1

Security Risk Consultant Jobs in New York (NOW HIRING)

Senior Cybersecurity GRC

Manhattan, NY · On-site

$110K - $142K/yr

Senior Cybersecurity GRC & Third Party Risk Consultant Location: New York, NY (Onsite/Hybrid ... The ideal candidate will have strong expertise in vendor risk management, information security ...

... consulting groups. That's why we continuously invest in innovative ideas, such as AI-enabled ... Documenting information security risk and compliance findings, presenting recommendations for ...

... consulting groups. That's why we continuously invest in innovative ideas, such as AI-enabled ... Documenting information security risk and compliance findings, presenting recommendations for ...

next page

Showing results 1-20

Security Risk Consultant information

See New York salary details

$11

$55

$119

How much do security risk consultant jobs pay per hour?

As of Jul 31, 2026, the average hourly pay for security risk consultant in New York is $55.70, according to ZipRecruiter salary data. Most workers in this role earn between $27.07 and $69.71 per hour, depending on experience, location, and employer.

How much does a risk consultant earn?

A security risk consultant's average salary varies by experience and location but typically ranges from $70,000 to $120,000 annually. Entry-level positions may start lower, while experienced professionals with certifications like CISSP or CISM can earn higher salaries, especially in high-demand industries or regions.

What are the key skills and qualifications needed to thrive as a Security Risk Consultant, and why are they important?

To thrive as a Security Risk Consultant, you need expertise in risk assessment, security frameworks, regulatory compliance, and a relevant degree such as in cybersecurity or information security. Familiarity with tools like risk management software, vulnerability assessment platforms, and recognized certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders set top consultants apart. These skills ensure the accurate identification and mitigation of security risks, safeguarding organizational assets and compliance with industry standards.

Can you make $500,000 a year in cyber security?

Security Risk Consultants and other cybersecurity professionals can potentially earn $500,000 or more annually, especially with senior roles, extensive experience, specialized skills, and certifications like CISSP or CISA. High earnings are often associated with leadership positions, consulting, or working in high-demand industries, but such salaries are not typical for entry-level roles. Achieving this level usually requires years of experience, advanced expertise, and a strong professional network.

How does a Security Risk Consultant typically collaborate with clients and internal teams during a risk assessment project?

Security Risk Consultants work closely with clients to understand their unique risk landscape, often conducting interviews and site visits to gather information. They collaborate with internal teams such as cybersecurity analysts, compliance experts, and IT staff to analyze data and develop comprehensive risk mitigation strategies. Throughout the project, consultants maintain open communication with stakeholders, presenting findings, making recommendations, and ensuring that solutions align with the client's business objectives and regulatory requirements. This collaborative approach helps build trust and ensures the delivery of actionable, tailored security solutions.

What does a Security Risk Consultant do?

A Security Risk Consultant assesses potential threats and vulnerabilities within an organization’s physical or digital infrastructure. They help identify risks, develop mitigation strategies, and ensure compliance with security regulations and best practices. Their responsibilities often include conducting risk assessments, advising on security policies, and recommending improvements to reduce exposure to threats. Security Risk Consultants work with clients across various industries to safeguard assets, data, and people. Their expertise helps organizations proactively address security challenges and minimize potential losses.

How much does a security consultant get paid?

The average salary for a security risk consultant varies depending on experience, location, and certifications, but typically ranges from $70,000 to $120,000 annually. Senior consultants with specialized skills or certifications like CISSP or CISA can earn higher salaries, and some may work on a contract basis or have additional bonuses.

What is the difference between Security Risk Consultant vs Security Analyst?

AspectSecurity Risk ConsultantSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentConsulting firms, corporate security teamsIT departments, security operations centers
Primary FocusAssessing and managing security risks, advising clientsMonitoring security systems, incident response
Industry UsageFinance, healthcare, government, consultingTechnology, finance, government agencies

While both roles involve cybersecurity, Security Risk Consultants focus on evaluating and advising on security risks for organizations, often working in consulting settings. Security Analysts primarily monitor and respond to security threats within an organization’s IT infrastructure. Understanding these differences helps in choosing the right career path or job search focus.

