1

Crisc Jobs (NOW HIRING)

Certifications related to the candidate's coverage responsibilities are preferred, such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), and ...

Cyber security manager

Atlanta, GA · On-site

$106K - $144K/yr

... CRISC, GSEC, or CCSP • Strong knowledge of NIST CSF, NIST 800-53, ISO 27001, CIS Controls & MITRE ATT&CK • AWS, Azure, or Google Cloud Platform Security experience • Experience with Qualys ...

Showing results 21-40

Crisc information

See salary details

$10

$16

$21

How much do crisc jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for crisc in the United States is $16.76, according to ZipRecruiter salary data. Most workers in this role earn between $15.14 and $18.27 per hour, depending on experience, location, and employer.

What is a CRISC?

A CRISC (Certified in Risk and Information Systems Control) job involves identifying, assessing, and managing IT and enterprise risks. Professionals in this role develop and implement information system controls to mitigate risks and ensure compliance with industry regulations. Typical job titles include IT Risk Manager, Security Analyst, and Compliance Officer. CRISC-certified individuals work closely with stakeholders to align risk management strategies with business objectives.

What are the key skills and qualifications needed to thrive in a CRISC position?

To thrive as a CRISC (Certified in Risk and Information Systems Control) professional, you need expertise in risk management, information systems controls, and business process analysis, typically underpinned by the CRISC certification. Familiarity with risk assessment tools, governance frameworks like COBIT, and IT audit systems is essential. Strong analytical thinking, effective communication, and stakeholder collaboration skills set top performers apart in this field. These skills ensure the effective identification and management of IT risks, safeguarding organizational assets and supporting compliance goals.

What are the typical daily responsibilities of someone in a CRISC role?

CRISC-certified professionals are primarily responsible for identifying, assessing, and managing enterprise IT risks on a daily basis. Their tasks often include conducting risk assessments, implementing risk mitigation strategies, updating risk registers, and ensuring that IT controls align with organizational objectives. They frequently collaborate across departments, working with IT teams, auditors, and business leaders to understand risk impact and communicate findings. This role requires staying up-to-date with regulatory changes and industry standards to ensure ongoing compliance and effective risk management.

More about Crisc jobs

What cities are hiring for Crisc jobs?

Cities with the most Crisc job openings:

What are the most commonly searched types of Crisc jobs?

The most popular types of Crisc jobs are:

What states have the most Crisc jobs?

States with the most job openings for Crisc jobs include:

Infographic showing various Crisc job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 1% Part Time, 1% Temporary, and 4% Contract. Highlights an 74% Physical, 10% Hybrid, and 16% Remote job distribution, with an average salary of $34,865 per year, or $16.8 per hour.

IT Consultant 1 / ITC1 (Security Resource)

SmartIPlace

Columbus, OH • Remote

$55 - $60/hr

Contractor

Re-posted 20 days ago


Job description

Key Responsibilities:

  1. Risk Assessment and Analysis
  1. Lead complex IT risk assessments and threat modeling activities across systems and applications.
  2. Analyze trends and emerging risks to proactively recommend strategic mitigations.
  1. Risk Mitigation and Management
  1. Develop and oversee implementation of advanced risk mitigation strategies.
  2. Monitor risk programs and revise controls based on performance metrics and audit outcomes.
  1. Compliance and Governance
  1. Ensure enterprise-wide compliance with federal and state regulations, including HIPAA, IRS Pub. 1075, NIST 800-53, MARS-E, and ISO standards.
  2. Support policy lifecycle management and contribute to enterprise GRC strategy.
  1. Incident Management
  1. Provide leadership in incident response and post-incident reviews.
  2. Collaborate with internal teams on root cause analysis and long-term remediation planning.
  1. Review System Security Plans (SSPs)
  1. Review, update, and validate system security documentation for critical systems.
  2. Ensure alignment with internal risk policies, external contractual requirements, and frameworks such as NIST and CIS.
  1. External Audit Support
  1. Serve as a key liaison to auditors and regulatory assessors.
  2. Oversee evidence collection, audit response documentation, and control testing coordination.
  1. IT Security Policy Leadership
  1. Lead the creation and revision of organizational IT security policies.
  2. Recommend and draft policy enhancements based on risk assessment results, audit findings, and regulatory changes.
  1. Reporting and Documentation
  1. Prepare and deliver executive-level reporting on risk posture, findings, and recommendations.
  2. Maintain thorough documentation aligned with organizational and audit standards.
  1. Collaboration and Communication
  1. Represent IT risk in executive discussions, technical project meetings, and external partner engagements.
  2. Coach and mentor junior staff, IT and business personnel.

Qualifications:

  • Education:
    Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field is required.
    Master’s degree in a related field preferred.
  • Experience:
    Minimum of 7 to 10 years of experience in IT risk management, cybersecurity, or information assurance.
    Demonstrated success leading cross-functional projects and managing compliance for large systems. Experiences in Heath and Human Services or Healthcare business preferred.
  • Certifications (Preferred):
    CISA, CISSP, CRISC, CISM, CGEIT, or similar credentials.
  • Technical Skills:
    Expertise in risk frameworks (NIST 800-53, MARS-E, ISO 27001), vulnerability management, system security plans, and audit lifecycle management.
  • Analytical Skills:
    Exceptional critical thinking, data analysis, and risk prioritization abilities.
  • Communication Skills:
    Strong verbal and written communication skills with the ability to tailor information to different audiences, including executives.

Interpersonal Skills:
Demonstrated ability to collaborate across teams, influence without authority,and drive organizational change

Skills

Required / Desired

Required  Amount of Experience in years

Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field is required.

Required

 

Master’s degree in a related field preferred.

Highly desired

 

Minimum of 7 to 10 years of experience in IT risk management, cybersecurity, or information assurance

Required

10

Experiences in Heath and Human Services or Healthcare business preferred.

Highly desired

 

CISA, CISSP, CRISC, CISM, CGEIT, or similar credentials.

Highly desired

 

Expertise in risk frameworks (NIST 800-53, MARS-E, ISO 27001), vulnerability management, system security plans, and audit lifecycle management.

Required

7

Demonstrated ability to collaborate across teams, influence without authority, and drive organizational change

Required

7


Smart-iPlace logo

About Smart-iPlace

Sourced by ZipRecruiter

SMART-iPLACE provides innovative staffing and consulting solutions that help our clients achieve their business objectives. We can understand and support all areas of your IT systems from back-end infrastructure to front-end personal productivity. Our goal is create innovative IT solutions that enable your business to be more agile and competitive.

Industry

It services

Company size

51 - 200 Employees

Headquarters location

Irving, TX, US

Year founded

2021

Social media