1

Information Risk Manager Jobs in Virginia (NOW HIRING)

Risk Manager Job Category: Project and Program Management Time Type: Full time Minimum Clearance ... The GMOS contract aims to provide world-class IT support by modernizing and maintaining ...

Risk Manager Job Category: Project and Program Management Time Type: Full time Minimum Clearance ... The GMOS contract aims to provide world-class IT support by modernizing and maintaining ...

IT Risk Manager #W0115

Richmond, VA · On-site

$121K - $130K/yr

IT Risk Manager #W0115 Apply now Job no: 5109791 Work type: Full-Time (Salaried) Location: Richmond (City), Virginia Categories: Information Technology Title: IT Risk Manager #W0115 State Role Title:

Risk Manager

Mclean, VA · On-site

$55 - $60/hr

Bachelor's degree in Information Technology or Risk Management (or equivalent professional qualification), Master's Degree desirable

Risk Manager Job Code: RM1505 ABOUT US We are ushering in a new era of healthcare where achieving ... Uses incident, complaint, and claims-related information to identify trends and support risk ...

Risk Manager Risk Managers at Capital One are the front line of defense to ensure our Company ... Please note that this salary information is solely for candidates hired to perform work within one ...

Risk Manager Job Code: RM1505 ABOUT US We are ushering in a new era of healthcare where achieving ... Uses incident, complaint, and claims-related information to identify trends and support risk ...

Risk Manager Risk Managers at Capital One are the front line of defense to ensure our Company ... Please note that this salary information is solely for candidates hired to perform work within one ...

next page

Showing results 1-20

Information Risk Manager information

See Virginia salary details

$51.1K

$110.6K

$168.5K

How much do information risk manager jobs pay per year?

As of Sep 10, 2026, the average yearly pay for information risk manager in Virginia is $110,599.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,200.00 and $127,900.00 per year, depending on experience, location, and employer.

What does an information risk manager do?

An Information Risk Manager is responsible for identifying, assessing, and mitigating risks related to an organization's information assets. They develop and implement risk management policies, conduct regular risk assessments, and ensure compliance with relevant standards and regulations. Their role often involves collaborating with IT, security, and business teams to protect sensitive data and support business continuity. By proactively managing information risks, they help organizations minimize the potential impact of security threats and data breaches.

What are the key skills and qualifications needed to thrive as an information risk manager?

To thrive as an Information Risk Manager, you need expertise in risk assessment, information security principles, and regulatory compliance, often supported by a degree in information technology or cybersecurity and relevant certifications like CISSP or CISM. Familiarity with risk management tools, governance frameworks (such as ISO 27001), and security incident management systems is typical. Strong analytical thinking, communication, and stakeholder management skills help set top performers apart. These capabilities are crucial for proactively identifying, assessing, and mitigating information risks to protect organizational assets and ensure compliance.

What are some common challenges information risk managers face when implementing new risk mitigation strategies?

Information Risk Managers often encounter resistance to change from employees and stakeholders when introducing new risk mitigation strategies. Balancing security requirements with business objectives can also be challenging, as overly restrictive controls may hinder productivity. Additionally, staying updated with evolving cyber threats and ensuring compliance with various regulatory standards requires continuous learning and adaptation. Successful Information Risk Managers proactively communicate the value of risk initiatives and foster collaboration across departments to achieve buy-in.

What is the difference between Information Risk Manager vs Cybersecurity Analyst?

AspectInformation Risk ManagerCybersecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISMCISSP, CompTIA Security+, CEH
Work EnvironmentRisk assessment, policy development, compliance managementSecurity monitoring, incident response, vulnerability assessment
Employer & IndustryFinancial, healthcare, government, large enterprisesIT firms, security service providers, corporate IT teams

The main difference is that an Information Risk Manager focuses on identifying, assessing, and managing overall information risks and compliance strategies, while a Cybersecurity Analyst primarily handles security monitoring, threat detection, and incident response. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

What cities in Virginia are hiring for Information Risk Manager jobs?

