1

Security Risk Management Jobs in New York (NOW HIRING)

Continuous improvement using AI into all aspects of vendor risk management * Lead and independently prioritize a range of vendor security risk assessments - scoped by service type and integration ...

Continuous improvement using AI into all aspects of vendor risk management * Lead and independently prioritize a range of vendor security risk assessments - scoped by service type and integration ...

... security, and service. As part of Team Amex, you'll experience our powerful backing with ... Partner with Control Management and other stakeholders to support broader risk, governance, and ...

M0 Labs - Head of Security & Risk

New York, NY · On-site +1

$117K - $153K/yr

Build and Own Enterprise Risk Management : Build M0's enterprise risk program from scratch. Cover security, operational, regulatory, and counterparty risk, including the risk register, annual ...

Showing results 41-60

Security Risk Management information

See New York salary details

$11

$55

$76

How much do security risk management jobs pay per hour?

As of Aug 19, 2026, the average hourly pay for security risk management in New York is $55.15, according to ZipRecruiter salary data. Most workers in this role earn between $44.71 and $65.77 per hour, depending on experience, location, and employer.

What is security risk management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in security risk management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in security risk management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What do you need to be a security risk manager?

A security risk manager typically needs a bachelor's degree in security management, information technology, or a related field, along with experience in security or risk assessment. Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) can enhance qualifications. Strong analytical skills, knowledge of security protocols, and familiarity with risk management tools are also important for the role.

What does security risk management do?

Security risk management involves identifying, assessing, and prioritizing potential security threats to an organization, then implementing measures to mitigate or eliminate those risks. Professionals in this field analyze vulnerabilities, develop security policies, and often use tools like risk assessment frameworks and security audits to protect assets and ensure safety.

What job categories do people searching Security Risk Management jobs in New York look for?

The top searched job categories for Security Risk Management jobs in New York are:

What cities in New York are hiring for Security Risk Management jobs?

Cities in New York with the most Security Risk Management job openings:

Infographic showing various Security Risk Management job openings in New York as of August 2026, with employment types broken down into 79% Full Time, 8% Part Time, and 13% Contract. Highlights an 96% In-person, and 4% Remote job distribution, with an average salary of $114,707 per year, or $55.1 per hour.

Principal Tech Resiliency

Early Warning Services LLC

Manhattan, NY • On-site

$221 - $276/hr

Other

Medical, Dental, Vision, Retirement, PTO

Re-posted 18 days ago


Job description

Responsibilities
  • Provide independent review, oversight, and credible challenge of first‑line technology risk management activities, controls, and decisions across the company.
  • Evaluate the design and execution of risk management practices to ensure alignment with enterprise frameworks, policies, regulatory expectations, and industry standards.
  • Challenge risk identification and assessment activities, review and challenge risk and control self‑assessments, issues management, remediation plans, control validation outcomes, and key risk indicators.
  • Assess adequacy of severity ratings, root cause analyses, action plans, and closure evidence for technology‑related issues and risk events.
  • Identify risk trends, concentrations, and emerging themes through analysis of risk data, governance materials, and business changes; develop an independent view of risk exposure and control effectiveness.
  • Prepare and support reporting, escalation, and discussion materials for senior leaders, governance forums, and risk committees.
  • Partner with first‑line leaders, subject‑matter experts, and independent testing or validation teams to improve clarity of control expectations, testing scope, and evidence requirements.
  • Provide ongoing risk advisory support while maintaining second‑line independence and accountability for effective challenge.
  • Recommend opportunities to strengthen risk awareness, governance routines, and training that improve technology risk management maturity.
  • Support the company’s commitment to risk management and protecting the integrity and confidentiality of systems and data.
Focus: Enterprise Technology and Information Security Risk
  • Provide independent challenge and oversight of technology risk management practices across infrastructure, cloud, cybersecurity, product, and operational technology domains.
  • Provide independent challenge and oversight of information security risk management practices across threat management, network, endpoint, cloud, architecture, data, access, AI, or application security domains.
  • Assess alignment of technology risk and control activities with enterprise policies, risk frameworks, and applicable industry standards.
  • Evaluate whether risk assessments, control inventories, issues management, and key risk indicators are executed consistently and effectively across the technology organization.
  • Challenge risk identification activities related to significant technology changes, new products or capabilities, and cross‑functional initiatives.
  • Assess risk trends and systemic themes across the technology environment and provide independent reporting and escalation as needed.
Minimum Qualifications
  • Education: Bachelor’s degree or equivalent.
  • Typically 12 years of experience or demonstrated portfolio consistent with technology risk, information security, operational risk, or related disciplines within a regulated or otherwise complex operating environment.
  • Strong understanding of risk management practices, control frameworks, and second‑line oversight within a three‑lines‑of‑defense model.
  • Demonstrated experience providing independent review, challenge, or governance of first‑line technology, security, data, or operational risk activities.
  • Strong ability to assess control design and effectiveness, synthesize risk data, identify themes, and translate technical issues into business risk.
  • Excellent written, verbal, presentation, and stakeholder management skills, including experience interacting with senior leaders and cross‑functional partners.
  • Strong critical thinking, judgment, and problem‑solving skills, with the ability to provide practical, risk‑based recommendations in a complex environment.
  • Ability to operate independently, manage competing priorities, and maintain effective working relationships while preserving second‑line objectivity.
  • Background and drug screen required.
Preferred Qualifications
  • Advanced degree or additional related education and/or experience.
  • Experience in financial services, payments, fintech, or another highly regulated industry.
  • Familiarity with relevant regulatory expectations and industry standards and frameworks applicable to technology and security risk management such as ISO 27002, PCI DSS, NIST, FFIEC, and SOC2.
  • Experience supporting governance committees, audits, examinations, or regulatory interactions.
  • Relevant risk, security, audit, or control certifications such as CISA, CISM, CISSP, CCSP, CRISC, GSNA, CGIH, or equivalent.
  • Project or process management experience supporting cross‑functional risk, control, or governance initiatives.
Physical Requirements

Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers. Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.

Compensation

Base pay scale (USD per year):

  • Phoenix, AZ / Chicago, IL / Washington, DC: $184,000 – $230,000
  • New York, NY / San Francisco, CA: $221,000 – $276,000

Eligible for a discretionary incentive plan and benefits.

Benefits Overview
  • Health, dental, and vision coverage with company contributions to Health Savings Account (HSA) or flexible spending accounts (FSA).
  • 401(k) plan with 100% company safe harbor match on first 6% deferral.
  • Paid time off: flexible time off for exempt employees, generous PTO for non‑exempt employees, 11 paid company holidays, and a paid volunteer day.
  • 12 weeks of paid parental leave.
  • Additional benefits include support for fertility, adoption, and early pediatric care.
Equal Employment Opportunity

Early Warning Services, LLC (“Early Warning”) considers for employment, hires, retains, and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, faith, religion, color, sex, sexual orientation, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status, or any factor prohibited by law, and affirms policy and practice to support and promote equal employment opportunity and affirmative action in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.

Legal Notice

Early Warning Services, LLC is a participant in E‑Verify.

#J-18808-Ljbffr