1

Cisa Risk Management Jobs (NOW HIRING)

... CPA, CISA, CISM, CISSP, or equivalent Responsibilities The VP, Risk Management serves as the ... dedicated second line risk officer supporting Ratings Operations, providing independent oversight ...

... CPA, CISA, CISM, CISSP, or equivalent Responsibilities The VP, Risk Management serves as the ... dedicated second line risk officer supporting Ratings Operations, providing independent oversight ...

New

... CPA, CISA, CISM, CISSP, or equivalent Responsibilities The VP, Risk Management serves as the ... dedicated second line risk officer supporting Ratings Operations, providing independent oversight ...

CISA, CISM, CRISC, CISSP or related. * Minimum 12 years in financial regulatory risk, internal or ... Minimum 5 years of people management experience. * Proficiency in Microsoft Office applications or ...

next page

Showing results 1-20

Cisa Risk Management information

See salary details

$51.5K

$111.6K

$170K

How much do cisa risk management jobs pay per year?

As of Sep 11, 2026, the average yearly pay for cisa risk management in the United States is $111,556.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,000.00 and $129,000.00 per year, depending on experience, location, and employer.

What is CISA Risk Management?

CISA Risk Management refers to the processes and frameworks used by Certified Information Systems Auditors (CISA) to identify, assess, and mitigate risks associated with information systems. Professionals in this field evaluate IT environments, identify potential vulnerabilities, and recommend controls to minimize risks to an organization's data and operations. Effective risk management ensures compliance with industry standards and protects businesses from cybersecurity threats and regulatory fines.

How does a CISA Risk Management professional typically collaborate with other departments to address IT audit findings?

CISA Risk Management professionals regularly work with IT, compliance, and business operations teams to communicate audit findings and develop action plans. They facilitate meetings to clarify risks, prioritize remediation efforts, and ensure that corrective actions are practical and aligned with organizational goals. Effective collaboration is essential for timely resolution of issues and for fostering a culture of continuous improvement in IT controls and risk mitigation.

What are the key skills and qualifications needed to thrive as a CISA Risk Management professional, and why are they important?

To excel in CISA Risk Management, professionals need a solid understanding of IT auditing, information systems controls, and risk assessment, typically backed by a CISA certification and experience in cybersecurity or compliance. Familiarity with risk management frameworks (such as COBIT or NIST), audit management tools, and GRC (Governance, Risk, and Compliance) platforms is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help distinguish top performers in this role. These capabilities are crucial for ensuring robust information security, regulatory compliance, and effective risk mitigation within organizations.

What is the difference between Cisa Risk Management vs Cisa Security Analyst?

AspectCisa Risk ManagementCisa Security Analyst
CertificationsCISA, CRISC (sometimes)CISA, CISSP (sometimes)
Work EnvironmentRisk assessment, compliance, audit environmentsSecurity monitoring, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk management, audit firms, consultingIT security teams, cybersecurity firms, corporate security departments

While both roles require CISA certification and involve information security, Cisa Risk Management focuses on assessing and managing organizational risks and compliance, whereas Cisa Security Analyst concentrates on monitoring security threats and responding to incidents. The roles often overlap but serve different core functions within cybersecurity and risk management frameworks.

Are CISA Risk Management professionals in demand?

CISA Risk Management professionals are in high demand due to increasing cybersecurity threats and the need for organizations to comply with regulatory standards. They often require knowledge of risk assessment, control frameworks, and certifications like CISA to qualify for roles in cybersecurity and IT audit teams.

Is CISA an entry-level job?

CISA (Certified Information Systems Auditor) is a certification often pursued by professionals with some experience in IT and cybersecurity, rather than an entry-level position. Entry-level roles in risk management or cybersecurity may require foundational knowledge and certifications like CISA, but the certification itself is typically obtained after gaining work experience. Therefore, CISA is generally not considered an entry-level job but a credential for more experienced professionals.

Is CISA risk management still in demand?

CISA risk management professionals are in high demand due to increasing cybersecurity threats and the need for organizations to comply with security standards. Skills in risk assessment, audit, and familiarity with frameworks like COBIT and NIST enhance job prospects in this field.

What are popular job titles related to Cisa Risk Management jobs?

For Cisa Risk Management jobs, the most frequently searched job titles are:

Infographic showing various Cisa Risk Management job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 82% Full Time, 15% Part Time, and 2% Contract. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution, with an average salary of $111,556 per year, or $53.6 per hour.

Risk Management Analyst

Sacramento, CA • On-site

West Advanced Technologies (WATI)
Computer and Electronic Product Manufacturing • 1 - 10 employees

Full-time

Re-posted 26 days ago


Job description

Position: Risk Management Analyst
Location: Sacramento, CA
Duration: 12 Months
Minimum Skills:
  • Must understand the current security threats model and demonstrate a strong willingness to stay at the forefront of security developments
  • Knowledge of risk assessment methodologies, IT policies and standards development
  • Working knowledge of common IT security impacted regulations and/or standards such as ISO/IEC 27001/2, NIST, PCI, and HIPAA.
  • Experience with audit processes and disciplines including third party risk management.
  • Working knowledge of industry leading GRC practices
  • 5+ years of experience in an IT Security/IT Risk environment with a large regulated organization
  • Experience with development and administration of risk assessments, reviews, corrective action planning
  • Must possess strong oral and written communication skills to assist in maintaining documentation, updating manuals, and producing reports
  • Have the ability to multi-task and adjust to shifting priorities, have keen analytical skills and be a critical thinker, as well as exhibit a high-level of attention
  • Must be highly motivated, dependable, and punctual

Certification Required : One or more industry certifications such as CISSP, CISM, CRISC, GSEC and CISA required
Thanks & Regards
Rajeev
West Advanced Technologies, Inc
E: *************
C:9162095915 | 5072292946