This role combines deep expertise in cyber risk, control design, CRI Profile maturity, and policy management with a strong understanding of modern engineering practices, data, automation, and AI ...
This role combines deep expertise in cyber risk, control design, CRI Profile maturity, and policy management with a strong understanding of modern engineering practices, data, automation, and AI ...
... management. * Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance ...
... management. * Experience supporting governance, risk, and compliance workflows, including risk reporting, audit data requests, controls monitoring, controls testing, compliance metrics, governance ...
Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using proven methodologies and tools in a consistent manner. Our ...
Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using proven methodologies and tools in a consistent manner. Our ...
Risk Manager - Insurance
$110K - $145K/yr
Risk Manager - Insurance Fully Remote: applicants in Eastern or Central Time Zone Supporting ... Conduct comprehensive risk evaluations across property, casualty, liability, professional, cyber ...
Risk Manager - Insurance
$110K - $145K/yr
Risk Manager - Insurance Fully Remote: applicants in Eastern or Central Time Zone Supporting ... Conduct comprehensive risk evaluations across property, casualty, liability, professional, cyber ...
Through powerful solutions and managed services that simplify complexity, we enable our clients to ... Oversee the delivery of ServiceNow-based cyber risk solutions, ensuring alignment with best ...
Through powerful solutions and managed services that simplify complexity, we enable our clients to ... Oversee the delivery of ServiceNow-based cyber risk solutions, ensuring alignment with best ...
Cyber Data Protection Manager
Columbus, OH · Remote
$107K - $144K/yr
If so, consider joining Deloitte & Touche LLP's growing Cyber Risk Digital Trust & Privacy practice ... Manage and lead the proposal development process * Contribute to Deloitte's thought leadership in ...
Cyber Data Protection Manager
Columbus, OH · Remote
$107K - $144K/yr
If so, consider joining Deloitte & Touche LLP's growing Cyber Risk Digital Trust & Privacy practice ... Manage and lead the proposal development process * Contribute to Deloitte's thought leadership in ...
Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship opportunities may be available Additional ...
Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship opportunities may be available Additional ...
Through solutions and managed services that simplify complexity, we help clients operate with resilience, grow with confidence, and proactively manage cyber, risk, and technology programs. Recruiting ...
Through solutions and managed services that simplify complexity, we help clients operate with resilience, grow with confidence, and proactively manage cyber, risk, and technology programs. Recruiting ...
Consultant - ServiceNow
Columbus, OH · Remote
Through solutions and managed services that simplify complexity, we help clients operate with resilience, grow with confidence, and proactively manage cyber, risk, and technology programs. Recruiting ...
Consultant - ServiceNow
Columbus, OH · Remote
Through solutions and managed services that simplify complexity, we help clients operate with resilience, grow with confidence, and proactively manage cyber, risk, and technology programs. Recruiting ...
Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using proven methodologies and tools in a consistent manner. Our ...
Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using proven methodologies and tools in a consistent manner. Our ...
Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using proven methodologies and tools in a consistent manner. Our ...
Our Cyber Risk practice helps organizations with the management of information and technology risks by delivering end-to-end solutions using proven methodologies and tools in a consistent manner. Our ...
Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
Business continuity management * Familiarity with industry standards and regulatory requirements around cyber risk management (e.g., ISO 27001, IEC 62443, NIST CSF) * Limited sponsorship ...
Qualifications Required: * 6+ years of experience in technical consulting, cyber risk, data ... Work you'll do As an Engineering Manager II on the Cyber team, you will be responsible for.
Qualifications Required: * 6+ years of experience in technical consulting, cyber risk, data ... Work you'll do As an Engineering Manager II on the Cyber team, you will be responsible for.
Cloud Security Senior Consultant - M365
Columbus, OH · On-site
$56.50 - $77/hr
Acting as a subject matter expert on cloud cyber risk for Microsoft Purview, Microsoft Intune ... Through powerful solutions and managed services that simplify complexity, we enable our clients to ...
Cloud Security Senior Consultant - M365
Columbus, OH · On-site
$56.50 - $77/hr
Acting as a subject matter expert on cloud cyber risk for Microsoft Purview, Microsoft Intune ... Through powerful solutions and managed services that simplify complexity, we enable our clients to ...
Through powerful solutions and managed services that simplify complexity, we enable our clients to ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Through powerful solutions and managed services that simplify complexity, we enable our clients to ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
VP, Cybersecurity & Technology Risk Officer
$151K - $189K/yr
This role is particularly well-suited to a candidate with both technical depth, risk management ... Fraudulent job postings may be used by cyber criminals to target your personally identifiable ...
VP, Cybersecurity & Technology Risk Officer
$151K - $189K/yr
This role is particularly well-suited to a candidate with both technical depth, risk management ... Fraudulent job postings may be used by cyber criminals to target your personally identifiable ...
Cyber Data Protection/PKI Manager
Columbus, OH · On-site
$107K - $144K/yr
Work you'll do As a Manager, Strategy, Growth, and Transformation on the Cyber Strategy ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Cyber Data Protection/PKI Manager
Columbus, OH · On-site
$107K - $144K/yr
Work you'll do As a Manager, Strategy, Growth, and Transformation on the Cyber Strategy ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Cloud Security Manager - Azure Infrastructure & AI
Columbus, OH · On-site
$63.25 - $84/hr
Leading Azure cloud cyber risk engagements across governance, identity, application security ... Managing project delivery activities across onshore and offshore teams, including solution design ...
Cloud Security Manager - Azure Infrastructure & AI
Columbus, OH · On-site
$63.25 - $84/hr
Leading Azure cloud cyber risk engagements across governance, identity, application security ... Managing project delivery activities across onshore and offshore teams, including solution design ...
Cyber Manager - ServiceNow
Columbus, OH · On-site
$107K - $144K/yr
As a Cyber Manager - ServiceNow, you will lead the delivery of multi-workstream ServiceNow programs ... Risk Management workstreams in partnership with architects and product owners • Managing ...
Cyber Manager - ServiceNow
Columbus, OH · On-site
$107K - $144K/yr
As a Cyber Manager - ServiceNow, you will lead the delivery of multi-workstream ServiceNow programs ... Risk Management workstreams in partnership with architects and product owners • Managing ...
Cyber Risk Manager information
See Columbus, OH salary details
$49.8K - $60.2K
4% of jobs
$60.2K - $70.7K
6% of jobs
$70.7K - $81.1K
11% of jobs
$85K is the 25th percentile. Wages below this are outliers.
$81.1K - $91.5K
11% of jobs
The median wage is $99.8K / yr.
$91.5K - $101.9K
23% of jobs
$101.9K - $112.3K
13% of jobs
$119.2K is the 75th percentile. Wages above this are outliers.
$112.3K - $122.7K
12% of jobs
$122.7K - $133.2K
8% of jobs
$133.2K - $143.6K
6% of jobs
$143.6K - $154K
4% of jobs
$154K - $164.4K
2% of jobs
$49.8K
$107.9K
$164.4K
How much do cyber risk manager jobs pay per year?
How does a Cyber Risk Manager typically collaborate with other departments to strengthen an organization's cybersecurity posture?
What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?
| Aspect | Cyber Risk Manager | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CISSP, CEH |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability testing |
| Employer & Industry Usage | Financial, healthcare, large enterprises | IT departments, security firms, corporate environments |
The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.
What are the key skills and qualifications needed to thrive as a Cyber Risk Manager, and why are they important?
Can you make $500,000 a year in cyber security?
Is CISO a high paying job?
What does a cyber risk manager do?
What is the 80 20 rule in cyber security?

Full-time
Medical, Dental, Retirement
Posted 17 days ago
Job description
Job Title:
Principal Engineer I, Cyber - IT Security GovernanceLocation:
CityScapeWhat you'll do:
As a Principal IT Security Governance Engineer, you will serve as a senior individual contributor responsible for leading and advancing the organization's cybersecurity governance, risk management, and maturity initiatives. This role combines deep expertise in cyber risk, control design, CRI Profile maturity, and policy management with a strong understanding of modern engineering practices, data, automation, and AI-driven capabilities.You will drive complex, cross-functional initiatives that embed secure, compliant, and scalable practices into technology, data, and AI solutions, ensuring alignment with enterprise risk management objectives and regulatory expectations. This includes designing and implementing governance frameworks, control structures, and engineering-enabled solutions that enhance the effectiveness, consistency, and automation of risk assessments, RCSAs, and control monitoring.
In this role, you will act as both a governance and technical authority, partnering closely with engineering, data, and risk teams to translate evolving technologies into defensible, regulator-ready processes, controls, and documentation. You will leverage data, automation, and AI to improve visibility into risk posture, drive operational efficiency, and enable sustained improvements in cybersecurity maturity and program scalability.
- Own and lead cybersecurity governance initiatives spanning risk identification, control design, policy management, and maturity improvement.
