1

Business Risk Manager Jobs in Gainesville, VA (NOW HIRING)

Program Manager, Cybersecurity Risk

Reston, VA · On-site

$110.10 - $176.90/hr

About the Role As a Program Manager on the Cybersecurity Risk team, you will be a hands‑on ... You will partner with business units and stakeholders to identify and assess security issues and ...

Communicate testing results and findings clearly to business partners, risk stakeholders, and various levels of management. * Track testing activities, findings, remediation efforts, and related ...

May manage a Model Risk team and provide guidance, support, and mentorship to team members ... Collaborate with cross-functional teams to understand business needs and requirements and ensure ...

Showing results 21-40

Business Risk Manager information

What are the key skills and qualifications needed to thrive as a business risk manager?

To thrive as a Business Risk Manager, you need strong analytical skills, risk assessment expertise, and a background in finance, business, or a related field, often backed by a bachelor's degree or higher. Familiarity with risk management frameworks, regulatory compliance systems, and certifications like FRM (Financial Risk Manager) or CRM (Certified Risk Manager) is typically required. Exceptional communication, problem-solving, and stakeholder management skills help you effectively identify, mitigate, and communicate risks across an organization. These competencies are crucial for proactively managing threats, ensuring regulatory compliance, and supporting the long-term stability and success of the business.

How does a business risk manager typically collaborate with other departments to address organizational risks?

As a Business Risk Manager, cross-functional collaboration is a key part of the role. You’ll regularly work with departments such as finance, compliance, operations, and IT to identify potential risks, assess their impact, and develop mitigation strategies. This often involves facilitating risk assessment workshops, sharing reports, and ensuring that risk controls are integrated into business processes. Effective communication and relationship-building skills are essential, as you’ll act as a bridge between senior management and operational teams to align risk management efforts with organizational goals.

What is the difference between Business Risk Manager vs Risk Analyst?

AspectBusiness Risk ManagerRisk Analyst
CredentialsCertifications like CRM, FRM, or CRC; bachelor's degree in business, finance, or related fieldCertifications such as FRM or CRM; bachelor's degree in finance, economics, or related field
Work EnvironmentStrategic planning, risk assessment, and policy development in corporate settingsData analysis, risk modeling, and reporting in finance or insurance firms
Employer & IndustryCorporations, financial institutions, insurance companiesFinancial services, consulting firms, insurance companies

The Business Risk Manager focuses on developing risk strategies and policies at a strategic level, while the Risk Analyst primarily conducts data analysis and risk assessments. Both roles require similar certifications and often work within the same industries, but their responsibilities differ in scope and focus.

Do business risk managers make good money?

Business risk managers typically earn a competitive salary that varies based on experience, industry, and location. According to industry data, median annual salaries range from $80,000 to over $120,000, with higher earnings possible for those with advanced certifications or in senior roles. The profession often requires strong analytical skills and knowledge of risk assessment tools.

How much do business risk managers make?

Business risk managers typically earn a median annual salary of around $100,000, with salaries ranging from approximately $70,000 to over $140,000 depending on experience, industry, and location. Advanced certifications and strong analytical skills can lead to higher compensation in this role.

What does a business risk manager do?

A business risk manager identifies, assesses, and develops strategies to mitigate potential risks that could impact an organization's operations, financial health, or reputation. They analyze data, implement risk management frameworks, and work with various departments to ensure compliance and resilience. Strong analytical skills and knowledge of industry regulations are essential for this role.

What job categories do people searching Business Risk Manager jobs in Gainesville, VA look for?

The top searched job categories for Business Risk Manager jobs in Gainesville, VA are:

What cities near Gainesville, VA are hiring for Business Risk Manager jobs?

Cities near Gainesville, VA with the most Business Risk Manager job openings:

Infographic showing various Business Risk Manager job openings in Gainesville, VA as of August 2026, with employment types broken down into 81% Full Time, 16% Part Time, and 3% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution.

