1

Security Risk Management Jobs in Maryland (NOW HIRING)

Security Analyst

Columbia, MD ยท Hybrid

$55 - $60/hr

Description Position Overview The Information Security Analyst II (GRC) provides support for ... risk management activities โ€ข Execute and oversee the third-party risk management process โ€ข ...

Security Analyst

Columbia, MD ยท Hybrid

$55 - $60/hr

Description Position Overview The Information Security Analyst II (GRC) provides support for ... risk management activities โ€ข Execute and oversee the third-party risk management process โ€ข ...

$62K - $141K/yr

As an information security risk specialist on our team, you'll work with industry partners to ... Experience in cybersecurity risk assessments and supply chain or risk management efforts

$130K - $155K/yr

Risk Management: Conduct risk-based assessments for new and existing cloud and network solutions, identify vulnerabilities, and recommend mitigation strategies. * Security Service Management: Build ...

$130K - $155K/yr

Risk Management: Conduct risk-based assessments for new and existing cloud and network solutions, identify vulnerabilities, and recommend mitigation strategies. * Security Service Management: Build ...

Program Security Manager

Annapolis, MD ยท On-site

$127K - $155K/yr

Support planning and execution of sensitive activities by integrating counter-intelligence, operational security, risk mitigation, and collection management considerations * Develop and maintain risk ...

Showing results 41-60

Security Risk Management information

See Maryland salary details

$10

$48

$67

How much do security risk management jobs pay per hour?

As of Aug 29, 2026, the average hourly pay for security risk management in Maryland is $48.92, according to ZipRecruiter salary data. Most workers in this role earn between $39.66 and $58.32 per hour, depending on experience, location, and employer.

What is security risk management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in security risk management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in security risk management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What do you need to be a security risk manager?

A security risk manager typically needs a bachelor's degree in security management, information technology, or a related field, along with experience in security or risk assessment. Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) can enhance qualifications. Strong analytical skills, knowledge of security protocols, and familiarity with risk management tools are also important for the role.

What does security risk management do?

Security risk management involves identifying, assessing, and prioritizing potential security threats to an organization, then implementing measures to mitigate or eliminate those risks. Professionals in this field analyze vulnerabilities, develop security policies, and often use tools like risk assessment frameworks and security audits to protect assets and ensure safety.

What are popular job titles related to Security Risk Management jobs in Maryland?

For Security Risk Management jobs in Maryland, the most frequently searched job titles are:

What job categories do people searching Security Risk Management jobs in Maryland look for?

The top searched job categories for Security Risk Management jobs in Maryland are:

Infographic showing various Security Risk Management job openings in Maryland as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 15% Part Time, and 2% Contract. Highlights an 84% Physical, 2% Hybrid, and 14% Remote job distribution, with an average salary of $101,759 per year, or $48.9 per hour.

Information Systems Security Manager

Modern Technology Solutions, Inc. (MTSI)

Patuxent River, MD โ€ข On-site

Full-time

This job post hasย expired 1 day ago.ย Applications are no longer accepted.


Job description

Job Summary:
Modern Technology Solutions, Inc. (MTSI) is seeking an experienced Information Systems Security Manager (ISSM) to lead cybersecurity efforts in a Navy-centric software development environment. The ISSM will manage the security posture of information systems, ensuring compliance with DoD standards and the Risk Management Framework (RMF), while potentially growing a small cybersecurity team.
Responsibilities:
โ€ข Lead cybersecurity efforts for a Navy-centric software development environment focused on novel software applications.
โ€ข Manage and oversee the security posture of information systems, ensuring compliance with DoD standards and the Risk Management Framework (RMF).
โ€ข Work across multidisciplinary teams to maintain the confidentiality, integrity, and availability of the program's critical systems and data.
โ€ข Support onsite operating independently with the potential to grow a small team for scaling cybersecurity capabilities.
Qualifications:
Required:
โ€ข 8+ years of combined experience working in defensive/offensive cybersecurity, information assurance, penetration testing, software engineering, or related field.
โ€ข Knowledge of the Department of Navy and Naval Air Systems Command (NAVAIR), to include digital infrastructure/environments, DevSecOps, Continuous Integration/Continuous Development (CI/CD), software factories, cloud-native containerized applications, Risk Management Framework (RMF), continuous Authority to Operate (cATO).
โ€ข Proven experience in designing, implementing, and maintaining multi-level security architectures across cloud, infrastructure, and platform applications.
โ€ข Deep proficiency in configuring and managing industry-standard security tools, including firewalls, intrusion detection systems (IDS).
โ€ข Strong background in DevSecOps, with the ability to integrate and automate cybersecurity within CI/CD pipelines.
โ€ข Hands-on experience with security monitoring, log analysis, threat intelligence, and digital forensics to identify and respond to system anomalies.
โ€ข Expert knowledge of the Risk Management Framework (RMF) and Department of War (DoW) cybersecurity directives, including system categorization and continuous monitoring.
โ€ข Demonstrated ability to lead the full Authorization to Operate (ATO) lifecycle and manage System Security Plans (SSPs) in accordance with federal regulations.
โ€ข Extensive experience conducting security risk assessments, penetration testing, and compliance audits.
โ€ข Skilled in developing and enforcing organizational security standards, policies, and procedural documentation.
โ€ข Ability to serve as a primary cybersecurity advisor to senior leadership, engineering teams, and external stakeholders.
โ€ข Proven leadership in mentoring information security teams and coordinating cybersecurity requirements with external agencies and vendors.
โ€ข Strategic thinker capable of analyzing emerging threat vectors and adjusting security measures to maintain a robust security posture.
โ€ข Strong communication skills, with experience preparing and delivering high-level briefings and metrics on cyber readiness to key stakeholders.
โ€ข Experience with cloud security (e.g. AWS, Azure GCP).
โ€ข Familiarity with DevSecOps/Platforms such as AWS (S3, RDS, EC2, ECS, Lambda, SQS, SNS, CloudFormation, etc.), Azure (Azure App Service, Azure Functions, Azure Storage, Azure SQL Database, etc.), Docker, Ansible and experience with DevSecOps tools such as GitHub and Jenkins.
โ€ข Experience with on-premise compute infrastructure and networks.
โ€ข Experience in Agile development methodologies.
โ€ข Experience with defending against known attack vectors.
โ€ข In-depth knowledge of security frameworks, standards, and guides (e.g. RMF, NIST, CIS, STIGs, FIPS, etc.).
โ€ข BS in Computer-Science field.
โ€ข IAM level 2- CISSP, CASP CE+, CGRC, or CISM.
โ€ข Must possess a Top Secret clearance with SCI/SAP eligibility.
Preferred:
โ€ข Data Operations (DataOps), Artificial Intelligence / Machine Learning Operations (AI/MLOps)
โ€ข Experience supporting electronic warfare systems.
โ€ข Familiarity with software development and DevSecOps integration.
โ€ข Awareness of aviation platforms and weapon systems.
โ€ข Experience with Multi-Level Security (MLS) or Cross Domain Solutions (CDS).
โ€ข MS in Computer-Science or Cybersecurity field.
Company:
Modern Technology Solutions, Inc. Founded in 1993, the company is headquartered in Alexandria, USA, with a team of 1001-5000 employees. The company is currently Late Stage.