1

Security Risk Manager Jobs in Ohio (NOW HIRING)

Security Operations & Risk Management * Identify, document, and assess security events, risks, and vulnerabilities, including defining remediation recommendations and tracking action plans to closure.

Security Operations & Risk Management * Identify, document, and assess security events, risks, and vulnerabilities, including defining remediation recommendations and tracking action plans to closure.

As a Program Security Specialist, you will be responsible for identifying, analyzing, and ... Gather artifacts from the Program Managers of various divisions and branches within the Aerospace ...

Implement the overall risk management framework and processes, tools, and reporting methodologies ... Perform third party supplier risk assessments by reviewing contracts for compliance with security ...

Cybersecurity Risk Manager

Columbus, OH ยท On-site +1

$70K - $140K/yr

Work with business segment management to ensure that the overall risk function is effectively ... CISSP, CISM, CISA, GIAC, CIPP/US or other security/privacy certifications preferred but not ...

Cybersecurity Risk Manager

Columbus, OH ยท On-site +1

$70K - $140K/yr

Work with business segment management to ensure that the overall risk function is effectively ... CISSP, CISM, CISA, GIAC, CIPP/US or other security/privacy certifications preferred but not ...

Cybersecurity Risk Manager

Fairlawn, OH ยท On-site +1

$70K - $140K/yr

Work with business segment management to ensure that the overall risk function is effectively ... CISSP, CISM, CISA, GIAC, CIPP/US or other security/privacy certifications preferred but not ...

Cybersecurity Risk Manager

Fairlawn, OH ยท On-site +1

$70K - $140K/yr

Work with business segment management to ensure that the overall risk function is effectively ... CISSP, CISM, CISA, GIAC, CIPP/US or other security/privacy certifications preferred but not ...

Direct market or counterparty risk modeling experience preferred Experience with securitized ... management frameworks Experience in a regulated financial institution Ability to communicate ...

Experience with securitized products or corporate loans preferred * CFA or FRM designation * Knowledge of US regulatory market and counterparty risk management frameworks * Experience in a regulated ...

Experience with securitized products or corporate loans preferred * CFA or FRM designation * Knowledge of US regulatory market and counterparty risk management frameworks * Experience in a regulated ...

next page

Showing results 1-20

Security Risk Manager information

See Ohio salary details

$13

$24

$49

How much do security risk manager jobs pay per hour?

As of Jun 10, 2026, the average hourly pay for security risk manager in Ohio is $24.70, according to ZipRecruiter salary data. Most workers in this role earn between $17.36 and $27.88 per hour, depending on experience, location, and employer.

What is the difference between Security Risk Manager vs Security Analyst?

AspectSecurity Risk ManagerSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP (optional)
Work EnvironmentStrategic, managerial, policy-focusedOperational, monitoring, incident response
Employer & Industry UsageOrganizations with risk management frameworksIT departments, cybersecurity teams

The Security Risk Manager focuses on identifying, assessing, and mitigating security risks at a strategic level, often managing policies and frameworks. In contrast, the Security Analyst handles day-to-day security monitoring, incident response, and vulnerability assessments. Both roles require cybersecurity certifications, but the Risk Manager's role is more strategic, while the Analyst's role is more technical and operational.

What are some common challenges Security Risk Managers face when implementing new security policies within an organization?

Security Risk Managers often encounter challenges such as resistance to change from employees, balancing security needs with business operations, and ensuring compliance with industry regulations. Gaining buy-in from various stakeholders requires strong communication and education efforts, as some team members may perceive new protocols as disruptive. Additionally, Security Risk Managers must continuously assess evolving threats while adapting policies to keep the organization protected without hindering productivity.

What are the key skills and qualifications needed to thrive as a Security Risk Manager, and why are they important?

To thrive as a Security Risk Manager, you need a solid understanding of risk assessment, security protocols, and regulatory compliance, typically supported by a degree in cybersecurity, information security, or a related field. Familiarity with risk management frameworks (like ISO 27001 or NIST), security information and event management (SIEM) systems, and certifications such as CISSP or CISM are commonly required. Strong analytical thinking, communication, and leadership skills help you effectively identify vulnerabilities and collaborate with stakeholders. These competencies are crucial for proactively managing threats, ensuring organizational resilience, and maintaining regulatory compliance.

