1

Security Risk Assessment Jobs (NOW HIRING)

Description We are seeking a Senior AI Security Risk Assessment Consultant to help establish and operationalize our client's organization's enterprise AI Security Risk Assessment Methodology. This ...

... IT security risk assessment across more than 30 independent entities. This role performs hands-on technical control evaluation and evidence review at assigned sites, contributing directly to the ...

An information system security risk assessment should also be performed in compliance with SEC501.09 and SEC520.00 using the risk assessment template: ( 1.Appeals and Rulings 2.FACSYS 3.Fraud ...

next page

Showing results 1-20

Security Risk Assessment information

See salary details

$10

$50

$69

How much do security risk assessment jobs pay per hour?

As of Sep 4, 2026, the average hourly pay for security risk assessment in the United States is $50.41, according to ZipRecruiter salary data. Most workers in this role earn between $40.87 and $60.10 per hour, depending on experience, location, and employer.

What is a security risk assessment?

A Security Risk Assessment job involves identifying, analyzing, and mitigating potential security threats to an organization's systems, data, and operations. Professionals in this role evaluate vulnerabilities, assess risks, and recommend security controls to protect against cyber threats, fraud, and compliance issues. They work with IT teams, management, and stakeholders to ensure security measures align with business objectives and regulatory requirements. This job often requires knowledge of cybersecurity frameworks, risk management methodologies, and relevant industry standards.

What are the key skills and qualifications needed for security risk assessment?

To thrive in Security Risk Assessment, a strong background in risk analysis, information security principles, and regulatory compliance is essential, often supported by a degree in cybersecurity or related fields. Familiarity with risk assessment tools, frameworks like NIST or ISO 27001, and certifications such as CISSP or CISA are highly valued. Exceptional attention to detail, analytical thinking, and effective communication skills set top professionals apart in this role. These competencies enable accurate identification of potential security threats and development of strategic mitigation plans, which are crucial for safeguarding organizational assets.

What are some common challenges faced in a security risk assessment role?

Professionals in Security Risk Assessment often face the challenge of keeping up with constantly evolving cyber threats and adapting assessment methodologies accordingly. Balancing thorough analysis with the need to provide timely recommendations can be demanding, especially when collaborating with multiple departments or stakeholders. Additionally, communicating complex risk findings to non-technical audiences requires both clarity and diplomacy. Overcoming these challenges is critical for delivering actionable insights that drive effective security decision-making and protect organizational assets.

More about Security Risk Assessment jobs

What cities are hiring for Security Risk Assessment jobs?

Cities with the most Security Risk Assessment job openings:

What are the most commonly searched types of Security Risk Assessment jobs?

The most popular types of Security Risk Assessment jobs are:

What states have the most Security Risk Assessment jobs?

States with the most job openings for Security Risk Assessment jobs include:

Infographic showing various Security Risk Assessment job openings in the United States as of August 2026, with employment types broken down into 50% Full Time, and 50% Contract. Highlights an 100% In-person job distribution, with an average salary of $104,848 per year, or $50.4 per hour.

Information Security Risk Assessment Sr. Analyst

Rootshell Enterprise Technologies, Inc.

Remote

Full-time

Re-posted 18 days ago


Job description

Hello All,
Greetings from Rootshell Inc.
Rootshell Enterprise Technologies Inc. is a recognized provider of professional IT Consulting services in the US. We are actively seeking Information Security Risk Assessment Sr. Analyst for one of our client, Please share your resume with current location & full contact info
Role: Information Security Risk Assessment Sr. Analyst
Location: San Jose or Remote
Job Summary:
Key Responsibilities:
• Conduct security risk assessments to identify, score and document potential risks from
threats and vulnerabilities within the organization's infrastructure and applications.
• Perform control effectiveness assessment by collaborating with cross-functional teams to
understand technical implementations and assess control strength
• Communicate identified security risks and their potential impact to stakeholders,
including technical and non-technical audiences.
• Track and report on the status of risk remediation efforts, ensuring timely resolution and
compliance with organizational policies.
• Maintain security risk register and ensure timely updates of the risk register
• Contribute to performing risk aggregation and risk analysis to identify top risks and areas
of focus/improvement for prioritization
• Contribute to developing detailed reports and presentations on risk assessments,
including identified aggregated top risks, risk treatment progress, trending and
escalation. Ensure these reports are understandable to technical and non-technical
stakeholders, including senior management
• Demonstrate a process-oriented, results-driven approach to security risk engineering,
employing effective problem-solving and communication skills to serve as a subject
matter expert and trusted advisor
• Actively contributes to the administration, maintenance and process improvements of the
GRC risk assessment program
• Performs other job duties as required
We'd love to chat if you have:
• Bachelor's degree in Computer Science, Information Security, or a related field.
• 5+ years of experience in security risk assessment, with strong background in
cybersecurity and risk management, with hands-on working knowledge and experience
in risk management frameworks such as NIST RMF, FAIR, and OWASP
• Strong technical knowledge of security controls, including but not limited to access
controls, encryption, network security, and vulnerability management.
• Demonstrated experience working within a GRC framework, with an understanding of
regulatory and compliance requirements (e.g., PCI DSS, SOC).
• Proven ability to work collaboratively with engineering teams to assess and mitigate
security risks.
• Experience with security risk remediation programs, including technical implementation
and compliance considerations.
• Strong analytical and problem-solving skills, with attention to detail and accuracy.
• Strong collaboration skills, with experience working cross-functionally with IT,
Engineering, and other stakeholders.
• Excellent communication skills, capable of translating technical concepts into actionable
insights for both technical and non-technical stakeholders.
• Experience in identifying process improvements and enhancing operational efficiencies
within security programs.
• Experience with GRC Risk Management tool including tool implementation will be plus
Preferred Skills:
• Experience with security assessment tools and methodologies.
• Knowledge of cloud security best practices and technologies (e.g., AWS, Azure, GCP).
• Strong project management skills with the ability to prioritize tasks and manage multiple
projects simultaneously.
• Certifications like PMP, CISSP, or CISM are a plus but not required
With regards
Naveen | Talent Acquisition
Rootshell Enterprise Technologies Inc.
Naveen@rootshellinc.com | www.rootshellinc.com