1

Security Risk Analyst Jobs (NOW HIRING)

... security risk, and model risk. * Track, manage, monitor, and report on risk issues and corrective ... Analyze and report Key Risk Indicators (KRIs) and Risk Appetite Statement (RAS) metrics. * Prepare ...

... security risk, and model risk. * Track, manage, monitor, and report on risk issues and corrective ... Analyze and report Key Risk Indicators (KRIs) and Risk Appetite Statement (RAS) metrics. * Prepare ...

Security Risk Manager

San Francisco, CA · Hybrid

$194K - $220K/yr

Our security team protects Asana's employees, users, and customers by proactively addressing ... analysis. You back up risk ratings with numbers, not just color codes. * Hands-on experience ...

Security Risk Manager

San Francisco, CA · On-site

$194K - $220K/yr

Our security team protects Asana's employees, users, and customers by proactively addressing ... analysis. You back up risk ratings with numbers, not just color codes. * Hands-on experience ...

Showing results 21-40

Security Risk Analyst information

See salary details

$10

$50

$69

How much do security risk analyst jobs pay per hour?

As of Aug 31, 2026, the average hourly pay for security risk analyst in the United States is $50.41, according to ZipRecruiter salary data. Most workers in this role earn between $40.87 and $60.10 per hour, depending on experience, location, and employer.

What does a security risk analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a security risk analyst?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges security risk analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.
More about Security Risk Analyst jobs

What cities are hiring for Security Risk Analyst jobs?

Cities with the most Security Risk Analyst job openings:

Who are the top companies hiring for Security Risk Analyst jobs?

The top employers for Security Risk Analyst jobs are:

What states have the most Security Risk Analyst jobs?

States with the most job openings for Security Risk Analyst jobs include:

Infographic showing various Security Risk Analyst job openings in the United States as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $104,848 per year, or $50.4 per hour.

Information Security Risk Analyst I

Columbus, OH • On-site


Nationwide Children's Hospital
Hospitals • 10K+ employees

6.9

Company rating: 6.9 out of 10

Based on 131 frontline employees who took The Breakroom Quiz

551st of 1,064 rated hospitals

People enjoy working here

Recommended by students

Respectful managers


Full-time

Posted 3 days ago

New


Job description

Overview:
Job Description Summary:
Supports the NCH Information Security and Risk Department (ISRD). Participates in varying subjects including Information Security, Risk Management, Privacy, and other related concepts.
Job Description:
Essential Functions:
  • Participates in the development and maintenance of information security policies, standards, and procedures.
  • Plans and conducts security assessments on new and existing systems, processes, and technologies to determine compliance with policies, standards and regulatory requirements.
  • Participates in risk analysis of identified issues to determine recommended risk treatment.
  • Supports day-to-day information security processes including incident response, third party risk management, vulnerability management reporting, security awareness training, and disaster recovery.
  • Coordinates business and information services resources for project and operational support.
  • Stays up-to-date and informed of information security industry changes and trends.

Education Requirement:
BS in Computer Science or equivalent experience required.
Continues to stay actively involved in outside education advancement.
Licensure Requirement:
(not specified)
Certifications:
Security+, CISSP or equivalent preferred.
Skills:
Strong problem-solving ability.
Exceptional presentation skills.
Exceptional interpersonal, written, and verbal communication skills.
Demonstrated project management skills.
Proficient in Microsoft Office.
Experience:
Twoyears of experience in IT; experience in healthcare, preferred.
Physical Requirements:
OCCASIONALLY: Climb stairs/ladder, Lifting / Carrying: 0-10 lbs, Lifting / Carrying: 11-20 lbs, Standing, Walking
FREQUENTLY: (none specified)
CONTINUOUSLY: Audible speech, Computer skills, Decision Making, Flexing/extending of neck, Hand use: grasping, gripping, turning, Hearing acuity, Interpreting Data, Problem solving, Repetitive hand/arm use, Seeing - Far/near, Sitting
Additional Physical Requirements performed but not listed above:
(not specified)
"The above list of duties is intended to describe the general nature and level of work performed by individuals assigned to this classification. It is not to be construed as an exhaustive list of duties performed by the individuals so classified, nor is it intended to limit or modify the right of any supervisor to assign, direct, and control the work of employees under their supervision. EOE M/F/Disability/Vet"

Nationwide Children's Hospital logo

About Nationwide Children's Hospital

Sourced by ZipRecruiter

Nationwide Children's Hospital, established in 1894, is a leading pediatric healthcare system based in Columbus, Ohio, United States. They serve as a primary pediatric network, providing wellness, preventive, diagnostic, treatment, and rehabilitative care for infants, children, adolescents, and adults with congenital disease. Being the third-largest pediatric hospital in the nation, Nationwide Children's Hospital prides itself on its relentless commitment to children and their families, driven by their core values of respect, integrity, determination, empathy, and solidarity. The institution's comprehensive mission is to enhance the health of children by providing high-quality, family-centered care, conducting groundbreaking research, advocating for pediatric health, and training top healthcare professionals.

Industry

Hospitals

Company size

10,000+ Employees

Headquarters location

Columbus, OH, US

Year founded

1892


What Nationwide Children's Hospital employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom