1

Security Risk Analyst Jobs in North Carolina (NOW HIRING)

National Security, Risk Mitigation Strategies, Threat Analysis Certifications: None Experience: 5 + years of related experience US Citizenship Required: Yes GDIT is seeking a qualified Risk ...

Produce security risk advisories based on newly identified threats and risk assessment * Assist in ... Experience with systems analysis including, but not limited to: Gathering requirements from ...

RSA Security Analytics Location: Charlotte, NC (20% on site (more at first) then 80% remote ... Strong knowledge of security risk procedures, security patterns, authentication technologies, and ...

RSA Security Analytics Location: Charlotte, NC (20% on site (more at first) then 80% remote ... Strong knowledge of security risk procedures, security patterns, authentication technologies, and ...

Produce security risk advisories based on newly identified threats and risk assessment * Assist in ... Experience with systems analysis including, but not limited to: Gathering requirements from ...

Network Security Engineer

Durham, NC

$101K - $138K/yr

... Systems Analysis Datawarehouse & Business Intelligence Infrastructure & Network Services Risk ... Design and implement network security solutions for all phases of network security using Managed ...

NC · On-site

$17 - $18/hr

Support risk assessments and audits by compiling data and documentation. *Monitor compliance with ... Track trends in incidents and assist with basic analysis. *Assist in organizing security drills ...

212406 Network Security Engineer

Durham, NC · On-site

$101K - $138K/yr

Network security * Risk analysis * Routing protocols - BGP - OSPF - STP - IPV6 - MPLS ... Troubleshoot and resolve complex technical issues * Troubleshoot end to end network connectivity ...

Showing results 21-40

Security Risk Analyst information

See North Carolina salary details

$9

$45

$63

How much do security risk analyst jobs pay per hour?

As of Sep 4, 2026, the average hourly pay for security risk analyst in North Carolina is $45.81, according to ZipRecruiter salary data. Most workers in this role earn between $37.12 and $54.62 per hour, depending on experience, location, and employer.

What does a security risk analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a security risk analyst?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges security risk analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.

What job categories do people searching Security Risk Analyst jobs in North Carolina look for?

The top searched job categories for Security Risk Analyst jobs in North Carolina are:

Infographic showing various Security Risk Analyst job openings in North Carolina as of August 2026, with employment types broken down into 90% Full Time, 8% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $95,286 per year, or $45.8 per hour.

Lead Security Governance Partner - Risk Management

Envestnet

Raleigh, NC • Hybrid

Full-time

Medical, Retirement, PTO

Posted 3 days ago

New


Job description

Description

The application window will close November 1st, 2026 

Job Location   

The primary work location for this role is Berwyn, PA or our Raleigh, NC office with a hybrid work model.   

  

About Envestnet  

Envestnet is an adaptive WealthTech company that is redefining the future of wealth management by helping advisors meet the moment with its comprehensive technology, actionable insights, and industry leading support. Backed byover 25 years of experience and approximately $7.0 trillion in platform assets, Envestnet is trusted by over one third of financial advisors across leading banks, wealth managers, brokerages, and RIAs.   

   

For a deeper look at how Envestnet is shaping the future of financial advice, visit www.envestnet.com.   

   

The Team You’ll Join  

You’ll join Envestnet’s Enterprise Cybersecurity team, a collaborative group focused on protecting the organization’s technology, data, and clients through effective security governance and risk management. Working closely with partners across Technology, Product, Infrastructure, Architecture, AI/ML Engineering, Legal, Compliance, and Risk & Assurance, the team identifies and evaluates security risks, strengthens controls, and supports informed business decision-making. In this role, you’ll help advance a consistent, proactive approach to managing cybersecurity risk across applications, cloud platforms, third-party integrations, and emerging technologies.

How You’ll Contribute   

Responsible for ensuring that technology decisions align with business strategy, regulatory requirements and client expectations. Encompasses administration of a strategic and comprehensive cybersecurity framework. Identifies, assesses and mitigates technology and information security risks to protect sensitive financial and client data. Establishes policies, controls and oversight to meet regulatory standards for the financial services and wealth management industry. Enables the company to operate securely, responsibly and at scale while maintaining trust with advisors, partners and regulators.  

  • Provides Security Governance support and advice companywide. 
  • Develops, validates, implements and maintains cybersecurity and related policies, standards, guidelines and procedures to ensure compliance with company and regulatory requirements. 
  • Collaborates with cross-functional teams and leaders to ensure security related controls are understood, documented and managed. 
  • Coordinates with Legal and across relevant compliance functions to ensure proper implementation of data privacy legislation and disclosure. 
  • Establishes and maintains the framework and roadmap for Security Governance documentation. 
  • Works with Cyber Security team members and business partners to define risk tolerance and construct risk scenarios. 
  • Ensures risk scenarios provide a realistic and relatable view of risks based on business context, system environment and pertinent threats. 
  • Perform Security Risk Assessments (SRAs) across applications, infrastructure, cloud platforms, third-party integrations, and AI systems to identify threats, vulnerabilities, and business impact, and determine inherent and residual risk levels using established risk taxonomies, scoring
  • methodologies, and impact criteria aligned to enterprise standards. 
  • Evaluate the design and effectiveness of technical, administrative, and operational security controls against identified risks, partnering with technology, product, infrastructure, architecture, and AI/ML engineering teams to design, recommend, and refine controls that mitigate risk to acceptable levels. 
  • Operate and leverage continuous risk monitoring tools (e.g., vulnerability management, configuration and cloud posture monitoring) to detect changes in risk posture, and analyze monitoring outputs to identify emerging risks, control degradation, and remediation needs. 
  • Own the full lifecycle of identified risks — documentation, remediation planning, validation of corrective actions, and risk closure — and produce clear, actionable risk reporting, metrics, and dashboards that communicate severity, trends, and priority issues to Information Security and technology leadership. 
  • Execute firmwide GRC activities such as RCSAs, risk acceptances and exceptions, and policy-driven risk assessments, and maintain accurate and current risk data within enterprise GRC and workflow tooling to support aggregated reporting and second-line oversight. 
  • Act as a trusted security risk advisor by translating technical findings into clear business risk context to support risk-informed decision-making, and partner closely with 2nd Line Risk & Assurance functions by providing high-quality risk artifacts and evidence, without performing independent assurance activities.

What You’ll Need to Bring  

  • Candidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role. Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences.
  • Hands‑on experience evaluating and defining security controls for AI agents, models, and applications, including model risk, data governance, and output‑integrity considerations.
  • Familiarity with risk and governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001).
  • Hands‑on experience performing Security Risk Assessments and documenting risk scenarios, impacts, controls, and conclusions.
  • Strong understanding of security control frameworks (NIST CSF, NIST SP 800-53) and risk methodologies.
  • Demonstrated experience evaluating control effectiveness and supporting remediation planning.
  • Familiarity with continuous monitoring concepts and tools (e.g., vulnerability management, CSPM, configuration monitoring).
  • Ability to clearly document and communicate security risk to both technical teams and non‑technical stakeholders.
  • Strong analytical, writing, and organizational skills with attention to detail.
  • Experience creating dashboards and KPI status from real-time data.
  • Experience operating in fast‑paced, matrixed environments with multiple stakeholders.  

Nice-to-Haves  

  • 7+ years of experience in information security, cybersecurity risk management, or technology risk.
  • Knowledge of Investment Banking or Wealth Management    
  • Resourceful and proactive in resolving technical challenges.    
  • Experience working within a Three Lines of Defense operating model, particularly in financial services or other regulated environments.
  • Hands‑on experience with Jira‑based risk workflows or enterprise GRC platforms.
  • Cloud security experience.
  • Experience with generative AI/LLM governance and secure AI development lifecycle practices.
  • Relevant certifications such as CISSP, CISM, CCSP, or equivalent.

Why You’ll Enjoy Working at Envestnet  

Help shape the future of WealthTech. At Envestnet you’ll gain hands-on experience and collaborate with some of the industry’s brightest minds to deliver meaningful, innovative solutions that make a real difference. 

We value flexibility in how and where work gets done, and we recognize strong performance with meaningful rewards—because your contributions should drive both business success and your own personal growth. If you’re looking for a place where your work has impact, your development is supported, and your contributions are truly valued, Envestnet is where you can build your future.  

The opportunity is now!  

  

Sponsorship  

This position is not open to candidates requiring visa sponsorship  

  

Our Investment in You 

This role offers a base salary range of $138,500 to $173,100. The range listed represents a good-faith estimate of base salary compensation for this position and does not include incentive compensation, equity or benefits. Individual pay will be determined based on factors including, but not limited to, relevant experience, skills, education, certifications, and geographic location, in accordance with applicable pay transparency laws.  This role is eligible for an additional incentive component as part of the total rewards package.   

 

We provide a comprehensive suite of benefits - subject to Envestnet’s plan eligibility rules - that support your overall well-being including, medical insurance, paid time off (PTO), 401k company match, paid parental leave, education reimbursement, disability coverage and mental health & wellness support. Our investment in you means supporting you professionally, financially, and personally at every stage of your journey with us.  Please visit our benefits page on our career site to learn more.  

  

Our Commitment to Inclusion & Belonging  

Envestnet is an Equal Opportunity Employer and is committed to creating an inclusive environment for all employees and applicants. We welcome and value individuals of all backgrounds and do not discriminate based on race, color, religion, creed, sex (including pregnancy or related medical conditions), gender identity or expression, sexual orientation, national origin, ancestry, age, disability, genetic information, military or veteran status, citizenship status, or any other status protected by applicable law. We encourage individuals from all backgrounds to apply.  

 

We strive to provide an inclusive application and interview process. If you are a candidate with a disability and require reasonable accommodation, please contact us at careers@envestnet.com. Please include your full name, the title of the role you are applying for, and the accommodation necessary toassistyou with the recruiting process.      

Recruitment Fraud 

At Envestnet, safeguarding the trust and safety of job seekers is a top priority. We are aware that scammers may impersonate Envestnet recruiters or create fake job opportunities to deceive candidates. Review the information on our recruitment fraud awareness page to help you recognize and avoid recruitment fraud. 

#LI-AA1