What does a Security Risk Manager do?

A Security Risk Manager is responsible for identifying, assessing, and mitigating security risks that could impact an organization. They develop and implement risk management policies, conduct security audits, and ensure compliance with relevant laws and standards. Security Risk Managers work closely with other departments to create strategies that protect assets, data, and personnel from potential threats. Their role is critical in helping organizations minimize losses and maintain business continuity.
Infographic showing various Security Risk Manager job openings in Ohio as of June 2026, with employment types broken down into 1% As Needed, 65% Full Time, 31% Part Time, 1% Temporary, and 2% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $51,372 per year, or $24.7 per hour.
GRC Analyst / Information Security

GRC Analyst / Information Security

MCPC

Cleveland, OH โ€ข On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 12 days ago


Job description

Title: Information Security Analyst

Department:Information Technology

Candidates must reside in NE Ohio

Position Summary: The Information Security Analyst is responsible for independently executing and supporting key components of MCPC's security, risk, and compliance program. This role reviews the organization's systems, facilities, processes, and departments to assess security posture and reduce risk across operations, systems, networks, data, and the endpoint lifecycle supply chain.

This position plays an active role in internal audits, policy development, risk management, access governance, and third-party risk management. The Information Security Analyst partners closely with IT, Operations, and business stakeholders and directly supports MCPC's commitment to protecting client data and maintaining trust by ensuring the confidentiality, integrity, and availability of information assets and services.

Responsibilities:

  1. Security Operations & Risk Management
    • Identify, document, and assess security events, risks, and vulnerabilities, including defining remediation recommendations and tracking action plans to closure.
    • Perform vulnerability and risk assessments and work with IT teams to drive remediation efforts, access reviews, and system hardening activities.
    • Monitor security alerts and events, contributing to the ongoing tuning and improvement of DLP, SIEM, SOAR, and EDR detections.
    • Evaluate emerging security threats and vulnerabilities and assess the effectiveness of existing security controls.
    • Support secure adoption of new technologies, including Artificial Intelligence solutions, by identifying risks and recommending appropriate safeguards.
    • Audits, Compliance & Policy
      • Plan and execute internal security audits of MCPC systems, processes, and facilities to identify control gaps, risks, and improvement opportunities.
      • Draft, review, and maintain information security policies, standards, and procedures aligned with industry best practices and regulatory requirements.
      • Act as a primary security point of contact for MCPC employees and external parties during audits, assessments, and security reviews.
      • Monitor and report on compliance with security awareness initiatives, phishing simulations, and related training programs.
      • Maintain and enhance MCPC's risk register, including risk analysis, prioritization, mitigation strategies, and progress tracking.
      • Vendor & Supply Chain Risk Management
        • Conduct security risk assessments for vendors and partners during onboarding and throughout the vendor lifecycle.
        • Evaluate third-party security controls, documentation, and attestations to identify and document risk.
        • Monitor vendors and partners for reported security incidents, events, and supply chain risks.
        • Support vendor risk management activities related to endpoint lifecycle management, IT asset management (ITAM), and IT asset disposition (ITAD) services.
        • Incident Response & Resilience
          • Maintain, document, and participate in testing of Incident Response, Disaster Recovery, and Business Continuity plans.
          • Participate in security incident response activities, including investigation, coordination, documentation, and post-incident reviews.
          • Provide recommendations to improve incident response readiness and operational resilience.
          • Program & Administrative Support
          • Collaborate with internal departments to ensure security requirements are embedded into operational and business processes.
          • Lead or contribute to security working sessions and document meeting agendas, decisions, and action items.
          • Contribute to continuous improvement initiatives across the MCPC Security Program.
          • Other tasks as assigned.