- Serve as a subjectmatter expert for cyber risk management, providing guidance on control effectiveness, risk treatment, and residual risk decisions.
- Drive execution of cybersecurity Risk & Control SelfAssessments (RCSAs), ensuring alignment to ERM standards and regulatory expectations.
- Own and manage CRI Profile assessments, maturity scoring, evidence standards, and remediation tracking. Partner with technology, security, and risk teams to drive improved and sustained maturity gains.
- Maintain traceability between risks, controls, assessment results, and remediation activities.
- Lead the development, maintenance, and rationalization of cybersecurity policies, standards, and procedures in alignment with industry best practices (e.g., GLBA, FFIEC, NIST).
- Design, document, and maintain cyber risk statements, control descriptions, and control narratives suitable for audits and regulatory exams.
- Support internal audits, regulatory exams, and second line credible challenge through structured responses, evidence packaging, and issue management.
- Track and report on control performance, risk posture, and remediation progress using defined metrics and governance forums.
- Manage complex projects requiring coordination across IT, Information Security, ERM, Privacy, and Audit.
- Act as a trusted advisor to senior leaders on risk posture, maturity trends, and program health.
- Produce clear, executiveready artifacts including risk summaries, maturity dashboards, remediation roadmaps, and briefing materials.
- Develop and maintain automation solutions (e.g., scripting, workflow tools, AI-assisted processes) to improve efficiency of risk assessments, control testing, and evidence collection.
- Enable data-driven insights and reporting through engineering-oriented solutions (e.g., dashboards, metrics automation, control monitoring).
- Drive integration of AI and automation into RCSA, CRI assessments, and risk reporting processes to improve scalability, consistency, and accuracy.
What you'll need:
- 8+ years of related experience in Cybersecurity, Information Security Governance, IT Risk, or Enterprise Risk Management.
- Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Risk Management, or a related field. Masters or MBA in related field preferred.
- Advanced to expert experience with:
- Cyber Risk Management frameworks (NIST CSF, CRI Profile, FFIEC, ISO 27001 principles).
- RCSAs, risk identification, control design, and residual risk assessment.
- Policy, standard, and procedure lifecycle management.
- Regulatory and audit engagement support in a financial services environment.
- Strong ability to translate complex technical and regulatory concepts into clear, defensible documentation.
- Proven experience managing cross functional initiatives with competing priorities.
- Expert speaking and writing communication skills.
- Demonstrated experience leveraging or governing AI/ML, automation, or advanced analytics within cybersecurity, risk, or compliance domains preferred.
- Strong understanding of data architectures, data flows, and system integrations, with the ability to assess associated cyber and privacy risks preferred.
- Familiarity with emerging regulatory expectations related to AI, model risk, and data usage in financial services preferred.
- Working knowledge of software engineering or scripting practices (e.g., Python, PowerShell, automation workflows) to support scalable governance solutions preferred.
- Strong analytical mindset with the ability to use data and automation to enhance risk identification, monitoring, and reporting preferred.
- Relevant industry certifications (e.g., CISA, CRISC, CISSP, CISM, CGEIT, ITIL) preferred.
Benefits you'll love:
We offer all the important things you'd want - like competitive salaries, an ownership stake in the company, medical and dental insurance, time off, a great 401k matching program, tuition assistance program, an employee volunteer program, and a wellness program. In addition, you'll have the opportunity to bolster your business knowledge, learning the ins and outs of how successful companies operate and manage their finances, giving you invaluable hands-on experience to help grow your career!
About the company:
Western Alliance Bank, Member FDIC, is a wholly owned subsidiary of Western Alliance Bancorporation. Serving clients nationwide, Western Alliance Bank includes six legacy bank brands - Alliance Association Bank, Alliance Bank of Arizona, Bank of Nevada, Bridge Bank, First Independent Bank and Torrey Pines Bank - that remain part of the company's heritage, as well as AmeriHome Mortgage, a Western Alliance Bank Company.
Western Alliance Bancorporation is committed to equal employment and will consider all qualified applicants without regard to race, sex, color, religion, age, nation origin, marital status, disability, protected veteran status, sexual orientation, gender identity or genetic information. Western Alliance Bancorporation is committed to working with and providing reasonable accommodations for individuals with disabilities. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process and/or need an alternative method of applying, please email HR@westernalliancebank.com or call 602-386-2488. When contacting us, please provide your contact information and state the nature of your accessibility issue. We will only respond to inquiries concerning requests that involve a reasonable accommodation in the application process.
Western Alliance Bancorporation