1

Security Risk Analyst Jobs in Baltimore, MD (NOW HIRING)

Security Analyst

Columbia, MD · Hybrid

$55 - $60/hr

The role supports risk assessments, audit readiness, control validation, and policy governance ... Security Analyst • Contract alignment • Implementing Security controls • Risk Management ...

SIMILAR CAREER TITLESInformation Security Auditor, IT Security Auditor, Cybersecurity Auditor, Compliance Analyst, Risk Assessment Specialist, Security Risk Auditor, Internal IT Auditor, Information ...

SIMILAR CAREER TITLES Information Security Auditor, IT Security Auditor, Cybersecurity Auditor, Compliance Analyst, Risk Assessment Specialist, Security Risk Auditor, Internal IT Auditor, Information ...

next page

Showing results 1-20

Security Risk Analyst information

See Baltimore, MD salary details

$10

$50

$69

How much do security risk analyst jobs pay per hour?

As of Jun 9, 2026, the average hourly pay for security risk analyst in Baltimore, MD is $50.09, according to ZipRecruiter salary data. Most workers in this role earn between $40.62 and $59.71 per hour, depending on experience, location, and employer.

What does a Security Risk Analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges Security Risk Analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

Infographic showing various Security Risk Analyst job openings in Baltimore, MD as of June 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, and 3% Contract. Highlights an 82% Physical, 7% Hybrid, and 11% Remote job distribution, with an average salary of $104,181 per year, or $50.1 per hour.
Senior Security Risk Analyst (HYBRID)

Senior Security Risk Analyst (HYBRID)

McCormick & Company

Hunt Valley, MD • Hybrid

$87K - $153K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 17 days ago


McCormick & Company rating

8.1

Company rating: 8.1 out of 10

Based on 40 frontline employees who took The Breakroom Quiz

65th of 380 rated food and drinks producers


Job description

You may know McCormick as a leader in herbs, spices, seasonings, and condiments – and we’re only getting started. At McCormick, we’re always looking for new people to bring their unique flavor to our team.

McCormick employees – all 14,000 of us across the world – are what makes this company a great place to work.

We are looking to hire an Senior Security Risk Analyst  immediately in a Hybrid (50/50) capacity at our Global Headquarters in Hunt Valley, Maryland. 

What We Bring To The Table:

The best people deserve the best rewards. In addition to the benefits you’d expect from a global leader (401k, health insurance, paid time off, etc.) we also offer:

• Competitive compensation

• Career growth opportunities

• Flexibility and Support for Diverse Life Stages and Choices

• Wellbeing programs including

Position Overview

The Senior Security Risk Analyst is a key member of the Cybersecurity Governance, Risk, and Compliance team and will report to the Senior Manager, Cybersecurity Governance, Risk & Compliance. This position will be responsible for leading assessments of security risk, establishing security standards, and ensuring compliance against those standards across all disciplines of the information security domain that support McCormick’s global brands and subsidiaries. The ideal candidate has a strong work ethic along with strong organizational, project management, and problem-solving skills. Additional key qualities include the ability to work with others to drive results. This position requires excellent verbal and written communication skills spanning across all levels of management. Candidates must thrive in a demanding, fast-paced work environment that is energetic, driven, and team-oriented. This role will also work with SMEs across the organization to mature/design security controls & mitigate risk.

Key Responsibilities

  • Intake and analysis of identified risks from a variety of sources including audits, compliance checks, automated vulnerability systems, and other internally or externally reported risks. Process risk acceptance requests and provide necessary information and analysis to allow business leaders to determine which risks are appropriate
  • Complete analyses and reports and work with the Senior Manager, Cybersecurity GRC to develop a comprehensive view of risk across the company.
  • Work with GRC tool to develop and improve workflows and processes related to management of risk
  • Process policy exception requests as needed or ad-hoc risk analysis as assigned as well as execute a detailed audit plan and identify risk areas, develop action plans, and monitor completion.
  • Draft clear, concise audit reports that communicate key insights and observations to functional/business personnel and executive leadership.
  • Demonstrate effective teaming skills with the ability to work independently as needed; leading initiation, execution, and completion to finalization and reporting for key work tasks

Required Qualifications

  • Bachelor’s degree in Information Technology, Information Systems, Risk Management, Accounting or similar
  • 5-8 years of experience related to internal/external audit, information technology, or internal controls
  • Internal/External Audit, Sarbanes-Oxley, or other internal control (IT or operational) project experiences. Strong verbal and written communication skills, with the ability to effectively communicate complex cybersecurity and IT issues and concepts to non-technical stakeholders
  • Experience using GRC tool for managing risk and compliance workflows

#LI-NP2  

McCormick & Company is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.

As a general policy, McCormick does not offer employment visa sponsorships upon hire or in the future. 

Base Salary: $87,910-$153,870 


Base salary compensation will be determined based on factors such as geographic location, skills, education, experience for this role, and/or internal equity of our current employees as part of any final offer. This position is also eligible to participate in McCormick’s Incentive Bonus (MIB) Plan. In addition to a competitive compensation package, permanent employees of McCormick are eligible for our extensive Total Rewards programs that include:
- Comprehensive health plans covering medical, vision, dental, life and disability benefits - Family-friendly benefits such as paid parental leave, fertility benefits, Employee Assistance Program, and caregiver support - Retirement and investment programs including 401(k) and profit-sharing plans


What McCormick & Company employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom