1

Security Risk Management Jobs in New York (NOW HIRING)

Information Security Analyst

New York, NY ยท Hybrid

$115K - $125K/yr

As a technology-driven financial services company, managing information security risk is critical to the trust that we foster with our clients, investors, and regulators. This role will operate ...

Strong knowledge of security domains such as auditing, policy, database security, firewall design and implementation, risk analysis, identity management, access management, cloud security, or web ...

Strong knowledge of security domains such as auditing, policy, database security, firewall design and implementation, risk analysis, identity management, access management, cloud security, or web ...

Head of Risk Management

New York, NY ยท On-site

$275K - $325K/yr

Risk Lifecycle Management: Standardize and lead core ERM components: Risk & Control Self ... Provide 2LoD oversight for Securities Lending (Stock Loan) activities and principal trading risks ...

Provide oversight of ERM programs related to model risk, third party risk, operational risk, business continuity/disaster recovery, policy management, and physical security. * Establish key risk ...

Strong working knowledge of vendor risk domains: security, privacy, operational, financial, and ... Prior people management or team lead experience Compensation Flex takes a market-based approach to ...

next page

Showing results 1-20

Security Risk Management information

See New York salary details

$11

$55

$76

How much do security risk management jobs pay per hour?

As of Jun 28, 2026, the average hourly pay for security risk management in New York is $55.15, according to ZipRecruiter salary data. Most workers in this role earn between $44.71 and $65.77 per hour, depending on experience, location, and employer.

What are the typical challenges faced by professionals in Security Risk Management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

Can I make $200,000 a year in cyber security?

Security Risk Management professionals can potentially earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and roles in high-demand industries or senior leadership positions. Salary levels vary based on location, company size, and individual expertise, but high-level cybersecurity roles often offer compensation in this range.

Can you make $500,000 a year in cyber security?

Security Risk Management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or within large organizations. Achieving this income typically requires extensive experience, advanced certifications like CISSP or CISM, and expertise in high-demand areas such as threat intelligence or security architecture.

Is security risk management a good career?

Security risk management is a viable career that involves identifying, assessing, and mitigating security threats to organizations. It often requires certifications such as CISSP or CISM and skills in risk analysis, security policies, and incident response. The field offers opportunities across various industries with increasing demand for cybersecurity expertise.

What is Security Risk Management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in Security Risk Management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

Is SOC 1 entry level?

SOC 1 (Service Organization Control 1) reports are audit reports used to evaluate internal controls at a service organization and are not job roles. In the context of security risk management, entry-level positions typically require foundational knowledge of security principles, certifications like CompTIA Security+ or CISSP, and experience with risk assessment tools, but SOC 1 itself is not an entry-level role.
What job categories do people searching Security Risk Management jobs in New York look for? The top searched job categories for Security Risk Management jobs in New York are:
Infographic showing various Security Risk Management job openings in New York as of June 2026, with employment types broken down into 93% Full Time, 5% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $114,707 per year, or $55.1 per hour.
Information Security Analyst

Information Security Analyst

Betterment

New York, NY โ€ข Hybrid

$115K - $125K/yr

Other

Retirement

This job post hasย expired today.ย Applications are no longer accepted.


Job description

About Betterment

Betterment is a leading, technology-driven financial services company that offers investing, savings and retirement solutions for retail investors and investment advisors as well as financial wellness solutions, including a 401(k) for small and medium-sized businesses. Our team is passionate about our mission, to empower people to build wealth with confidence and ease.ย  We're headquartered in NYC and offer hybrid NY-based positions (four days/ week in-office, with no required office days during the summer and winter holidays).

About the Role:

We are looking foran information security professional with 2+ years experience in technology operations, technology audit, or GRC. The successful candidate in this role will perform a variety of governance, risk, and compliance activities related to security. Examples of assigned activities will include perform risk assessments for SaaS applications, consulting with application owners to apply strong logical access controls, monitoring and reporting on the timely remediation of vulnerabilities, or gathering evidence to support audits or examinations.

As a technology-driven financial services company, managing information security risk is critical to the trust that we foster with our clients, investors, and regulators. This role will operate within our Govern & Control team, which is a small independent (second line-of-defense) team which is integrated with the broader security program. The role reports to the Director of Information Security, and works closely with the security teams within engineering, lines of business throughout the company, and other risk management teams including Compliance and Legal.

This role is based out of our NYC office. Below we've reflected the base salary range for this position. Actual salaries may vary depending on factors including but not limited to location, experience, and performance. The range listed is just one component of Betterment's total compensation package for employees.ย 

  • New York City: $115,000-$125,000

This job may also be eligible for variable compensation in the form of a company incentive bonus.ย 

A Day in the Life:
  • Operates assigned risk management processes such as vulnerability monitoring, due diligence questionnaire completion, audit or examination evidence gathering. A number of AI and automation tools will be available to facilitate increasing efficiency and scale in this work over time. The role will have some flexibility for specialization among the team.
  • Perform application-level risk assessments by interviewing and documenting the key business processes and risks related to an application, and providing guidance regarding strong logical access controls to reduce risk. When appropriate, document issues and foster management attention related to remediation for control deficiencies.
  • Perform due diligence or ongoing monitoring activities to evaluate security risks introduced through third-party relationships or applications or tools used by employees.
  • Contribute to security awareness training or phishing simulation activities for training of employees and contractors.
  • Gather data and ensure management attention towards key risk indicator (KRI) metrics for security.ย 
  • Monitor assigned issues through regular follow-up and reporting to ensure management attention and timely remediation.
What We're Looking For:

We are seeking a team member with 2+ years experience in technology operations, technology audit, or GRC. They will be a significant contributor to the security program.

The following skills/competencies are required:

  • You've operated security controls in an IT operations role, or served as a Staff or Senior-level auditor (in public accounting or internal audit), or previously worked in a security role successfully.
  • You have knowledge and familiarity with the principles of security risk management, including the CIA triad, design and operation of controls, and one or more control governance frameworks.
  • You have a familiarity with security controls applicable to cloud computing and third-party SaaS applications, including logical access management processes, third-party due diligence and monitoring, and more
  • You have experience learning new skills, including through research and the use of AI and automation.