Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Risk Manager
$155K - $165K/yr
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
Quick apply
Risk Manager
$155K - $165K/yr
Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...
... to senior/executive leaders and cross-functional partners (IT, Information Security, Audit ... Risk Oversight Manager At Fifth Third, we understand the importance of recognizing our employees ...
... to senior/executive leaders and cross-functional partners (IT, Information Security, Audit ... Risk Oversight Manager At Fifth Third, we understand the importance of recognizing our employees ...
... to senior/executive leaders and cross-functional partners (IT, Information Security, Audit ... Risk Oversight Manager At Fifth Third, we understand the importance of recognizing our employees ...
... to senior/executive leaders and cross-functional partners (IT, Information Security, Audit ... Risk Oversight Manager At Fifth Third, we understand the importance of recognizing our employees ...
The Information Security Risk Oversight Professional serves as a key member of the Cybersecurity ... This position is intentionally designed for a senior, autonomous professional who can manage their ...
The Information Security Risk Oversight Professional serves as a key member of the Cybersecurity ... This position is intentionally designed for a senior, autonomous professional who can manage their ...
The Information Security Risk Oversight Professional serves as a key member of the Cybersecurity ... This position is intentionally designed for a senior, autonomous professional who can manage their ...
The Information Security Risk Oversight Professional serves as a key member of the Cybersecurity ... This position is intentionally designed for a senior, autonomous professional who can manage their ...
Information Security Risk Officer
Houston, TX Ā· On-site
... manages over $10 billion in client assets. With a state-of-the-art trust accounting system, the ... Responsibilities of the VP, Information Security Risk Officer: Strategic Leadership and Technology ...
Information Security Risk Officer
Houston, TX Ā· On-site
... manages over $10 billion in client assets. With a state-of-the-art trust accounting system, the ... Responsibilities of the VP, Information Security Risk Officer: Strategic Leadership and Technology ...
Be Seen First
We are seeking a Senior Information Security GRC & AI Governance Specialist to lead governance, risk, compliance, and AI assurance initiatives across the organization. "Also known as GRC Manager ...
New
Quick apply
Be Seen First
We are seeking a Senior Information Security GRC & AI Governance Specialist to lead governance, risk, compliance, and AI assurance initiatives across the organization. "Also known as GRC Manager ...
New
Sr. Mgr. Cybersecurity Risk
Newark, NJ Ā· On-site
In partnership with the CSO, CISO, CCO, and other senior leaders, this role regularly engages with ... The role collaborates closely with Information Security, Legal, Audit, Enterprise Risk Management ...
Sr. Mgr. Cybersecurity Risk
Newark, NJ Ā· On-site
In partnership with the CSO, CISO, CCO, and other senior leaders, this role regularly engages with ... The role collaborates closely with Information Security, Legal, Audit, Enterprise Risk Management ...
... senior leadership. CANDIDATE PROFILE Education and Experience Required: * Bachelor's degree in ... Risk and Information Systems Controls (CRISC), Certified Information Security Manager (CISM ...
New
... senior leadership. CANDIDATE PROFILE Education and Experience Required: * Bachelor's degree in ... Risk and Information Systems Controls (CRISC), Certified Information Security Manager (CISM ...
New
... senior leadership. CANDIDATE PROFILE Education and Experience Required: * Bachelor's degree in ... Risk and Information Systems Controls (CRISC), Certified Information Security Manager (CISM ...
New
... senior leadership. CANDIDATE PROFILE Education and Experience Required: * Bachelor's degree in ... Risk and Information Systems Controls (CRISC), Certified Information Security Manager (CISM ...
New
Overview Waters is seeking a driven and experienced Sr. Information Security Compliance and Risk ... Responsibilities Information Security Governance & Risk Management: * Lead and manage security ...
Overview Waters is seeking a driven and experienced Sr. Information Security Compliance and Risk ... Responsibilities Information Security Governance & Risk Management: * Lead and manage security ...
Be Seen First
Senior Information Security Lead
Sherman Oaks, CA Ā· On-site
$125K - $165K/yr
The Senior Information Security Lead is a handsāon senior individual contributor responsible for ... Vulnerability & Configuration Risk Management * Own the vulnerability management lifecycle using ...
Quick apply
Be Seen First
Senior Information Security Lead
Sherman Oaks, CA Ā· On-site
$125K - $165K/yr
The Senior Information Security Lead is a handsāon senior individual contributor responsible for ... Vulnerability & Configuration Risk Management * Own the vulnerability management lifecycle using ...
Senior Information Security Lead
Sherman Oaks, CA Ā· On-site
$111K - $150K/yr
The Senior Information Security Lead is a hands-on senior individual contributor responsible for ... Vulnerability & Configuration Risk Management * Own the vulnerability management lifecycle using ...
