1

Director Technology Risk Management Jobs in Clearwater, FL

IT Enterprise Risk Analyst

Tampa, FL · On-site

$80 - $100/hr

The role manages the firm's GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications. Key Responsibilities * Policy, Standards and ...

Develop and implement meaningful risk management strategy to ensure the company identifies, assesses, and mitigates enterprise risk. * Work with business unit leaders to identify, document, and ...

The Opportunity As a Director, Risk Management, you will lead a high-performing team responsible ... technologies, with demonstrated experience building scalable data solutions, dashboards, and risk ...

The IT Risk Analyst helps manage the Firm's GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications. Reporting to the IT Enterprise ...

next page

Showing results 1-20

Director Technology Risk Management information

See Clearwater, FL salary details

$49.8K

$132K

$239.6K

How much do director technology risk management jobs pay per year?

As of Sep 8, 2026, the average yearly pay for director technology risk management in Clearwater, FL is $131,970.00, according to ZipRecruiter salary data. Most workers in this role earn between $97,200.00 and $154,400.00 per year, depending on experience, location, and employer.

What does a director of technology risk management do?

A Director of Technology Risk Management is responsible for identifying, assessing, and mitigating technology-related risks within an organization. They develop and implement policies, frameworks, and strategies to ensure that IT systems and processes comply with regulatory requirements and best practices. Their work helps protect the company's data, assets, and reputation from threats such as cyberattacks, data breaches, and system failures. They also collaborate with other departments to promote a culture of risk awareness and provide guidance on risk-related matters.

How does a director of technology risk management typically collaborate with other departments to ensure effective risk mitigation?

A Director of Technology Risk Management works closely with IT, compliance, legal, and business operations teams to identify and address technology risks. This involves leading cross-functional risk assessments, facilitating communication between technical and non-technical stakeholders, and ensuring that risk mitigation strategies align with organizational goals. Regular meetings, workshops, and reporting structures are established to maintain transparency and drive a culture of risk awareness across departments. Effective collaboration is essential for implementing controls and responding proactively to emerging threats.

What are the key skills and qualifications needed to thrive as a director of technology risk management, and why are they important?

To excel as a Director of Technology Risk Management, a strong background in information security, risk assessment, regulatory compliance, and a relevant degree such as in computer science or information systems is essential. Familiarity with risk management frameworks (such as NIST, ISO 27001), GRC (Governance, Risk, and Compliance) platforms, and certifications like CISSP or CISM are commonly required. Leadership, strategic thinking, and effective communication skills are vital for driving risk initiatives and collaborating across business units. These competencies ensure robust risk mitigation, regulatory adherence, and alignment of technology strategies with organizational goals.

What is the difference between Director Technology Risk Management vs Cybersecurity Manager?

AspectDirector Technology Risk ManagementCybersecurity Manager
Primary FocusOverseeing technology risk strategies and enterprise risk mitigationManaging cybersecurity operations and security measures
CertificationsCRISC, CISSP, CISMCISSP, CISA, CEH
Work EnvironmentStrategic, cross-departmental, executive levelOperational, technical teams, security operations centers
Industry UsageFinancial, healthcare, large enterprisesIT security firms, corporate IT departments

The main difference is that the Director Technology Risk Management focuses on broad technology risk strategies across the organization, while the Cybersecurity Manager concentrates on implementing and managing cybersecurity measures. Both roles require similar certifications but differ in scope and strategic versus operational responsibilities.

What job categories do people searching Director Technology Risk Management jobs in Clearwater, FL look for?

The top searched job categories for Director Technology Risk Management jobs in Clearwater, FL are:

What cities near Clearwater, FL are hiring for Director Technology Risk Management jobs?

Cities near Clearwater, FL with the most Director Technology Risk Management job openings:

Infographic showing various Director Technology Risk Management job openings in Clearwater, FL as of September 2026, with employment types broken down into 100% Full Time. Highlights an 91% In-person, and 9% Remote job distribution, with an average salary of $131,970 per year, or $63.4 per hour.

IT Enterprise Risk Analyst

Tampa, FL • On-site

Holland & Knight
Law Firms • 1 - 5K employees

$80 - $100/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 9 days ago


Holland & Knight rating

8.3

Company rating: 8.3 out of 10

Based on 8 frontline employees who took The Breakroom Quiz

18th of 35 rated law firms


Job description

Overview

We are a firm that strives for the highest standards of performance and success. This position, based in the firm’s global operations center in Tampa, FL, seeks an IT Enterprise Risk Analyst to join our team. The role manages the firm’s GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications.

