1

Security Risk Analyst Jobs in Baltimore, MD (NOW HIRING)

... Risk Analyst, Cyber Defense Analyst, Network Security Analyst, IT Security Specialist, Security Consultant, Cybersecurity Specialist, Malware Analyst, Security Architect, ect. DEGREE (Level Desired ...

... securities, sectors, etc.) and material changes in risk profiles. * Analyze tail risks and conduct stress tests based on hypothetical and historical scenarios. * Collaborate with equity investment ...

Showing results 41-60

Security Risk Analyst information

See Baltimore, MD salary details

$10

$50

$69

How much do security risk analyst jobs pay per hour?

As of Jul 25, 2026, the average hourly pay for security risk analyst in Baltimore, MD is $50.09, according to ZipRecruiter salary data. Most workers in this role earn between $40.62 and $59.71 per hour, depending on experience, location, and employer.

Can I make $200,000 a year in cyber security?

Security Risk Analysts and other cybersecurity professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP, and expertise in areas such as threat analysis or security architecture. High salaries are often found in senior roles, management, or specialized fields within cybersecurity.

What does a Security Risk Analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges Security Risk Analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

Can you make $500,000 a year in cyber security?

Security Risk Analysts typically earn salaries below $200,000 annually, but senior roles such as Chief Information Security Officers or cybersecurity executives can reach or exceed $500,000 with extensive experience, certifications, and leadership responsibilities. Achieving this level often requires advanced skills, industry certifications like CISSP, and years of experience in high-level security management. Salary potential varies based on the organization, location, and individual expertise.

Is SOC an entry-level job?

A Security Operations Center (SOC) analyst role is often considered an entry-level position in cybersecurity, suitable for individuals with foundational knowledge of security principles, network protocols, and security tools. However, some SOC roles may require prior experience or certifications such as CompTIA Security+ or Certified SOC Analyst (CSA).

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.
What are popular job titles related to Security Risk Analyst jobs in Baltimore, MD? For Security Risk Analyst jobs in Baltimore, MD, the most frequently searched job titles are:
Infographic showing various Security Risk Analyst job openings in Baltimore, MD as of July 2026, with employment types broken down into 78% Full Time, 11% Temporary, and 11% Contract. Highlights an 89% In-person, and 11% Remote job distribution, with an average salary of $104,181 per year, or $50.1 per hour.
Sr. Research Analyst

$114K - $115K/yr

Full-time

Medical, Life, Retirement

Posted 10 days ago


Job description

Overview

Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter. Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.  

The Joint, Office of the Secretary of Defense, Interagency Division provides expert support services to a range of customers spanning across the Department of Defense, Federal Civilian, and international markets. JOID provides a diverse portfolio of analytical and programmatic capabilities to help our customers make informed decisions on their most challenging issues.

The Industry and Security Analysis Group (ISAG) within JOID provides analytical, technical, and program support to promote, grow, and protect the U.S. industrial base. ISAG's support spans the Department of Defense (DOD), Department of Commerce, and other agencies to deliver critical decision support to national security leaders. Our team informs policy decisions, enables execution of comprehensive strategies and monitors and reports on the effectiveness of implementation. This enables senior leaders to execute strategies for developing and sustaining a robust industrial base that meets our nation's strategic resource objectives. From policy to practice, we are a team of economic and national security professionals providing innovative solutions for our Nation's most pressing security challenges.

We have an immediate need for a Sr. Research Analyst to provide onsite support at the Applied Research Laboratory for Intelligence and Security (ARLIS) in College Park, MD, with the potential of working at alternative sites across the National Capital Region (e.g., Mark Center, Pentagon, etc.) based on client needs.

Responsibilities

This role supports the Office of the Under Secretary of Defense for Research and Engineering's (OUSD(R&E's)) Joint Acquisition Protection and Exploitation Cell (JAPEC). This position requires collaboration with Law Enforcement (LE) and Counterintelligence (CI) organizations and ARLIS personnel. The candidate will serve as a Senior Researcher on the JAPEC team in the OUSD(R&E's) Office of Science & Technology Program Protection, conducting collaboration with LE and CI organizations, onsite USG clients, and DoD leadership at the Mark Center and Pentagon. Will respond to emergent requests for technology risk assessments synthesizing information from diverse sources resulting in recommendations for enhanced protection of the DoD's critical technologies and programs. To support this, the candidate will be expected to take the initiative to proactively seek out and engage with intelligence, security, academia, and government personnel to collect key data and sources to inform assessments. The position will also support the development of complex gap analyses and risk matrices for high-value dual-use or military technologies to identify opportunities to maintain, and potentially increase, U.S. technological advantage. 

Qualifications

Required:

  • PhD in a STEM field pertaining to the OUSD(R&E) Critical Technology Areas of Applied Artificial Intelligence, Biomanufacturing, Contested Logistics Technologies, Quantum and Battlefield Information Dominance, Scaled Hypersonics, and Scaled Directed Energy.
  • Active Top Secret Clearance with SCI eligibility.
  • 5+ years of experience.
  • Experience conducting in-depth technical and security risk assessments through literature research and data evaluation.
  • Experience working with an interdisciplinary team of experts that collectively implement and recommend security features for the nation's most pertinent technology.
  • Exceptional oral and written communication skills.
  • Excellent interpersonal and organizational skills.
  • Proficiency with computers, search-functionality, databases, and Microsoft Office Suite.
  • Able to work fully onsite based on client needs.

Desired:

  • Experience working on an inter-governmental Task Force or with the DoD Intelligence/Counterintelligence Community.
  • Demonstrated ability to work from high-level, limited, and evolving guidance to produce timely and effective results.
  • Ability to work both independently and with personnel from multiple organizations.
  • Familiarity with DoD technology development and acquisition policies.

At SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc.Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. VA Pay Transparency Salary range: $160k - $200k

Employment Type: FULL_TIME