1

Security Risk Manager Jobs in Arizona (NOW HIRING)

Information Security * Enterprise Risk and Governance Functions The role requires strong ... Experience in technology risk management, operational risk, compliance, controls, governance, audit ...

next page

Showing results 1-20

Security Risk Manager information

See Arizona salary details

$12

$24

$48

How much do security risk manager jobs pay per hour?

As of Jul 21, 2026, the average hourly pay for security risk manager in Arizona is $24.21, according to ZipRecruiter salary data. Most workers in this role earn between $17.02 and $27.31 per hour, depending on experience, location, and employer.

How much does a risk manager get paid?

A Security Risk Manager's average salary in the United States ranges from $80,000 to $130,000 annually, depending on experience, certifications, and industry. Senior roles or those with specialized skills can earn higher salaries, often exceeding $150,000. Compensation may also include bonuses and benefits related to security and risk management tools.

What is the difference between Security Risk Manager vs Security Analyst?

AspectSecurity Risk ManagerSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP (optional)
Work EnvironmentStrategic, managerial, policy-focusedOperational, monitoring, incident response
Employer & Industry UsageOrganizations with risk management frameworksIT departments, cybersecurity teams

The Security Risk Manager focuses on identifying, assessing, and mitigating security risks at a strategic level, often managing policies and frameworks. In contrast, the Security Analyst handles day-to-day security monitoring, incident response, and vulnerability assessments. Both roles require cybersecurity certifications, but the Risk Manager's role is more strategic, while the Analyst's role is more technical and operational.

What are some common challenges Security Risk Managers face when implementing new security policies within an organization?

Security Risk Managers often encounter challenges such as resistance to change from employees, balancing security needs with business operations, and ensuring compliance with industry regulations. Gaining buy-in from various stakeholders requires strong communication and education efforts, as some team members may perceive new protocols as disruptive. Additionally, Security Risk Managers must continuously assess evolving threats while adapting policies to keep the organization protected without hindering productivity.

What are the key skills and qualifications needed to thrive as a Security Risk Manager, and why are they important?

To thrive as a Security Risk Manager, you need a solid understanding of risk assessment, security protocols, and regulatory compliance, typically supported by a degree in cybersecurity, information security, or a related field. Familiarity with risk management frameworks (like ISO 27001 or NIST), security information and event management (SIEM) systems, and certifications such as CISSP or CISM are commonly required. Strong analytical thinking, communication, and leadership skills help you effectively identify vulnerabilities and collaborate with stakeholders. These competencies are crucial for proactively managing threats, ensuring organizational resilience, and maintaining regulatory compliance.

What is the highest salary for a risk manager?

The highest salary for a Security Risk Manager can exceed $150,000 annually, especially for those with extensive experience, advanced certifications like CISSP or CISM, and leadership roles in large organizations. Salaries vary based on industry, location, and the complexity of security environments managed.

What does a security risk manager do?

A security risk manager assesses and identifies potential security threats to an organization’s information systems and physical assets. They develop strategies, implement policies, and oversee security measures to mitigate risks, often using tools like risk assessment frameworks and security audits. Strong analytical skills and relevant certifications such as CISSP or CISM are typically required.

Can I make $200,000 a year in cyber security?

Security Risk Managers with extensive experience, advanced certifications, and specialized skills can potentially earn $200,000 or more annually, especially in high-demand industries or senior roles. Salary levels depend on factors such as location, company size, and individual expertise, with senior positions often offering higher compensation.
What cities in Arizona are hiring for Security Risk Manager jobs? Cities in Arizona with the most Security Risk Manager job openings:
Infographic showing various Security Risk Manager job openings in Arizona as of July 2026, with employment types broken down into 88% Full Time, 11% Part Time, and 1% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $50,356 per year, or $24.2 per hour.
Principal Technology Risk Management - Data Security

Principal Technology Risk Management - Data Security

Early Warning Services, LLC

Scottsdale, AZ • On-site

Other

Medical, Dental, Vision, Retirement, PTO

Re-posted 12 days ago


Job description

At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle , Paze , and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Job Description
Overall Purpose
Provides independent second-line oversight, assessment, and credible challenge of first-line technology risk management activities across the company. Partners across Technology, Security, Product, Data, and other business functions to evaluate risk and control practices, including risk assessments, issues management, control validation, key risk indicators, governance reporting, and escalation. Helps ensure technology-related risks are managed consistent with enterprise risk appetite, regulatory expectations, and sound industry practice. May support one or more focus areas based on business need, including Enterprise Technology Risk, Data Security Risk, Access Management Risk, Offensive Security Risk, Vulnerability Management Risk, AI Security Risk, and Asset and Inventory Management Risk.
Essential Functions
  • Provide independent review, oversight, and credible challenge of first-line technology risk management activities, controls, and decisions.
  • Evaluate the design and execution of risk management practices to ensure alignment with enterprise frameworks, policies, regulatory expectations, and relevant industry standards.
  • Provide independent challenge and oversight of risk identification and assessment activities.
  • Review and challenge risk and control self-assessments, issues management, remediation plans, control validation outcomes, and key risk indicators.
  • Assess the adequacy of severity ratings, root cause analyses, action plans, and closure evidence for technology-related issues and risk events.
  • Identify risk trends, concentrations, and emerging themes through analysis of risk data, governance materials, and business changes; develop an independent view of risk exposure and control effectiveness.
  • Prepare and support reporting, escalation, and discussion materials for senior leaders, governance forums, and risk committees.
  • Partner with first-line leaders, subject matter experts, and independent testing or validation teams to improve clarity of control expectations, testing scope, and evidence requirements.
  • Provide ongoing risk advisory support while maintaining second-line independence and accountability for effective challenge.
  • Recommend opportunities to strengthen risk awareness, governance routines, and training that improve technology risk management maturity.
  • Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.

Focus: Enterprise Technology and Information Security Risk
  • Provide independent challenge and oversight of technology risk management practices across infrastructure, cloud, cybersecurity, product, and operational technology domains.
  • Provide independent challenge and oversight of information security risk management practices across threat management, network, endpoint, cloud, architecture, data, access, AI, or application security domains.
  • Assess alignment of technology risk and control activities to enterprise policies, risk frameworks, and applicable industry standards.
  • Evaluate whether risk assessments, control inventories, issues management, and key risk indicators are executed consistently and effectively across the technology organization.
  • Challenge risk identification activities related to significant technology changes, new products or capabilities, and cross-functional initiatives.
  • Assess risk trends and systemic themes across the technology environment and provide independent reporting and escalation as needed.

Minimum Qualifications
  • Education and/or experience typically obtained through completion of a Bachelor's degree or equivalent.
  • Typically has 12 years of experience or demonstrated portfolio consistent with experience required of the role in technology risk, information security, operational risk, or related disciplines within a regulated or otherwise complex operating environment.
  • Strong understanding of risk management practices, control frameworks, and second-line oversight within a three lines of defense model.
  • Demonstrated experience providing independent review, challenge, or governance of first-line technology, security, data, or operational risk activities.
  • Strong ability to assess control design and effectiveness, synthesize risk data, identify themes, and translate technical issues into business risk.
  • Excellent written, verbal, presentation, and stakeholder management skills, including experience interacting with senior leaders and cross-functional partners.
  • Strong critical thinking, judgment, and problem-solving skills, with the ability to provide practical, risk-based recommendations in a complex environment.
  • Ability to operate independently, manage competing priorities, and maintain effective working relationships while preserving second-line objectivity.
  • Background and drug screen.

Preferred Qualifications
  • Advanced degree or additional related education and/or experience preferred.
  • Experience in financial services, payments, fintech, or another highly regulated industry.
  • Familiarity with relevant regulatory expectations and industry standards and frameworks applicable to technology and security risk management such as; ISO 27002, PCI DSS, NIST, FFIEC, and SOC 2.
  • Experience supporting governance committees, audits, examinations, or regulatory interactions.
  • Relevant risk, security, audit, or control certifications preferred such as CISA, CISM, CISSP, CCSP, CRISC, GSNA, CGIH, or equivalent preferred.
  • Project or process management experience supporting cross-functional risk, control, or governance initiatives preferred.

The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.
Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.
Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.
The base pay scale for this position in:
Phoenix, AZ/ Chicago, IL / Washington, DC in USD per year is: $184,000 - $230,000.
New York, NY/ San Francisco, CA in USD per year is: $221,000 - $276,000.
Additionally, candidates are eligible for a discretionary incentive plan and benefits.
This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate's education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers). The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.
#Dice
#LI-AV
Some of the Ways We Prioritize Your Health and Happiness
  • Healthcare Coverage -Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
  • 401(k) Retirement Plan -Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
  • Paid Time Off - Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
  • 12 weeks of Paid Parental Leave
  • Maven Family Planning - provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.

And SO much more! We continue to enhance our program, so be sure to check our Benefits page here for the latest. Our team can share more during the interview process!
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Early Warning Services, LLC ("Early Warning") considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.