Key Responsibilities
  • Policy, Standards and Governance: support development, review, and maintenance of information security and technology risk policies, standards, procedures, and guidance documents; maintain policy‑lifecycle processes, stakeholder reviews, approvals, version control; map policies to ISO, NIST, CIS, SOC2, HIPAA, GLBA, GDPR, CCPA, CPRA, and client Outside Counsel Guidelines; administer policy exceptions and risk acceptance workflows; contribute to awareness materials and operative guidance.
  • Information Security and Technology Risk Management: conduct or facilitate risk assessments for applications, infrastructure, cloud services, and firm‑critical legal‑industry platforms; maintain risk register, including inherent and residual ratings and treatment plans; partner with control owners for remediation; support risk monitoring, key risk indicators, and control health metrics; draft risk reporting for governance forums; support incident response activities and post‑incident lessons learned.
  • Vendor/Third‑Party Risk Management (TPRM): perform third‑party security due diligence based on vendor criticality and risk tiering; coordinate security questionnaires and evidence collection; review SOC reports, ISO certificates, penetration test summaries, and other assurance artifacts; identify gaps, recommend remediation, track vendor action plans; partner with Procurement/Legal on contract security requirements; support periodic vendor reassessments; draft responses to inbound client security questionnaires.
  • Audit, Assurance and Compliance: support internal and external audits by coordinating evidence collection, control walkthroughs, and audit responses; assist with gap assessments and control testing against ISO27001/27002, NIST CSF/SP800‑53/800‑171, SOC2, GLBA, HIPAA, GDPR, NIS2, and CUI/ITAR/EAR requirements; track audit findings and corrective action plans; maintain audit artifacts; support EU compliance activities and controlled unclassified information (CUI) handling; compile control attestations for cyber‑insurance applications.
Expected Work Schedule

Maintain a regular and predictable work schedule and full attention during business hours, except as otherwise approved or required by law.

Required Skills
  • Strong written and verbal communication skills, ability to translate control requirements into clear documentation and actionable guidance.
  • Strong organizational skills, meticulous attention to detail, and the ability to manage multiple priorities and deadlines.
  • Knowledge or ability to learn Microsoft Office Suite or Microsoft365.
Required Qualifications & Education
  • Bachelor’s degree in information security, information technology, risk management, business, or equivalent practical experience.
  • 3+ years of experience in GRC, information security, technology risk management, compliance, internal audit, or third‑party risk management.
  • Working knowledge of ISO/IEC27000 family, NIST CSF/SP800‑53/800‑171, and HIPAA.
  • Familiarity with EU information security and privacy requirements (e.g., GDPR) and NIS2 concerns.
  • Experience collecting, organizing, and validating control evidence and supporting audits/assessments.
  • Certifications: ISACA CRISC and/or CISA.
Preferred Qualifications & Education
  • Prior exposure to GRC, IT risk, or information security work in a law firm, professional services firm, or client‑confidential environment.
  • Familiarity with legal‑industry technology (e.g., iManage, NetDocuments, 3E, Aderant, Intapp, Relativity) and data‑sensitivity considerations.
  • Awareness of ABA Model Rules of Professional Conduct (Rules1.1 and1.6) and applicable state bar requirements.
  • Familiarity with CUI handling, NIST SP800‑171, CMMC, and ITAR/EAR data‑handling; prior exposure to federal, defense, or government‑contract client matters.
  • Certifications: ISACA COBITFoundation, CDPSE, CGEIT; ISO/IEC27001 internal auditor, lead implementer, or lead auditor; cloud/platform risk certifications (Microsoft SC‑900, AZ‑500, etc.).
Physical Requirements

Ability to sit or stand for extended periods; moderate to advanced keyboard usage.

Benefits
  • Medical (PPO and HDHPs), dental and vision plans; life and AD&D insurance; short‑ and long‑term disability insurance.
  • Tax‑advantaged health accounts (FSA, HSA), dependent‑care FSA; health advocacy services; behavioral health and counseling resources for all family members.
  • 401(k) and profit‑sharing; backup dependent care; senior care planning support; paid holidays and other paid time off, including paid leave for new parents.
Equal‑Opportunity Employer

Holland & Knight is an Equal Opportunity Employer and does not discriminate on the basis of race, color, religion, sex (including pregnancy, childbirth or related conditions, transgender status and sexual orientation), national origin, age, disability, genetic information, veteran status or any other factor prohibited by law. Applicants who require accommodations during the application process should contact ApplicantAccommodations@hklaw.com.

#J-18808-Ljbffr

What Holland & Knight employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom