As part of this oversight role, experience with cybersecurity domains, operations, architecture ... Provide expert advice on risk management practices, offering practical solutions to mitigate ...
As part of this oversight role, experience with cybersecurity domains, operations, architecture ... Provide expert advice on risk management practices, offering practical solutions to mitigate ...
This role is particularly well-suited to a candidate with both technical depth, risk management ... Cybersecurity Consulting & Enablement Serve as the primary cybersecurity advisor to the business ...
This role is particularly well-suited to a candidate with both technical depth, risk management ... Cybersecurity Consulting & Enablement Serve as the primary cybersecurity advisor to the business ...
... risk management. • Support vulnerability management integration with enterprise cybersecurity tools. • Maintain documentation and standard operating procedures for vulnerability management ...
... risk management. • Support vulnerability management integration with enterprise cybersecurity tools. • Maintain documentation and standard operating procedures for vulnerability management ...
Develop dashboards, reports, and metrics supporting cybersecurity risk management. * Support vulnerability management integration with enterprise cybersecurity tools. * Maintain documentation and ...
Develop dashboards, reports, and metrics supporting cybersecurity risk management. * Support vulnerability management integration with enterprise cybersecurity tools. * Maintain documentation and ...
Cybersecurity Engineer
Columbus, OH · On-site
... risk management, vulnerability management, and incident response. • Experience securing both software and hardware systems in manufacturing environments. • Strong understanding of cybersecurity ...
Quick apply
Cybersecurity Engineer
Columbus, OH · On-site
... risk management, vulnerability management, and incident response. • Experience securing both software and hardware systems in manufacturing environments. • Strong understanding of cybersecurity ...
This role provides handson exposure to cybersecurity engineering, security operations, and risk management in a largescale, missioncritical environment. The intern will assist with security ...
This role provides handson exposure to cybersecurity engineering, security operations, and risk management in a largescale, missioncritical environment. The intern will assist with security ...
R&I Cybersecurity & AI Risk Senior Manager
Columbus, OH · On-site
$91K - $321.50K/yr
Those in enterprise risk management at PwC will focus on identifying and mitigating potential risks ... Responsibilities - Provide specialized support in cybersecurity, privacy, data, and AI risk ...
R&I Cybersecurity & AI Risk Senior Manager
Columbus, OH · On-site
$91K - $321.50K/yr
Those in enterprise risk management at PwC will focus on identifying and mitigating potential risks ... Responsibilities - Provide specialized support in cybersecurity, privacy, data, and AI risk ...
Working knowledge of risk management frameworks and industry standards applicable to technology and cybersecurity risk * Ability to evaluate control design and operating effectiveness, including ...
Working knowledge of risk management frameworks and industry standards applicable to technology and cybersecurity risk * Ability to evaluate control design and operating effectiveness, including ...
CYBERSECURITY ENGINEER 2
Columbus, OH · On-site
They are seeking a Cybersecurity Engineer 2 to support governance, risk management, and compliance initiatives while maintaining and enhancing cybersecurity governance platforms and ensuring ...
CYBERSECURITY ENGINEER 2
Columbus, OH · On-site
They are seeking a Cybersecurity Engineer 2 to support governance, risk management, and compliance initiatives while maintaining and enhancing cybersecurity governance platforms and ensuring ...
Cybersecurity Engineer 2
Columbus, OH · On-site
Position Overview iP-Plus Consulting is seeking a Cybersecurity Engineer 2 to support governance, risk management, and compliance (GRC) initiatives across a large federal operational environment.
Cybersecurity Engineer 2
Columbus, OH · On-site
Position Overview iP-Plus Consulting is seeking a Cybersecurity Engineer 2 to support governance, risk management, and compliance (GRC) initiatives across a large federal operational environment.
Working knowledge of risk management frameworks and industry standards applicable to technology and cybersecurity risk * Ability to evaluate control design and operating effectiveness, including ...
Working knowledge of risk management frameworks and industry standards applicable to technology and cybersecurity risk * Ability to evaluate control design and operating effectiveness, including ...