What do security risk consultants do?

Security risk consultants analyze an organization’s security posture to identify vulnerabilities and develop strategies to mitigate risks. They conduct assessments, review policies, and recommend security measures, often using tools like risk management frameworks and security audits. Their work helps organizations protect sensitive data and comply with industry standards.
What are the most commonly searched types of Security Risk Consultant jobs in New York? The most popular types of Security Risk Consultant jobs in New York are:
What are popular job titles related to Security Risk Consultant jobs in New York? For Security Risk Consultant jobs in New York, the most frequently searched job titles are:
What job categories do people searching Security Risk Consultant jobs in New York look for? The top searched job categories for Security Risk Consultant jobs in New York are:
Infographic showing various Security Risk Consultant job openings in New York as of July 2026, with employment types broken down into 1% Locum Tenens, 86% Full Time, 9% Part Time, and 4% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $115,848 per year, or $55.7 per hour.

Security, Risk and Compliance Consultant

SEI

New York, NY • On-site

Other

Re-posted 17 hours ago


Job description

WHAT WE DO

Our Security, Risk and Compliance consultants work with clients at all levels of the organization, from the C-suite to the shop floor, helping them to deliver on their most strategic initiatives. We're known for making realistic, data-driven decisions that deliver value in tangible ways to our clients. Our clients ask for us on projects that require a superior combination of technical and business capabilities, people and management skills, and a collaborative mindset. We excel in understanding complex programs and strategic initiatives and breaking them into actionable pieces.

We are actively looking for professionals in the following areas:

  • Compliance
  • Information Security
  • Risk Management
  • Data Privacy

The ideal candidate's experience may include but is not limited to the following:

  • Management or participation in Cybersecurity, Information Security, Risk, Compliance and/or Data Privacy Programs or Projects
    • Sample projects/programs could include but are not limited to:
      • Compliance framework mapping and implementation,
      • Regulatory mapping and implementation
      • Audit, risk or regulatory remediation management,
      • Readiness for new laws and regulations,
      • Risk, Compliance or Information Security risk reporting and monitoring
      • Creation of roadmaps to mature or advance Risk, Compliance or Information Security Strategies/Programs/Controls
      • Design and enablement of cyber controls functions and processes
      • Change management related to regulatory adoption or compliance changes
      • Audit or certification readiness
    • Familiarity or direct experience with GRC/Cybersecurity solutions, tools and technologies
    • Control design or maturation for high-demand technical areas such as ERP, Identity and Access Management, Business Continuity and Resiliency, Cloud
    • Knowledge of and/or application of industry specific regulations, laws, and standards such as the EU-GDPR, CCPA/CPRA, HIPAA, PCI
    • Knowledge of and/or application of compliance and security frameworks and standards such as COSO, NIST, ISO
    • Management of regulatory, internal or external audits, or experience as an auditor
    • Projects or roles requiring coordination across lines of defense working with technical, business, compliance, risk and audit teams to deliver solutions
    • Work or projects with military or federal government agencies in Risk, Compliance or Information Security/Cyber Security sectors
    • Certifications: CIPP, CRCM, CRM, ARM, CISSP, CISM

QUALIFICATIONS

Required-

  • Alignment to our core values: Excellence, Participation, Integrity, and Collaboration
  • Hungry, Humble, Smart
  • Demonstrated business and technology acumen
  • Strong written and verbal communication skills
  • Understanding and experience solving real business problems
  • Proven track record of delivering results
  • Experience working with and/or leading a team
  • Ability to work across industries, roles, functions & technologies
  • Authorization for permanent employment in the United States (this position is not eligible for immigration sponsorship)

Preferred-

  • Bachelor's degree
  • 8+ years professional experience
  • Experience across our service offerings