Manager, Cybersecurity Risk Management
Bechtel
Manager, Cybersecurity Risk Management
Extraordinary teams building inspiring projects: Since 1898, we have helped customers complete more than 25,000 projects in 160 countries on all seven continents that have created jobs, grown economies, improved the resiliency of the world's infrastructure, increased access to energy, resources, and vital services, and made the world a safer, cleaner place. Differentiated by the quality of our people and our relentless drive to deliver the most successful outcomes, we align our capabilities to our customers' objectives to create a lasting positive impact. We serve the Infrastructure; Nuclear, Security & Environmental; Energy; Mining & Metals, and the Manufacturing and Technology markets. Our services span from initial planning and investment, through start-up and operations.
Core to Bechtel is our Vision, Values and Commitments. They are what we believe, what customers can expect, and how we deliver. Learn more about our extraordinary teams building inspiring projects in our Impact Report.
Job Summary
The Manager, Cybersecurity Risk Management focuses efforts on managing and reporting on cyber risks globally across Bechtel, playing a crucial role in assessing and managing risk, and driving mitigation plans associated with our wider cybersecurity program. The manager drives a comprehensive risk management program, while supporting peer cybersecurity teams in maturing and standardizing their programs. The manager identifies and mitigates security risks; provides subject matter expertise and technical guidance to process owners; partners with Service Owners, GBU Managers, IT Architecture, Operations and Support, and Software Development, to contribute to the reporting of a comprehensive view of the security risk posture and its impact on the business.
Major Responsibilities
- Risk Oversight : Develops and maintains a comprehensive cybersecurity risk management strategy, leads enterprise-wide cyber risk assessments and mitigation / remediation activities. Collaborates with IT, legal, compliance, and business units to ensure risk mitigation strategies are embedded in operations. Monitors emerging threats and risk posture and activities accordingly. Presents risk analysis, metrics, and mitigation plans to management and stakeholders. Identifies risk and mitigating controls for information security exceptions based on adherence to relevant company policies, standards, baselines, and industry standards (e.g., ISO 27001, NIST, GDPR, HIPAA, CIS, FedRAMP). Mentors and develops junior risk analysts and cybersecurity professionals. Assists with the administration and maintenance of the ServiceNow GRC platform.
- Strategic Leadership, Business Partnership & Enablement : Translates risk insights into strategic decisions and enterprise-wide policies. Contributes to the design of cybersecurity strategies by advising on risk reduction priorities related to exception and risk register trends. Develops metrics to track exception mitigation rates, approval / review rates, aging, and SLA compliance. Drives initiatives that reduce recurring exception requests through enterprise-wide solutions.
- Analytics : Monitors the effectiveness of the information security exceptions process in accordance with agreed upon metrics and performance measures to drive continuous improvements. Conducts root cause analysis on recurring issues to enhance process efficiency and reduce exception requests. Collaborates with cross-functional teams to gather, interpret, and validate mitigating controls to ensure accuracy and relevance.
Education and Experience Requirements
Requires bachelor's degree plus 8+ years experience in information security risk, with at least 3 years in a risk management role or similar function.
Required Knowledge and Skills
Strong knowledge of cybersecurity frameworks, company policies, and regulatory requirements. Strong expertise across commercial and government cloud services (AWS, Azure, GCP, OCI, etc.), on-premises and application environments. Experience with tools such as ServiceNow, GRC tools, Power BI, and cloud technologies. Strong knowledge of risk frameworks (e.g., ISO 27005, NIST, ISO, PCI, SOX, etc.). Proven ability to translate complex technical concepts into plain language for decision-makers. Skilled in preparing polished deliverables that support informed decision-making. Team player who builds trust across technical and non-technical teams. Demonstrated ability to work independently, adapt quickly, and drive tasks forward with limited direction. Strong project management and delegation skills across diverse, cross-functional initiatives
Preferred
Certifications such as CISSP, CISM, CRISC, or CISA. 5+ years of prior experience in EPCM (Engineering, Procurement, Construction / Project Management). Prefer global company background and/or Fortune 500 and/or EPC industry. Comfortable working in a highly iterative environment, both structured and unstructured. Metrics and visualization tools knowledge a plus (i.e., ServiceNow, Power BI, Tableau). Advanced user of M365 Suite to prepare all project plans, deliverables, presentations, reports, and findings.
Total Rewards/Benefits
For decades, Bechtel has worked to inspire the next generation of employees and beyond! Because our teams face some of the world's toughest challenges, we offer robust benefits to ensure our people thrive. Whether it is advancing careers, delivering programs to enhance our culture, or providing time to recharge, Bechtel has the benefits to build a legacy of sustainable growth. Learn more at Bechtel Total Rewards
Diverse Teams Build the Extraordinary
As a global company, Bechtel has long been home to a vibrant multitude of nationalities, cultures, ethnicities, and life experiences. This diversity has made us a more trusted partner, more effective problem solvers and innovators, and a more attractive destination for leading talent. We are committed to being a company where every colleague feels that they belong-where colleagues feel part of "One Team," respected and rewarded for what they bring, supported in pursuing their goals, invested in our values and purpose, and treated equitably.
- .... Learn more about our extraordinary teams building inspiring projects in our Impact Report . Job Summary: The Manager, Cybersecurity Risk Management focuses efforts on managing and reporting on cyber risks globally across Bechtel, playing a crucial role in assessing...SuggestedPart timeLocal areaRemote workRelocation
$155k - $190k
...Senior Manager - Risk Advisory (Cybersecurity) Miller Kaplan is a different kind of CPA firm; we believe in building a legacy—yours. We want to give our clients the very best, and we understand that begins with helping our employees be their best through professional...SuggestedWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hoursDay shift- ...Manager, Cybersecurity Governance and Riskm Chicago, IL The Manager, Cybersecurity Governance and Risk will lead IT risk management (ITRM) initiatives to increase the transparency of risk impacts to the firm, manage the Cyber risk register, issue log, facilitate the...Suggested
- ...your mark with the world’s largest equipment rental provider, come build your future with United Rentals! The Sr. Manager of Cybersecurity GRC (Gov, Risk Mgt & Comp) is a leader responsible for shaping the firm’s governance, risk, compliance, and data privacy posture....SuggestedHourly payContract workWork at office
$150k - $200k
A global cybersecurity leader is seeking a Sr. Product Manager in Dallas to drive product development and enhance customer value through data-driven decision-making. The ideal candidate will have over 5 years of product management experience, 2 years in cybersecurity, and...Suggested$150k - $200k
A leading cybersecurity firm in San Francisco is seeking a Sr. Product Manager to drive product development from concept to launch. The ideal candidate will have over 5 years of software product management experience, with at least 2 years in cybersecurity. Strong analytical...- LAM RESEARCH Corporation is seeking an IT Audit Manager in Tualatin, Oregon. This role involves leading a team of IT auditors in evaluating... ...and on-site days. Strong communication skills and experience in cybersecurity are preferred. #J-18808-Ljbffr LAM RESEARCH CorporationFlexible hours
- ...Job Description Position Summary The Sr. Manager of Cybersecurity Third-Party Risk Management leads the enterprise program responsible for identifying, assessing, monitoring, reporting, and reducing cybersecurity risks introduced by suppliers, vendors, service...Contract workFor contractorsFor subcontractorWork at officeLocal areaWork from home
$100k - $135k
Operational Risk Manager - Cybersecurity Citizens currently has an opening for a Manager on our Operational Risk Management Oversight team focused on Cybersecurity risk. The role will provide independent oversight, review, and challenge of information security and technology...Local areaMonday to FridayFlexible hours- ...firm is looking for an experienced IT/IS Audit Manager to join their Corporate Audit Services team.... ...security, requiring robust knowledge in risk management and a master's degree. Ideal candidates will have cybersecurity certifications and significant experience in...
$175k - $200k
A leading government support provider is seeking a Cybersecurity Manager to oversee all cybersecurity operations and ensure compliance with government regulations. Candidates must have at least 5 years of experience in information assurance and security operations, hold...Work at office- THIS OPPORTUNITY IS FULLY ONSITE AT OUR COROPRATE OFFICE IN WARREN, RI. The Cybersecurity Program & Risk Manager is accountable for owning, integrating, and advancing the organization’s enterprise cybersecurity risk posture. This role goes beyond program coordination...Contract workTemporary workWork at office
$192k - $278k
Google Inc. is hiring a Technical Program Manager for Technology Cyber Security to oversee risk and compliance for data center operational technology. The role requires 10 years of experience in security systems and excellent program management skills. This position will...- Lindt in Kansas City is looking for an IT Manager, Cybersecurity, to provide strategic vision, ensuring compliance and effective governance of IT security. Responsibilities include overseeing technology governance, developing IT security strategies, and mentoring team...
