1

It Risk Management Jobs (NOW HIRING)

The incumbent will implement and support day-to-day IT risk management activities (such as risk and controls assessments), handle deadlines and collaborator expectations, and lead or participate in ...

The incumbent will execute and support day-to-day IT risk management activities (such as risk and controls assessments), manage deadlines and stakeholder expectations, and lead or participate in ...

The incumbent will execute and support day-to-day IT risk management activities (such as risk and controls assessments), manage deadlines and stakeholder expectations, and lead or participate in ...

RISK MANAGEMENT Compensation Type: Salaried Job Category: Business / Professional Hours Worked: 8:00AM - 5:00PM Location: JPOC 1350 Shift Worked: Day Job Summary: The IT Security Risk Manager is a ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

What You Bring * 8+ years of experience in IT audit, IT compliance, technology risk management, or ... a related field, ideally within insurance, reinsurance, banking, financial services, or another ...

The incumbent will execute and support day-to-day IT risk management activities for the Enterprise Product & Platform Engineering (EPPE) department, manage deadlines and stakeholder expectations, and ...

next page

Showing results 1-20

IT Risk Management information

See salary details

$51.5K

$111.6K

$170K

How much do it risk management jobs pay per year?

As of Aug 8, 2026, the average yearly pay for it risk management in the United States is $111,556.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,000.00 and $129,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an IT risk management professional, and why are they important?

To thrive in IT Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance frameworks, typically supported by a degree in information technology, cybersecurity, or a related field. Familiarity with risk management tools (such as RSA Archer or MetricStream), knowledge of ISO 27001, and certifications like CISSP or CISM are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help in identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets, ensuring compliance, and enabling informed decision-making regarding technology risks.

What are some common challenges faced by IT risk management professionals, and how can they effectively address them?

IT Risk Management professionals often encounter challenges such as rapidly evolving cyber threats, balancing compliance with operational efficiency, and communicating technical risks to non-technical stakeholders. Staying updated with the latest security trends and regulations is essential for effective risk assessment. Building strong cross-departmental relationships can help ensure that risk mitigation strategies are both practical and well-understood across the organization. Continuous learning and leveraging risk management frameworks, like NIST or ISO 27001, can also provide a solid foundation for addressing these challenges.

What is the difference between It Risk Management vs Cybersecurity Analyst?

AspectIt Risk ManagementCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentFocus on risk assessment, compliance, and mitigation strategies across IT systemsFocus on monitoring, analyzing, and responding to security threats
Employer & Industry UsageUsed in organizations prioritizing risk management and complianceUsed in security operations centers and cybersecurity teams

While both roles involve IT security, It Risk Management emphasizes assessing and mitigating risks across IT systems, whereas Cybersecurity Analysts focus on detecting and responding to security threats. Understanding these differences helps organizations assign the right roles for their security needs.

What does an IT risk management do?

An IT risk management professional identifies, assesses, and prioritizes potential technology-related threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, ensuring data security and compliance with industry standards. This role often involves using risk assessment tools and maintaining awareness of emerging cybersecurity threats.

What is IT risk management?

IT Risk Management is the process of identifying, assessing, and mitigating risks related to information technology systems and data within an organization. This discipline aims to protect information assets from threats such as cyberattacks, data breaches, and system failures by implementing security controls and policies. Effective IT Risk Management helps organizations comply with regulations, minimize financial losses, and ensure business continuity. Professionals in this field continuously monitor and update risk strategies to adapt to evolving technological threats.

What are careers in it risk management?

Careers in IT risk management involve identifying, assessing, and mitigating technology-related security threats to protect organizational data and systems. Roles include IT risk analyst, cybersecurity manager, and compliance officer, often requiring knowledge of security frameworks, risk assessment tools, and relevant certifications like CISSP or CISM.
More about IT Risk Management jobs
What cities are hiring for It Risk Management jobs? Cities with the most It Risk Management job openings:
What states have the most It Risk Management jobs? States with the most job openings for It Risk Management jobs include:
Infographic showing various It Risk Management job openings in the United States as of August 2026, with employment types broken down into 83% Full Time, 13% Part Time, 1% Temporary, and 3% Contract. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $111,556 per year, or $53.6 per hour.

Full-time

Re-posted 14 hours ago


John Peter Smith Hospital rating

8.2

Company rating: 8.2 out of 10

Based on 40 frontline employees who took The Breakroom Quiz

97th of 1,055 rated hospitals


Job description

Job Summary: The IT Security Risk Manager is a key member of the Enterprise Risk Management team within the Tarrant County Hospital District's Office of Legal Affairs. Reporting to the Deputy General Counsel, this role is responsible for leading the identification, assessment, monitoring, and mitigation of information technology and security risks across the health system. The IT Security Risk Manager plays a critical role in ensuring that information systems are appropriately protected and aligned with applicable regulatory requirements, industry standards, and internal policies.

Essential Job Functions & Accountabilities:

  1. Conducts risk assessments and reviews of the IT control framework to identify control gaps and risk exposures.

  2. Partners with IT, cybersecurity, infrastructure, and business leaders to assess and reduce technology and security risk.

  3. Provides risk guidance and recommendations for new initiatives, technologies, system implementations, and significant system changes.

  4. Facilitates IT security risk workshops, training sessions, and awareness programs for employees and stakeholders.

  5. Assists with cybersecurity incident investigations, including root cause analysis and remediation tracking.

  6. Participates in business continuity and disaster recovery planning, testing, and evaluation activities.

  7. Recommends and evaluates controls to enhance system resilience and minimize operational and security impact.

  8. Identifies and supports the implementation of practical and cost-effective solutions to IT security and risk issues.

  9. Provides aggregated risk oversight and supervision for high-impact IT service areas.

  10. Develops, analyzes, and presents reports on key IT risk metrics, assessments, and activities to management and stakeholders.

  11. Builds and maintains effective working relationships with risk team members, Enterprise Risk Management, Legal, IT, Compliance, and other key partners.

  12. Provides guidance in the development, implementation, and communication of IT risk-related policies, standards, and procedures.

  13. Establishes and maintains an external professional network with IT risk peers, industry groups, and applicable risk forums.

  14. Coordinates and works collaboratively with internal and external auditors, as requested.

  15. Evaluates alternative strategies to reduce the organization's exposure to catastrophic and operational loss.

  16. Participates in end-to-end risk remediation planning, execution, monitoring, and closure activities.

  17. Supports Office of Legal Affairs projects and strategic initiatives related to IT risk and security.

  18. Job description is not an all-inclusive list of duties and may be subject to change with or without notice. Staff are expected to perform other duties as assigned.

What John Peter Smith Hospital employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom