1

Security Risk Manager Jobs in Kentucky (NOW HIRING)

AI Risk Management: Apply AI risk management standards to assess and mitigate risks in AI pipelines.Mentor architects, engineers, and analysts in AI security best practices and contribute to the ...

Collaborate with Legal, Privacy, Procurement, and Vendor Risk Management teams to define security requirements and controls for AI vendors and service providers. * Review current internal ...

AI Security Engineer Senior Manager

Louisville, KY · On-site

$110K - $150K/yr

Embed Security into AI at Scale Ensure secure-by-design principles across the AI lifecycle ... Lead AI Risk & Governance Establish frameworks to manage AI-specific risks (e.g., model integrity ...

Business Risk Specialist

Owensboro, KY · On-site

$20 - $24.38/hr

The organization's risk management framework is designed to promote strong governance and effective ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...

Business Risk Specialist

Owensboro, KY · On-site

$20 - $24.38/hr

The organization's risk management framework is designed to promote strong governance and effective ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...

... Risk Managers, and key stakeholders to support a comprehensive risk management framework that ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...

... Risk Managers, and key stakeholders to support a comprehensive risk management framework that ... S. Department of Homeland Security E-Verify program in all facilities located in the United States ...

$41.75 - $55.75/hr

Quote from Hiring Manager: The IT Governance/Risk/Compliance Analyst position offers a dynamic ... Ensure data security and privacy compliance by providing guidance on appropriate access controls ...

Security Architect

Louisville, KY · On-site

$62.25 - $80.50/hr

We are currently seeking a Security Architect to shape and advance the firm's enterprise security architecture, lead the implementation of modern security frameworks and risk management initiatives ...

next page

Showing results 1-20

Security Risk Manager information

See Kentucky salary details

$12

$22

$45

How much do security risk manager jobs pay per hour?

As of Jul 21, 2026, the average hourly pay for security risk manager in Kentucky is $22.56, according to ZipRecruiter salary data. Most workers in this role earn between $15.87 and $25.48 per hour, depending on experience, location, and employer.

How much does a risk manager get paid?

A Security Risk Manager's average salary in the United States ranges from $80,000 to $130,000 annually, depending on experience, certifications, and industry. Senior roles or those with specialized skills can earn higher salaries, often exceeding $150,000. Compensation may also include bonuses and benefits related to security and risk management tools.

What is the difference between Security Risk Manager vs Security Analyst?

AspectSecurity Risk ManagerSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP (optional)
Work EnvironmentStrategic, managerial, policy-focusedOperational, monitoring, incident response
Employer & Industry UsageOrganizations with risk management frameworksIT departments, cybersecurity teams

The Security Risk Manager focuses on identifying, assessing, and mitigating security risks at a strategic level, often managing policies and frameworks. In contrast, the Security Analyst handles day-to-day security monitoring, incident response, and vulnerability assessments. Both roles require cybersecurity certifications, but the Risk Manager's role is more strategic, while the Analyst's role is more technical and operational.

What are some common challenges Security Risk Managers face when implementing new security policies within an organization?

Security Risk Managers often encounter challenges such as resistance to change from employees, balancing security needs with business operations, and ensuring compliance with industry regulations. Gaining buy-in from various stakeholders requires strong communication and education efforts, as some team members may perceive new protocols as disruptive. Additionally, Security Risk Managers must continuously assess evolving threats while adapting policies to keep the organization protected without hindering productivity.

What are the key skills and qualifications needed to thrive as a Security Risk Manager, and why are they important?

To thrive as a Security Risk Manager, you need a solid understanding of risk assessment, security protocols, and regulatory compliance, typically supported by a degree in cybersecurity, information security, or a related field. Familiarity with risk management frameworks (like ISO 27001 or NIST), security information and event management (SIEM) systems, and certifications such as CISSP or CISM are commonly required. Strong analytical thinking, communication, and leadership skills help you effectively identify vulnerabilities and collaborate with stakeholders. These competencies are crucial for proactively managing threats, ensuring organizational resilience, and maintaining regulatory compliance.

