2,310 security risk jobs at 1,255 companies in United States

3w
Save
Mark Applied
Hide
Security Risk Manager
San Francisco, California, United States
$194k-$220k/yr HybridFull Time
Asana
AsanaNYSE: ASAN: Software platform for team project management and workflow automation.
7+ YOE7+ years in information security with proven experience building security risk management programs, quantitative risk methodologies (e.g., FAIR), scripting/automation for risk monitoring, and knowledge of NIST, ISO, SOC 2, and FedRAMP.
FAIR, SIEMs, vulnerability scanners, cloud security tooling, NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, FedRAMP
1mo
Save
Mark Applied
Hide
Director, Security & Risk
United States
RemoteFull Time
Equality Health
Equality Health: Tech-enabled healthcare platform for value-based primary care.
10+ YOE10+ years in information security with 5+ years leading teams/programs; hands-on HIPAA/HITECH experience; ownership of security roadmap, SIEM/SOC, vulnerability management, IAM, DLP, cloud security (AWS), third-party risk, IR, BC/DR; CISSP or CISM required; Bachelor’s in CS/IT/Cyber or equivalent.
Microsoft Sentinel, Splunk, Microsoft Defender for Endpoint, CrowdStrike, Mimecast, Netskope, Microsoft Purview, Microsoft Defender for Office 365, Microsoft Defender for Identity, Tenable, Qualys, Rapid7, PowerShell, Python, Terraform, Checkov, Palo Alto, Fortinet, Amazon S3, AWS KMS, AWS GuardDuty, AWS Security Hub, AWS WAF, AWS Shield, Amazon VPC, AWS CloudTrail, AWS Config, Microsoft Entra ID, Azure AD, Okta, SIEM
2mo
Save
Mark Applied
Hide
Cyber Security Risk Analyst
New York, New York, United States
$170k-$230k/yr OnsiteFull Time
Federal Reserve System
Federal Reserve System: The central bank of the United States.
Cloud security risk assessments, risk management (NIST 800-53), application security testing, DevSecOps, vendor risk management.
1w
Save
Mark Applied
Hide
Senior Security Risk Manager
San Francisco, California, United States
$146k-$235k/yr HybridFull Time
DocuSign
DocuSignNASDAQ: DOCU: Provides electronic signature and agreement management software solutions.
8+ YOE8+ years in security risk management/GRC, bachelor’s in CS/InfoSec, experience with cloud (AWS/Azure/GCP), GRC platforms, risk quantification (FAIR), and security domain expertise; CISSP/CRISC/CISM preferred.
AWS, Azure, GCP, ServiceNow IRM, OneTrust, FAIR, Tableau, Power BI
1w
Save
Mark Applied
Hide
Senior Security Risk Manager
San Francisco, California, United States
$146k-$235k/yr HybridFull Time
DocuSign
DocuSignNASDAQ: DOCU: Provider of e-signature and intelligent agreement management software.
8+ YOE8+ years in security risk/GRC, Bachelor's in CS/InfoSec, experience with cloud (AWS/Azure/GCP), GRC platforms, risk quantification (FAIR), and strong communication; CISSP/CRISC/CISM preferred.
AWS, Azure, GCP, ServiceNow IRM, OneTrust, Tableau, Power BI
3mo
Save
Mark Applied
Hide
Security Risk Management Specialist, Leo Security
Redmond, Washington, United States
$102k-$178k/yr OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
3+ YOE3+ years in identifying security issues and risks; experience triaging risks and developing mitigations.
SAP GRC, Identity Management, Single Sign-On
1mo
Save
Mark Applied
Hide
Security Risk Management Lead
United States or California or Washington or New York or New Jersey or Connecticut or Los Angeles or San Francisco
$146k-$225k/yr RemoteFull Time
Affirm
AffirmNasdaq: AFRM: Financial platform providing installment loans for consumer purchases.
5+ YOE5+ years in information security or risk roles; hands-on with Python and agentic coding tools (Cursor, Claude, Copilot); familiarity with cloud (AWS/GCP/Azure), security frameworks, strong communication and project delivery skills.
Python, Cursor, Claude, Copilot, SQL, AWS, GCP, Azure, NIST Cyber Security Framework, ISO 2700x, SOC1, SOC2, SSAE18, PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, BI tools
2w
Save
Mark Applied
Hide
IT Security Risk Mgr
Fort Worth, Texas, United States
OnsiteFull Time
JPS Health Network
JPS Health Network: Public health system providing medical care and residency training.
5+ YOEBachelor's in IT-related field required,5+ years in IT risk/cybersecurity/IT audit,experience with IT risk frameworks,cloud and vendor risk assessments,incident response and enterprise risk programs;certifications such as CRISC,CISSP,CISM,CEH or CompTIA Security+ desired.
3d
Save
Mark Applied
Hide
Information Security Risk Associate
Sacramento County, California, United States
$5k-$9k/mo HybridFull Time
State Controller's Office
State Controller's Office: California's fiscal controller managing state financial operations and assets.
Perform risk management activities for IT systems, review security plans, help shape and enforce security policies, follow NIST/SAM/SIMM guidelines, and pass background investigation; must be authorized to work in the US.
National Institute of Standards and Technology (NIST), State Administrative Manual (SAM), Statewide Information Management Manual (SIMM)
1w
Save
Mark Applied
Hide
Lead Security Governance & Risk Engineer
Boston or Denver
$156k-$234k/yr OnsiteFull Time
Klaviyo
KlaviyoNYSE: KVYO: Software platform for automated e-commerce marketing and customer data.
7+ YOE7+ years in information/technology/cyber risk with hands-on risk engineering, cyber risk quantification, SQL and Python skills, API integration, knowledge of security/AI frameworks and risk tooling.
SQL, Python, APIs, Tableau, AWS, Kubernetes
1mo
Save
Mark Applied
Hide
Information Security Risk Specialist
Scott Air Force Base or United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
Experience with information assurance/cybersecurity processes, ACAS, HBSS, eMASS, vulnerability review, residual risk statements, incident reporting; Secret clearance and HS diploma/GED required.
Assured Compliance Assessment Solution (ACAS), Host-Based Security System (HBSS), Enterprise Mission Assurance Support Service (eMASS), Microsoft Intune, Microsoft Defender, Tenable Nessus, SecurityCenter, IBM Guardium, HP WebInspect, Network Mapper
1mo
Save
Mark Applied
Hide
Information Security Risk Specialist
Scott Air Force Base, Illinois, United States
$99k-$225k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
Experience with information assurance/cybersecurity processes, ACAS, HBSS, eMASS, vulnerability review and reporting, writing residual risk statements, and possession of a Secret clearance and high school diploma/GED.
Assured Compliance Assessment Solution (ACAS), Host-Based Security System (HBSS), Enterprise Mission Assurance Support Service (eMASS), Microsoft Intune, Microsoft Defender, Tenable Nessus, SecurityCenter, IBM Guardium, HP WebInspect, Network Mapper
1mo
Save
Mark Applied
Hide
Information Security Risk Analyst
New Brunswick, New Jersey, United States
$108k-$165k/yr HybridFull Time
Rutgers University
Rutgers University: Providing higher education degrees and conducting academic research.
5+ YOEBachelor's in a related field and 5+ years information security experience; knowledge of HIPAA, GLBA, PCI DSS, NIST CSF; experience with GRC/VRM; strong communication and risk assessment skills.
HIPAA, GLBA, PCI DSS, NIST CSF, NIST 800-171, ISO 27001, ISO 27002, GRC, VRM
1mo
Save
Mark Applied
Hide
Senior IT Security Risk Analyst
Farmington Hills, Michigan, United States
HybridFull Time
Amerisure
Amerisure: Provides commercial property and casualty insurance for businesses.
5+ YOE5+ years cybersecurity experience; advanced cyber risk certification (CISSP, CISM, CRISC, CCSP, or AWS Security); 2+ years control testing; SOC 2 review, third-party risk assessments, NIST expertise, Logicgate experience, and ability to translate risk to business leaders.
NIST CSF, New York State Department of Financial Services (NYDFS), NIS2, PCI DSS, Logicgate
2mo
Save
Mark Applied
Hide
Head of Security & Risk
New York City or United States
RemoteFull Time
M0
M0: Infrastructure for launching and managing application-specific digital dollar stablecoins.
7+ YOE7-10 years in information security, risk, GRC, or compliance with fintech/crypto/B2B SaaS exposure; proven track record building compliance programs; hands-on with AWS and GRC tools; multi-entity/regulatory exposure; strong communication and governance skills.
Vanta, Drata, AWS, GRC automation, BCP/DR, SOC 2, ISO 27001, CMMC, HIPAA, GDPR, NIST 800-53, Cloud+, CySA+, CISSP, CISM
2w
Save
Mark Applied
Hide
Information Security Risk Analyst 2
Minnesota, United States
$85k-$95k/yr HybridFull Time
University of Minnesota
University of Minnesota: Public research university providing undergraduate and graduate education.
1+ YOEBachelor's degree plus 2 years relevant experience (or Master's); 1 year information security risk assessment experience; strong communication and analytical skills; knowledge of security standards and regulations.
ISO 27001, ISO 27002, NIST 800-171, SANS, OWASP
1mo
Save
Mark Applied
Hide
SECURITY & RISK ENGINEER (SRE)
United States or Arlington or Springfield
RemoteFull Time
Zermount
Zermount: Provides cybersecurity and IT consulting services to government agencies.
7+ YOE7+ years cybersecurity experience supporting U.S. Government systems, 4+ years performing RMF/ISSO/assessment/GRC functions, active Secret clearance, hands-on validation of security controls, deep knowledge of NIST RMF/Zero Trust, and one of several industry security certifications.
Tenable, Qualys, CrowdStrike, Splunk, Microsoft Sentinel, IBM QRadar, Ansible, Terraform, Puppet, Archer, ServiceNow
1mo
Save
Mark Applied
Hide
M0 Labs - Head of Security & Risk
New York or United States
HybridFull Time
YieldNest
YieldNest: Liquid restaking protocol for risk-adjusted DeFi yields.
7+ YOE7–10 years in information security, risk, GRC, or compliance; build and own enterprise risk and compliance programs; manage audits; implement SOC 2, ISO 27001; AWS/GCP/Azure security; GRC automation; multi-entity, regulated environment.
Vanta, Drata, AWS, GCP, Azure, BCP, DR
3mo
Save
Mark Applied
Hide
SECURITY & RISK ENGINEER (SRE)
Arlington or Springfield
RemoteFull Time
Zermount
Zermount: Provider of cybersecurity and IT solutions to government agencies.
7+ YOE7+ years cybersecurity experience; RMF/ISSO/GRC with technical validation; hands-on in multiple domains; proven ability to assess and validate security controls across complex environments.
Vulnerability scanning/Tenable, Vulnerability scanning/Qualys, Vulnerability scanning/CrowdStrike, Log analysis/Splunk, Log analysis/Microsoft Sentinel, Log analysis/IBM QRadar, Configuration and inspection/Ansible, Configuration and inspection/Terraform, Configuration and inspection/Puppet, GRC/Archer, GRC/ServiceNow
1mo
Save
Mark Applied
Hide
Cyber Security Risk Analyst
Pittsburgh or Bécancour or Montréal or Baie-Comeau or Deschambault
OnsiteFull Time
Alcoa
AlcoaNYSE: AA: Produces aluminum through bauxite mining, refining, and smelting.
6+ YOE6+ years in cybersecurity or IT risk; experience assessing IT and OT risk; knowledge of ISO/NIST/CIS frameworks, GRC activities and tools; strong written/verbal communication and facilitation skills; bachelor's degree or equivalent experience.
Governance, Risk, and Compliance (GRC), SIEM, ISO 27001, NIST CSF, NIST 800-53, CIS Controls, SOX