Support the process of Privacy and Security by Design reviews, in particular, wherethey relate to ... Third-Party Risk Management: * Perform quality assurance and effective challenge of third-party ...
Support the process of Privacy and Security by Design reviews, in particular, wherethey relate to ... Third-Party Risk Management: * Perform quality assurance and effective challenge of third-party ...
Senior Information Systems Security Engineer (ISSE) with Security Clearance
Fort George G Meade, MD · On-site
$200K - $270K/yr
Apply RMF processes and security risk methodologies, including threat modeling and vulnerability assessments. * Collaborate with diverse technical teams while maintaining consistency through ...
Senior Information Systems Security Engineer (ISSE) with Security Clearance
Fort George G Meade, MD · On-site
$200K - $270K/yr
Apply RMF processes and security risk methodologies, including threat modeling and vulnerability assessments. * Collaborate with diverse technical teams while maintaining consistency through ...
Collaborate with executive leadership on security risk management, investment priorities, and incident response * Lead and write procedures on approving security exceptions,foreign travel,and ...
Collaborate with executive leadership on security risk management, investment priorities, and incident response * Lead and write procedures on approving security exceptions,foreign travel,and ...
Manager, Information Security
Brentwood, MD · On-site
$140 - $190/hr
Governance, Risk & Compliance * Own the organization's compliance posture for HIPAA, and applicable state/federal security regulations. * Conduct and maintain enterprise risk assessments ...
Manager, Information Security
Brentwood, MD · On-site
$140 - $190/hr
Governance, Risk & Compliance * Own the organization's compliance posture for HIPAA, and applicable state/federal security regulations. * Conduct and maintain enterprise risk assessments ...
Senior Microsoft Security Engineer
Adelphi, MD · On-site
$119K - $163K/yr
Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures. The Microsoft Senior ...
Senior Microsoft Security Engineer
Adelphi, MD · On-site
$119K - $163K/yr
Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures. The Microsoft Senior ...
Senior Microsoft Security Engineer
Adelphi, MD · On-site
$116 - $131/hr
Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures. The Microsoft Senior ...
Senior Microsoft Security Engineer
Adelphi, MD · On-site
$116 - $131/hr
Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures. The Microsoft Senior ...
Senior Microsoft Security Engineer
$119K - $163K/yr
Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures. The Microsoft Senior ...
Senior Microsoft Security Engineer
$119K - $163K/yr
Performs Security Risk Assessments (SRAs) and performs compliance reviews to ensure applications and servers are operating in accordance with established policies and procedures. The Microsoft Senior ...
Cybersecurity Risk & Authorization Engineer - DAOR 3 with Security Clearance
Fort George G Meade, MD · On-site
The DAOR supports enterprise Cybersecurity and risk management activities by identifying security requirements, evaluating and validating security controls, and ensuring systems meet federal ...
Cybersecurity Risk & Authorization Engineer - DAOR 3 with Security Clearance
Fort George G Meade, MD · On-site
The DAOR supports enterprise Cybersecurity and risk management activities by identifying security requirements, evaluating and validating security controls, and ensuring systems meet federal ...
Cybersecurity Governance and Risk Management (GRC) Lead
Laurel, MD · On-site
$165K - $210K/yr
Conduct security control assessments and risk analyses. * Review and maintain security authorization documentation. * Support implementation of NIST, FISMA, and agency cybersecurity requirements ...
Cybersecurity Governance and Risk Management (GRC) Lead
Laurel, MD · On-site
$165K - $210K/yr
Conduct security control assessments and risk analyses. * Review and maintain security authorization documentation. * Support implementation of NIST, FISMA, and agency cybersecurity requirements ...
Senior Information Systems Security Engineer (ISSE)
Fort George G Meade, MD · On-site
$200K - $270K/yr
Apply RMF processes and security risk methodologies, including threat modeling and vulnerability assessments. * Collaborate with diverse technical teams while maintaining consistency through ...