Cities in Virginia with the most Information Risk Manager job openings:

Infographic showing various Information Risk Manager job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 22% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $110,599 per year, or $53.2 per hour.

Analyst II, Cybersecurity- Information Risk Management

Richmond, VA • On-site

Carmax
Automobile Dealers • 10K+ employees

$78K - $118K/yr

Other

PTO

Re-posted 6 days ago


CarMax rating

7.9

Company rating: 7.9 out of 10

Based on 376 frontline employees who took The Breakroom Quiz


Job description

8901 - Corp Office West Crk - 12800 Tuckahoe Creek Parkway, Richmond, Virginia, 23238

CarMax, the way your career should be! 

We are looking for an Analyst II, Information Risk Management to maintain and enhance the Information Risk Management posture of an innovative and fast paced company that is leveraging technology to provide innovative methods to improve the car buying experience.

The Analyst II, Information Risk Management is an integral individual contributor role within the CarMax Information Security Organization, focused on planning and executing critical risk and privacy operations and initiatives for the company to ensure continuous privacy operations, modernize control methodologies through automation and artificial intelligence, and streamline privacy assessments to improve the program’s efficiency and effectiveness.

This is a unique opportunity to work at a Fortune 200 company and national brand to expand your skills and influence a growing Technology Program.  This role will partner across Business and Technology teams to design, implement and manage privacy operations practices ensuring CarMax effectively assesses and mitigates risk to company and customer data.  The successful candidate will leverage strengths in privacy operations execution and drive continuous improvement through process optimization, automation and AI for streamlined efficiency. 

What you will do – Essential Responsibilities

The Analyst II, Information Risk Management – Privacy will focus primarily on facilitating and supporting regulatory and privacy operations for the company to ensure an effective and compliant posture for CarMax and our customers. This role serves as the conduit between the business community, Privacy core team, technology, and the application development teams.  The Analyst II – Privacy manages the intake, analysis and completion of privacy requests and facilitates all operational aspects of the privacy lifecycle, including:  

  • Privacy Request Support – Coordinate with multiple technology teams to capture, assess and process data subject access requests (DSAR) timely and accurately.  

  • Privacy Operations Management – Use service delivery principles to implement, execute and measure the program and related services consistently and effectively.  Prepare and deliver regular program updates with KPIs that illustrate volumes, trends and risk areas to stakeholders.  Maintain appropriate work management practices and backlogs to meet or exceed SLAs.  

  • Process Improvement – Identify and implement opportunities to simplify and strengthen our privacy risk management processes and capabilities using process analysis, automation and AI where applicable.  

  • Privacy Technology Administration – Utilize standalone and integrated platforms in daily operations and perform system improvements and administration.

  • Privacy Impact Assessment – Facilitate ongoing data privacy assessments of internal systems to effectively manage data sensitivity risk across in the enterprise. 

  • Policy Governance Lifecycle Management – Own and manage the technology and information security focused guidance to ensure all policies, procedures, standards and job aids remain current, published and available for our associates. 

  • Knowledge Management – Document and maintain clear, effective reference documentation (playbooks, processes, job aids, technical diagrams) as an internal knowledgebase and for ease of customer experience. 

  • Projects, as defined – Participate in related strategic and tactical projects as necessary to mature the privacy operations function.  

  • As an integral member of the team, exhibiting ownership, follow-through, initiative, awareness and effective communication with peers and management and ability to speak to details of privacy operations. 

  • Maintain a strong knowledge base and awareness of industry and technological trends, external regulations for new or changed requirements within privacy and technology for core processes (e.g. NiST, PCI, ITIL, data privacy etc.). 

Qualifications and Requirements:

  • Bachelor’s degree in business / computer science / information systems (or related)

  • 2+ years working experience in privacy, technology compliance, IT Audit, cybersecurity, or related experience.

