1

Security Risk Management Jobs in Kentucky (NOW HIRING)

... risk management program, including vendor tiering and assessments * Coordinating regulatory and audit engagements (internal and external) * Partnering across Security, IT, Legal, Compliance, and ...

The Global Senior IT Security Specialist serves as the strategic leader for our global security program, driving security initiatives, governance, and risk management across the organization.

Security Officer

Henderson, KY · On-site

$14.50 - $17/hr

JOB SUMMARY Are you a security professional who excels at customer relations and risk management? Are you interested in joining the exciting world of horse racing and gaming? Ellis Park Racing ...

Security Officer

Henderson, KY · On-site

$12.75 - $15.25/hr

JOB SUMMARY Are you a security professional who excels at customer relations and risk management? Are you interested in joining the exciting world of horse racing and gaming? Ellis Park Racing ...

Cyber Manager - ServiceNow

Louisville, KY · On-site

$106.50K - $143.90K/yr

... Risk Management, Security Operations, Information Technology Operations Management, Information Technology Asset Management, and Third-Party Risk Management workstreams in partnership with architects ...

Security Officer

Henderson, KY · On-site

$12.75 - $15.25/hr

JOB SUMMARY Are you a security professional who excels at customer relations and risk management? Are you interested in joining the exciting world of horse racing and gaming? Ellis Park Racing ...

next page

Showing results 1-20

Security Risk Management information

See Kentucky salary details

$8

$43

$60

How much do security risk management jobs pay per hour?

As of May 30, 2026, the average hourly pay for security risk management in Kentucky is $43.78, according to ZipRecruiter salary data. Most workers in this role earn between $35.48 and $52.21 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in Security Risk Management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in Security Risk Management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is Security Risk Management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What are popular job titles related to Security Risk Management jobs in Kentucky? For Security Risk Management jobs in Kentucky, the most frequently searched job titles are:
What job categories do people searching Security Risk Management jobs in Kentucky look for? The top searched job categories for Security Risk Management jobs in Kentucky are:
IT Security and Governance Analyst

IT Security and Governance Analyst

Brown-Forman Corporation

Louisville, KY • On-site

$43.25 - $57.75/hr

Full-time

Posted 19 days ago


Brown‑Forman rating

7.6

Company rating: 7.6 out of 10

Based on 7 frontline employees who took The Breakroom Quiz

115th of 378 rated food and drinks producers


Job description

CURRENT EMPLOYEES, CONSULTANTS, AND AGENCY PARTNERS:
If you currently work for Brown-Forman, please apply by clicking the Careers icon on the Workday portal.
For best results, use Google Chrome to view this page.
Quote from Hiring Manager:
The IT Governance/Risk/Compliance Analyst position offers a dynamic opportunity for an experienced analyst to help shape the future of our governance, risk, and compliance initiatives. In this role, you'll be at the forefront of identifying and mitigating IT risks, ensuring regulatory compliance, and enhancing our security posture through robust frameworks and controls. We're seeking candidates with strong analytical skills, knowledge of risk management frameworks, and the ability to communicate technical concepts to diverse stakeholders.
Meaningful Work From Day One:
The IT GRC Analyst plays a critical role in ensuring that the organization's IT governance is aligned with business objectives while also adhering to governance standards, risk management practices, and regulatory compliance obligations. In this role, you'll collaborate with cross-functional teams to align risk management strategies, ensure compliance, and foster a unified approach to IT governance.
What You Can Expect:
• Develop and maintain IT governance frameworks and policies that align with industry standards and regulatory requirements, which are then implemented by IT owners.
• Support our IT risk management program to ensure both internal and third-party IT risks are identified, assessed, prioritized and remediated.
• Raise awareness within the organization of IT governance, risk and compliance programs that are risk based and align with compliance requirements.
• Track and ensure compliance with internal policies and external regulations through periodic audits and assessments.
• Ensure data security and privacy compliance by providing guidance on appropriate access controls, data classification protocols, and data protection measures.
• Collaborate with key stakeholders throughout the IT organization as well as with Internal Audit, Compliance, and Legal.
• Monitor evolving regulations, compliance standards, and best practices to strengthen our IT GRC capabilities and frameworks.
What You Bring to the Table:
• 3+ years of experience focused on governance, compliance, risk, audit or similar functions.
• Knowledge of IT governance and risk management frameworks including compliance practices (e.g., PCI, NIST, GDPR, COBIT, NIS2, Operation Technology, etc.).
• Strong analytical skills, attention to detail, and a problem-solving mindset.
• Excellent collaboration, communication and influencing skills with the ability to develop effective working relationships with all levels of the company.
• Exposure to risk assessments, policy development, and internal control audits.
What Makes You Unique:
• Bachelor's degree within a related area of study.
• Information security related training or certifications such as CISA, CRISC, PCI QSA.
• Experience working with GRC platforms and tools.
• Familiarity with third-party risk management and vendor compliance.
Who We Are:
We believe great people build great brands. And we know there is Nothing Better in the Market than a career at Brown-Forman. Being a part of Brown-Forman means you will grow both personally and professionally. You will have the opportunity to solve problems, seize opportunities, and generate bold ideas. You will belong to a place where teamwork matters and where you are encouraged to bring your best self to work.
What We Offer:
Total Rewards at Brown-Forman is designed to engage our people to ensure sustainable and profitable growth for generations to come. As a premium spirits company, we offer equitable pay structures for individual and company performance alongside a premium employee experience. We offer a range of premium benefits that reflect our company values and meet the needs of our diverse workforce. #LI
Requisition Type:
Employee
Management Level:
Professional
Global Job Level:
P5
Number of Openings Available:
1