Senior Information Systems Security Engineer (ISSE)
Fort George G Meade, MD · On-site
$200K - $270K/yr
Apply RMF processes and security risk methodologies, including threat modeling and vulnerability assessments. * Collaborate with diverse technical teams while maintaining consistency through ...
The Risk Management Framework * Developing and maintaining SSPs * IAVA review and handling * Interpreting Security Scan results * Interfacing with System Administrators and Software Engineers * Task ...
The Risk Management Framework * Developing and maintaining SSPs * IAVA review and handling * Interpreting Security Scan results * Interfacing with System Administrators and Software Engineers * Task ...
The Risk Management Framework * Developing and maintaining SSPs * IAVA review and handling * Interpreting Security Scan results * Interfacing with System Administrators and Software Engineers * Task ...
The Risk Management Framework * Developing and maintaining SSPs * IAVA review and handling * Interpreting Security Scan results * Interfacing with System Administrators and Software Engineers * Task ...
Built Asset Security Advisor - SC
Salisbury, MD · Hybrid
£650 - £681.16/day
Lead and support security risk assessments, threat analyses, and vulnerability studies for high-risk environments. Develop, review, and assure security design documentation, including protective ...
Built Asset Security Advisor - SC
Salisbury, MD · Hybrid
£650 - £681.16/day
Lead and support security risk assessments, threat analyses, and vulnerability studies for high-risk environments. Develop, review, and assure security design documentation, including protective ...
Senior Information Systems Security Engineer (Sr. ISSE)
Linthicum, MD · On-site
$200 - $270/hr
Apply RMF processes and security risk methodologies, including threat modeling and vulnerability assessments. * Collaborate with diverse technical teams while maintaining consistency through ...
Senior Information Systems Security Engineer (Sr. ISSE)
Linthicum, MD · On-site
$200 - $270/hr
Apply RMF processes and security risk methodologies, including threat modeling and vulnerability assessments. * Collaborate with diverse technical teams while maintaining consistency through ...
Delegated Authorizing Official 3 with Security Clearance
Annapolis Junction, MD · On-site
$17.25 - $20.50/hr
... risk analysis, risk management process, security control assessments, and awareness activities for systems and networking operations. Provide assistance to ensure Cybersecurity functions are ...
Delegated Authorizing Official 3 with Security Clearance
Annapolis Junction, MD · On-site
$17.25 - $20.50/hr
... risk analysis, risk management process, security control assessments, and awareness activities for systems and networking operations. Provide assistance to ensure Cybersecurity functions are ...
This plan will include performing an internal security risk assessment and will focus on the operations and programs within the Decennial Directorate. In addition, this includes developing an ...
This plan will include performing an internal security risk assessment and will focus on the operations and programs within the Decennial Directorate. In addition, this includes developing an ...
Senior Cybersecurity Analyst / Information Security Manager - To with Security Clearance
Rockville, MD · On-site
$150K - $190K/yr
Document test results, risk assessments, and residual risk reports, and provide recommendations for ... Demonstrate expertise in Security Assessment and Authorization (SA&A), including NIST 800-37, NIST ...
Senior Cybersecurity Analyst / Information Security Manager - To with Security Clearance
Rockville, MD · On-site
$150K - $190K/yr
Document test results, risk assessments, and residual risk reports, and provide recommendations for ... Demonstrate expertise in Security Assessment and Authorization (SA&A), including NIST 800-37, NIST ...
Identity / Risk Management Specialist (Tech Ops) (Mission Assura with Security Clearance
Fort George G Meade, MD · On-site
$82K - $145K/yr
Establishes and maintains operational security risk management strategies, including defining security requirements, performing risk assessments, and implementing proactive solutions to mitigate ...
Identity / Risk Management Specialist (Tech Ops) (Mission Assura with Security Clearance
Fort George G Meade, MD · On-site
$82K - $145K/yr
Establishes and maintains operational security risk management strategies, including defining security requirements, performing risk assessments, and implementing proactive solutions to mitigate ...
Security Analyst
Columbia, MD · Hybrid
$55 - $60/hr
Description Position Overview The Information Security Analyst II (GRC) provides support for ... The role supports risk assessments, audit readiness, control validation, and policy governance.
New
Security Analyst
Columbia, MD · Hybrid
$55 - $60/hr
Description Position Overview The Information Security Analyst II (GRC) provides support for ... The role supports risk assessments, audit readiness, control validation, and policy governance.
New
Security Analyst
Columbia, MD · Hybrid
$55 - $60/hr
Description Position Overview The Information Security Analyst II (GRC) provides support for ... The role supports risk assessments, audit readiness, control validation, and policy governance.
New
Security Analyst
Columbia, MD · Hybrid
$55 - $60/hr
Description Position Overview The Information Security Analyst II (GRC) provides support for ... The role supports risk assessments, audit readiness, control validation, and policy governance.
New
Security Risk information
What is a security risk professional?
What are the key skills and qualifications needed to thrive as a security risk analyst, and why are they important?
What are some common challenges faced by security risk professionals, and how can they overcome them?
What is the difference between Security Risk vs Security Analyst?
| Aspect | Security Risk | Security Analyst |
|---|---|---|
| Required Credentials | Knowledge of security principles, risk assessment skills | Certifications like CompTIA Security+, CISSP, or CISA |
| Work Environment | Identifying potential threats, assessing vulnerabilities | Monitoring security systems, analyzing security data |
| Employer & Industry Usage | Used across industries to identify threats | Commonly employed in cybersecurity teams |
| Search & Comparison Intent | Understanding risk factors and mitigation | Analyzing security incidents and improving defenses |
Security Risk involves identifying and assessing potential threats to an organization, focusing on risk management strategies. Security Analysts, on the other hand, monitor and analyze security systems to detect and respond to threats. While both roles require security knowledge and certifications, Security Risk professionals focus on risk assessment, whereas Security Analysts are more involved in operational security monitoring.
What is a security risk officer?
What are popular job titles related to Security Risk jobs in Maryland?
For Security Risk jobs in Maryland, the most frequently searched job titles are:
What job categories do people searching Security Risk jobs in Maryland look for?
The top searched job categories for Security Risk jobs in Maryland are:

Full-time
Re-posted 13 days ago
T. Rowe Price rating
9.1
Based on 21 frontline employees who took The Breakroom Quiz
Job description
Role Summary
The Senior Risk Analyst - Privacy &ThirdPartyRisk is aSecond Line of Defense (2LoD)role and a member of theGlobal Privacy Office (GPO)andThirdPartyRisk Management (TPRM)function. The role provides independent risk oversight, effective challenge, and assurance over first-line activities andoutsourced TPRM services,operatingwithminimal supervisionand a high degree of professional judgment.
This position is expected to independently manage complex risk assessments, lead oversight activities,identifyemerging risk themes, and deliver clear, actionable insights to senior stakeholders and governance committees.
Responsibilities
Privacy Risk- Global Privacy Office:
- Independently provide 2LoD oversight of privacy risks arising from first-line business activitiesand serveas a subject matter resource on privacy risk matters.
- Lead review andchallengeofPrivacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), and privacy risk assessments.
- Evaluate the design and operating effectiveness of privacy controls and recommend enhancements aligned with regulatory expectations and risk appetite.
- Independently review privacy incidents, including root cause analyses and remediation plans.
- Provide technicalexpertiseandsupportthe implementation of privacy and data protection processes, controls, and procedures based on enterprise-wide guidance issued by the Global Privacy Office.
- Support the process of Privacy and Security by Design reviews, in particular, wherethey relate to the development and deployment of new technologies.This includes reviewing technical implementation details and design documentation for new systems andfeatures, andproviding guidance on improving privacy features in
- those systems.
- Collaborate with technology and security teams to embed privacy controls into the architecture of products and services, including providing advice and best practices to protect and mitigate privacy risks.