  • One or more of the following privacy-focused certifications such as: CIPP, CIPM, CIPT, CIA, CRSC, CISA.

  • Experience / familiarity with relevant U.S. legal frameworks and privacy regulation such as: CCPA, GLBA, PCI, NYDFS, CFPB.

  • Detail oriented – Possess a keen eye for detail and accuracy in all operations. Leverage defined, repeatable methods for managing work and communicating progress and priority.

  • Analytical approach – Ability to perform data analysis and trending,  problem solve obstacles and find alternative ways to meet and achieve privacy goals,

  • Ability to understand and implement information risk and privacy principles across disciplines. Apply a risk-based approach to analysis in a fast-paced, rapidly evolving environment .

  • Customer Focus – Ability to provide exceptional customer service for our internal partners, with a mindset for understanding their need and consistently finding ways to exceed expectation.

  • Communication – Excellent verbal and written communication skills, with the ability to structure and deliver clear, accurate messaging. Ability to create and present concepts to various audiences, facilitate discussion with diplomacy while seeking diverse opinions to reach consensus

  • Collaboration – Strong emphasis on effective relationship building and partnership.

  • Demonstrate initiative, ownership, and a service-oriented mindset in all interactions.

Work Location and Arrangement: This role will be based out of the Richmond, VA Technology Innovation Center.  Associates based in Richmond work onsite 4 days per week. 

Work Authorization: Applicants must be currently authorized to work in the United States on a full-time basis. Sponsorship will not be considered for this specific role.

About CarMax

CarMax disrupted the auto industry by delivering the honest, transparent and high-integrity experience customers want and deserve. This innovative thinking around the way cars are bought and sold has helped us become the nation’s largest retailer of used cars, with over 200 locations nationwide.

Our amazing team of more than 25,000 associates work together to deliver iconic customer experiences. Along the way, we help every associate grow their career and achieve their best, at work and in their community.  We are recognized for our commitment to training and diversity and are one of the FORTUNE 100 Best Companies to Work For®.

Our Commitment to Diversity and Inclusion:

CarMax is committed to bringing together people from different backgrounds and perspectives, providing employees with a safe, welcoming, and inclusive work environment.

CarMax is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, gender expression, genetic information, national origin, protected veteran status, disability status, and any other characteristics protected by law.

The annual salary for this position is:

$78,800.00 - $118,200.00

May be eligible for bonus and equity.

Benefits:

Except as otherwise required by state law, CarMax Associates are entitled to the following paid sick, vacation, and holiday time.

Associates that are considered full-time hourly or commission/incentive eligible:

  • To earn up to 48 hours of sick time per year accrued on a per pay period basis and between 80 hours and 200 hours per year of vacation time after a 90 day waiting period depending on years of continuous service with the Company. 
  • For 8 hours of pay for each of a total of 6 paid scheduled holidays per year plus 1 floating holiday.  If such an Associate does work on a scheduled holiday due to business need, they are eligible for Holiday Premium Pay. 

Associates considered full-time salaried are entitled to paid time away with no specified limit as needed for sick, vacation, bereavement, jury duty, holidays, floating holiday, etc. subject to manager approval. 

For more details about benefits, please visit our CarMax Benefits website.

Upon an applicant's request, CarMax will consider reasonable accommodation to complete the CarMax Job Application.


What CarMax employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


CarMax logo

About CarMax

Sourced by ZipRecruiter

CarMax disrupted the auto industry by delivering the honest, transparent and high-integrity experience customers want and deserve. This innovative thinking around the way cars are bought and sold has helped us become the nation's largest retailer of used cars, with over 200 locations nationwide. Our amazing team of more than 25,000 associates work together to deliver iconic customer experiences. Along the way, we help every associate grow their career and achieve their best, at work and in their community. We are recognized for our commitment to training and diversity and are one of the FORTUNE 100 Best Companies to Work For®.

Industry

Automobile dealers and finance and insurance

Company size

10,000+ Employees

Headquarters location

Henrico, VA, US