideal candidate is a cybersecurity professional with expertise in incident response, threat detection, security monitoring, cloud security, security analytics, and Identity and Access Management (IAM). This individual possesses strong analytical and investigative skills, experience leveraging SIEM, SOAR, and EDR technologies, and the ability to identify and respond to complex cybersecurity threats.
Successful candidates will have experience supporting enterprise security operations, conducting threat hunting activities, performing vulnerability assessments, developing security metrics and reporting, and collaborating with risk, compliance, audit, and technology teams. Experience within large-scale, highly regulated environments such as financial services organizations is highly preferred.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everfo