1

Security Risk Management Jobs in Chicago, IL (NOW HIRING)

Sr. Cybersecurity Operational Risk Officer

Chicago, IL · On-site

$103K - $132K/yr

... cloud security architecture, identity and access management, and cyber defenses - along with ... Essential Functions Evaluate risk and control identification within key processes and perform gap ...

next page

Showing results 1-20

Security Risk Management information

See Chicago, IL salary details

$10

$51

$72

How much do security risk management jobs pay per hour?

As of Sep 10, 2026, the average hourly pay for security risk management in Chicago, IL is $51.93, according to ZipRecruiter salary data. Most workers in this role earn between $42.12 and $61.92 per hour, depending on experience, location, and employer.

What is security risk management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in security risk management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in security risk management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What do you need to be a security risk manager?

A security risk manager typically needs a bachelor's degree in security management, information technology, or a related field, along with experience in security or risk assessment. Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) can enhance qualifications. Strong analytical skills, knowledge of security protocols, and familiarity with risk management tools are also important for the role.

What does security risk management do?

Security risk management involves identifying, assessing, and prioritizing potential security threats to an organization, then implementing measures to mitigate or eliminate those risks. Professionals in this field analyze vulnerabilities, develop security policies, and often use tools like risk assessment frameworks and security audits to protect assets and ensure safety.

What are popular job titles related to Security Risk Management jobs in Chicago, IL?

For Security Risk Management jobs in Chicago, IL, the most frequently searched job titles are:

What job categories do people searching Security Risk Management jobs in Chicago, IL look for?

The top searched job categories for Security Risk Management jobs in Chicago, IL are:

Infographic showing various Security Risk Management job openings in Chicago, IL as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 17% Part Time, 2% Contract, and 1% Nights. Highlights an 82% Physical, 3% Hybrid, and 15% Remote job distribution, with an average salary of $108,094 per year, or $52 per hour.

Vice President, Information Security & Risk

Chicago, IL • On-site

Other

Medical, Dental, Vision, Retirement, PTO

Re-posted 3 days ago


Job description

Vice President, Information Security & Risk

Job Category: Vice President

Requisition Number: VICEP008455

  • Posted : August 7, 2026
  • Full-Time
Locations

Showing 1 location

4101 N Ravenswood Ave
Chicago, IL 60613, USA

Description

The Vice President (VP), Information Security & Risk is responsible for leading the execution and continuous improvement of the Thresholds information security and risk management program. The scope of the program is the protection of Thresholds’ information and technology assets as well as Thresholds’ digital data in the cloud. The VP, Information Security & Risk is accountable for fulfilling the program’s protection and compliance requirements while enabling innovation, analytics, and digital transformation in a secure and compliant manner; provides strong technical leadership; and serves as a trusted advisor to the Chief Information Officer and agency leaders in addition to serving as the agency’s designated security official.

ESSENTIAL DUTIES & RESPONSIBILITIES:

Security Operations and Execution

  • Manages the day-to-day information security operations, including security posture and event monitoring, threat and vulnerability identification, policy violation, access control and attack surface monitoring, monitoring the effectiveness of email and URL filtering, and incident response activities.
  • Manages the remediation of security issues, policy violation, ineffective rules for access control, attack surface reduction, and email/URL filtering as well as the creation and maintenance of standard operating procedures for security operations.
  • Develops and maintains dashboard(s) of security operations KPI’s for Information Technology (IT/ITS) management review.

Application, Cloud, Digital, Infrastructure and Platform Security

  • Supports secure implementation and operation of applications, cloud services, infrastructure, and platforms (cloud, digital, end-user, and server).
  • Partners with Information Technology Services (ITS) and digital teams to incorporate needed security controls into the design, development, and deployment of Thresholds applications, cloud services, infrastructure, and platforms.
  • Performs and/or coordinates risk reviews of application and digital systems, and their underlying configurations.

Data Security and Privacy

  • Manages the IT Risk Management Program using Thresholds’ risk management tool to record and assess identified risks, assign a risk owner, track risk treatment progress in the risk register, and provide risk management reporting to ITS leadership.
  • Leads enterprise, regulatory, service provider, and project IT risk assessments.
  • Supports internal and external audits, regulatory reviews, and customer or partner security inquiries.

Policy, Awareness & Documentation

  • Owns development and enforcement of the Information Security & Risk Management Program’s policies, standards, and procedures, as well as the agency’s Acceptable Use Policies.
  • Leads or oversees security awareness and training programs for the agency and the ITS staff.
  • Maintains and improves the Incident Response Playbook.

Collaboration and Continuous Improvement

  • Serves as a trusted advisor to business units and project teams on matters related to AI security, application security, information security, network security, AI risk, IT risk, regulatory compliance, emerging threats, social engineering, data classification; promoting security as a mission enabler for Thresholds.
  • Promotes a strong, practical security/risk culture that balances protection with usability and business needs.
  • Influences decisions by clearly articulating risk, tradeoffs, and recommendations.

Program Leadership and Strategy Execution

  • Embeds security by design principles into system implementations, vendor selection, and operational processes.
  • Translates security strategy into actionable roadmaps, initiatives, and measurable outcomes.
  • Stays current on evolving AI and cyber threats, data protection practices, and regulatory requirements.

Vulnerability and Threat Management

  • Manages the Vulnerability Management Program using Thresholds’ vulnerability management tools to identify and assess vulnerabilities, assign a vulnerability treatment owner, track vulnerability treatment progress in the vulnerability register, and provide vulnerability management reporting to IT leadership.
  • Reviews threat intelligence to identify potential negative impacting issues and proactively performs remedial actions to block or avoid the threat(s).
  • Provides threat action summaries to ITS leadership.

Team Leadership and Development

  • Directly manages, mentors, and develops security staff; setting performance goals and supporting career growth.
  • Provides technical guidance and decision support to security team members and cross-functional partners.
  • Helps shape workforce planning, resource allocation, and budget inputs for security initiatives.

EDUCATION:

  • Accredited bachelor’s degree in information security, Computer Science, Information Systems, or related field (or equivalent experience) required.

EXPERIENCE:

Required

  • Minimum of seven (7) Years of progressive experience in information security, cybersecurity, data protection, or IT risk management.
  • Minimum of three (3) Years of experience leading teams or major security/risk management programs.
  • Hands-on experience with security operations, incident response, risk assessments, or compliance activities.
  • Working knowledge of security and risk frameworks (e.g., NIST, ISO 27001, CIS Controls), AI security and risk management best practices, regulatory requirements (e.g., HIPAA, PCI DSS), Microsoft security and risk management tools, identity and access management, network access controls, data loss prevention, and SIEM systems.
  • Demonstrated ability to explain security risk and control matter to non-technical audiences.

Preferred

  • Experience supporting cloud environments, SaaS platforms, or digital transformation initiatives.
  • Experience in a mid-sized, non-profit and/or regulated organization.
  • Familiarity with data analytics, and reporting tools.
  • Familiarity with computer forensic techniques.
  • Demonstrated experience partnering with leaders/senior leaders and influencing outcomes.

SKILLS/CERTIFICATIONS

  • Security certifications (e.g. CISSP, CISM, Security+, CCSP)
  • Microsoft certified
  • Demonstrated and effective analytical and problem-solving skills
  • Strong analytical and problem-solving skills
  • Practical, risk-based approach to security
  • Clear interpersonal and communication skills, both written and oral
  • Policy writing
  • Scripting languages, preferably PowerShell
  • Collaboration and relationship management
  • Attention to detail and follow-through
  • High integrity and discretion
  • Demonstrated project management and people management skills
  • Strategic execution and program ownership
  • Demonstrated effective cross-functional collaboration

What Sets Thresholds Apart:

  • Competitive pay – Salary Range: $155,000.00 - 175,000.00 annually
  • Generous PTO (9 federal holidays, 8 days of sick leave, 15-22 days personal and vacation)
  • Dental insurance, vision insurance, choice of 3 medical insurance plans
  • 403(b) retirement plan with 3% employer match
  • Robust employee assistance program (EAP)

Thresholds is a mission-driven agency with a deep commitment to fostering an environment where all feel valued and respected, a place where every employee can be themselves, thrive, and support the agency’s mission. Click here to learn more.

One of the oldest and largest community mental health organizations in Illinois, we pride ourselves in being a Chicago Tribune Top Workplace and one of Chicago’s 101 Best & Brightest Companies to Work For, several years in a row.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

#J-18808-Ljbffr