What is the highest salary for a risk manager?

The highest salary for a Security Risk Manager can exceed $150,000 annually, especially for those with extensive experience, advanced certifications like CISSP or CISM, and leadership roles in large organizations. Salaries vary based on industry, location, and the complexity of security environments managed.

What does a security risk manager do?

A security risk manager assesses and identifies potential security threats to an organization’s information systems and physical assets. They develop strategies, implement policies, and oversee security measures to mitigate risks, often using tools like risk assessment frameworks and security audits. Strong analytical skills and relevant certifications such as CISSP or CISM are typically required.

Can I make $200,000 a year in cyber security?

Security Risk Managers with extensive experience, advanced certifications, and specialized skills can potentially earn $200,000 or more annually, especially in high-demand industries or senior roles. Salary levels depend on factors such as location, company size, and individual expertise, with senior positions often offering higher compensation.
What cities in Kentucky are hiring for Security Risk Manager jobs? Cities in Kentucky with the most Security Risk Manager job openings:
Infographic showing various Security Risk Manager job openings in Kentucky as of July 2026, with employment types broken down into 84% Full Time, 14% Part Time, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $46,932 per year, or $22.6 per hour.
Senior IT Security Systems Analyst

Senior IT Security Systems Analyst

PPL Corporation

Louisville, KY • Hybrid

$43.25 - $57.75/hr

Other

Posted 12 days ago


PPL rating

6.8

Company rating: 6.8 out of 10

Based on 46 frontline employees who took The Breakroom Quiz

44th of 52 rated energy and utility


Job description

Company Summary Statement
As one of the largest investor-owned utility companies in the United States, PPL Corporation (NYSE: PPL), is committed to creating long-term, sustainable value for our 3.5 million customers, our shareowners and the communities we serve. Our high-performing regulated utilities - PPL Electric Utilities, Louisville Gas and Electric, Kentucky Utilities and Rhode Island Energy - provide an outstanding experience for our customers, consistently ranking among the best utilities in the nation. PPL's companies are also addressing challenges head-on by investing in new infrastructure and technology that is creating a smarter, more reliable and resilient energy grid. We are committed to doing our part to advance a cleaner energy future and drive innovation that enables us to achieve net-zero carbon emissions by 2050 while maintaining energy reliability and affordability for the customers and communities we serve. PPL is a positive force in the cities and towns where we do business, providing support for programs and organizations that empower the success of future generations by helping to build and maintain strong, diverse communities today.
Overview

NOTE:  This role is hybrid requiring 3 days a week onsite at one of our local offices in: Allentown, PA; Louisville, KY or Providence, RI.    #LI-Hybrid     #INDPPL

The IT Security Systems Analyst will leverage tools to perform vulnerability and threat monitoring. Investigates, responds to, and reports on network and security risks to PPL EU tools which include but are not limited to SIEM, NIDS/NIPS, and HIDS/HIPS suites. This position is required to do shift work. The Senior level performs assigned tasks under minimal guidance from supervisor.  Additionally, this role is responsible for supporting firewall security operations, including interpreting, reviewing, and assessing firewall rules for security risk, ensuring alignment with cybersecurity standards, and least privilege principles.


Responsibilities

Essential Functions:

  • Performs a variety of complex assignments (may lead some projects) and analyzes and solves complex problems in the below areas.
  • Network and Cyber Threat Monitoring:
    • Conduct ongoing review of multiple systems and sources to detect network access, network intrusion, information integrity, and NERC CIP compliance risks
    • Investigate network security events, conducting root-cause analysis to identify threats for recurring incidents
    • Monitor and track incidents related to network access, network intrusion, cybersecurity, and NERC CIP regulatory compliance
  • Corrective Actions:
    • Troubleshoot, diagnose network problems, and implement corrective action within prescribed guidelines to mitigate impact to business continuity
    • Support restoration of secure network services as quickly as possible while limiting business impact
    • Report network incidents, cybersecurity incidents, and NERC CIP compliance risks
    • Assist in minor network or system configuration changes to improve system security and meet NERC CIP compliance requirements
    • Recommend and implement firewall rule tuning or configuration changes to mitigate identified risks and improve security posture
    • Assist in firewall policy remediation efforts to address audit findings, compliance gaps, or identified vulnerabilities
    • Interpret, review, and analyze firewall rules to identify security risks, misconfigurations, overly permissive access, and compliance gaps
    • Perform risk-based reviews of firewall rule requests and existing rule sets to ensure adherence to security standards and least privilege access
    • Support firewall governance processes, including intake validation, rule lifecycle management (create/modify/remove), and periodic recertification activities
    • Conduct firewall rule reviews to identify redundant, shadowed, or unused rules and recommend remediation actions
    • Assess firewall configurations against security baselines and hardening standards to reduce attack surface
    • Collaborate with network, infrastructure, and OT teams to ensure firewall changes are properly designed, tested, and implemented with minimal business risk
    • Utilize firewall management and policy analysis tools (e.g., FireMon, AlgoSec) to evaluate rule effectiveness, policy compliance, and risk exposure
    • Support incident response efforts by analyzing firewall logs and rule behavior to determine potential threat activity or unauthorized access paths
    • Develop and maintain documentation related to firewall policies, standards, and review procedures
    • Performs other duties as assigned
    • Complies with all policies and standards

Qualifications

Required Experience:

  • Bachelor's degree and 5+ years of related work experience.
  • Deep knowledge and hands-on experience with enterprise firewall platforms, including Cisco ASA and Palo Alto Networks firewalls
  • Experience administering and managing Palo Alto Panorama for centralized firewall policy management
  • Familiarity with DLP, SIEM, NIDS/NIPS, HIDS/HIPS, and endpoint protection suite
  • Experience with firewall management, including rule lifecycle management, governance processes, and access control design
  • Strong understanding of firewall hardening practices, segmentation strategies, and least privilege network design
  • Ability to interpret complex firewall rule sets and translate findings into actionable security recommendations
  • Easily adapts to changing circumstances
  • Understands business goals and strategic priorities

Preferred Qualifications:

  • NERC CIP Compliance Analysis Certification, System Operator Certification, GIAC Critical Infrastructure Protection Security Certification
  • Possesses knowledge and understanding of specific testing tools (e.g., Windows automation tool)
  • Ability to establish and maintain the appropriate programs to recover the systems in the event of a disaster or security threat
  • Presents a creative approach to problems
  • Experience supporting fast-changing business organizations
Qualifications:

Required Experience:

  • Bachelor's degree and 5+ years of related work experience.
  • Deep knowledge and hands-on experience with enterprise firewall platforms, including Cisco ASA and Palo Alto Networks firewalls
  • Experience administering and managing Palo Alto Panorama for centralized firewall policy management
  • Familiarity with DLP, SIEM, NIDS/NIPS, HIDS/HIPS, and endpoint protection suite
  • Experience with firewall management, including rule lifecycle management, governance processes, and access control design
  • Strong understanding of firewall hardening practices, segmentation strategies, and least privilege network design
  • Ability to interpret complex firewall rule sets and translate findings into actionable security recommendations
  • Easily adapts to changing circumstances
  • Understands business goals and strategic priorities

Preferred Qualifications:

  • NERC CIP Compliance Analysis Certification, System Operator Certification, GIAC Critical Infrastructure Protection Security Certification
  • Possesses knowledge and understanding of specific testing tools (e.g., Windows automation tool)
  • Ability to establish and maintain the appropriate programs to recover the systems in the event of a disaster or security threat
  • Presents a creative approach to problems
  • Experience supporting fast-changing business organizations
Education:UNAVAILABLEEmployment Type: UNAVAILABLE

What PPL employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom