1

Security Risk Management Jobs in Arizona (NOW HIRING)

Security Leadership & Risk Management * Develop and execute the overall security strategy for Sloan Park and the Nike Performance Center, ensuring alignment with organizational objectives and ...

Security Leadership & Risk Management * Develop and execute the overall security strategy for Sloan Park and the Nike Performance Center, ensuring alignment with organizational objectives and ...

Risk Management & Security Operations * Conduct security risk assessments, vulnerability reviews, and threat analyses to identify potential risks and vulnerabilities. * Develop and implement ...

Perform remediation of security assessment review issues, complex ad hoc data, and reporting to support information security risk management * Provide guidance and direction in reviewing assessment ...

Showing results 41-60

Security Risk Management information

See Arizona salary details

$9

$46

$65

How much do security risk management jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for security risk management in Arizona is $46.97, according to ZipRecruiter salary data. Most workers in this role earn between $38.08 and $56.01 per hour, depending on experience, location, and employer.

What is security risk management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in security risk management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in security risk management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What do you need to be a security risk manager?

A security risk manager typically needs a bachelor's degree in security management, information technology, or a related field, along with experience in security or risk assessment. Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) can enhance qualifications. Strong analytical skills, knowledge of security protocols, and familiarity with risk management tools are also important for the role.

What does security risk management do?

Security risk management involves identifying, assessing, and prioritizing potential security threats to an organization, then implementing measures to mitigate or eliminate those risks. Professionals in this field analyze vulnerabilities, develop security policies, and often use tools like risk assessment frameworks and security audits to protect assets and ensure safety.

What are popular job titles related to Security Risk Management jobs in Arizona?

For Security Risk Management jobs in Arizona, the most frequently searched job titles are:

What cities in Arizona are hiring for Security Risk Management jobs?

Cities in Arizona with the most Security Risk Management job openings:

Infographic showing various Security Risk Management job openings in Arizona as of September 2026, with employment types broken down into 1% As Needed, 81% Full Time, 15% Part Time, 1% Temporary, and 2% Contract. Highlights an 86% Physical, 3% Hybrid, and 11% Remote job distribution, with an average salary of $97,706 per year, or $47 per hour.

Lead Security Governance, Risk & Compliance Analyst

Scottsdale, AZ • Hybrid

Early Warning Services
Finance and Insurance • 201 - 500 employees

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 4 days ago


Job description

At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle, Paze, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.

Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.

Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.

Overall Purpose

This position supports the Security Governance, Risk Analytics, and Compliance function by improving the effectiveness, consistency, and scalability of security compliance activities. The role establishes repeatable operating practices for audits, assessments, evidence management, compliance obligations, and remediation activities while helping Security, Technology, Risk, Audit, and business stakeholders understand and meet applicable requirements.

The position serves as a lead partner for complex compliance activities, improving evidence quality, clarifying accountability, identifying recurring process gaps, and developing practical solutions that reduce unnecessary effort while strengthening audit and assessment readiness. The role uses data, workflow improvements, automation, and cross-functional coordination to improve compliance outcomes and support the organization's broader security and risk management objectives.

Essential Functions

  • Establish and improve repeatable processes for security audits, assessments, customer requests, regulatory activities, control reviews, evidence collection, and related compliance obligations.
  • Define and maintain clear intake, triage, ownership, evidence, review, escalation, and closure practices in coordination with Security stakeholders and first-line risk management partners.
  • Identify and implement workflow and automation opportunities that improve audit readiness, evidence management, compliance tracking, and operational efficiency.
  • Maintain visibility into compliance activities through appropriate GRC, workflow, collaboration, and reporting platforms, including clear ownership, due dates, status, dependencies, blockers, and closure evidence.
  • Develop reusable evidence packages, control narratives, evidence maps, templates, playbooks, checklists, and guidance for recurring compliance activities.
  • Review evidence and compliance responses for completeness, consistency, traceability, and readiness before submission to audit, assessment, regulatory, or customer stakeholders.
  • Partner with Security, Technology, and business subject matter experts to identify recurring audit and assessment issues, reduce duplicative requests, and address root causes of evidence and process gaps.
  • Monitor adherence to applicable security controls, standards, procedures, remediation commitments, and assessment outcomes; identify overdue, incomplete, or ineffective activities and facilitate appropriate escalation.
  • Coordinate findings, observations, and remediation activities by establishing clear ownership, target dates, validation requirements, supporting evidence, escalation paths, and closure criteria.
  • Maintain alignment between operational tracking, GRC records, remediation documentation, and governance or leadership reporting, as applicable.
  • Develop and report metrics related to compliance workload, cycle time, evidence quality, service-level performance, aging items, recurring requests, remediation progress, and closure readiness.
  • Analyze audit, assessment, control, issue, and compliance data to identify recurring themes, systemic process opportunities, emerging concerns, and areas requiring leadership attention.
  • Prepare clear reporting and supporting narratives for Security leadership, cross-functional governance forums, auditors, regulators, customers, and other stakeholders, as appropriate.
  • Translate compliance requirements into practical operating guidance for business and technology teams and provide support that enables stakeholders to understand requirements, ownership, expected evidence, and completion criteria.
  • Support retrospectives and continuous-improvement activities following significant audits, assessments, customer reviews, or remediation efforts.
  • Support the company's commitment to risk management and protecting the integrity, confidentiality, and availability of systems and data.

Minimum Qualifications

  • Education and/or experience typically obtained through completion of a bachelor's degree or equivalent practical experience.
  • Typically has 7 years of experience or demonstrated portfolio consistent with experience required of the role.
  • Relevant experience in security governance, risk and compliance, information security, technology risk, IT audit, control testing, regulatory readiness, or a comparable operational governance discipline.
  • Demonstrated understanding of control environments, evidence requirements, audit and assessment processes, issue management, and remediation tracking.
  • Experience translating security or compliance requirements into practical processes, operating procedures, or guidance for business and technology stakeholders.
  • Demonstrated program, project, or workstream management skills, including the ability to coordinate cross-functional activities with competing priorities, dependencies, and ownership.
  • Experience identifying root causes and implementing sustainable process or workflow improvements.
  • Strong written and verbal communication skills, including experience preparing process documentation, stakeholder guidance, management reporting, or executive-level summaries.
  • Demonstrated ability to build stakeholder alignment and influence outcomes without relying on direct authority.
  • Experience working with GRC, workflow, reporting, collaboration, or comparable enterprise systems.
  • Strong analytical skills and attention to evidence quality, documentation, traceability, and follow-through.

Preferred Qualifications

  • Experience supporting security or technology compliance within financial services, payments, banking, or another regulated or complex operating environment.
  • Familiarity with security and control frameworks or standards such as NIST, CRI, ISO 27001/27002, SOC 2, PCI DSS, FFIEC, or comparable frameworks.
  • Experience supporting customer audits, regulatory examinations, internal audits, external assessments, or security attestations.
  • Experience with issue management, risk acceptance, remediation validation, risk and control self-assessments, control testing, or policy and standards governance.
  • Experience improving compliance processes through workflow automation, reusable evidence repositories, reporting dashboards, standardized templates, or process redesign.
  • Experience with tools such as Jira, ServiceNow, GRC platforms, Confluence, SharePoint, Excel, or comparable systems.
  • Relevant professional certifications such as CISA, CRISC, CISSP, CISM, PMP, or equivalent demonstrated experience.

Physical Requirements

Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.
Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.

The base pay scale for this position in:
Phoenix, AZ/ Chicago, IL in USD per year is: $116,000 - $145,000.
New York, NY/ San Francisco, CA in USD per year is: $139,000 - $174,000.
Additionally, candidates are eligible for a discretionary incentive plan and benefits.

This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate's education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers). The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.

Some of the Ways We Prioritize Your Health and Happiness

  • Healthcare Coverage-Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.

  • 401(k) Retirement Plan-Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.

  • Paid Time Off -Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.

  • 12 weeks of Paid Parental Leave

  • Maven Family Planning - provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.

AndSOmuch more! We continue to enhance our program, so be sure tocheck our Benefits page herefor the latest. Ourteamcan share more during the interview process!

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Early Warning Services, LLC ("Early Warning") considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.