1

Security Risk Analyst Jobs in Baltimore, MD (NOW HIRING)

Today, our expertise extends broadly across closely related security and risk-based fields - from accessibility consulting and risk analysis to process safety, forensic investigations, security risk ...

SIMILAR CAREER TITLESCyber Threat Analyst, Intelligence Analyst, Security Analyst, Risk Analyst, Threat Intelligence Specialist, Vulnerability Analyst, Incident Response Analyst, Counterintelligence ...

Financial Analyst I (FP&A)

Columbia, MD ยท On-site +1

$68K - $75K/yr

Today, our expertise extends broadly across closely related security and risk-based fields - from accessibility consulting and risk analysis to process safety, forensic investigations, security risk ...

next page

Showing results 1-20

Security Risk Analyst information

See Baltimore, MD salary details

$10

$50

$69

How much do security risk analyst jobs pay per hour?

As of Jun 10, 2026, the average hourly pay for security risk analyst in Baltimore, MD is $50.09, according to ZipRecruiter salary data. Most workers in this role earn between $40.62 and $59.71 per hour, depending on experience, location, and employer.

What does a Security Risk Analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges Security Risk Analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

Infographic showing various Security Risk Analyst job openings in Baltimore, MD as of June 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, and 3% Contract. Highlights an 82% Physical, 7% Hybrid, and 11% Remote job distribution, with an average salary of $104,181 per year, or $50.1 per hour.
Information Security Analyst Lead

Information Security Analyst Lead

eSimplicity

Fort George G Meade, MD โ€ข On-site

$112K - $165K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 14 days ago


Job description

Description:

About Us

eSimplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to children, families, and seniors. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that equip federal agencies with solutions to courageously transform today for a better tomorrow.


Purpose and Scope

We are seeking an Information Security Analyst who is responsible for providing security support services while meeting security control compliance requirements for a portfolio of systems at various states of maturity and modernization. This role will provide support for continuously monitoring the cybersecurity posture of systems to secure against cyber threats.


The primary responsibility is to facilitate security tool and control implementation, security tool usage, and ensure tools and controls remain compliant and configured properly, all the while ensuring a successful program Authorization to Operate (ATO). Additionally, the expectation is to take ownership of communication and visualization of security issues, especially where coordination between product teams, information owners, engineering, and infrastructure staff is necessary for remediation.


The candidate will own coordination and response to the agencyโ€™s security-related inquiries, compliance with agency policy, security controls, and the maintenance of security documentation and artifacts. You will function as the primary liaison to provide timely and accurate responses to security-related data calls (System Security & Compliance Status, Vulnerability, and Compliance scanning issues) and provide security guidance throughout the system development lifecycle. This role requires interfacing with multiple stakeholders through multiple touchpoints weekly.



Responsibilities

  • Work closely with Product Owners, other ISSOs, ISSMs, and engineering and infrastructure staff to provide guidance on the implementation of security policies, standards, and procedures.
  • Analyze new or updated security requirements, collaborate with stakeholders, and develop responses that are clear and accurate.
  • Support the review and update of ATO artifacts such as System Security Plans, Information System Contingency Plans, Configuration and Change Management Plans, Incident Response Plans, Privacy Impact Analyses, and more.
  • Interpret security risk assessments, review security scan results, assess security vulnerabilities, and support the development and remediation of vulnerability and compliance issues via Plans of Action and Milestones (POA&Ms).
  • Support the development and implementation of design documentation.
  • Work with engineering and infrastructure personnel to document remediation for vulnerabilities and non-compliance issues.
  • Analyze and interpret agency security requirements and provide governance communication to non-security personnel.
  • Collaborate with product teams, ISSOs, and other stakeholders in support of continuous monitoring and ATO efforts.
  • Conduct vulnerability assessments and monitor systems, networks, databases, and Web-based assets for potential system breaches.
  • Recommend and take the lead on implementing changes to enhance security systems, prevent unauthorized access, and help mitigate security vulnerabilities.
  • Respond to alerts from information security tools. Report, investigate, and resolve higher-level security incidents.
  • Respond to security tool outages and degradations in service, tune security rules and alerts, and set up/maintain security tool dashboards and reporting.
  • Research security trends, new methods, and techniques used in unauthorized access of data to preemptively eliminate the possibility of system breach.
  • Ensure compliance with regulations and privacy laws. Conduct research to identify new attack vectors.
  • Educate and communicate security requirements and procedures to all users and new employees.
  • Recommend process improvements to the information system for risk mitigation.
  • Support continuous improvement and security automation practices to strengthen the programโ€™s overall security posture.
  • Conduct audit log reviews, present findings, and plan for investigation or remediation activities.
  • Perform periodic user and privileged access reviews.



Requirements:

Required Qualifications

  • Minimum of 8+ years of related experience.
  • Must hold a current Security+ certification.
  • Bachelorโ€™s degree in Computer Science, Information Systems, Engineering, Business, or a related technical discipline is preferred. Additional relevant experience may be considered in lieu of a degree.
  • Experience designing security "baked-in" to architectures including Cloud and IaC, applications, web applications, data processing, data-centric applications, AI/ML, and CI/CD pipelines.
  • A proven track record of seeking automation-driven designs.
  • Familiarity with Agile methodologies.
  • Working knowledge of AWS or Azure security tools, their functionality, and their purpose.
  • Ability to assist customers with defining appropriate management processes (responsible for documenting application criticality, privacy, and security impact analysis).
  • Knowledge of hardening standards (DISA STIG, CIS).
  • Experience with the NIST Risk Management Framework, NIST 800-53 rev5, and NIST 800-171..

Desired Qualifications

  • Federal Government contracting work experience.
  • Experience as an ISSO for the DoD.
  • Highly preferred industry certifications such as CISSP, CEH, GIAC, etc.
  • Experience with Security Information and Event Management (SIEM) systems (e.g., Splunk).

Location and Hours


Location: This role is primarily remote; however, the employee must be able to report on-site to Fort Meade, MD when requested due to customer or business needs. The frequency and timing of on-site support may vary and cannot be guaranteed in advance.

Hours: Expected hours are 9:00 AM to 5:00 PM Eastern Time unless otherwise directed by your manager.

Travel: Occasional travel for training and project meetings, estimated to be less than 5% per year.


Benefits:

eSimplicity offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k) retirement benefits, paid time off, paid holidays, life and disability insurance, and additional wellness and employee support programs. Eligibility may vary based on employment status and applicable plan terms.

Reasonable Accommodation:

eSimplicity is committed to providing reasonable accommodations to qualified individuals with disabilities during the application and hiring process. Applicants who need assistance or an accommodation should contact Human Resources.

Equal Employment Opportunity:
eSimplicity is an Equal Opportunity Employer, including disability and protected veteran status. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other legally protected status.