$119.6k - $197.35k
A leading pediatric care provider in Chicago seeks a Cybersecurity Program Manager to drive the organization’s cybersecurity initiatives. This role requires extensive experience in cybersecurity and strong program management skills to ensure successful delivery of multi...- ...Sr. Manager - Cybersecurity and Identity Management Date: May 9, 2026 Location: Oklahoma City, OK, US, 73118Spring, TX, US, 77389 Company... ...identifying, assessing, and managing material cybersecurity risks associated with information systems, digital platforms, and...For contractorsWork experience placementRemote work
- ...Director, Cyber And Information Risk Lead The Cyber and Information Risk Program... ...execution of company's Enterprise Risk Management and Operational Risk Management programs... ...Information Management, Computer Engineering, Cybersecurity or equivalent). M.S. desired. ·...
$62.59 - $93.9 per hour
...Cyber Risk Manager Seattle City Light, a department of the City of Seattle, is one of the nation's largest municipally owned utilities... ...leading the cyber risk management function, ensuring that cybersecurity risks are identified, assessed, mitigated, and monitored...Hourly payWork experience placement- ...PST time zone) Job Description:- As the Senior Cyber Risk Manager, you will be responsible for overseeing the identification,... ...Minimum of 10 years of experience in technology risk management, cybersecurity, or information security roles. Proven expertise in...Contract workRemote work
- ...ASSYST is seeking a Senior Project Manager with demonstrated experience managing Information... ...Manager will lead and coordinate cybersecurity assessment initiatives to strengthen and... ...will drive actionable outcomes to enhance risk management and improve overall cybersecurity...Contract workFor contractorsLocal areaFlexible hours
- ...A leading professional services firm is seeking a Manager in Technology Risk Assurance with a focus on cybersecurity risk. Candidates should possess a solid understanding of cybersecurity fundamentals and have at least 5 years of relevant experience. Responsibilities...Full time
- ...A global professional services firm is seeking a highly motivated Manager in Technology Risk Assurance - Cybersecurity Assurance. This role involves managing client engagement teams, focusing on cybersecurity risk and controls, and driving business development activities...Full timeFlexible hours
$59 - $62 per hour
...mitigate information security and technology risks across our organization's... ...partnerships with engineering, architecture, risk management, compliance, legal, communications,... ...information technologies (e.g., AI / ML); cybersecurity threats and vulnerabilities; risk...Hourly payFull timeLocal areaRemote workFlexible hours- ...Cyber Security Product Risk Manager Airbus U.S. Space & Defense, Inc offers advanced solutions to meet the most complex U.S. defense... ..., implement, and execute Risk Management Framework (RMF) CyberSecurity, CyberResilience, Cyber Survivability requirements of satellite...Contract workWork at officeLocal areaVisa sponsorship
$100k - $135k
Citizens Bank is seeking an Operational Risk Manager focused on Cybersecurity in Johnston, RI or Boston, MA. This role requires oversight of information security risks and active engagement in risk management processes. The ideal candidate should have over 4 years of experience...$100k - $135k
Citizens is seeking a Manager for the Operational Risk Management Oversight team in Boston, focused on Cybersecurity risk. This role entails providing oversight and review of technological risks, advising on complex issues, and participating in incident response activities...$96k - $192k
Carrier Global Corporation is hiring an Insider Risk Manager in New York. This role involves monitoring networks and user activities... ...holds a Bachelor’s Degree and has over 5 years of experience in cybersecurity operations. A competitive salary range of $96,000 to $192,00...$123.84k - $234.77k
...highly dynamic team focused on providing exceptional client service in the areas of risk and advisory? If yes, consider joining Baker Tilly (BT) as an IT Audit, Cybersecurity & Risk Manager (HITRUST)! Our Risk Advisory practice provides a full spectrum of services to...Work experience placementLocal areaWorldwide- Capital One is hiring a Manager for Cyber Technical ISO in Plano, Texas. This role involves consulting on... ...Security initiatives and managing cyber security risks. Candidates should have strong experience in cybersecurity concepts, risk assessments, and cloud infrastructure...
- ...Information Security for their business operations. The role involves acting as a central contact for cybersecurity, coordinating security consulting efforts, and providing risk assessments. Candidates must have extensive experience in Cloud security and architecture design....
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Manager, Cybersecurity Risk Management. Be the first to apply!
- cyber security lead United States
- director - cyber security United States
- cybersecurity project manager United States
- cyber security program manager United States
- cyber security project manager United States
- cybersecurity manager United States
- cyber security account manager United States
- senior manager cyber security United States
- quality risk manager United States
- enterprise risk manager United States