Senior Information Security Lead
Sherman Oaks, CA Ā· On-site
$111K - $150K/yr
The Senior Information Security Lead is a hands-on senior individual contributor responsible for ... Vulnerability & Configuration Risk Management * Own the vulnerability management lifecycle using ...
Company Description A Major International Bank in Midtown Manhattan is seeking an AVP of Information Security Risk Management. Fluency in Mandarin is required due to the nature of the Position/Client ...
Company Description A Major International Bank in Midtown Manhattan is seeking an AVP of Information Security Risk Management. Fluency in Mandarin is required due to the nature of the Position/Client ...
Security Risk Manager
San Francisco, CA Ā· On-site
Security Risk Manager Duration: 10 months Location: San Francisco CA(Hybrid) IMPORTANT: * Specifically, the company wants someone with adept experience in security risk management (not just third ...
Security Risk Manager
San Francisco, CA Ā· On-site
Security Risk Manager Duration: 10 months Location: San Francisco CA(Hybrid) IMPORTANT: * Specifically, the company wants someone with adept experience in security risk management (not just third ...
Information Security Risk and Governance Specialist, Senior
El Dorado Hills, CA Ā· On-site
$102K - $154K/yr
The Information Security Risk & Governance Specialist, Senior will report to the Senior Manager, Technology External Assurance. In this role, you will be a key individual contributor to the ...
Information Security Risk and Governance Specialist, Senior
El Dorado Hills, CA Ā· On-site
$102K - $154K/yr
The Information Security Risk & Governance Specialist, Senior will report to the Senior Manager, Technology External Assurance. In this role, you will be a key individual contributor to the ...
Lead Security Risk Manager
San Francisco, CA Ā· On-site +1
Bachelor's degree in Computer Science, Information Systems, Information Security, or a related ... Experience with risk management frameworks (RMF, ISO 27005, NIST 800-37, NIST 800-30) * Experience ...
Lead Security Risk Manager
San Francisco, CA Ā· On-site +1
Bachelor's degree in Computer Science, Information Systems, Information Security, or a related ... Experience with risk management frameworks (RMF, ISO 27005, NIST 800-37, NIST 800-30) * Experience ...
Information Security Risk Specialist
Bethesda, MD Ā· On-site
$62K - $141K/yr
Experience applying NIST Risk Management Framework (RMF) across categorization, control selection ... Experience communicating complex security concepts clearly to non-technical stakeholders and senior ...
Information Security Risk Specialist
Bethesda, MD Ā· On-site
$62K - $141K/yr
Experience applying NIST Risk Management Framework (RMF) across categorization, control selection ... Experience communicating complex security concepts clearly to non-technical stakeholders and senior ...
Senior Information Security Risk Manager information
See salary details
$22.5K - $39.5K
2% of jobs
$39.5K - $56.6K
2% of jobs
$56.6K - $73.6K
12% of jobs
$84K is the 25th percentile. Wages below this are outliers.
$73.6K - $90.7K
15% of jobs
$90.7K - $107.7K
16% of jobs
The median wage is $111.1K / yr.
$107.7K - $124.8K
16% of jobs
$139.9K is the 75th percentile. Wages above this are outliers.
$124.8K - $141.8K
14% of jobs
$141.8K - $158.9K
9% of jobs
$158.9K - $175.9K
10% of jobs
$175.9K - $193K
3% of jobs
$193K - $210K
2% of jobs
$22.5K
$118.3K
$210K
How much do senior information security risk manager jobs pay per year?
What are the key skills and qualifications needed to thrive as a Senior Information Security Risk Manager, and why are they important?
How does a Senior Information Security Risk Manager typically collaborate with other departments to mitigate risks?
What does a Senior Information Security Risk Manager do?
What is the difference between Senior Information Security Risk Manager vs Information Security Analyst?
| Aspect | Senior Information Security Risk Manager | Information Security Analyst |
|---|---|---|
| Certifications | CISSP, CISM, CRISC | CISSP, Security+, CEH |
| Work Environment | Risk management, policy development, strategic planning | Monitoring security systems, incident response, vulnerability assessment |
| Employer & Industry Usage | Financial, healthcare, large enterprises | IT departments, cybersecurity firms, government agencies |
The Senior Information Security Risk Manager focuses on identifying, assessing, and mitigating security risks at a strategic level, often managing policies and compliance. In contrast, the Information Security Analyst primarily monitors security systems, investigates incidents, and performs vulnerability assessments. Both roles require relevant certifications, but the Risk Manager's role is more strategic and managerial, while the Analyst's role is more technical and operational.

Job description
CVP is seeking an Cybersecurity Risk ManagerĀ for a large government agency enterprise-level cybersecurity program. The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency's CIO and CISO in cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security reporting; and other information security-related tasks.
Responsibilities- Identify, evaluate, and develop strategies for handling risks to reduce information security and privacy risk across the agency.
- Provide recommendations, guidance, planning, and implementation support for agency risk management activities and tools, and provide support as needed to enhance the agency's Information Security Program related to governance, optimizations, automation, and supporting tools.
- Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for Information Systems and Organizations and SP 800-39, Managing Information Security Risk (as revised).
- Conducting an enterprise risk assessment and developing an agency Information Security Risk Assessment Report that addresses all findings from the assessment
- Developing an agency Privacy and Security Roadmap that recommends privacy and information security capabilities based on risks identified in the agency's Information Security Risk Assessment Report
- Developing an agency Information Security Risk Management Plan that addresses how the agency will implement and perform risk management activities regarding risk tolerance, risk assessment, risk response, risk monitoring, and risk capabilities
- Providing risk management guidance to the agency offices for A&A activities as required, ensuring continuous risk monitoring of information security control implementation effectiveness and required information security compliance requirements
- Support the Information Security and Assurance Office (ISAO) in implementing and overseeing the organization's information security risk management and security assessment and authorization (A&A) activities.
- Advise the agency on how best to tailor the revised A&A process to handle non-traditional technologies including, but not limited to, cloud, mobile, and Internet of Things.
- Provide the agency recommendations on how it can continuously monitor and assess the security posture of agency information systems over time and alert agency decision makers when an information system presents an increased risk or eminent threat to agency data and/or operations.
- Develop guidance, templates, other tools, and advice to the program offices to support their risk management and ATO activities.
- Provide risk management and information security continuous monitoring program implementation recommendations to program offices
- Track and review Plans of Actions and Milestones (POA&Ms) agency-wide to identify areas of risk as a result of unimplemented POA&Ms, a buildup of risk-based decisions, or other cross-cutting issues observed as a result of its risk management support.
- Track the A&A status for all divisions and programs that have information systems to validate they meet the requirements to protect the agency's data and operations.
- Develop the required artifacts to complete security accreditation packages for OCIO information systems and perform any required assessments, as requested. The Contractor shall provide oversight and advisory support to agency program office personnel for completion of information system A&A packages, as requested.
- Follow NIST Federal Information Processing Standards (FIPS) and Special Publications (SPs) to include, but not limited to, FIPS 199 and 200, SP 800-39, SP 800-37, SP 800-137, SP 800-60, SP 800-53, SP 800-53A, SP 800-34, SP 800-30, and SP 800-18. The Contractor shall comply with all agency IT security and Privacy policies and standards including, and the agency Privacy Impact Assessment (PIA) requirements and associated templates.
- Minimum of six years' experience in cybersecurity. 10+ years' experience is preferred.
- Minimum of six years' experience leading and delivering in FISMA-based and FedRAMP Assessment and Authorization (A&A) programs for comparably sized federal agencies and programs. Seven plus years' experience is preferred.
- Shall have at least one of the following industry-recognized certifications:
- Certified Information System Security Professional (CISSP)
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- Familiarity with Information Technology Infrastructure Library (ITIL) Foundation Compliance (GRC) tool, continuous monitoring, and vulnerability management tools or services. Note: NIH currently uses CSAM.
- Demonstrated experience managing cybersecurity teams including personnel, workload, priorities, scheduling, and risks.
- Proven experience bringing innovative approaches to help reduce the FISMA workload and time to authorization/reauthorization through such methods as boundary consolidation, common control identification and re-use, automation, assessment readiness reviews, and digital transformation.
Desired Skills
- PMP Certification
- CISSP Certification
- Experience with Security Assessment Tools (Tenable Nessus, DBProtect, Wireshark, WebInspect)
- NIH/HHS experience
Location
- Rockville, MD (Hybrid)
Salary Band: $155-165k (Depending on experience)
About CVP
CVP is an award-winning healthcare and next-gen technology and consulting services firm solving critical problems for healthcare, national security, and public sector clients. We help organizations achieve lasting transformation.CVP is an Equal Opportunity Employer dedicated to actively recruiting individuals and providing advancement opportunities based on merit and legitimate job qualifications. We ensure that all associates receive equal opportunities based on their personal qualifications and job requirements. CVP strictly prohibits any form of discrimination or harassment.At CVP, we cultivate a work environment that encourages fairness, teamwork, and respect among all associated. We are committed to maintaining a workplace where everyone can grow both personally and professionally.
Employment Type: FULL_TIMEAbout Customer Value Partners
Sourced by ZipRecruiter
Company size
51 - 200 Employees
Headquarters location
Fairfax, VA, US
Year founded
2002