SUMMARY The IT Risk Analyst II is responsible for measuring and identifying technical risks within ... Performs technical security assessments against FIB's existing infrastructure and products to ...
SUMMARY The IT Risk Analyst II is responsible for measuring and identifying technical risks within ... Performs technical security assessments against FIB's existing infrastructure and products to ...
Manager, Treasury Risk
OR · On-site +1
... security risk, and compliance risk. We partner with first-line business functions, senior and executive leadership, and the board of directors to ensure effective identification, assessment ...
Manager, Treasury Risk
OR · On-site +1
... security risk, and compliance risk. We partner with first-line business functions, senior and executive leadership, and the board of directors to ensure effective identification, assessment ...
Conduct identity risk assessments and develop remediation plans. Oversee authentication modernization initiatives and Zero Trust security models. Healthcare Security & Regulatory Compliance Ensure ...
Quick apply
Conduct identity risk assessments and develop remediation plans. Oversee authentication modernization initiatives and Zero Trust security models. Healthcare Security & Regulatory Compliance Ensure ...
Principal Enterprise Risk Management Analyst
Hillsboro, OR · Hybrid
$146K - $176K/yr
Lead complex risk assessments for significant initiatives, including technology implementations ... Partner with Technology, Information Security, Compliance, Business Continuity, Internal Audit, and ...
Quick apply
Principal Enterprise Risk Management Analyst
Hillsboro, OR · Hybrid
$146K - $176K/yr
Lead complex risk assessments for significant initiatives, including technology implementations ... Partner with Technology, Information Security, Compliance, Business Continuity, Internal Audit, and ...
Provide system-level risk assessments and actionable recommendations, including impact and ... Support security assessments, audits, and inspections as the ISSO representative, including direct ...
Provide system-level risk assessments and actionable recommendations, including impact and ... Support security assessments, audits, and inspections as the ISSO representative, including direct ...
Conduct security risk assessments and oversee vulnerability scanning and penetration testing activities * Manage security incident response coordination and reporting * Maintain continuous monitoring ...
Conduct security risk assessments and oversee vulnerability scanning and penetration testing activities * Manage security incident response coordination and reporting * Maintain continuous monitoring ...
Assess and manage security risk associated with vendors, contractors, and third-party service providers. * Future team leadership: Lay the groundwork to scale the function. As the program matures ...
Assess and manage security risk associated with vendors, contractors, and third-party service providers. * Future team leadership: Lay the groundwork to scale the function. As the program matures ...
Security Analyst I
$70K - $116K/yr
ESSENTIAL FUNCTIONS & RESPONSIBILITIES: * Assist with thirdparty risk management, including vendor security assessments and documentation review * Support responses to customer security ...
Security Analyst I
$70K - $116K/yr
ESSENTIAL FUNCTIONS & RESPONSIBILITIES: * Assist with thirdparty risk management, including vendor security assessments and documentation review * Support responses to customer security ...
Conduct comprehensive network and system security risk assessments using frameworks like NIST; develop and manage robust remediation tracking workflows to ensure timely mitigation of identified ...
Conduct comprehensive network and system security risk assessments using frameworks like NIST; develop and manage robust remediation tracking workflows to ensure timely mitigation of identified ...
Advanced capability in risk assessment, threat management, executive protection, emergency response, and incident command. Advanced knowledge of physical security technologies, systems administration ...
Advanced capability in risk assessment, threat management, executive protection, emergency response, and incident command. Advanced knowledge of physical security technologies, systems administration ...
OR · On-site
Conducts structured Threat Modeling & Risk Assessment exercises for generative AI, RAG, and agent ... Builds and scales AI Security Testing & Red Teaming workflows by creating repeatable adversarial ...
OR · On-site
Conducts structured Threat Modeling & Risk Assessment exercises for generative AI, RAG, and agent ... Builds and scales AI Security Testing & Red Teaming workflows by creating repeatable adversarial ...
Senior Security Compliance Analyst
OR · Remote
$110K - $140K/yr
Perform gap analyses and risk assessments to identify and remediate compliance risks. * Manage and improve security governance frameworks, ensuring alignment with industry best practices and business ...
Senior Security Compliance Analyst
OR · Remote
$110K - $140K/yr
Perform gap analyses and risk assessments to identify and remediate compliance risks. * Manage and improve security governance frameworks, ensuring alignment with industry best practices and business ...
Web Developer Security Engineer
$77K - $85K/yr
Proven background in threat modeling, risk assessment, and security architecture design * Advanced experience with CI/CD pipeline security gate automation * Cloud security experience with AWS and ...
Web Developer Security Engineer
$77K - $85K/yr
Proven background in threat modeling, risk assessment, and security architecture design * Advanced experience with CI/CD pipeline security gate automation * Cloud security experience with AWS and ...
OR · On-site
$400K - $680K/yr
... risk while enabling business needs. We provide cloud security subject matter expertise, build ... Furthermore, you will perform threat assessments, apply knowledge of AWS architecture and new AWS ...
Director of Security and Compliance
$200K - $225K/yr
Risk Assessment, Business Continuity & Incident Response: * Conduct comprehensive enterprise risk assessments and develop strategies that strengthen business continuity, disaster recovery, and ...
New
Director of Security and Compliance
$200K - $225K/yr
Risk Assessment, Business Continuity & Incident Response: * Conduct comprehensive enterprise risk assessments and develop strategies that strengthen business continuity, disaster recovery, and ...
New
Senior Third-Party Risk Management Analyst
$93K - $111K/yr
Assess third-party controls, policies, and practices to ensure alignment with regulatory ... Partner cross-functionally with Procurement, Legal, Risk, Information Security, and business units ...
Quick apply
Senior Third-Party Risk Management Analyst
$93K - $111K/yr
Assess third-party controls, policies, and practices to ensure alignment with regulatory ... Partner cross-functionally with Procurement, Legal, Risk, Information Security, and business units ...
Security Architect
$65 - $84/hr
Proven ability to assess and evaluate enterprise security postures and identify impacts from new ... Contribute to risk management and compliance, performing architecture reviews, identifying security ...
Security Architect
$65 - $84/hr
Proven ability to assess and evaluate enterprise security postures and identify impacts from new ... Contribute to risk management and compliance, performing architecture reviews, identifying security ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
Lead cybersecurity-focused risk assessments and contribute to audit planning to proactively ... Relevant certifications such as CISA, CISSP, CISM, CRISC, CEH, or CompTIA Security+ #LI-JD1 This is ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
Lead cybersecurity-focused risk assessments and contribute to audit planning to proactively ... Relevant certifications such as CISA, CISSP, CISM, CRISC, CEH, or CompTIA Security+ #LI-JD1 This is ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
Lead cybersecurity-focused risk assessments and contribute to audit planning to proactively ... Relevant certifications such as CISA, CISSP, CISM, CRISC, CEH, or CompTIA Security+ #LI-JD1 This is ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
Lead cybersecurity-focused risk assessments and contribute to audit planning to proactively ... Relevant certifications such as CISA, CISSP, CISM, CRISC, CEH, or CompTIA Security+ #LI-JD1 This is ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
Lead cybersecurity-focused risk assessments and contribute to audit planning to proactively ... Relevant certifications such as CISA, CISSP, CISM, CRISC, CEH, or CompTIA Security+ #LI-JD1 This is ...
Senior Auditor, Technology - Global Audit & Enterprise Risk Management
Portland, OR · On-site
$85K - $105K/yr
Lead cybersecurity-focused risk assessments and contribute to audit planning to proactively ... Relevant certifications such as CISA, CISSP, CISM, CRISC, CEH, or CompTIA Security+ #LI-JD1 This is ...
Security Risk Assessment information
See Oregon salary details
$10.93 - $16.66
2% of jobs
$16.66 - $22.39
0% of jobs
$22.39 - $28.12
1% of jobs
$28.12 - $33.85
1% of jobs
$33.85 - $39.58
1% of jobs
$43.88 is the 25th percentile. Wages below this are outliers.
$39.58 - $45.31
26% of jobs
$45.31 - $51.04
11% of jobs
The median wage is $53.09 / hr.
$51.04 - $56.77
22% of jobs
$56.77 - $62.50
9% of jobs
$62.95 is the 75th percentile. Wages above this are outliers.
$62.50 - $68.23
17% of jobs
$68.23 - $73.96
9% of jobs
$10
$53
$73
How much do security risk assessment jobs pay per hour?
What is a Security Risk Assessment job?
A Security Risk Assessment job involves identifying, analyzing, and mitigating potential security threats to an organization's systems, data, and operations. Professionals in this role evaluate vulnerabilities, assess risks, and recommend security controls to protect against cyber threats, fraud, and compliance issues. They work with IT teams, management, and stakeholders to ensure security measures align with business objectives and regulatory requirements. This job often requires knowledge of cybersecurity frameworks, risk management methodologies, and relevant industry standards.
What are the key skills and qualifications needed to thrive in the Security Risk Assessment position, and why are they important?
To thrive in Security Risk Assessment, a strong background in risk analysis, information security principles, and regulatory compliance is essential, often supported by a degree in cybersecurity or related fields. Familiarity with risk assessment tools, frameworks like NIST or ISO 27001, and certifications such as CISSP or CISA are highly valued. Exceptional attention to detail, analytical thinking, and effective communication skills set top professionals apart in this role. These competencies enable accurate identification of potential security threats and development of strategic mitigation plans, which are crucial for safeguarding organizational assets.
What are some common challenges faced in a Security Risk Assessment role?
Professionals in Security Risk Assessment often face the challenge of keeping up with constantly evolving cyber threats and adapting assessment methodologies accordingly. Balancing thorough analysis with the need to provide timely recommendations can be demanding, especially when collaborating with multiple departments or stakeholders. Additionally, communicating complex risk findings to non-technical audiences requires both clarity and diplomacy. Overcoming these challenges is critical for delivering actionable insights that drive effective security decision-making and protect organizational assets.

Job description
This position may be located at any of First Interstate Bank's offices in Idaho, Iowa, Missouri, Montana, Nebraska, Oregon, South Dakota, or Wyoming.
What's Important to You
We know your career is just one aspect of a meaningful, complex, and demanding life. That's why we designed our compensation and benefits package to provide employees and their families with as much choice as possible.
- Generous Paid Time Off (PTO) in addition to paid federal holidays.
- Student debt employer repayment program.
- 401(k) retirement plan with a 6% match.
- The health and happiness of the places we call home matter to us. Learn a little more about what we do for the communities we serve and why we want YOU to be a part of it.
We encourage you to apply. Reach for what you want and tell us why your work ethic and willingness to learn make you a natural fit for #TeamFirstInterstate.
SUMMARY
The IT Risk Analyst II is responsible for measuring and identifying technical risks within First Interstate Bank's (FIB) infrastructure and third-party solutions. This position is also responsible for performing testing to validate systems and application security configurations continue to meet industry and FIB architecture and security standards, establishing and leveraging risk metrics and dashboards to continuously assess and report on technical risk, and providing guidance on IT security architecture and configurations based on the risks and controls evaluated.
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Leverages technical knowledge to assist in developing and enhancing cyber and information security policies, procedures, and standards.
- Works with Enterprise Architecture to assist in developing and enhancing the information security architecture standards and IT security technology roadmaps.
- Researches and evaluates proposed new technologies and platforms to ensure the appropriate technical security controls are specified in the requirements and are in alignment with the security reference architecture and security controls framework.
- Provides security consulting on projects to ensure solutions are designed in accordance with security architecture and that security configurations are properly implemented.
- Performs technical security assessments against FIB's existing infrastructure and products to ensure compliance with security architecture, policies, standards, procedures, and industry best practices.
- Monitors and matures the risk-based IT security metrics, scorecards, and dashboards to track cybersecurity performance and trends across the organization.
- Assists the business in identifying root causes and develops mitigation for deficiencies.
- Works with various groups during product upgrades or new product design to ensure security best practices are implemented.
- Performs technical reviews of third-party cyber and information risk.
- Researches emerging technologies in support of security enhancement and development efforts.
QUALIFICATIONS
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
KNOWLEDGE, SKILLS AND ABILITIES
- Knowledge of concepts and principles in information security functional areas such as cloud security, firewalls and security mediation services, identity and access management, industry standard security frameworks, security controls, and compliance frameworks.
- Strong oral, written, and interpersonal communication skills resulting in the ability to interface with managers and staff at all levels within the organization.
- Strong communication skills with all levels of the business and the ability to leverage knowledge of the appropriate approach and degree of detail for each.
- Remain up to date with emerging threats, best practices, and relevant frameworks, guidance, and legislation.
- Capable of managing varied assignments and working independently.
- Ability to define problems, collect data, establish facts, and draw valid conclusions.
- Ability to interpret an extensive variety of technical instructions in mathematical or diagram form and deal with several abstract and concrete variables.
- Experience with methods used in performing risk analyses and assessments and measuring cybersecurity compliance.
- Experience maintaining and updating documentation necessary for supporting security environments, including policies, standards, patterns, and reference architectures.
- Experience in working with compliance and regulatory program requirements.
EDUCATION AND/OR EXPERIENCE
- Bachelor's Degree in a related field required
- 4-6 years experience in IT security audit, architecture, engineer, risk monitoring, and/or equivalent combination of education and experience required
LICENSES AND CERTIFICATIONS
- CISSP - Certified Information Systems Security Professional preferred
- CISA - Certified Information Systems Auditor preferred
- CEH - Certified Ethical Hacker preferred
- CCSP - Certified Cloud Security Professional preferred
- GSEC - GIAC Security Essentials Certification preferred
- GISP - GIAC Information Security Professional preferred
PHYSICAL DEMANDS AND WORKING ENVIRONMENT
The physical demands and work environment are representative of those that must be met or encountered to successfully perform the essential functions of the job. In compliance with the Americans with Disabilities Act, the company provides reasonable accommodation to qualified individuals with disabilities and encourages both prospective and current employees to discuss potential accommodations with the employer.
- Dexterity of hands/fingers to operate computer keyboard and mouse - Frequently
- Lifting - Occasionally (up to 50 lbs)
- Sitting - Frequently
- Standing - Occasionally
- Noise Level - Moderate
- Typical Work Hours - M-F (8-5)
- Regular and Predictable Attendance - Required
**If you are a current FIB employee, please apply through the Career Worklet in the Employee Portal.
About First Interstate BancSystem
Sourced by ZipRecruiter
Industry
Commercial banking
Company size
1,001 - 5,000 Employees
Headquarters location
Billings Metropolitan Area, MT, US
Year founded
1971