2,310 security risk jobs at 1,255 companies in United States
3w
Save
Mark Applied
Hide
3w
Security Risk Manager
San Francisco, California, United States
$194k-$220k/yrHybridFull Time
AsanaNYSE: ASAN: Software platform for team project management and workflow automation.
7+ YOE7+ years in information security with proven experience building security risk management programs, quantitative risk methodologies (e.g., FAIR), scripting/automation for risk monitoring, and knowledge of NIST, ISO, SOC 2, and FedRAMP.
Equality Health: Tech-enabled healthcare platform for value-based primary care.
10+ YOE10+ years in information security with 5+ years leading teams/programs; hands-on HIPAA/HITECH experience; ownership of security roadmap, SIEM/SOC, vulnerability management, IAM, DLP, cloud security (AWS), third-party risk, IR, BC/DR; CISSP or CISM required; Bachelor’s in CS/IT/Cyber or equivalent.
Microsoft Sentinel, Splunk, Microsoft Defender for Endpoint, CrowdStrike, Mimecast, Netskope, Microsoft Purview, Microsoft Defender for Office 365, Microsoft Defender for Identity, Tenable, Qualys, Rapid7, PowerShell, Python, Terraform, Checkov, Palo Alto, Fortinet, Amazon S3, AWS KMS, AWS GuardDuty, AWS Security Hub, AWS WAF, AWS Shield, Amazon VPC, AWS CloudTrail, AWS Config, Microsoft Entra ID, Azure AD, Okta, SIEM
DocuSignNASDAQ: DOCU: Provides electronic signature and agreement management software solutions.
8+ YOE8+ years in security risk management/GRC, bachelor’s in CS/InfoSec, experience with cloud (AWS/Azure/GCP), GRC platforms, risk quantification (FAIR), and security domain expertise; CISSP/CRISC/CISM preferred.
AWS, Azure, GCP, ServiceNow IRM, OneTrust, FAIR, Tableau, Power BI
DocuSignNASDAQ: DOCU: Provider of e-signature and intelligent agreement management software.
8+ YOE8+ years in security risk/GRC, Bachelor's in CS/InfoSec, experience with cloud (AWS/Azure/GCP), GRC platforms, risk quantification (FAIR), and strong communication; CISSP/CRISC/CISM preferred.
AWS, Azure, GCP, ServiceNow IRM, OneTrust, Tableau, Power BI
United States or California or Washington or New York or New Jersey or Connecticut or Los Angeles or San Francisco
$146k-$225k/yrRemoteFull Time
AffirmNasdaq: AFRM: Financial platform providing installment loans for consumer purchases.
5+ YOE5+ years in information security or risk roles; hands-on with Python and agentic coding tools (Cursor, Claude, Copilot); familiarity with cloud (AWS/GCP/Azure), security frameworks, strong communication and project delivery skills.
Python, Cursor, Claude, Copilot, SQL, AWS, GCP, Azure, NIST Cyber Security Framework, ISO 2700x, SOC1, SOC2, SSAE18, PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, BI tools
JPS Health Network: Public health system providing medical care and residency training.
5+ YOEBachelor's in IT-related field required,5+ years in IT risk/cybersecurity/IT audit,experience with IT risk frameworks,cloud and vendor risk assessments,incident response and enterprise risk programs;certifications such as CRISC,CISSP,CISM,CEH or CompTIA Security+ desired.
State Controller's Office: California's fiscal controller managing state financial operations and assets.
Perform risk management activities for IT systems, review security plans, help shape and enforce security policies, follow NIST/SAM/SIMM guidelines, and pass background investigation; must be authorized to work in the US.
National Institute of Standards and Technology (NIST), State Administrative Manual (SAM), Statewide Information Management Manual (SIMM)
KlaviyoNYSE: KVYO: Software platform for automated e-commerce marketing and customer data.
7+ YOE7+ years in information/technology/cyber risk with hands-on risk engineering, cyber risk quantification, SQL and Python skills, API integration, knowledge of security/AI frameworks and risk tooling.
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
Experience with information assurance/cybersecurity processes, ACAS, HBSS, eMASS, vulnerability review, residual risk statements, incident reporting; Secret clearance and HS diploma/GED required.
Assured Compliance Assessment Solution (ACAS), Host-Based Security System (HBSS), Enterprise Mission Assurance Support Service (eMASS), Microsoft Intune, Microsoft Defender, Tenable Nessus, SecurityCenter, IBM Guardium, HP WebInspect, Network Mapper
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
Experience with information assurance/cybersecurity processes, ACAS, HBSS, eMASS, vulnerability review and reporting, writing residual risk statements, and possession of a Secret clearance and high school diploma/GED.
Assured Compliance Assessment Solution (ACAS), Host-Based Security System (HBSS), Enterprise Mission Assurance Support Service (eMASS), Microsoft Intune, Microsoft Defender, Tenable Nessus, SecurityCenter, IBM Guardium, HP WebInspect, Network Mapper
Rutgers University: Providing higher education degrees and conducting academic research.
5+ YOEBachelor's in a related field and 5+ years information security experience; knowledge of HIPAA, GLBA, PCI DSS, NIST CSF; experience with GRC/VRM; strong communication and risk assessment skills.
HIPAA, GLBA, PCI DSS, NIST CSF, NIST 800-171, ISO 27001, ISO 27002, GRC, VRM
Amerisure: Provides commercial property and casualty insurance for businesses.
5+ YOE5+ years cybersecurity experience; advanced cyber risk certification (CISSP, CISM, CRISC, CCSP, or AWS Security); 2+ years control testing; SOC 2 review, third-party risk assessments, NIST expertise, Logicgate experience, and ability to translate risk to business leaders.
NIST CSF, New York State Department of Financial Services (NYDFS), NIS2, PCI DSS, Logicgate
M0: Infrastructure for launching and managing application-specific digital dollar stablecoins.
7+ YOE7-10 years in information security, risk, GRC, or compliance with fintech/crypto/B2B SaaS exposure; proven track record building compliance programs; hands-on with AWS and GRC tools; multi-entity/regulatory exposure; strong communication and governance skills.
University of Minnesota: Public research university providing undergraduate and graduate education.
1+ YOEBachelor's degree plus 2 years relevant experience (or Master's); 1 year information security risk assessment experience; strong communication and analytical skills; knowledge of security standards and regulations.
Zermount: Provides cybersecurity and IT consulting services to government agencies.
7+ YOE7+ years cybersecurity experience supporting U.S. Government systems, 4+ years performing RMF/ISSO/assessment/GRC functions, active Secret clearance, hands-on validation of security controls, deep knowledge of NIST RMF/Zero Trust, and one of several industry security certifications.
Tenable, Qualys, CrowdStrike, Splunk, Microsoft Sentinel, IBM QRadar, Ansible, Terraform, Puppet, Archer, ServiceNow
YieldNest: Liquid restaking protocol for risk-adjusted DeFi yields.
7+ YOE7–10 years in information security, risk, GRC, or compliance; build and own enterprise risk and compliance programs; manage audits; implement SOC 2, ISO 27001; AWS/GCP/Azure security; GRC automation; multi-entity, regulated environment.
Zermount: Provider of cybersecurity and IT solutions to government agencies.
7+ YOE7+ years cybersecurity experience; RMF/ISSO/GRC with technical validation; hands-on in multiple domains; proven ability to assess and validate security controls across complex environments.
Vulnerability scanning/Tenable, Vulnerability scanning/Qualys, Vulnerability scanning/CrowdStrike, Log analysis/Splunk, Log analysis/Microsoft Sentinel, Log analysis/IBM QRadar, Configuration and inspection/Ansible, Configuration and inspection/Terraform, Configuration and inspection/Puppet, GRC/Archer, GRC/ServiceNow
Pittsburgh or Bécancour or Montréal or Baie-Comeau or Deschambault
OnsiteFull Time
AlcoaNYSE: AA: Produces aluminum through bauxite mining, refining, and smelting.
6+ YOE6+ years in cybersecurity or IT risk; experience assessing IT and OT risk; knowledge of ISO/NIST/CIS frameworks, GRC activities and tools; strong written/verbal communication and facilitation skills; bachelor's degree or equivalent experience.
Governance, Risk, and Compliance (GRC), SIEM, ISO 27001, NIST CSF, NIST 800-53, CIS Controls, SOX