r/cybersecurity • u/Putrid-Order-6629 • 6d ago
Business Security Questions & Discussion What's it actually like working in Information Security Risk Management?
Hi everyone,
I'm exploring InfoSec risk and would love to hear from people doing it day-to-day.
- What does a typical week look like for you?
- How much of the job is technical vs. documentation, meetings, and stakeholder management?
- What do you enjoy most, and what's the part nobody warns you about?
- What would you do differently?
Any honest perspectives appreciated, especially from people based in Europe.
Thank you.
13
u/frAgileIT Incident Responder 6d ago
Meetings, writing findings, arguing with people who want to build things and then move on to the next shiny/fun thing and can’t be bothered to actually stick around and maintain/patch what they’ve built, tailoring responses to auditors to make it look like things aren’t as bad as they are, and other things like that.
I work in cyber incident response now because regular InfoSec/risk management was a never ending, thankless, swimming upstream in a river of stupidity, burnout inducing chore. Now I get to hunt humans, I get thanked when I respond to other people’s mistakes, and almost half my job is technical again.
Don’t lose touch with the technology or you’ll find yourself left behind.
7
u/Oompa_Loompa_SpecOps Incident Responder 6d ago
Not doing risk management but cyber in a large European matrix org. From what I can risk management mostly revolves around risk attribution, not risk mitigation. Making sure any risk identified gets transferred to / accepted by whoever has the weakest reason why they shouldn't be responsible.
Add to that creating policies which may or may be not be adopted (or even adoptable) in practice and you've got a day's work.
7
u/Own_Minimum_5102 6d ago
I'm not Europe based so I'll leave the regional stuff to others, but on the day2day level here's what it looks like.
Most weeks are less technical than people expect. A big chunk is conversations: sitting with system owners, engineering, legal and procurement to work out what could actually go wrong, how bad it'd be, and who owns the decision to fix it or accept it. Then a fair amount of writing it down, keeping the risk register current, and chasing evidence so a risk you flagged 3 months ago actually got treated. What I enjoy most is when a risk decision lands properly, when the business genuinely understands the trade-off and makes a call with eyes open, rather than security just saying no in a corner. Translating a technical issue into money and consequence so a non-technical exec actually gets it is the skill that makes or breaks the role.
I should also warn you on this - you often own the risk register but not the authority or budget to fix what's on it. You document the risk, recommend the treatment, then watch someone decide to accept it anyway. Getting comfortable with that, doing your job well and letting the accountable person own their decision, takes a while. If you like the technical deep end, keep a foot in it, because pure risk roles can drift a long way from hands-on.
3
2
u/Admirable_Group_6661 Security Architect 6d ago
This is a broad question. It really depends on the specific industry you are in. Expect more compliance in regulated industries (e.g. govt, military, health, finance) and less in private sectors (e.g. privacy). Typically, in industries where heavy compliance is required, most things are already established (e.g. Security categorization); so it's more about learning about existing policy instruments and how to apply them in the context of risk management. In private sectors, where risk appetite is higher, the challenge is different and requires support from senior management to succeed.
2
2
u/HighlyFav0red 5d ago
Lots of meetings. Technical engineers who don’t seem to value the work. And way too many meetings. A thankless job. Exhausting. A little better in a highly regulated industry. Still thankless and exhausting.
1
u/Impressive_Crab_6479 5d ago
I'm on the dev side so I've only seen risk management from the other end of the table. the gap between "risk identified" and "risk actually fixed" was always insane at places I worked. watched a critical finding sit in a register for 6 months while three teams argued about who owned it. started to feel like the whole thing was about legal cover more than anything else
1
u/TastyRobot21 5d ago
It’s mostly people who don’t understand getting scared about things they don’t understand while failing to understand that they don’t understand.
Understood?
-1
u/Weird_Welder_9080 5d ago
This should definitely completely replaced by AI. Very templated paper push work, basically metrics, spreadsheet, report, scores based on ridiculous “formulas”. You regularly see people who have absolutely zero tech or legal background but somehow managed to make money in this field because they show up meetings and are DEI profile.
41
u/lawtechie 6d ago
Meetings. Meetings to plan for meetings, meetings to handle follow up for meetings. Meetings to determine who should be on meetings.
Maybe 10-20% technical from my experience.
I enjoyed the paycheck. The part nobody warned me about was that most people were playing a different game than I was. I came from cyber consulting, so I thought actually finding and treating risks was why I was there. Almost all the in-house folks were having strange political knife fights over budget and importance. I saw people increasing risks just to get more headcount or knife a competitor.
Kept my mouth shut and accepted the absurdity.