1

Cisa Risk Management Jobs (NOW HIRING)

... management Analytical skills Research skills Risk assessment Policy development Incident response Employee training Statistical Analysis Software CISSP certification CISM certification CISA ...

Possess or in the process of obtaining a relevant risk or business certification such as CPA, CIA, CISA, or CISM. Skills: * Service Now IRM. * Service Now TPRM. * Risk Management. * Third Party Risk ...

Possess or in the process of obtaining a relevant risk or business certification such as CPA, CIA, CISA, or CISM. Skills: * Service Now IRM. * Service Now TPRM. * Risk Management. * Third Party Risk ...

Leidos is seeking a Supply Chain Risk Management Analyst to provide technical and analytical ... Certified Information Systems Auditor (CISA) * Specialized federal SCRM or Counterintelligence ...

Leidos is seeking a Supply Chain Risk Management Analyst to provide technical and analytical ... Certified Information Systems Auditor (CISA) * Specialized federal SCRM or Counterintelligence ...

Showing results 21-40

Cisa Risk Management information

See salary details

$51.5K

$111.6K

$170K

How much do cisa risk management jobs pay per year?

As of Sep 11, 2026, the average yearly pay for cisa risk management in the United States is $111,556.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,000.00 and $129,000.00 per year, depending on experience, location, and employer.

What is CISA Risk Management?

CISA Risk Management refers to the processes and frameworks used by Certified Information Systems Auditors (CISA) to identify, assess, and mitigate risks associated with information systems. Professionals in this field evaluate IT environments, identify potential vulnerabilities, and recommend controls to minimize risks to an organization's data and operations. Effective risk management ensures compliance with industry standards and protects businesses from cybersecurity threats and regulatory fines.

How does a CISA Risk Management professional typically collaborate with other departments to address IT audit findings?

CISA Risk Management professionals regularly work with IT, compliance, and business operations teams to communicate audit findings and develop action plans. They facilitate meetings to clarify risks, prioritize remediation efforts, and ensure that corrective actions are practical and aligned with organizational goals. Effective collaboration is essential for timely resolution of issues and for fostering a culture of continuous improvement in IT controls and risk mitigation.

What are the key skills and qualifications needed to thrive as a CISA Risk Management professional, and why are they important?

To excel in CISA Risk Management, professionals need a solid understanding of IT auditing, information systems controls, and risk assessment, typically backed by a CISA certification and experience in cybersecurity or compliance. Familiarity with risk management frameworks (such as COBIT or NIST), audit management tools, and GRC (Governance, Risk, and Compliance) platforms is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help distinguish top performers in this role. These capabilities are crucial for ensuring robust information security, regulatory compliance, and effective risk mitigation within organizations.

What is the difference between Cisa Risk Management vs Cisa Security Analyst?

AspectCisa Risk ManagementCisa Security Analyst
CertificationsCISA, CRISC (sometimes)CISA, CISSP (sometimes)
Work EnvironmentRisk assessment, compliance, audit environmentsSecurity monitoring, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk management, audit firms, consultingIT security teams, cybersecurity firms, corporate security departments

While both roles require CISA certification and involve information security, Cisa Risk Management focuses on assessing and managing organizational risks and compliance, whereas Cisa Security Analyst concentrates on monitoring security threats and responding to incidents. The roles often overlap but serve different core functions within cybersecurity and risk management frameworks.

Are CISA Risk Management professionals in demand?

CISA Risk Management professionals are in high demand due to increasing cybersecurity threats and the need for organizations to comply with regulatory standards. They often require knowledge of risk assessment, control frameworks, and certifications like CISA to qualify for roles in cybersecurity and IT audit teams.

Is CISA an entry-level job?

CISA (Certified Information Systems Auditor) is a certification often pursued by professionals with some experience in IT and cybersecurity, rather than an entry-level position. Entry-level roles in risk management or cybersecurity may require foundational knowledge and certifications like CISA, but the certification itself is typically obtained after gaining work experience. Therefore, CISA is generally not considered an entry-level job but a credential for more experienced professionals.

Is CISA risk management still in demand?

CISA risk management professionals are in high demand due to increasing cybersecurity threats and the need for organizations to comply with security standards. Skills in risk assessment, audit, and familiarity with frameworks like COBIT and NIST enhance job prospects in this field.

What are popular job titles related to Cisa Risk Management jobs?

For Cisa Risk Management jobs, the most frequently searched job titles are:

Infographic showing various Cisa Risk Management job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 82% Full Time, 15% Part Time, and 2% Contract. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution, with an average salary of $111,556 per year, or $53.6 per hour.

Cybersecurity Risk Manager

Chicago, IL • On-site

Other

Posted 12 days ago


Job description

Softchoice is a software-focused IT solutions and services provider that helps organizations innovate and enhance their technology decisions. The Cybersecurity Risk Manager will identify, assess, and mitigate risks affecting the company's financial health and compliance, while leading the development of a robust cybersecurity risk management program.

Cloud Computing Enterprise Software Information Technology Collaboration

Responsibilities

Take ownership for, mature our Risk Management governance/process, and leverage the broader teams for execution of risk remediation based on priorities and risk appetite

Set strategic direction for cybersecurity risk management, and related compliance initiatives

Develop and maintain a cybersecurity risk framework aligned with ISO 27001

Establish robust governance structures to oversee risk and compliance activities

Guide the organization through compliance audits and engagements with auditors

Oversee risk assessments to define and analyze possible risks, ensuring a comprehensive approach to risk identification

Evaluate the gravity (risk score) of each risk by considering potential organizational impact

Develop, prioritize, and lead the execution of risk treatment plans and control measures

Monitor and ensure evidence-based implementation of controls to achieve compliance

Drive process changes to eliminate or mitigate potential risks

Drive the execution of appropriate technology platform access reviews

Present risk score updates for ISMS committee and recommendations for senior leadership review

Define and implement contingency plans and incident response playbooks to handle cybersecurity crises effectively

Assess existing policies and procedures, identifying gaps and opportunities for improvement as relates to risk management

Recommend and drive the adoption of improved policies to strengthen the organization's cybersecurity posture

Drive initiatives to enhance employees' understanding of cybersecurity risks and best practices

Provide strategic direction, mentorship, and guidance to cross-functional teams involved in cybersecurity risk activities

Lead, motivate, and develop direct and indirect reports to excel in their roles. (future once ICs added under)

Qualification

Cybersecurity governance Risk management ISO 27001 Compliance audits Security operations Project management Analytical skills Research skills Risk assessment Policy development Incident response Employee training Statistical Analysis Software CISSP certification CISM certification CISA certification CRISC certification Professional Risk Manager Leadership Communication skills Problem-solving Team collaboration Technical writing

Required

10-15 years' experience in IT including security operations (SOC)

5 years experience managing people directly and indirectly

At least 5 years working in cybersecurity governance, risk, and compliance (GRC)

Demonstrated knowledge of risk management in the context of cybersecurity, IT compliance, risk assessment, and control

Demonstrated understanding of security practices, trends, and compliance audits

Knowledge of auditing against information security management frameworks (SOC2T2, ISO 27001:2022)

Proven project management approach to drive outcomes is mandatory

Bachelor's or master's degree in computer science, engineering, information security, or a related field

Relevant certifications such as CISSP, CISM, CISA, CRISC

Analytical mind with problem-solving aptitude

Preferred

Experience as a Security Analyst and/or IT Infrastructure work is desirable

Familiarity with industry compliance standards and regulations (e.g., GDPR, Occupational Safety and Health Act)

Strong computer and research skills; knowledge of analysis software preferred (e.g., Statistical Analysis Software, or SAS)

Professional Risk Manager (PRM) certification is a plus

Competitive Benefits: Benefit from competitive perks that start on day one

IT solutions provider for cloud, AI, software, and digital workplaces.

Cybersecurity governance Risk management ISO 27001 Compliance audits Security operations

#J-18808-Ljbffr