The Lead Security, Risk and Compliance Specialist leads cross functional security initiatives and assists with representing the cybersecurity function with internal and external stakeholders.
The Lead Security, Risk and Compliance Specialist leads cross functional security initiatives and assists with representing the cybersecurity function with internal and external stakeholders.
The Lead Security, Risk and Compliance Specialist leads cross functional security initiatives and assists with representing the cybersecurity function with internal and external stakeholders.
The Lead Security, Risk and Compliance Specialist leads cross functional security initiatives and assists with representing the cybersecurity function with internal and external stakeholders.
Conduct comprehensive security risk assessments and gap analyses * Implement and maintain continuous monitoring solutions * Perform security control testing and validation * Develop and deliver ...
Conduct comprehensive security risk assessments and gap analyses * Implement and maintain continuous monitoring solutions * Perform security control testing and validation * Develop and deliver ...
Information Security Analyst - SME
Camp Springs, MD · On-site +1
Conduct comprehensive security risk assessments and gap analyses * Implement and maintain continuous monitoring solutions * Perform security control testing and validation * Develop and deliver ...
Information Security Analyst - SME
Camp Springs, MD · On-site +1
Conduct comprehensive security risk assessments and gap analyses * Implement and maintain continuous monitoring solutions * Perform security control testing and validation * Develop and deliver ...
Program Security Manager
Annapolis, MD · On-site
$127K - $155K/yr
Serve as the primary security, risk, and mission assurance advisor for sensitive programs and operational activities * Assess threats, vulnerabilities, and operational risks related to personnel ...
Program Security Manager
Annapolis, MD · On-site
$127K - $155K/yr
Serve as the primary security, risk, and mission assurance advisor for sensitive programs and operational activities * Assess threats, vulnerabilities, and operational risks related to personnel ...
... risk analysis and incident response. • Four (4) years experience applying security risk assessment methodology to system development, including threat model development, vulnerability assessments ...
... risk analysis and incident response. • Four (4) years experience applying security risk assessment methodology to system development, including threat model development, vulnerability assessments ...
Senior Information Systems Security Engineer (ISSE) with Security Clearance
Fort George G Meade, MD · On-site
$200K - $270K/yr
Apply RMF processes and security risk methodologies, including threat modeling and vulnerability assessments. * Collaborate with diverse technical teams while maintaining consistency through ...
Senior Information Systems Security Engineer (ISSE) with Security Clearance
Fort George G Meade, MD · On-site
$200K - $270K/yr
Apply RMF processes and security risk methodologies, including threat modeling and vulnerability assessments. * Collaborate with diverse technical teams while maintaining consistency through ...
Support the process of Privacy and Security by Design reviews, in particular, wherethey relate to ... Third-Party Risk Management: * Perform quality assurance and effective challenge of third-party ...
Support the process of Privacy and Security by Design reviews, in particular, wherethey relate to ... Third-Party Risk Management: * Perform quality assurance and effective challenge of third-party ...
Collaborate with executive leadership on security risk management, investment priorities, and incident response * Lead and write procedures on approving security exceptions,foreign travel,and ...
Collaborate with executive leadership on security risk management, investment priorities, and incident response * Lead and write procedures on approving security exceptions,foreign travel,and ...
Senior Microsoft Security Engineer
Adelphi, MD · On-site
$119K - $163K/yr
Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures. The Microsoft Senior ...
Senior Microsoft Security Engineer
Adelphi, MD · On-site
$119K - $163K/yr
Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures. The Microsoft Senior ...
Senior Microsoft Security Engineer
Adelphi, MD · On-site
$119K - $163K/yr
Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures. The Microsoft Senior ...
Senior Microsoft Security Engineer
Adelphi, MD · On-site
$119K - $163K/yr
Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures. The Microsoft Senior ...
Reporting to the Chief Information Security Officer, the Governance, Risk, and Compliance (GRC) Analyst manages the day-to-day operation of CareMetx's governance, risk, and compliance program. This ...
New
Reporting to the Chief Information Security Officer, the Governance, Risk, and Compliance (GRC) Analyst manages the day-to-day operation of CareMetx's governance, risk, and compliance program. This ...
New
Senior Information Systems Security Engineer (ISSE)
Fort George G Meade, MD · On-site
$200K - $270K/yr
Apply RMF processes and security risk methodologies, including threat modeling and vulnerability assessments. * Collaborate with diverse technical teams while maintaining consistency through ...
Senior Information Systems Security Engineer (ISSE)
Fort George G Meade, MD · On-site
$200K - $270K/yr
Apply RMF processes and security risk methodologies, including threat modeling and vulnerability assessments. * Collaborate with diverse technical teams while maintaining consistency through ...
The Risk Management Framework * Developing and maintaining SSPs * IAVA review and handling * Interpreting Security Scan results * Interfacing with System Administrators and Software Engineers * Task ...
The Risk Management Framework * Developing and maintaining SSPs * IAVA review and handling * Interpreting Security Scan results * Interfacing with System Administrators and Software Engineers * Task ...
The Risk Management Framework * Developing and maintaining SSPs * IAVA review and handling * Interpreting Security Scan results * Interfacing with System Administrators and Software Engineers * Task ...
The Risk Management Framework * Developing and maintaining SSPs * IAVA review and handling * Interpreting Security Scan results * Interfacing with System Administrators and Software Engineers * Task ...
Sr. Information System Security Engineer with Security Clearance
Columbia, MD · On-site
$104K - $142K/yr
... risk analysis • A Master's Degree in Computer Science or IT Engineering is desired and may be substituted for 6 years of experience • Knowledge of Federal, NSA, IC, and DoD Information Security ...
Sr. Information System Security Engineer with Security Clearance
Columbia, MD · On-site
$104K - $142K/yr
... risk analysis • A Master's Degree in Computer Science or IT Engineering is desired and may be substituted for 6 years of experience • Knowledge of Federal, NSA, IC, and DoD Information Security ...
Delegated Authorizing Official Representative (DAOR) - Level 3 with Security Clearance
Fort George G Meade, MD · On-site
$18.75 - $22.25/hr
THE OPPORTUNITY The Delegated Authorizing Official Representative (DAOR) supports the organization's Cybersecurity and risk management activities by identifying security requirements, evaluating ...
Delegated Authorizing Official Representative (DAOR) - Level 3 with Security Clearance
Fort George G Meade, MD · On-site
$18.75 - $22.25/hr
THE OPPORTUNITY The Delegated Authorizing Official Representative (DAOR) supports the organization's Cybersecurity and risk management activities by identifying security requirements, evaluating ...
This plan will include performing an internal security risk assessment and will focus on the operations and programs within the Decennial Directorate. In addition, this includes developing an ...
This plan will include performing an internal security risk assessment and will focus on the operations and programs within the Decennial Directorate. In addition, this includes developing an ...
Senior Cybersecurity Analyst / Information Security Manager - To with Security Clearance
Rockville, MD · On-site
$150K - $190K/yr
Document test results, risk assessments, and residual risk reports, and provide recommendations for ... Demonstrate expertise in Security Assessment and Authorization (SA&A), including NIST 800-37, NIST ...
Senior Cybersecurity Analyst / Information Security Manager - To with Security Clearance
Rockville, MD · On-site
$150K - $190K/yr
Document test results, risk assessments, and residual risk reports, and provide recommendations for ... Demonstrate expertise in Security Assessment and Authorization (SA&A), including NIST 800-37, NIST ...
This role partners closely with Security, Infrastructure, Risk, and Audit teams to reduce operational risk, maintain audit readiness, and deliver a stable, secure enduser computing platform.
This role partners closely with Security, Infrastructure, Risk, and Audit teams to reduce operational risk, maintain audit readiness, and deliver a stable, secure enduser computing platform.
Security Risk information
What is the difference between Security Risk vs Security Analyst?
| Aspect | Security Risk | Security Analyst |
|---|---|---|
| Required Credentials | Knowledge of security principles, risk assessment skills | Certifications like CompTIA Security+, CISSP, or CISA |
| Work Environment | Identifying potential threats, assessing vulnerabilities | Monitoring security systems, analyzing security data |
| Employer & Industry Usage | Used across industries to identify threats | Commonly employed in cybersecurity teams |
| Search & Comparison Intent | Understanding risk factors and mitigation | Analyzing security incidents and improving defenses |
Security Risk involves identifying and assessing potential threats to an organization, focusing on risk management strategies. Security Analysts, on the other hand, monitor and analyze security systems to detect and respond to threats. While both roles require security knowledge and certifications, Security Risk professionals focus on risk assessment, whereas Security Analysts are more involved in operational security monitoring.
What are security risk professionals?
Can you make $500,000 a year in cyber security?
Is 40 too old for cyber security?
What is the highest paying security job?
What are some common challenges faced by Security Risk professionals, and how can they overcome them?
What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?
Is security risk management a good career?

$162K/yr
Full-time
Medical, Dental, Vision, Retirement, PTO
Posted 24 days ago
Job description
California, US residentsclick here.
The job details are as follows:
Who We Are
We are the first publicly-traded biotech or pharmaceutical company to take the form of a public benefit corporation. Our public benefit purpose is to provide a brighter future for patients through the development of novel pharmaceutical therapies; and technologies that expand the availability of transplantable organs.
United Therapeutics (Nasdaq: UTHR) seeks to travel down the corridors of indifference to develop treatments for rare, deadly diseases. We were founded in 1996 by a family seeking a cure for their daughter's pulmonary arterial hypertension (PAH). Today, we have six FDA-approved therapies that treat PAH, pulmonary hypertension associated with interstitial lung disease (PH-ILD) and neuroblastoma, a rare pediatric cancer. Our near-term pipeline seeks to develop additional therapies for PAH and pulmonary fibrosis (PF).
The cure for end-stage life-threatening diseases like PAH, PH-ILD, PF, and many others is an organ transplant, but only a small percentage of donated organs are available to address the vast need. For this reason, we are working to create manufactured organs to address the shortage of kidneys, hearts, lungs, and livers available for transplant. We believe an unlimited supply of tolerable, transplantable organs will eliminate the transplant waiting list and cure end-stage organ diseases for which transplant is not currently an option.
Who you are
This role partners with senior management to safeguard intellectual property, protect critical manufacturing systems, ensure compliance with FDA regulations, and strengthen the cyber defense posture. The Lead Security, Risk and Compliance Specialist leads cross functional security initiatives and assists with representing the cybersecurity function with internal and external stakeholders.
- Support senior management in developing and executing the global cybersecurity strategy aligned to business, compliance, and manufacturing priorities
- Serve as the operational lead for enterprise security governance, risk management, and compliance programs across multiple regions and regulatory environments
- Drive adoption of security frameworks such as NIST CSF, NIST AI RMF, 21 CFR Part 11 and other industry specific requirements in alignment with organizational culture and risk appetite
- Partner with senior management to oversee outsourced MDR Security Operations Center (SOC), threat intelligence, incident response, investigations, security architecture and maintain cybersecurity regulatory/legal requirements
- Oversee development of advanced defense capabilities including zero trust architecture, identity security, and endpoint/OT protection
- Ensure successful delivery of security programs such as Identity and Access Management, Vulnerability Management and Cloud Security
- Partner with senior management to manage delivery of the IT Risk Management program. Direct IT risk assessments, manage IT risk register, supplier security evaluations, penetration testing and assist with audits across operations
- Partner with Legal, Privacy, Compliance, Information Technology, other key stake holders to ensure adherence to IT security and regulatory requirements
- Ensure AI risks are incorporated into the IT risk management program and are managed in accordance with the organization's risk appetite and culture
- Collaborate with OT and other key business leaders to embed security into product design, avionics systems, and industrial control systems
- Operationalize security programs for manufacturing, research and development, IoT and other life sciences technologies
- Ensure secure integration of IT/OT systems, ensure required availability and protection of proprietary intellectual property
- Mentor and develop technical teams
- All other duties as required
Minimum Requirements
- Bachelor's Degree in cybersecurity, computer science, or related field
- 8+ years of progressive experience in cybersecurity, including leadership roles in biotechnology/pharmaceutical organizations
- CISSP Certified Information Systems Security Professional
- Progressive experience in cybersecurity, including leadership roles in biotechnology/pharmaceutical organizations
- Experience securing OT/ICS environments and manufacturing systems
- Proven ability to lead teams, manage crises, and influence senior leaders and executives
- Ability to operate effectively in a high throughput, demanding, environment
- Familiarity with GxP (GMP, GCP, GLP) regulated systems and environments
- Ability to translate cybersecurity risk into business and scientific impact
- Experience supporting lab environments, OT/ICS, or manufacturing systems
- Strong background in program management, governance, and risk management
- Ability to manage cross-functional initiatives across IT, R&D, and Quality
- Build strong partnerships with all other business units
- Strong cross-functional coordination, the ability to communicate and escalate risk effectively, and the capacity to influence outcomes without direct authority.
Preferred Qualifications
- CISM - Certified Information Security Manager
- Strong knowledge of NIST, COSO, and other relevant frameworks
At United Therapeutics, our mission and vision are one. We use our enthusiasm, creativity, and persistence to innovate for the unmet medical needs of our patients and to benefit our other stakeholders. We are bold and unconventional. We have fun, we do good.
Eligible employees may participate in the Company's comprehensive benefits suite of programs, including medical / dental / vision / prescription coverage, employee wellness resources, savings plans (401k and ESPP), paid time off & paid parental leave benefits, disability benefits, and more. For additional information on Company benefits, please visit https://www.unither.com/careers/benefits-and-amenities
United Therapeutics Corporation is an Equal Opportunity Employer, including veterans and individuals with disabilities.
About United Therapeutics
Sourced by ZipRecruiter
Industry
Pharmaceutical and medicine manufacturing
Company size
501 - 1,000 Employees
Headquarters location
Silver Spring, MD, US
Year founded
1996