1

Security Risk Management Jobs (NOW HIRING)

$115K - $165K/yr

The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls ...

The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls ...

Security Risk Engineer

San Francisco, CA · Hybrid

$202K - $230K/yr

As the Security Risk Engineer, you will own Asana's internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists - you will ...

Security Risk Manager

San Francisco, CA · On-site

$194K - $220K/yr

Own Asana's security risk management program: Design and continuously mature a quantitative risk framework - including risk scoring methodologies, likelihood and impact modeling, and risk appetite ...

Preferred Experience leading enterprise-wide Crisis Management, GSOC, or intelligence operations programs Knowledge of Enterprise Security Risk Management principles Experience in business continuity ...

Meta's Security Risk Program (SRP) is the second-line function accountable for how Metaidentifies ... Drive cross-domain unification with Privacy Risk Management, Integrity Risk Management, Legal ...

Preferred • Experience leading enterprise-wide Crisis Management, GSOC, or intelligence operations programs • Knowledge of Enterprise Security Risk Management principles • Experience in ...

Own Asana's security risk management program: Design and continuously mature a quantitative risk framework -- including risk scoring methodologies, likelihood and impact modeling, and risk appetite ...

Showing results 21-40

Security Risk Management information

See salary details

$10

$50

$69

How much do security risk management jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for security risk management in the United States is $50.41, according to ZipRecruiter salary data. Most workers in this role earn between $40.87 and $60.10 per hour, depending on experience, location, and employer.

What is security risk management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in security risk management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in security risk management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What do you need to be a security risk manager?

A security risk manager typically needs a bachelor's degree in security management, information technology, or a related field, along with experience in security or risk assessment. Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) can enhance qualifications. Strong analytical skills, knowledge of security protocols, and familiarity with risk management tools are also important for the role.

What does security risk management do?

Security risk management involves identifying, assessing, and prioritizing potential security threats to an organization, then implementing measures to mitigate or eliminate those risks. Professionals in this field analyze vulnerabilities, develop security policies, and often use tools like risk assessment frameworks and security audits to protect assets and ensure safety.
More about Security Risk Management jobs

What cities are hiring for Security Risk Management jobs?

Cities with the most Security Risk Management job openings:

What states have the most Security Risk Management jobs?

States with the most job openings for Security Risk Management jobs include:

Infographic showing various Security Risk Management job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 86% Physical, 2% Hybrid, and 12% Remote job distribution, with an average salary of $104,848 per year, or $50.4 per hour.

Security Engineer - Security Risk Management

Menlo Park, CA • On-site

Meta
Internet and IT • 10K+ employees

$154K/yr

Full-time

Posted 21 days ago


Key responsibilities

  • Design, build, and own software solutions that scale high fidelity security risk contextualization, tracking, and reporting.

  • Understand and influence the evolution of security capabilities to scale and automate monitoring and increase maturity.

  • Scale managing and responding to risk management and compliance related requests.


Meta rating

7.8

Company rating: 7.8 out of 10

Based on 45 frontline employees who took The Breakroom Quiz

139th of 247 rated software companies


Job description

The Meta Security team is responsible for improving the security posture of the software and services used throughout our company. Our work spans Facebook, Instagram, WhatsApp, Oculus, and all of the underlying systems and infrastructure that power these products behind the scenes.We are seeking a committed and experienced security engineer to join our Security Risk Management (SRM) team to help design and build solutions to:* Drive better understanding of security risk and enable investment decisions through automation, monitoring, and tracking of Meta’s security tools, systems, and controls* Enable security and software engineers to seamlessly respond to requests to prove effective design and operation of security capabilities* Increase maturity of security capabilities through control improvements and redesign
Security Engineer - Security Risk Management Responsibilities:
  • Work with a team of software, data, and security engineers that design, build, and own software solutions that scale high fidelity security risk contextualization, tracking, and reporting
  • Understand and influence evolution of security capabilities across various domains to scale and automate: a) monitoring the effectiveness, and b) increasing the maturity of those capabilities
  • Design and build solutions to scale managing and responding to risk management & compliance related requests

Minimum Qualifications:
  • Bachelor's degree in Computer Science, Information Security, or relevant field (or equivalent experience)
  • 5+ years work experience securing enterprise-scale infrastructure software and services
  • 3-5+ years programming experience with at least one of the following languages: Python, PHP, Ruby, or similar scripting languages
  • Experience remediating infrastructure security gaps across broad corporate boundaries using influence and relationships
  • Experience with security control automation/monitoring or “compliance as code” implementations
  • Experience thinking critically and defending solutions with communication skills in a cross-functional setting to influence decision makers across all levels of technical background

Preferred Qualifications:
  • Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
  • Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
  • Networking and system administration experience of server (Linux, Windows) and client (Windows, macOS, Linux) operating systems
  • Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
  • Experience with common risk & compliance program activities (e.g., controls, risk, policy management)
  • Experience generating automated metrics to measure service and program effectiveness and consistency
  • Experience influencing software engineers to build products meant to scale security solutions

About Meta:
Meta builds technologies that help people connect, find communities, and grow businesses. When Facebook launched in 2004, it changed the way people connect. Apps like Messenger, Instagram and WhatsApp further empowered billions around the world. Now, Meta is moving beyond 2D screens toward immersive experiences like augmented and virtual reality to help build the next evolution in social technology. People who choose to build their careers by building with us at Meta help shape a future that will take us beyond what digital connection makes possible today—beyond the constraints of screens, the limits of distance, and even the rules of physics.
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@meta.com.
$154,000/year to $217,000/year + bonus + equity + benefits
Individual compensation is determined by skills, qualifications, experience, and location. Compensation details listed in this posting reflect the base hourly rate, monthly rate, or annual salary only, and do not include bonus, equity or sales incentives, if applicable. In addition to base compensation, Meta offers benefits. Learn more about benefits at Meta.

What Meta employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom