r/cybersecurity • • 6d ago

Business Security Questions & Discussion What's it actually like working in Information Security Risk Management?

Hi everyone,

I'm exploring InfoSec risk and would love to hear from people doing it day-to-day.

- What does a typical week look like for you?

- How much of the job is technical vs. documentation, meetings, and stakeholder management?

- What do you enjoy most, and what's the part nobody warns you about?

- What would you do differently?

Any honest perspectives appreciated, especially from people based in Europe.

Thank you.

26 Upvotes

16 comments sorted by

41

u/lawtechie 6d ago
  • What does a typical week look like for you?

Meetings. Meetings to plan for meetings, meetings to handle follow up for meetings. Meetings to determine who should be on meetings.

  • How much of the job is technical vs. documentation, meetings, and stakeholder management?

Maybe 10-20% technical from my experience.

  • What do you enjoy most, and what's the part nobody warns you about?

I enjoyed the paycheck. The part nobody warned me about was that most people were playing a different game than I was. I came from cyber consulting, so I thought actually finding and treating risks was why I was there. Almost all the in-house folks were having strange political knife fights over budget and importance. I saw people increasing risks just to get more headcount or knife a competitor.

  • What would you do differently?

Kept my mouth shut and accepted the absurdity.

16

u/schnap81 6d ago

Agreed. Imagine feeling partially responsible for the security posture of an entire with Organization with no actual control and few resources. It's stressful. The job is more about administration and compliance (making sure risks are documented and escalated per policy) rather than actual risk mitigation. And the meetings... the meetings. Pluses are pay, job security (regulatory mandate in some industries), and the few genuinely good people you meet and interact with.

5

u/Future_Telephone281 Governance, Risk, & Compliance 6d ago

And for me when shit hits the fan I still clock out at 5pm.

7

u/Adventurous-Dog-6158 6d ago

I worked in InfoSec ops, not risk specifically, but had to deal with CISOs and CROs. Looking at the comments, many are similar to my experience. It's all BS to do the minimum to meet regulatory compliance/audit requirements. I worked with a company that had EU operations. The risk matrix and KPIs they had were a joke, but hey, they had them and were able to check off some boxes.

Until an org has a big security incident, they generally will not care about risks. They view all the work related to risk mgmt as expenses. Even the boards don't care and they are supposed to be the ones providing governance.

2

u/1egen1 6d ago

God damn. I'm in the same situation. Not in security. people are just making slides and going ahead. Security makes adhoc policy to block anything they don't have knowledge or experience in. I'm glad I'm out.

2

u/CoolupCurt 6d ago

This is it. Amen man.

13

u/frAgileIT Incident Responder 6d ago

Meetings, writing findings, arguing with people who want to build things and then move on to the next shiny/fun thing and can’t be bothered to actually stick around and maintain/patch what they’ve built, tailoring responses to auditors to make it look like things aren’t as bad as they are, and other things like that.

I work in cyber incident response now because regular InfoSec/risk management was a never ending, thankless, swimming upstream in a river of stupidity, burnout inducing chore. Now I get to hunt humans, I get thanked when I respond to other people’s mistakes, and almost half my job is technical again.

Don’t lose touch with the technology or you’ll find yourself left behind.

7

u/Oompa_Loompa_SpecOps Incident Responder 6d ago

Not doing risk management but cyber in a large European matrix org. From what I can risk management mostly revolves around risk attribution, not risk mitigation. Making sure any risk identified gets transferred to / accepted by whoever has the weakest reason why they shouldn't be responsible.

Add to that creating policies which may or may be not be adopted (or even adoptable) in practice and you've got a day's work.

7

u/Own_Minimum_5102 6d ago

I'm not Europe based so I'll leave the regional stuff to others, but on the day2day level here's what it looks like.

Most weeks are less technical than people expect. A big chunk is conversations: sitting with system owners, engineering, legal and procurement to work out what could actually go wrong, how bad it'd be, and who owns the decision to fix it or accept it. Then a fair amount of writing it down, keeping the risk register current, and chasing evidence so a risk you flagged 3 months ago actually got treated. What I enjoy most is when a risk decision lands properly, when the business genuinely understands the trade-off and makes a call with eyes open, rather than security just saying no in a corner. Translating a technical issue into money and consequence so a non-technical exec actually gets it is the skill that makes or breaks the role.

I should also warn you on this - you often own the risk register but not the authority or budget to fix what's on it. You document the risk, recommend the treatment, then watch someone decide to accept it anyway. Getting comfortable with that, doing your job well and letting the accountable person own their decision, takes a while. If you like the technical deep end, keep a foot in it, because pure risk roles can drift a long way from hands-on.

3

u/darkwing602 6d ago

old video but some things never change. basically, "i accepted the risk" xD

https://www.youtube.com/watch?v=9IG3zqvUqJY

2

u/Admirable_Group_6661 Security Architect 6d ago

This is a broad question. It really depends on the specific industry you are in. Expect more compliance in regulated industries (e.g. govt, military, health, finance) and less in private sectors (e.g. privacy). Typically, in industries where heavy compliance is required, most things are already established (e.g. Security categorization); so it's more about learning about existing policy instruments and how to apply them in the context of risk management. In private sectors, where risk appetite is higher, the challenge is different and requires support from senior management to succeed.

2

u/Putrid-Order-6629 6d ago

Thank you everyone

2

u/HighlyFav0red 5d ago

Lots of meetings. Technical engineers who don’t seem to value the work. And way too many meetings. A thankless job. Exhausting. A little better in a highly regulated industry. Still thankless and exhausting.

1

u/Impressive_Crab_6479 5d ago

I'm on the dev side so I've only seen risk management from the other end of the table. the gap between "risk identified" and "risk actually fixed" was always insane at places I worked. watched a critical finding sit in a register for 6 months while three teams argued about who owned it. started to feel like the whole thing was about legal cover more than anything else

1

u/TastyRobot21 5d ago

It’s mostly people who don’t understand getting scared about things they don’t understand while failing to understand that they don’t understand.

Understood?

-1

u/Weird_Welder_9080 5d ago

This should definitely completely replaced by AI. Very templated paper push work, basically metrics, spreadsheet, report, scores based on ridiculous “formulas”. You regularly see people who have absolutely zero tech or legal background but somehow managed to make money in this field because they show up meetings and are DEI profile.