- Identifyopportunities to enhance the Global Privacy Office's technical capabilities, develop,testand work with technology teams to deploy such capabilities.
- Support the maintenance of the firm's required privacy compliance documentation (e.g., Records of Processing Activities, Transfer Impact Assessments, procedures, guides, training, SharePoint sites).
- Support the execution of the privacy compliance monitoring program.
Third-Party Risk Management:
- Perform quality assurance and effective challenge of third-party risk outputs produced by external service providers and first-line stakeholders.
- Monitor adherence to SLAs, KPIs, and contractual obligations of outsourced TPRM providers and escalate deficiencies asappropriate.
- Identifysystemic control gaps, concentration risk, and emerging third-party risk trends across the vendor population.
- Support thirdparty cyber and information security risk review activities.
- Contribute to the ongoing development of fourth-party risk governance and oversight practices.
- Identifyopportunities to enhanceTRPM's technical capabilities, develop,testand work with technology teams to deploy such capabilities.
- Support the maintenance of the firm's requiredTPRMcompliance documentation (e.g.,Policy, Supplier Management Standards, questionnaire templates, frameworks, training, Share Point sites).
Risk Governance, Reporting & Analytics:
- Independently develop and deliver executive-level risk reporting, dashboards, and management information.
- Assistwith monitoring and reporting emerging AI and technology risks across privacy andthird partyrisk, contributing to oversight of controls, assessments, and reporting.
- Leverage AI-enabled tools and advanced analytics toidentifytrends, emerging risks, and control weaknesses.
- Lead preparation for regulatory examinations, internal audits, and management assurance activities related to privacy and third-party risk oversight.
- Maintainaccurate, complete documentation in GRC, privacy, and TPRM systems and ensure audit-ready artifacts.
Qualifications
Required:
- Bachelor's degree in Risk Management, Information Systems, Finance, Business, Law, ora relatedfield.
- 5+ years of experience insecond-line risk management, privacy risk, or third-party risk oversight, preferably within financial services or asset management(or other industry subject to equivalent regulatory scrutiny).
- Demonstrated ability tooperateindependently with minimal guidance in a 2LoD environment.
- In-depth knowledge of global privacy regulations andoutsourced TPRM operating models.
- Required Certifications (at least one):
- Certified Information Privacy Professional (CIPP/US, CIPP/E)
- Certified Information Systems Auditor (CISA)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Third Party Risk Professional (CTPP)
Preferred:
- Experience leading or independently managing 2LoD privacy or TPRM oversight activities.
- Asset management or broader financial services experience.
- Additionalcertifications:
- CIPM or CIPT
- ISO 27001 Lead Implementer or Auditor
- Familiarity with SEC, FINRA, and global regulatory expectations.
Tools & Technology (Preferred)
- Advanced experience with GRC, privacy, and TPRM platforms (e.g., Archer, ServiceNow, OneTrust,IBM OpenPages).
- Strongproficiencywith reporting and analytics tools (e.g., Power BI, advanced Excel).
- Practical experience using AI-enabled risk, compliance, or data analytics tools to enhance oversight and reporting(e.g., Microsoft Co-Pilot, ChatGPT Enterprise).
- Ability to automate reporting and improve risk visibility.
Key Competencies
- Strong independent judgment and risk-based decision-making.
- Ability to provide credible, effectivechallengeat senior levels.
- Excellent written and verbal communication skills.
- Strong issue management, quality assurance, and governance discipline.
- Comfortoperatingautonomously in a global, regulated environment.
FINRA Requirements
FINRA licenses are not required and will not be supported for this role.
Work Flexibility
This role is eligible for hybrid work, with up to one day per week from home.
What T. Rowe Price employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About T. Rowe Price
Sourced by ZipRecruiter
Industry
Funds, trusts and financial programs
Company size
5,001 - 10,000 Employees
Headquarters location
Baltimore, MD, US
Year founded
1937