1

Security Risk Compliance Jobs in Ohio (NOW HIRING)

Perform third party supplier risk assessments by reviewing contracts for compliance with security policies, standards and practices; document security gaps and recommend appropriate remediation ...

Assesses security and/or compliance of university systems; responsible for assessing, monitoring and analyzing data, identifying security, risk or compliance issues and/or events Leveraging job aids ...

Partners with their assigned Line of Business, other Risk/Compliance/Audit (RCA) professionals, and ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...

Partners with their assigned Line of Business, other Risk/Compliance/Audit (RCA) professionals, and ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...

Partners with their assigned Line of Business, other Risk/Compliance/Audit (RCA) professionals, and ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...

Partners with their assigned Line of Business, other Risk/Compliance/Audit (RCA) professionals, and ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...

Showing results 21-40

Security Risk Compliance information

See Ohio salary details

$30.9K

$77.1K

$117.4K

How much do security risk compliance jobs pay per year?

As of Aug 10, 2026, the average yearly pay for security risk compliance in Ohio is $77,143.00, according to ZipRecruiter salary data. Most workers in this role earn between $57,500.00 and $95,100.00 per year, depending on experience, location, and employer.

What is the difference between Security Risk Compliance vs Security Analyst?

AspectSecurity Risk ComplianceSecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISACISSP, CompTIA Security+, GIAC Security Certifications
Work EnvironmentPolicy development, compliance audits, risk assessmentsMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government sectors focusing on regulatory adherenceIT departments across various industries focusing on security operations

Security Risk Compliance professionals focus on ensuring organizations meet regulatory standards and manage security risks through policies and audits. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within similar environments, their core responsibilities differ: compliance versus active security monitoring.

What are some common challenges faced by security risk compliance professionals when balancing regulatory requirements with business objectives?

Security Risk Compliance professionals often need to navigate the delicate balance between adhering to complex regulatory standards and supporting the organization's operational goals. A major challenge is ensuring compliance without hindering business innovation or efficiency. This involves working closely with various departments to interpret regulations, communicate risks, and implement pragmatic controls that satisfy both legal requirements and business needs. Effective collaboration and ongoing education are key to overcoming these challenges and maintaining a strong security posture.

What are the key skills and qualifications needed to thrive as a security risk compliance professional?

To thrive as a Security Risk Compliance professional, you need a solid understanding of information security frameworks, risk assessment methodologies, and relevant regulations, often supported by a degree in cybersecurity or a related field. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms, vulnerability scanners, and certifications like CISSP, CISA, or CRISC is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and collaborate with stakeholders. These skills are vital to ensure organizations meet compliance requirements, mitigate risks, and maintain trust with clients and regulators.

Is risk and compliance a good career?

A career in security risk compliance involves assessing and managing organizational risks related to security and regulatory requirements. It often requires knowledge of industry standards, certifications like CISSP or CISA, and strong analytical skills. The field offers growth opportunities and is essential for organizations to maintain security and legal adherence.

What is security risk compliance?

Security Risk Compliance refers to the process of identifying, assessing, and managing risks to an organization's information systems while ensuring adherence to relevant laws, regulations, and industry standards. Professionals in this field develop policies, conduct risk assessments, and implement controls to protect sensitive data from threats. Their work helps organizations minimize security vulnerabilities and avoid legal or financial consequences related to non-compliance.
What cities in Ohio are hiring for Security Risk Compliance jobs? Cities in Ohio with the most Security Risk Compliance job openings:
Infographic showing various Security Risk Compliance job openings in Ohio as of June 2026, with employment types broken down into 1% As Needed, 82% Full Time, 14% Part Time, 1% Temporary, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $77,143 per year, or $37.1 per hour.

Assistant Vice President, Deputy Chief Information Security Officer

Western & Southern Financial Group

Cincinnati, OH

Full-time

Re-posted 20 days ago


Western & Southern Financial Group rating

8.9

Company rating: 8.9 out of 10

Based on 8 frontline employees who took The Breakroom Quiz

48th of 304 rated insurance


Job description

Provides strategic leadership in the development of Western & Southern Financial Group's (WSFG) Information Security management program to support the business objectives of W&SFG. Leads the Information Security Risk Management and Identity & Access Management (IAM) teams. Additionally, ensures efficient, cost-effective operation, and oversees project development and implementation, in addition to normal managerial expectations. Works with minimal supervision and is responsible to independently make a broad range of critical decisions, escalating to executive-level associates only when appropriate.

What you will do:

  • Directs Information Security Risk Management services for the Enterprise through effective and collaborative corporate governance structures, ensuring adherence to information security principles and corporate expectations. Coordinates resources in the assessment of information security risk and partnering with others in the Enterprise to provide guidance for risk treatment plans.
  • Facilitates metrics and reporting on the efficiency and effectiveness of the Information Security Risk Management function. Provides regular reporting on the current status of information security risks to senior-level management.
  • Leads the information security and risk management awareness training programs for all associates, contractors and authorized system users.
  • Oversees third-party vendor due diligence security reviews to ensure compliance with information security policy, security procedures and regulatory requirements. Handles escalations from the team in reporting deficiencies or risks to the appropriate executive-level stakeholders in IT, the business and third parties. Partners with IT leadership and compliance teams to support process/program improvements.
  • Develops and oversees the implementation of W&SFG's IAM strategy that is aligned with business priorities, industry best practices and the Information Security strategic plan. The desired end state is a single set of identities access the Enterprise in support of internal and external access needs.
  • Ensures the successful delivery of IAM products and services required to meet business and technology requirements, which includes directory services (e.g., AD), identity federation (e.g., SAML, SSO, and ADFS), Multi-Factor Authentication (MFA), and Identity Management (IdM).
  • Is responsible for the development and enforcement of companywide information security policies, standards and procedures within Information Security Risk Management and Identity and Access Management.
  • Develops and manages the team's budget, monitors for variances and actively assists with the completion of the Information Security budget.
  • Collaborate with IT in support of Disaster Recovery and Business Continuity.
  • Manages and ensures timely completion of all assigned audit remediation work, internal projects and Portfolio level project deliverables.
  • Recruits, hires, trains and develops management staff. Provides direction to and development to managers through coaching, the administration of the Performance Management Program, and the creation and implementation of development plans.
  • Promotes development of management team and associates to ensure they are adequately trained to carry out their responsibilities and stay current on state-of-the-art technology.
  • Potential on-call support during nights and weekends.
  • Performs other duties as assigned.
  • Complies with all policies and standards.

  • Bachelor's Degree In information security, computer science or information technology, or commensurate selection criteria experience. - Required
  • Minimum of 10 years of management level experience. Prefer experience in a combination of risk management, information security and IT-related positions. - Required
  • Proven track record and experience in developing information security policies and procedures, as well as successfully executing programs that meet the objectives of excellence in a dynamic environment. - Required
  • Demonstrated experience effectively influencing a group to a recommended course of action. - Required
  • Proven experience in working with complex programs, which require identifying complex data and analyzing the quality of the output provided. - Required
  • Demonstrated knowledge and understanding of relevant legal and regulatory requirements, such as New York Department of Financial Services Cybersecurity regulation, NAIC Data Security Model Law, and Health Insurance Portability and Accountability Act (HIPAA). -
  • Demonstrated excellent verbal and written communication skills, interpersonal and collaborative skills with the ability to convey complex concepts and security and risk-related information to internal and external customers (technical and nontechnical) at all levels in a clear, accurate, focused and concise manner, and presentation style. Verbal and written communications are to conform to proper rules of punctuation, grammar, diction and style. -
  • Proven leadership, interpersonal skills and ability to work cross-functionally and to develop associates in their skills and proficiency, while achieving tactical and strategic goals. -
  • Demonstrated poise and ability to act calmly and competently in high-pressure, high-stress situations. -
  • Proven strong quantitative and analytical skills, including demonstrated experience identifying, defining and resolving complex programs, and collecting or interpreting data to establish facts and draw valid conclusions to provide effective resolutions. Proven experience with sound decision-making and critical thinking skills when dealing with multiple alternatives. Must demonstrate the ability to conceptualize and apply new methodologies. -
  • Demonstrated ability to direct multiple projects under strict timelines, within budget and financial targets and with appropriate resource management as well as the ability to work well in a demanding, dynamic environment and meet overall objectives. -
  • Proficient in word processing, spreadsheet and presentation applications. -
  • Familiarity with Project Management systems and processes. -
  • CISSP Certified Information Systems Security Professional or Certified Information Security Manager Upon Hire - Required
  • GIAC Security Expert (GSE) - Preferred
  • Certified Information Systems Auditor (CISA) - Preferred
  • ISACA certifications including CRISC or CGEIT - Preferred
  • Series 99 certification - Preferred

Work Setting/Position Demands:

  • Works in an office setting and remains in a stationary position for long periods of time while working at a desk, on a computer or with other standard office equipment, or while in meetings.
  • Requires the ability to verbally communicate and exchange accurate information to customers and associates on a regular basis.
  • Requires visual acuity to read and interpret a variety of correspondence, procedures, reports and forms via paper and electronic documents, visual inspection involving small defects; small parts, and/or operation of machinery (including inspection); using measurement devices continuously. Visual acuity is required to determine accuracy, neatness, and thoroughness of work assigned.
  • Requires the ability to prepare written correspondence, reports and forms using prescribed formats and conforming to rules of punctuation, grammar, diction, and style on a regular basis.
  • Requires the ability to apply principles of logical thinking to define problems, collect data, establish facts, and draw valid conclusions
  • Performs substantial movement of wrists, hands, and fingers for continuous computer work.
  • Extended hours required during peak workloads or special projects/events.

Travel Requirements:

  • Occasional travel may be required.


What Western & Southern Financial Group employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom