1

Security Risk Management Jobs (NOW HIRING)

Security Risk Manager

San Francisco, CA · Hybrid

$194K - $220K/yr

Own Asana's security risk management program: Design and continuously mature a quantitative risk framework - including risk scoring methodologies, likelihood and impact modeling, and risk appetite ...

Own Asana's security risk management program: Design and continuously mature a quantitative risk framework -- including risk scoring methodologies, likelihood and impact modeling, and risk appetite ...

Security Risk Manager

San Francisco, CA · On-site

$194K - $220K/yr

Own Asana's security risk management program: Design and continuously mature a quantitative risk framework - including risk scoring methodologies, likelihood and impact modeling, and risk appetite ...

Preferred • Experience leading enterprise-wide Crisis Management, GSOC, or intelligence operations programs • Knowledge of Enterprise Security Risk Management principles • Experience in ...

Vulnerability Management, Third Party Risk, Product Security, Detection and Response, etc ... Review holistically Risk, Control, and Issue data to culminate recommendations on top security ...

Vulnerability Management, Third Party Risk, Product Security, Detection and Response, etc ... Review holistically Risk, Control, and Issue data to culminate recommendations on top security ...

Showing results 21-40

Security Risk Management information

See salary details

$10

$50

$69

How much do security risk management jobs pay per hour?

As of Aug 19, 2026, the average hourly pay for security risk management in the United States is $50.41, according to ZipRecruiter salary data. Most workers in this role earn between $40.87 and $60.10 per hour, depending on experience, location, and employer.

What is security risk management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in security risk management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in security risk management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What do you need to be a security risk manager?

A security risk manager typically needs a bachelor's degree in security management, information technology, or a related field, along with experience in security or risk assessment. Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) can enhance qualifications. Strong analytical skills, knowledge of security protocols, and familiarity with risk management tools are also important for the role.

What does security risk management do?

Security risk management involves identifying, assessing, and prioritizing potential security threats to an organization, then implementing measures to mitigate or eliminate those risks. Professionals in this field analyze vulnerabilities, develop security policies, and often use tools like risk assessment frameworks and security audits to protect assets and ensure safety.
More about Security Risk Management jobs

What cities are hiring for Security Risk Management jobs?

Cities with the most Security Risk Management job openings:

What states have the most Security Risk Management jobs?

States with the most job openings for Security Risk Management jobs include:

What job categories do people searching Security Risk Management jobs look for?

The top searched job categories for Security Risk Management jobs are:

Infographic showing various Security Risk Management job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $104,848 per year, or $50.4 per hour.

Senior Security Risk Management SME*

SIERTEK LTD

Washington, DC • Hybrid

Full-time

Posted 20 days ago


Job description

SierTeK proudly serves our clients by providing expertise in the Program Management, Information Technology, and Administrative Support domains. Founded in 2007 as a minority and service-disabled veteran-owned company, we serve as prime- and subcontractor for a multitude of Federal Department of Defense contracts. By focusing on continual improvement, our services remain at the forefront of our industry, and we pride ourselves on delivering our services with the highest degree of integrity.

SierTeK Ltd. is seeking a Senior Security Risk Management SME to support an opportunity in Washington D.C..

Position Overview Section

The Senior Security Risk Management Subject Matter Expert drives complex security risk management operations, including Assessment and Authorization (A&A), continuous monitoring, and FISMA compliance for the agency.

Essential Job Functions

The SME is tasked with implementing emerging risk management practices and applying NIST 800 series and CNSSI 1253 security controls to secure cloud and hybrid environments.

Minimum Position Requirements

  • At least 10 years of total related experience and must include at least 2 years of recent experience in each of the following areas: A&A, FISMA compliance, IC cybersecurity policy and standards, continuous monitoring, Cross Domain Solutions, and secure cloud and hybrid engineering 

Certifications:

  • Required: CISM, CAP, or GRC Certification, or comparable demonstrable experience 
  • Desired: Certifications in AWS, Microsoft Azure, and Microsoft Office 365 cloud platforms

SierTeK is an equal opportunity employer. Employment is decided based on qualifications, merit, and business need. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected Veteran status, gender identity and sexual orientation.

This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, transfer, leaves of absence, compensation, and training.

If you need assistance or accommodation due to a disability, you may contact us at 1+833.743.7835.

*This job posting is to identify potential candidates for positions in order to respond to a request for proposal. This job posting, including but not limited to, qualifications, duties, compensation and benefits, is subject to change based on the terms and conditions of the awarded contract and is contingent on SierTeK being awarded the contract


Siertek logo

About Siertek

Sourced by ZipRecruiter

Industry

Guided missile and space vehicle manufacturing

Company size

201 - 500 Employees

Headquarters location

Beavercreek, OH, US

Year founded

2007