The incumbent will work with Information Technology, Internal Compliance / Risk Management, Human Resources, operational groups, and users in the development and implementation of an IT security ...
The incumbent will work with Information Technology, Internal Compliance / Risk Management, Human Resources, operational groups, and users in the development and implementation of an IT security ...
The role partners with the CIO to balance risk management, innovation, and operational efficiency , embedding security-by-design principles across all IT initiatives. Actively participate in the RFP ...
The role partners with the CIO to balance risk management, innovation, and operational efficiency , embedding security-by-design principles across all IT initiatives. Actively participate in the RFP ...
The incumbent will work with Information Technology, Internal Compliance / Risk Management, Human Resources, operational groups, and users in the development and implementation of an IT security ...
The incumbent will work with Information Technology, Internal Compliance / Risk Management, Human Resources, operational groups, and users in the development and implementation of an IT security ...
Be Seen First
Information Security Manager
Atlanta, GA · On-site
$120K - $150K/yr
... IT management, cyber security, security risk assessment, protecting sensitive data, and maintaining integrity of systems within the banking industry. A CISSP, CISM, or CISA Certification is ...
Quick apply
Be Seen First
Information Security Manager
Atlanta, GA · On-site
$120K - $150K/yr
... IT management, cyber security, security risk assessment, protecting sensitive data, and maintaining integrity of systems within the banking industry. A CISSP, CISM, or CISA Certification is ...
Risk Management & Administrative Specialist
Ellabell, GA · On-site
$59K - $62K/yr
Information Security: Manage all departmental documentation in strict accordance with the corporate ... Bachelor's degree in Business Administration, Risk Management, Human Resources, or a closely ...
Quick apply
Risk Management & Administrative Specialist
Ellabell, GA · On-site
$59K - $62K/yr
Information Security: Manage all departmental documentation in strict accordance with the corporate ... Bachelor's degree in Business Administration, Risk Management, Human Resources, or a closely ...
Compliance and Risk Management : * Ensure compliance with all relevant laws, regulations, and industry standards. * Oversee security risk assessments and implement appropriate mitigation measures.
Compliance and Risk Management : * Ensure compliance with all relevant laws, regulations, and industry standards. * Oversee security risk assessments and implement appropriate mitigation measures.
Risk Management and Incident Response (25%) - Develop, implement, and administer technical security standards and a portfolio of security services and tools to identify, mitigate, and monitor ...
Risk Management and Incident Response (25%) - Develop, implement, and administer technical security standards and a portfolio of security services and tools to identify, mitigate, and monitor ...
Risk Management and Incident Response (25%) - Develop, implement, and administer technical security standards and a portfolio of security services and tools to identify, mitigate, and monitor ...
Risk Management and Incident Response (25%) - Develop, implement, and administer technical security standards and a portfolio of security services and tools to identify, mitigate, and monitor ...
This executive will define and execute Candescent's enterprise-wide security, compliance, and risk management strategy, ensuring regulatory alignment (FFIEC, SOC2, ISO 27001, PCI-DSS), securing the ...
This executive will define and execute Candescent's enterprise-wide security, compliance, and risk management strategy, ensuring regulatory alignment (FFIEC, SOC2, ISO 27001, PCI-DSS), securing the ...
VP, Cybersecurity & Technology Risk Officer
$153K - $191K/yr
Influence prioritization of security investments and drive remediation strategies that align with ... management practices Key Competencies * Strong business acumen and the ability to apply risk-based ...
VP, Cybersecurity & Technology Risk Officer
$153K - $191K/yr
Influence prioritization of security investments and drive remediation strategies that align with ... management practices Key Competencies * Strong business acumen and the ability to apply risk-based ...
20167 - Security Engineer III
Savannah, GA · On-site
Support security audits, compliance reviews, and risk-management activities, delivering required documentation and remediation follow-up. * Participate in or lead incident response activities and ...
20167 - Security Engineer III
Savannah, GA · On-site
Support security audits, compliance reviews, and risk-management activities, delivering required documentation and remediation follow-up. * Participate in or lead incident response activities and ...
VP, Cybersecurity & Technology Risk Officer
Alpharetta, GA · On-site
$153K - $191K/yr
Influence prioritization of security investments and drive remediation strategies that align with ... management practices Key Competencies * Strong business acumen and the ability to apply risk-based ...
VP, Cybersecurity & Technology Risk Officer
Alpharetta, GA · On-site
$153K - $191K/yr
Influence prioritization of security investments and drive remediation strategies that align with ... management practices Key Competencies * Strong business acumen and the ability to apply risk-based ...
Experience leading or supporting security awareness and education programs, risk management or compliance initiatives. * Familiarity with security frameworks (e.g. NIST CSF, ISO 27001) * Exceptional ...
New
Experience leading or supporting security awareness and education programs, risk management or compliance initiatives. * Familiarity with security frameworks (e.g. NIST CSF, ISO 27001) * Exceptional ...
New
Technology Risk and Controls Lead
Atlanta, GA · On-site
Familiarity with risk management frameworks, industry standards, and financial industry regulatory requirements * Proficient knowledge and expertise in data security, risk assessment & reporting ...
Technology Risk and Controls Lead
Atlanta, GA · On-site
Familiarity with risk management frameworks, industry standards, and financial industry regulatory requirements * Proficient knowledge and expertise in data security, risk assessment & reporting ...
Experience with using and configuring Oracle Risk Management Cloud GRC solution (RMC). Proficiency ... Experience with other ERP security would be nice to have. * Demonstrated knowledge of auditing ...
Experience with using and configuring Oracle Risk Management Cloud GRC solution (RMC). Proficiency ... Experience with other ERP security would be nice to have. * Demonstrated knowledge of auditing ...
Principal Product Security Engineer
Lawrenceville, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Lawrenceville, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Technology Risk and Controls Lead
Atlanta, GA · On-site
Familiarity with risk management frameworks, industry standards, and financial industry regulatory requirements * Proficient knowledge and expertise in data security, risk assessment & reporting ...
Technology Risk and Controls Lead
Atlanta, GA · On-site
Familiarity with risk management frameworks, industry standards, and financial industry regulatory requirements * Proficient knowledge and expertise in data security, risk assessment & reporting ...
Familiarity with risk management frameworks, industry standards, and financial industry regulatory requirements * Proficient knowledge and expertise in data security, risk assessment & reporting ...
Familiarity with risk management frameworks, industry standards, and financial industry regulatory requirements * Proficient knowledge and expertise in data security, risk assessment & reporting ...
Principal Product Security Engineer
Athens, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Athens, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Atlanta, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Principal Product Security Engineer
Atlanta, GA · On-site +1
Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be ...
Security Risk Management information
See Georgia salary details
$8.73 - $13.30
2% of jobs
$13.30 - $17.88
0% of jobs
$17.88 - $22.46
1% of jobs
$22.46 - $27.03
1% of jobs
$27.03 - $31.61
1% of jobs
$35.04 is the 25th percentile. Wages below this are outliers.
$31.61 - $36.18
26% of jobs
$36.18 - $40.76
11% of jobs
The median wage is $42.40 / hr.
$40.76 - $45.34
22% of jobs
$45.34 - $49.91
9% of jobs
$50.27 is the 75th percentile. Wages above this are outliers.
$49.91 - $54.49
17% of jobs
$54.49 - $59.07
9% of jobs
$8
$42
$59
How much do security risk management jobs pay per hour?
What are the typical challenges faced by professionals in Security Risk Management, and how can they be addressed?
Can I make $200,000 a year in cyber security?
Can you make $500,000 a year in cyber security?
Is security risk management a good career?
What is Security Risk Management?
What are the key skills and qualifications needed to thrive in Security Risk Management, and why are they important?
What is the difference between Security Risk Management vs Security Analyst?
| Aspect | Security Risk Management | Security Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CISSP, CEH |
| Work Environment | Strategic, policy-focused, risk assessment | Operational, monitoring, incident response |
| Employer & Industry Usage | Organizations managing enterprise security risks | Security teams, cybersecurity firms, IT departments |
Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.
Is SOC 1 entry level?

Other
Medical, Life, Retirement
Posted 24 days ago
Job description
OUR MISSION
The mission of the Georgia Student Finance Commission is to promote and increase access to education beyond high school for Georgians. To achieve this mission the commission administers state and lottery-funded student financial aid programs including the HOPE Scholarship and HOPE Grant and provides college planning and other educational services to more than 2 million Georgians through GAfutures.org. The commission seeks to improve its own operations and inform policymakers and other stakeholders through analysis, interpretation and publication of information using the extensive data collected in support of its programs.
WE OFFER
We offer excellent benefits including 13 paid holidays, 3 weeks annual + 3 weeks sick leave per year, health/life/disability benefits after 30 days, employer 401k match, medical/childcare spending account options, and deferred compensation plan. Our standard business hours are Monday through Friday from 8am to 5pm. We also offer employee recognition and a great place to work! Our office is conveniently located in Tucker only 2 minutes from I-285.
JOB DESCRIPTION
Working under broad supervision, the Chief Information Security Officer is the leader of the corporate information security function for the Georgia Student Finance Commission, to include responsibility for overall corporate security strategy and security architecture planning and development. The scope of this role covers all utilized security technologies and services, including protection services, perimeter defenses, physical and logical access control, and profile management of all employees and contractors. As the company's senior security officer, the incumbent also has enterprise-level responsibility for all data/information security policies, standards, evaluations, roles, and corporate awareness.
The incumbent will work with Information Technology, Internal Compliance / Risk Management, Human Resources, operational groups, and users in the development and implementation of an IT security strategy designed to provide a high level of information security while preserving and enhancing system processes and usability. The individual must be a results-oriented person who can achieve tangible improvements in the corporate security arena. Excellent technical and communications skills are a must, as well as proven security leadership experience. The incumbent will be responsible for staff security and awareness training.
JOB RESPONSIBILITIES
The Chief Information Security Officer will be responsible for directing the activities of the information security function. Responsibilities will include:
      Develop, implement, and manage the overall enterprise process for security strategy and associated architecture and engineering standards.
      Develop and implement policies, standards, and guidelines related to corporate security.
      Oversee the continuous daily monitoring and protection of and information systems.
      Design and implement security controls across onpremises and cloud environments (IaaS, PaaS, SaaS), with a focus on data residency, data loss prevention, identitycentric security, and access governance across platforms such as Microsoft 365/Azure and AWS.
      Drive the responsible adoption of emerging technologies, including artificial intelligence, by evaluating AI risks and value and integrating agentic, AIdriven threat detection into agency workflows.
      Develop and manage an Incident Report and Response System to address organization security incidents (breaches), responding to alleged policy violations, or complaints from external parties. Serve as the enterprise focal point for security incident response planning and execution.
      Evaluate suspected security breaches and recommend corrective actions (including incidents involving outside vendors).
      Partner with Internal Compliance / Risk Management to design, implement, and manage a comprehensive Governance, Risk, and Compliance (GRC) program.
      Lead continuous information security risk assessments that identify and classify critical assets, evaluate associated threats and vulnerabilities, and drive the implementation of risk mitigation controls.
      Serve as compliance officer with respect to state and federal information security policies and regulations, working with Internal Compliance / Risk Management as necessary. Prepare and submit required security-related documents to state and federal agencies and departments.
      Develop appropriate criteria to assess the new/existing applications and/or technology infrastructure elements for compliance with enterprise security standards.
      Establish and monitor formal evaluation processes regarding enterprise security standards relating to the planned acquisition and/or procurement of new applications or technologies.
      Assist in the review of applications and/or technology environments during the development or acquisitions process to (a) assure compliance with corporate security policies and directions and (b) assist in the overall integration process regarding GSFC's own technology environment.
      Oversee the implementation of the State of Georgia security awareness and training program, including appropriate introductory training for new employees as well as ongoing training for all employees and managers.
      Evaluate changes to the corporate environment for security impact and present findings to management.
      Work with Information Technology on the evaluation, selection, testing, and deployment of security-related tools and services.
      Coordinate enterprise business continuity planning across business units and integrated services.
REPORTING
The Chief Information Security Officer will report directly to the Executive Vice President & Chief Operating Officer.
MINIMUM QUALIFICATIONS
The following standards express the minimum background of education and experience as evidence of an applicant's ability to qualify for this class title. Any combination of education and experience, if evaluated as equivalent, may qualify an applicant for a position within this class.
      Bachelor's degree from an accredited college or university AND eight years in the specific field of IT Security, five years of which include team leadership or management experience.
      Knowledge of network and application protocols (IP, UDP, FTP, HTTP, HTTPS, DNS, DHCP, routing, etc.).
      Broad knowledge in authentication systems, risk analysis, threat mitigation, and security domains.
      Ability to design and manage standards-based architecture including compliance monitoring and enforcement.
      High-proficiency level knowledge of security technologies such as cloudnative endpoint cybersecurity platforms, physical firewalls, and virtualized firewall solutions.
      Expertise in intrusion detection systems, proxy and VPN technologies, vulnerability assessment platforms, and identitycentric security architectures, including IAM and Zero Trust.
      Proficiency in data classification and loss prevention (DLP) specifically for high-volume personally identifiable information (PII).
      Experience with log management systems and tools, encryption, and VOIP.
      Knowledge of Linux and Windows server operating systems.
      Knowledge of business and management principles involved in strategic planning, resource allocation, leadership, production methods and coordination of people and resources.
      Strong written, verbal and facilitative communication skills, including ability to maintain cooperative and effective working relationships with colleagues.
      Strong analytical skills, critical thinking, and agility.
PREFERRED QUALIFICATIONS
      A college degree (BA/BS) in Information Security and ten years of experience in Information Security management, at least five of which were in a leadership role.
      Experience with CrowdStrike, Tenable, NinjaPro Anti-Virus, and vulnerability and configuration assessment products.
      Detailed knowledge of and experience in implementing and managing against National Institute of Standards and Technology Special Publications; (i.e. NIST SP 800-53).
      Detailed knowledge of and experience in implementing and managing security configuration and applications guidelines such as the Department of Defense's Security Technical Implementation Guides (STIGs) or the National Institute of Standards and Technology's National Checklist Program (NCP).
      IT industry security certification such as CISM, CISSP, GIAC, or CISA.
- Agency Logo:
- Requisition ID: INF02V2
- Number of Openings: 1
- Shift: Day Job
- Posting End Date: Jun 29, 2026