Program Manager, Cybersecurity Risk

Reston, VA • On-site

$110.10 - $176.90/hr

Other

Posted 6 days ago


Job description

Your work days are brighter here.

We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.

About the Team

The Cybersecurity Risk team is responsible for cybersecurity risk assessments, security exception management, TPRM, and partner eco-system security.

About the Role

As a Program Manager on the Cybersecurity Risk team, you will be a hands‑on execution partner within our third‑party risk management (TPRM) program, working closely with the Principal Program Manager to assess and manage security risk across our vendor and partner ecosystem. You will conduct third‑party risk assessments, track control gaps and remediation to closure, monitor high‑risk vendors, and support broader cyber risk assessment activities. You will partner with business units and stakeholders to identify and assess security issues and gaps, communicate impact, and help drive remediation actions and timelines.

Responsibilities
  • Third‑Party Risk Assessments: Conduct security risk assessments for third parties — including cloud service providers, SaaS platforms, technology partners, and infrastructure providers — across the third‑party lifecycle (intake, due diligence, ongoing monitoring, and off‑boarding).
  • Issue and Remediation Management: Identify, document, track, and drive remediation of control gaps and security risks through remediation, exception, or formal risk acceptance, and elevate when risks or remediation efforts are insufficient or delayed.
  • Ongoing Monitoring: Monitor critical and high‑risk vendors for control changes, risk signals, remediation progress, and ongoing compliance concerns.
  • Cross‑Functional Collaboration: Partner with Legal, Procurement, Security, Privacy, and business owners to ensure third‑party risks are appropriately documented, communicated, accepted, or mitigated.
  • Documentation and Reporting: Maintain accurate third‑party records, assessment results, and issues within the system of record, and support preparation of metrics, dashboards and management reporting.
  • Broader Risk Support: Support principal‑level risk assessment activities as needed — including security exception reviews and internal control assessments — working under the direction of the Principal Program Manager.
  • Continuous Improvement: Contribute to the maturation of TPRM processes, procedures, and best practices, and support other risk, governance, and program activities as needed.
Basic Qualifications
  • 5+ years of experience in governance, risk, and compliance (GRC), including third‑party / vendor risk management.
  • 2+ years of experience conducting security or third‑party risk assessments across the vendor lifecycle.
  • Bachelor’s degree in a relevant discipline such as Information Security, Computer Science, Risk Management, Business, or a related field, or equivalent practical experience.
Other Qualifications
  • Solid understanding of third‑party / vendor risk management across the lifecycle — intake, due diligence, ongoing monitoring, issue remediation, and off‑boarding.
  • Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and SIG.
  • Familiarity with GRC / TPRM platforms and security‑ratings services (e.g., OneTrust, Archer, ServiceNow, Vanta, BitSight, SecurityScorecard, RiskRecon).
  • Ability to review and interpret technical assurance evidence (e.g., SOC 2 Type II reports, penetration testing results) to evaluate vendor control effectiveness.
  • Understanding of qualitative risk analysis and the ability to translate risk into clear business impact.
  • Awareness of AI/ML vendor risk and how AI‑enabled services are assessed, monitored, and governed.
  • Strong written and verbal communication skills, with the ability to work with both technical and non‑technical stakeholders.
  • Strong attention to detail and the ability to manage multiple assessments and competing priorities in a fast‑paced environment.
  • Certifications such as CRISC, CISA, CISSP, or CISM preferred.
  • Nice to have: some hands‑on automation experience such as scripting or low‑code / no‑code workflow tools used to streamline risk assessments and reporting.
Workday Pay Transparency Statement

The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role‑specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday’s comprehensive benefits, please click here.

Primary Location: USA.VA.Reston

Primary Location Base Pay Range: $110,100 USD - $165,100 USD

Additional US Location(s) Base Pay Range: $99,600 USD - $176,900 USD

Our Approach to Flexible Work

With Flex Work, we’re combining the best of both worlds: in‑person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in‑office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you’ll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.

Equal Opportunity and Accessibility

Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.

At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email accommodations@workday.com.

#J-18808-Ljbffr