1

Security Risk Management Jobs in Raleigh, NC (NOW HIRING)

... manage the technical risk assessment team, and ensure consistent, high-quality execution across all counties. The Client Privacy & Security Office is launching a large-scale cybersecurity initiative ...

C2C/W2 3The Compliance Officer will be familiar with risk management, comfortable leading internal risk assessments, and possess knowledge of HIPAA and NIST privacy and security requirements for ...

Network Security Engineer

Raleigh, NC · On-site +1

$101K - $139K/yr

Implement segmentation, boundary protection, secure management access, and identity-aware ... Demonstrated ability to translate security risk into practical engineering priorities and designs ...

... Services Risk Management & Compliance Business Continuity & Disaster Recovery Security & Privacy ... Specialties Contract Staffing (Staff Augmentation) Permanent Placement (Staff Augmentation) ICAP ...

... manage the technical risk assessment team, and ensure consistent, high-quality execution across all counties. The client Privacy & Security Office is launching a large-scale cybersecurity initiative ...

next page

Showing results 1-20

Security Risk Management information

See Raleigh, NC salary details

$10

$48

$67

How much do security risk management jobs pay per hour?

As of Jun 19, 2026, the average hourly pay for security risk management in Raleigh, NC is $49.00, according to ZipRecruiter salary data. Most workers in this role earn between $39.71 and $58.41 per hour, depending on experience, location, and employer.

What are the typical challenges faced by professionals in Security Risk Management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

Can I make $200,000 a year in cyber security?

Security Risk Management professionals can potentially earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and roles in high-demand industries or senior leadership positions. Salary levels vary based on location, company size, and individual expertise, but high-level cybersecurity roles often offer compensation in this range.

Can you make $500,000 a year in cyber security?

Security Risk Management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or within large organizations. Achieving this income typically requires extensive experience, advanced certifications like CISSP or CISM, and expertise in high-demand areas such as threat intelligence or security architecture.

Is security risk management a good career?

Security risk management is a viable career that involves identifying, assessing, and mitigating security threats to organizations. It often requires certifications such as CISSP or CISM and skills in risk analysis, security policies, and incident response. The field offers opportunities across various industries with increasing demand for cybersecurity expertise.

What is Security Risk Management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in Security Risk Management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

Is SOC 1 entry level?

SOC 1 (Service Organization Control 1) reports are audit reports used to evaluate internal controls at a service organization and are not job roles. In the context of security risk management, entry-level positions typically require foundational knowledge of security principles, certifications like CompTIA Security+ or CISSP, and experience with risk assessment tools, but SOC 1 itself is not an entry-level role.
What are popular job titles related to Security Risk Management jobs in Raleigh, NC? For Security Risk Management jobs in Raleigh, NC, the most frequently searched job titles are:
What job categories do people searching Security Risk Management jobs in Raleigh, NC look for? The top searched job categories for Security Risk Management jobs in Raleigh, NC are:
Infographic showing various Security Risk Management job openings in Raleigh, NC as of June 2026, with employment types broken down into 4% As Needed, 88% Full Time, and 8% Part Time. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $101,915 per year, or $49 per hour.

Principal Product Security Engineer

Johnson & Johnson

Durham, NC • On-site, Remote

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 10 days ago


Johnson & Johnson rating

8.1

Company rating: 8.1 out of 10

Based on 102 frontline employees who took The Breakroom Quiz

32nd of 71 rated pharmaceutical


Job description

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Solution Architecture

Job Category:

Scientific/Technology

All Job Posting Locations:

Albuquerque, New Mexico, United States of America, Albuquerque, New Mexico, United States of America, Alexandria, Virginia, United States, Atlanta, Georgia, United States, Austin, Texas, United States, Baltimore, Maryland, United States, Billings, Montana, United States, Birmingham, Alabama, United States, Bismarck, North Dakota, United States, Bloomington, Illinois, United States, Boise, Idaho, United States, Boulder, Colorado, United States, Bridgeport, Connecticut, United States, Burlington, Vermont, United States, Charleston, South Carolina, United States, Charleston, West Virginia, United States, Charlotte, North Carolina, United States, Chattanooga, Tennessee, United States, Cleveland, Ohio, United States, Concord, New Hampshire, United States, Danvers, Massachusetts, United States of America, Detroit, Michigan, United States, Dover, Delaware, United States, Flagstaff, Arizona, United States, Indianapolis, Indiana, United States {+ 23 more}

Job Description:

We are searching for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote work options may be considered on a case-by-case basis and if approved by the Company.

Are you passionate about security and interested in joining a community of collaborative colleagues working in a Patient First! culture? If that’s you, we have an immediate opportunity for a Principal Product Security Engineer to join the newly formed Product Security team to help ensure security is implemented by design for this top-performing medical device company. This is an exciting opportunity to impact development initiatives that will shape future product development and industry standards. You will own the Product Security process that includes both pre-market and post-market processes engineering teams leverage throughout the product development lifecycle. If you are eager to leverage your security risk and compliance skills to make a difference and directly impact patient lives, this could be perfect for you.

Primary Duties and Responsibilities

  • Being at the office in Danvers MA for a minimum of 3 days per week (for candidates within commutable distance to site).
  • Partner with engineering teams (cloud, console, pump, etc.) to drive successful adherence to Abiomed’s product security policies, processes, program objectives.
  • Create, update, and improve product security processes.
  • Act as a SME on cyber security matters and provide guidance to development teams.
  • Advocate for proactive inclusion of cyber security input into all phases of the product life cycle, process improvements, CAPAs, strategic product road map planning.
  • Deliver documentation for pre-market product development activities including security plans, architecture diagrams, data flow diagrams, threat models, security requirements, Design for Security, SBOM, and risk management documentation.
  • Drive and monitor and post-market vulnerability management activities, with adherence to strict timelines.
  • Support compliance certification activities, such as SOC2, FedRAMP, ISO 27001, etc.
  • Identify, research, evaluate, and integrate new compliance requirements, industry standards, and best practices into the product security programs.
  • Maintain relationships with Abiomed’s Information Sharing and Analysis Organizations.
  • Guide teams to make decisions that balance business needs with medical device security objectives.
  • Work across organizational boundaries and exhibit empathy with customers, both internal and external.
  • Perform other related duties and responsibilities, as assigned.

Qualifications

Required:

  • Bachelor’s degree
  • 5+ years industry experience in Information Security.
  • Working knowledge of regulatory standards and compliance frameworks (e.g., NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR).
  • Experience with security risk management techniques.
  • Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be able to meet assigned deadlines.
  • Committed to working with a sense of urgency and embracing new challenges.
  • Strong communication and interpersonal skills.

Preferred:

  • Experience working in a regulated environment, FDA-regulated

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson and Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please email the Employee Health Support Center (ra-employeehealthsup@its.jnj.com) or contact AskGS to be directed to your accommodation resource.

#JNJTech

#LIHybrid

#LIRemote

The anticipated base pay range for this position is :

$100,000 - $172,500.

Additional Description for Pay Transparency:

The Company maintains highly competitive, performance-based compensation programs. Under current guidelines, this position is eligible for an annual performance bonus in accordance with the terms of the applicable plan. The annual performance bonus is a cash bonus intended to provide an incentive to achieve annual targeted results by rewarding for individual and the corporation’s performance over a calendar/performance year. Bonuses are awarded at the Company’s discretion on an individual basis. Employees and/or eligible dependents may be eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance. Employees may be eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Employees are eligible for the following time off benefits: Vacation – up to 120 hours per calendar year Sick time - up to 40 hours per calendar year; for employees who reside in the State of Washington – up to 56 hours per calendar year Holiday pay, including Floating Holidays – up to 13 days per calendar year of Work, Personal and Family Time - up to 40 hours per calendar year Additional information can be found through the link below. http://www.careers.jnj.com/employee-benefits The compensation and benefits information set forth in this posting applies to candidates hired in the United States. Candidates hired outside the United States will be eligible for compensation and benefits in accordance with their local market.


What Johnson & Johnson employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom