1

Security Risk Management Jobs in Brooklyn, NY (NOW HIRING)

Risk & Compliance Engineer

Newark, NJ · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Continuous improvement using AI into all aspects of vendor risk management * Lead and independently prioritize a range of vendor security risk assessments - scoped by service type and integration ...

Chief Risk Officer - Managing Director

New York, NY · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

... security risk in a technology-enabled business model. Safety, Resilience & Incident Management ... Business & Technology Resilience: Ensure the firm's ability to continue delivering critical ...

Directors, Risk Management

Manhattan, NY · On-site

$195K - $215K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

American Express Company seeks Directors, Risk Management to drive credit line underwriting, as ... security, and service. As part of Team Amex, you'll experience our powerful backing with ...

Directors, Risk Management

New York, NY · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

... security, and service. As part of Team Amex, you'll experience our powerful backing with ... years of risk management and risk analysis experience. Experience must include 2 years of ...

Dir-Risk Management

New York, NY · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

... security, and service. As part of Team Amex, you'll experience our powerful backing with ... Partner with Control Management and other stakeholders to support broader risk, governance, and ...

M0 Labs - Head of Security & Risk

New York, NY · On-site +1

$117K - $153K/yr

  • Medical

Build and Own Enterprise Risk Management : Build M0's enterprise risk program from scratch. Cover security, operational, regulatory, and counterparty risk, including the risk register, annual ...

Dir-Risk Management

New York, NY · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

... security, and service. As part of Team Amex, you'll experience our powerful backing with ... Knowledge of risk management frameworks, regulatory landscape, and methodologies. Preferred ...

Be Seen First

... , HR, Procurement, Employee Health & Safety, Marketing/Sales, Global Risk teams, and other ... Manage insurance programs including Property; Commercial General Liability / Excess Umbrella;

Risk & Compliance Engineer

Newark, NJ · On-site

$82 - $97/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Continuous improvement using AI into all aspects of vendor risk management * Lead and independently prioritize a range of vendor security risk assessments -- scoped by service type and integration ...

Showing results 41-60

Security Risk Management information

See Brooklyn, NY salary details

$10

$53

$73

How much do security risk management jobs pay per hour?

As of Aug 19, 2026, the average hourly pay for security risk management in Brooklyn, NY is $53.00, according to ZipRecruiter salary data. Most workers in this role earn between $42.98 and $63.17 per hour, depending on experience, location, and employer.

What is security risk management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in security risk management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in security risk management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What do you need to be a security risk manager?

A security risk manager typically needs a bachelor's degree in security management, information technology, or a related field, along with experience in security or risk assessment. Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) can enhance qualifications. Strong analytical skills, knowledge of security protocols, and familiarity with risk management tools are also important for the role.

What does security risk management do?

Security risk management involves identifying, assessing, and prioritizing potential security threats to an organization, then implementing measures to mitigate or eliminate those risks. Professionals in this field analyze vulnerabilities, develop security policies, and often use tools like risk assessment frameworks and security audits to protect assets and ensure safety.

What are popular job titles related to Security Risk Management jobs in Brooklyn, NY?

For Security Risk Management jobs in Brooklyn, NY, the most frequently searched job titles are:

What job categories do people searching Security Risk Management jobs in Brooklyn, NY look for?

The top searched job categories for Security Risk Management jobs in Brooklyn, NY are:

Infographic showing various Security Risk Management job openings in Brooklyn, NY as of August 2026, with employment types broken down into 67% Full Time, and 33% Part Time. Highlights an 100% In-person job distribution, with an average salary of $110,248 per year, or $53 per hour.

CRO - Information Security & Risk Oversight Lead

Bloomberg L.P.

Manhattan, NY • On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 18 days ago


Bloomberg rating

9.4

Company rating: 9.4 out of 10

Based on 11 frontline employees who took The Breakroom Quiz

11th of 245 rated software companies


Job description

Description & Requirements
The energy of a newsroom, the pace of a trading floor, the buzz of a recent tech breakthrough; we work hard, and we work fast - while keeping up the quality and accuracy we're known for. It's what keeps us inventing and reinventing, all the time. Our culture is wide open, just like our spaces. We bring out the best in each other through collaboration. Through our countless volunteer projects, we also help network with the communities around us, too. You can do amazing work here. Work you couldn't do anywhere else. It's up to you to make it happen.
About the Role:
We're looking for an Information Security Risk Oversight Lead who can translate cybersecurity risk into executive insight and action. Sitting in the Company's Second Line of Defense , the Chief Risk Office and reporting directly to our Head of Technology Risk , you will provide independent oversight and credible challenge across the firm's enterprise-wide information security program. Operating at the intersection of technology, risk management , cybersecurity, governance, and strategy, you will partner with the Chief Information Security Office , Engineering, and CTO teams to ensure cyber risks are appropriately identified , measured, monitored , and aligned with the firm's risk appetite. The "so what" is critical: your oversight will enable leadership to understand not only what the risks are, but whether they are being managed effectively-and where decisive action is required to strengthen the firm's overall security posture.
Key Responsibilities
* Serve as the primary Second Line risk advisor for cybersecurity - related risks and lead independent oversight and credible challeng e of First Line of Defense activities.
* Identify and measure threat-actor initiated risks and risk scenarios that may impact the confidentiality, integrity, and availability of information systems .
* Evaluate the design and operating effectiveness of security controls, particularly across complex, high-risk, or enterprise-scale technology initiatives.
*Quantify risk and control posture to support executive decision-making through scenario analysis and metrics (e.g., KRIs, KPIs, SLA/SLOs , ALE ).
* Review and challenge security-driven programs and initiatives to ensure alignment with enterprise risk appetite , industry control frameworks, and regulatory expectations.
* Partner closely with Information Security and Engineering teams to enhance risk awareness, accountability, and control ownership.
* Identify root causes of control failures, security incidents, or systemic weaknesses and support the development of actionable, preventative recommendations.
* Prepare and present risk oversight materials to senior leadership committees, internal audit, Board of Directors , and regulatory bodies as required.
* Act as a strategic thought partner to senior leaders by advising on emerging threats, evolving regulatory requirements, and industry best practices.
Required Qualifications
* Bachelor's Degree required.
* 10+ years of experience in Information Security.
* 10+ years of experience in IT or Cyber Risk Management.
* Demonstrated experience operating within a Second Line of Defense or independent risk oversight function.
* Strong understanding of cybersecurity control frameworks (e.g., NIST CSF, NIST 800-53, M I TRE ATT& CK, ISO 27001, COBIT, CIS).
* Experience interacting with Boards, regulators, internal audit , and /or executive governance forums.
* Authorized to work in the United States.
Preferred Qualifications
* Relevant professional certifications (e.g., FAIR, CISSP, CISM, CRISC, CISA).
* Experience in regulated industries (e.g., financial services).
* Strong understanding of cloud security, application security, identity and access management, and cyber resilience.
* Familiarity with enterprise risk management methodologies and risk appetite frameworks.
Core Competencies
* Strong analytical and critical thinking skills with the ability to provide constructive challenge .
* Executive-level communication and presentation skills.
* Ability to influence without direct authority.
* Strategic mindset with strong attention to detail.
* High integrity and independent judgment.
Salary Range = 215,000 - 290,000 USD Annual + Benefits + Bonus
The referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.
We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation (exempt roles only), paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.
Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success.

What Bloomberg employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Bloomberg logo

About Bloomberg

Sourced by ZipRecruiter

Bloomberg runs on data. As the Data Management & Analytics team within Engineering, we support our organization's needs around managing data efficiently. The vision of the team is to build solutions that drive data quality, data dictionary, data stewardship, data lineage, reference, and master data management across various data domains (prospect, customer, vendor, material etc.). We partner with business teams across the organization in addressing their data needs and ultimately helping run business operations efficiently and make improved decisions.

Industry

Finance and insurance

Company size

10,000+ Employees

Headquarters location

New York, NY, US

Year founded

1981