Working knowledge of risk management frameworks and industry standards applicable to technology and cybersecurity risk * Ability to evaluate control design and operating effectiveness, including ...
Working knowledge of risk management frameworks and industry standards applicable to technology and cybersecurity risk * Ability to evaluate control design and operating effectiveness, including ...
Cyber Manager - ServiceNow
Columbus, OH · On-site
$107.20K - $144.90K/yr
... Risk Management workstreams in partnership with architects and product owners • Managing ... Required : • Bachelor's degree in Computer Science, Cyber Security, Information Security ...
Cyber Manager - ServiceNow
Columbus, OH · On-site
$107.20K - $144.90K/yr
... Risk Management workstreams in partnership with architects and product owners • Managing ... Required : • Bachelor's degree in Computer Science, Cyber Security, Information Security ...
Supplier Cybersecurity Assessor - Vice President
Columbus, OH · On-site
$147.80K - $185K/yr
As a Supplier Cybersecurity Assessor - Vice President in Global Supplier Services, you will conduct ... manages the source-to-pay cycle, engaging with suppliers, negotiating contracts, conducting risk ...
Supplier Cybersecurity Assessor - Vice President
Columbus, OH · On-site
$147.80K - $185K/yr
As a Supplier Cybersecurity Assessor - Vice President in Global Supplier Services, you will conduct ... manages the source-to-pay cycle, engaging with suppliers, negotiating contracts, conducting risk ...
As a Supplier Cybersecurity Assessor - Vice President in Global Supplier Services, you will conduct ... manages the source-to-pay cycle, engaging with suppliers, negotiating contracts, conducting risk ...
As a Supplier Cybersecurity Assessor - Vice President in Global Supplier Services, you will conduct ... manages the source-to-pay cycle, engaging with suppliers, negotiating contracts, conducting risk ...
What You'll Do * Assist in the build-out and lead the Cybersecurity GRC program * Lead with hands-on support of the day-to-day activities of the GRC program * Provide project management across ...
What You'll Do * Assist in the build-out and lead the Cybersecurity GRC program * Lead with hands-on support of the day-to-day activities of the GRC program * Provide project management across ...
As a Supplier Cybersecurity Assessor - Vice President in Global Supplier Services, you will conduct ... manages the source-to-pay cycle, engaging with suppliers, negotiating contracts, conducting risk ...
As a Supplier Cybersecurity Assessor - Vice President in Global Supplier Services, you will conduct ... manages the source-to-pay cycle, engaging with suppliers, negotiating contracts, conducting risk ...
What You'll Do * Assist in the build-out and lead the Cybersecurity GRC program * Lead with hands-on support of the day-to-day activities of the GRC program * Provide project management across ...
What You'll Do * Assist in the build-out and lead the Cybersecurity GRC program * Lead with hands-on support of the day-to-day activities of the GRC program * Provide project management across ...
Cyber Manager - ServiceNow
Columbus, OH · On-site +1
$107.20K - $144.90K/yr
... cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever ... Risk Management workstreams in partnership with architects and product owners * Managing ...
Cyber Manager - ServiceNow
Columbus, OH · On-site +1
$107.20K - $144.90K/yr
... cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever ... Risk Management workstreams in partnership with architects and product owners * Managing ...
Required : • Formal training or certification on risk management, technology controls, cybersecurity, or related concepts and 5+ years of applied experience in technology risk management ...
Required : • Formal training or certification on risk management, technology controls, cybersecurity, or related concepts and 5+ years of applied experience in technology risk management ...
Cybersecurity Risk Management information
See Columbus, OH salary details
$55.1K - $66.4K
1% of jobs
$66.4K - $77.7K
4% of jobs
$77.7K - $89K
5% of jobs
$89K - $100.4K
9% of jobs
$106.6K is the 25th percentile. Wages below this are outliers.
$100.4K - $111.7K
11% of jobs
$111.7K - $123K
10% of jobs
The median wage is $127.4K / yr.
$123K - $134.3K
28% of jobs
$140.9K is the 75th percentile. Wages above this are outliers.
$134.3K - $145.7K
14% of jobs
$145.7K - $157K
11% of jobs
$157K - $168.3K
4% of jobs
$168.3K - $179.7K
4% of jobs
$55.1K
$128.4K
$179.7K
How much do cybersecurity risk management jobs pay per year?
What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?
What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?
What is cybersecurity risk management?
What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?
| Aspect | Cybersecurity Risk Management | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government, large enterprises | IT departments, cybersecurity firms, corporate security teams |
Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.
KeyBank rating
8.2
Based on 89 frontline employees who took The Breakroom Quiz
37th of 141 rated banks
Job description
Location:
4910 Tiedeman Road, Brooklyn OhioAbout the Job
Reporting to the Director of Cybersecurity Risk Oversight, the Sr. Cybersecurity Risk Oversight Professional is a 2nd Line of Defense risk management position that provides independent oversight and Risk Management subject matter expertise to 1st Line of Defense Business units and their corresponding Business Risk and Control Analysts.
This position is responsible for Operational Risk oversight of the Key Technology and Operations Services line of business, as well as technology and information security risk oversight for areas of the enterprise that manage technology. As part of this oversight role, experience with cybersecurity domains, operations, architecture, governance, information security, and the ability to leverage that experience to identify material risks, provide credible challenge and assist in developing effective mitigation strategies.
Essential Functions
- Evaluate risk and control identification within key processes and perform gap assessments on control coverage as well as first line of defense identification processes
- Collaborate with leaders to gain insights on operational performance, emerging risks and strategic initiatives while identifying opportunities for improvement.
- Evaluate and monitor projects, strategic initiatives, and new technologies to ensure alignment with risk tolerance and business goals.
- Review risks, controls and, conduct assessments to support effective oversight and compliance with risk management requirements.
- Oversee the technology portfolio, assessing projects and initiatives to ensure alignment with risk appetite and adequate mitigation strategies.
- Support and enhance the overall risk oversight framework by developing and updating oversight practices.
- Partner with various teams to influence the implementation of operational practices to mitigate risk within appetite.
- Provide expert advice on risk management practices, offering practical solutions to mitigate identified risks.
- Analyze and assess risks associated with new products or services including third parties.
- Assist with audits and regulatory examinations, ensuring through and timely responses to inquiries and findings.
- Foster positive relationships with business partners and senior management ensuring open communication on risk matters.
- Escalate and report any significant risk issues and facilitate appropriate corrective actions.
- Perform ongoing monitoring of emerging risks, industry and regulatory trends.
Required Qualifications
- Bachelor's degree in business, finance, technology, or economics or commensurate/relevant degree is required.
- Minimum of 5 years industry experience, within Operational Risk, Enterprise Risk, Technology Risk, Information Security Risk, External/Internal Audit or in the technology or information security lines of business.
- Outstanding active listening skills
- Demonstrated ability to work with internal and external auditors and regulators.
- Ability to think strategically coupled with the ability to drive to execution
- Ability to view risk holistically within a dynamic, fast paced team environment
- In-depth practical knowledge of internal controls, risk assessments and operational and compliance processes, and applicable techniques for implementation of compliance and legal requirements and operational processes.
- Familiarity with Microsoft Office tools such as Excel, Teams, and the proven ability to learn how to use other unique technologies.
- Capable of conducting in depth testing of systems, processes and controls
- Manage workflows and task assignment to ensure timely completion of work
- Have an execution oriented, process efficiency and continuous improvement mindset
- Possessing intellectual curiosity and a passion for seeking to understand
- Proven ability to have, maintain, and establish strong contacts within the industry so as to be aware of current industry issues and practices
Licenses and Certifications
- Applicable certifications such as:
- ISACA: CISA, CRISC, CET, CGEIT, CISM
- ISC2: CISSP, CCSP, SSCP
- Cloud Security Alliance Certs: CCAK
- Cloud Provider-Specific Certifications
Preferred Qualifications
- MBA, Law Degree or other relevant advanced education
- Current and practical knowledge of Technology and/or Information Security activities, challenges, and workflows
- Additional industry certifications such as those listed above
- BS or Masters in Technology or Security related field
- Foundational knowledge of Archer GRC preferred
- Project management, Agile experience preferred
Tactical Skills
- Demonstrated experience working with regulatory agencies, guidelines and requirements
- Strong ability to work with all levels of management within the company
- Experience working/managing projects across multiple functional areas and dealing with multiple business partners
- Experience working on initiatives that require strategic planning/thinking
- Flexibility to switch priorities based on the needs of the company in a fast-paced environment
- Ability to grasp complex processes quickly and be able to identify risks and compensating controls
- Excellent problem-solving abilities and results oriented; able to make decisions independently
- Proven ability to work as a team
- Strong leadership skills and ability to influence others
- Sound understanding of compliance and operational risks and internal control frameworks
- Strong analytical/research skills coupled with ability to effectively summarize findings
- Excellent oral, written and interpersonal skills
- Ability to adapt to change and communicate changing requirements
- Excellent organizational skills and meticulous attention to detail
- Self-motivated
- Proficient PC skills with experience in Microsoft Office, Outlook and, SharePoint
Personal Skills
- Adaptability: Demonstrates a willingness to listen to other opinions and adjusts to new or changing assignments, processes, and people while avoiding snap reactions
- Agile Mindset: Explains specific agile processes and its associated checkpoints and deliverables and applies major agile tools and techniques to accomplish tasks; understands that failures/defects equate to new learnings
- Collaboration: Demonstrates experience in participating in productive collaborative processes that help solve business problems and meet business goals
- Problem Solving: Demonstrates the ability to examine a specific problem and understand the perspective of stakeholders; uses fact-finding techniques to identify and document specific problems
Practical Skills
- Business Acumen: Participates in business tasks to get things done in own business unit and communicates key considerations for business decision-making processes
- Data Analysis: Identifies correlations that reveal trends and determine conditions, often with disparate data sets; Evaluates the quality of data collected and the effectiveness of data analysis methods for evaluating performance
- Oral & Written Communication: Possesses the ability to adapt listening and facilitation style to others' communication styles and uses various approaches appropriately and effectively
- Risk Management: Implements or manages risk management for own business unit and documents key steps of the risk management process and associated procedures
- Systems Thinking: Analyzes the dynamics of a system to determine key characteristics, properties, and functions; surfaces problems within systems and searches for root causes while leveraging a foundational knowledge of continuous improvement
Core Competencies
- All KeyBank employees are expected to demonstrate Key's Values and sustain proficiency in identified Leadership Competencies.
Physical Demands
- General Office - Prolonged sitting, ability to communicate face to face in person or on the phone with teammates and clients, frequent use of PC/laptop, occasional lifting/pushing/pulling of backpacks, computer bags up to 10 lbs.
Travel
- Occasional travel to include overnight stay.
COMPENSATION AND BENEFITS
This position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.Please click here for a list of benefits for which this position is eligible.
Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.
Job Posting Expiration Date: 06/28/2026 KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law.Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing HR_Compliance@keybank.com.
#LI-HybridAbout KeyBank
Sourced by ZipRecruiter
Key is one of the nation's largest bank-based financial services companies. Key provides deposit, lending, cash management, insurance, and investment services to individuals and businesses in 15 states under the name KeyBank National Association through a network of more than 1,200 branches and more than 1,500 ATMs. Key also provides a broad range of sophisticated corporate and investment banking products, such as merger and acquisition advice, public and private debt and equity, syndications, and derivatives to middle market companies in selected industries throughout the United States under the KeyBanc Capital Markets trade name.
Industry
Banking and credit intermediation
Company size
10,000+ Employees
Headquarters location
Cleveland, OH, US
Year founded
1849