          Key Outcomes of this Position

          • The continuous improvement of MCPC's Security Program.
          • Be a member of a skilled, engaged, and forward-looking security team
          • Reduction in delta between vulnerability discovery and remediation
          • Measurable increase in items analyzed in MCPC's risk register

          Required Qualifications:

          • 2โ€“5 years of experience in Information Security, Risk Management, Compliance, Internal Audit, or Security Operations.
          • Bachelor's degree in Information Security, Information Technology, Computer Science, or a related field, or equivalent professional experience.
          • Working knowledge of:
            • Entra ID / Active Directory
            • SCCM / MECM / Intune
            • Patch and endpoint lifecycle management
            • CVSS vulnerability scoring and remediation prioritization
            • Data disposition standards such as NIST 800 88 and NAID AAA
          • Experience working with industry security frameworks such as AICPA SOC 2, ISO 27001, NIST, and CIS.
          • Strong written communication skills for audit reporting, policy drafting, and risk documentation.
          • Ability to communicate security concepts effectively to both technical and non technical audiences.
          • Proven ability to work independently and cross functionally with IT, Operations, and business teams.

            Preferred Qualifications:

          • Experience leading or independently executing internal security audits or assessments.
          • Hands-on experience with third-party risk management programs.
          • Professional certifications such as Security+, Azure Fundamentals, CRISC, CISA, or similar.

          Physical Requirements:

          • The physical requirements of this job include frequent sitting, occasionally walking around, carrying light objects, grasping, and reaching for things, rare stooping/crouching, clarity of vision, speaking and listening ability with or without reasonable accommodation.
          • Ability to occasionally drive or travel to MCPC's satellite offices in the Greater Cleveland Area, Grand Rapids Michigan, Erie PA, and Kansans City MO, and any other facility.

            Who We Are: At MCPC, we pride ourselves on being Outcome Engineers, delivering end-to-end solutions and expertise that empower businesses to thrive in the digital age. We combine top-tier services and cutting-edge technology solutions to solve complex business challenges, ensuring data security, cost efficiency, and seamless digital transformation. Our commitment to our clients requires providing quality people that allow us to excel at exceeding our clients' expectations. The MCPC employee experience is built on a foundation of collaboration, innovation, and growth. We offer the balance of a close-knit workforce and pathways for professional growth. Our team members are encouraged to bring their unique perspectives and ideas to the table. Join us and be part of a principled, quality-driven, respectful, and innovative team that values continuous improvement and community commitment. Together, we tackle today's challenges and pioneer solutions for tomorrow.

            Where We Are/Who We Serve: MCPC is a global organization, but we are headquartered in Cleveland, OH, with regional offices in Grand Rapids, MI and Erie, PA, which is a source of pride for everyone here at MCPC. MCPC has a longstanding culture of unwavering commitment to giving back to the communities we serve. (link to our blog)

            What We Do: Endpoint Lifecycle Management

            Advisory Services โ€“ MCPC is the go-to resource for all our client's end user device procurement and service needs. We help address tactical pain points that allow our clients' workforce to have a seamless and secure environment.

            Configuration and Integration โ€“ Custom solutions that fit within a client's endpoint environment. Ensuring new devices meet the requirements of the client and are ready to be deployed on day 1.

            IT Supply Chain โ€“ MCPC offers expert level supply chain services to help clients in the process of assembling, securing, managing, and delivering desk-ready IT inventory.

            Managed Deployment โ€“ Coordination of experienced IT technicians ensuring clients' devices, servers, data, and more are securely delivered, protected, and supported.

            Secure Technology Asset Disposition - Allows clients to remove old or outdated devices from their environment. Our facility will erase all data to Department of Defense standards and provide reverse logistics to the client as to whether their devices can be repurposed, recycled, or disposed of properly.

            Benefits & Appreciation:

          • 401k matching and ROTH option.
          • Company sponsored events (picnics, cookouts, and volunteering opportunities).
          • Competitive Medical, Dental and Vision package.
          • Company paid Holidays and Paid Time Off.
          • Career paths and advancement.


          This job description in no way states or implies that these are the only duties to be performed by the employee occupying this position. Employees will be required to follow any other job-related instructions and to perform other job-related duties requested by their supervisor.