1

Security Risk Analyst Jobs in Utah (NOW HIRING)

Improve decision-making using security insights, data analytics, and modeling to validate the organization's risk landscape. Manage Adobe's Security Management framework, integrate industry-leading ...

Stand up and operationalize the enterprise risk register, anchored by a baseline HIPAA Security Risk Analysis. * Build the vendor risk inventory, validate BAA coverage across all PHI-handling vendors ...

next page

Showing results 1-20

Security Risk Analyst information

See Utah salary details

$9

$45

$63

How much do security risk analyst jobs pay per hour?

As of May 29, 2026, the average hourly pay for security risk analyst in Utah is $45.89, according to ZipRecruiter salary data. Most workers in this role earn between $37.21 and $54.71 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges Security Risk Analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What does a Security Risk Analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What are popular job titles related to Security Risk Analyst jobs in Utah? For Security Risk Analyst jobs in Utah, the most frequently searched job titles are:
What job categories do people searching Security Risk Analyst jobs in Utah look for? The top searched job categories for Security Risk Analyst jobs in Utah are:
Infographic showing various Security Risk Analyst job openings in Utah as of May 2026, with employment types broken down into 1% As Needed, 92% Full Time, 5% Part Time, and 2% Contract. Highlights an 95% Physical, 2% Hybrid, and 3% Remote job distribution, with an average salary of $95,450 per year, or $45.9 per hour.
IT Security Risk Analyst II

IT Security Risk Analyst II

Western Governors University

Salt Lake City, UT • On-site

$105.60K - $158.40K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 16 days ago


Western Governors University rating

8.6

Company rating: 8.6 out of 10

Based on 41 frontline employees who took The Breakroom Quiz

49th of 529 rated colleges and universities


Job description

If you're passionate about building a better future for individuals, communities, and our country-and you're committed to working hard to play your part in building that future-consider WGU as the next step in your career.
Driven by a mission to expand access to higher education through online, competency-based degree programs, WGU is also committed to being a great place to work for a diverse workforce of student-focused professionals. The university has pioneered a new way to learn in the 21st century, one that has received praise from academic, industry, government, and media leaders. Whatever your role, working for WGU gives you a part to play in helping students graduate, creating a better tomorrow for themselves and their families.
The salary range for this position takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs.
At WGU, it is not typical for an individual to be hired at or near the top of the range for their position, and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is:
Grade: Technical 407
Pay Range: $105,600.00 - $158,400.00
Job Description
Impact at WGU
As an IT Security Risk Analyst II, you will play a critical role in protecting WGU's students, data, and mission by ensuring third parties and suppliers meet the university's security and risk management standards. This is a hands-on, experienced role where you will own vendor risk assessments end to end, contribute to broader enterprise risk initiatives, and help mature WGU's third-party risk management program through strong judgment, clear communication, and continuous improvement.
What You'll Do
  • Own and execute third-party and supplier risk assessments using NIST 800-171 and similar frameworks
  • Independently scope assessments by identifying data flows, CUI exposure, inherent risk, and assessment approach
  • Validate vendor controls and trace conclusions from inherent risk through residual risk with defensible rationale
  • Review and analyze vendor evidence such as SOC 2 Type II reports, ISO 27001 certifications, SIG responses, and penetration test summaries
  • Evaluate security controls across infrastructure, applications, and cloud environments including AWS and Azure, clearly identifying gaps
  • Assess vendor criticality and business impact, including breach and termination scenarios
  • Conduct OSINT research to inform third-party security posture and risk profile
  • Deliver clear, actionable risk assessment reports, including executive summaries for leadership
  • Partner with business units to translate technical risk into business impact and guide remediation efforts
  • Contribute to internal risk assessments, exception-to-policy evaluations, and enterprise risk discussions
  • Identify process gaps and propose practical improvements, including AI-driven efficiencies to enhance assessment quality and speed

What You'll Bring
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, or a related field
  • 3 or more years of experience in IT security or risk management with direct third-party or vendor risk assessment ownership
  • Demonstrated ability to independently deliver end-to-end risk assessments on schedule
  • Broad understanding of information security risk beyond TPRM, including internal systems, projects, and policy exceptions
  • Hands-on experience evaluating SOC 2, ISO certifications, SIG questionnaires, and penetration test results
  • Practical knowledge of cloud environments and associated security controls
  • Strong risk judgment with the ability to weigh evidence and make defensible determinations
  • Clear written and verbal communication skills, able to articulate risk to technical and non-technical audiences
  • Accountability for quality, accuracy, and timelines without constant oversight

Bonus Points
  • Certifications such as CRISC, CISA, CISM, CISSP, or cloud security credentials
  • Experience in higher education or financial services environments
  • Experience with TPRM programs aligned to NIST 800-171 or CMMC
  • Knowledge of FERPA and GLBA as applied to third-party data sharing and sensitive data protection

What to Expect
At WGU, our mission drives everything we do, including how we hire. Our interview experience is designed to give qualified candidates the opportunity to show their best work through meaningful conversations and collaboration.
We thoughtfully review every application and invite forward the candidates whose experience and potential best align with the role and our mission.
Interview Steps
  • Introductory call
  • Hiring leader interview
  • Director interview

Work Location
This is a full-time, in-office position at WGU's office in Salt Lake City, Utah.
Visa Sponsorship
While we welcome applicants from all backgrounds, WGU is not able to provide visa sponsorship for this role.
As an equal opportunity employer, we recognize our strength lies in our people and are committed to creating an inclusive environment where all can thrive.
#LI-aw2
Position & Application Details
Full-Time Regular Positions (classified as regular and working 40 standard weekly hours): This is a full-time, regular position (classified for 40 standard weekly hours) that is eligible for bonuses; medical, dental, vision, telehealth and mental healthcare; health savings account and flexible spending account; basic and voluntary life insurance; disability coverage; accident, critical illness and hospital indemnity supplemental coverages; legal and identity theft coverage; retirement savings plan; wellbeing program; discounted WGU tuition; and flexible paid time off for rest and relaxation with no need for accrual, flexible paid sick time with no need for accrual, 11 paid holidays, and other paid leaves, including up to 12 weeks of parental leave.
How to Apply: If interested, an application will need to be submitted online. Internal WGU employees will need to apply through the internal job board in Workday.
Additional Information
Disclaimer: The job posting highlights the most critical responsibilities and requirements of the job. It's not all-inclusive.
Accommodations: Applicants with disabilities who require assistance or accommodation during the application or interview process should contact our Talent Acquisition team at recruiting@wgu.edu.
Equal Employment Opportunity: All qualified applicants will receive consideration for employment without regard to any protected characteristic as required by law.

What Western Governors University employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom