1

Information Risk Manager Jobs in Houston, TX (NOW HIRING)

As a Risk Manager, you will support that Purpose by helping protect our Team Members, Homeowners ... Additional Information What We Offer: Come build your future with our winning team, recognized by ...

As a Risk Manager, you will support that Purpose by helping protect our Team Members, Homeowners ... Additional Information . What We Offer: Come build your future with our winning team, recognized by ...

... Information and Event Management, User and Entity Behavior Analytics, and Data Loss Prevention capabilities Evaluating insider risk scenarios, high-risk user groups, and crown jewel assets to help ...

Senior Associate, Risk Manager Are you ready to lead from the front line of a top 10 bank? Do you ... Please note that this salary information is solely for candidates hired to perform work within one ...

next page

Showing results 1-20

Information Risk Manager information

See Houston, TX salary details

$43.3K

$93.7K

$142.8K

How much do information risk manager jobs pay per year?

As of Sep 11, 2026, the average yearly pay for information risk manager in Houston, TX is $93,726.00, according to ZipRecruiter salary data. Most workers in this role earn between $75,600.00 and $108,400.00 per year, depending on experience, location, and employer.

What does an information risk manager do?

An Information Risk Manager is responsible for identifying, assessing, and mitigating risks related to an organization's information assets. They develop and implement risk management policies, conduct regular risk assessments, and ensure compliance with relevant standards and regulations. Their role often involves collaborating with IT, security, and business teams to protect sensitive data and support business continuity. By proactively managing information risks, they help organizations minimize the potential impact of security threats and data breaches.

What are the key skills and qualifications needed to thrive as an information risk manager?

To thrive as an Information Risk Manager, you need expertise in risk assessment, information security principles, and regulatory compliance, often supported by a degree in information technology or cybersecurity and relevant certifications like CISSP or CISM. Familiarity with risk management tools, governance frameworks (such as ISO 27001), and security incident management systems is typical. Strong analytical thinking, communication, and stakeholder management skills help set top performers apart. These capabilities are crucial for proactively identifying, assessing, and mitigating information risks to protect organizational assets and ensure compliance.

What are some common challenges information risk managers face when implementing new risk mitigation strategies?

Information Risk Managers often encounter resistance to change from employees and stakeholders when introducing new risk mitigation strategies. Balancing security requirements with business objectives can also be challenging, as overly restrictive controls may hinder productivity. Additionally, staying updated with evolving cyber threats and ensuring compliance with various regulatory standards requires continuous learning and adaptation. Successful Information Risk Managers proactively communicate the value of risk initiatives and foster collaboration across departments to achieve buy-in.

What is the difference between Information Risk Manager vs Cybersecurity Analyst?

AspectInformation Risk ManagerCybersecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISMCISSP, CompTIA Security+, CEH
Work EnvironmentRisk assessment, policy development, compliance managementSecurity monitoring, incident response, vulnerability assessment
Employer & IndustryFinancial, healthcare, government, large enterprisesIT firms, security service providers, corporate IT teams

The main difference is that an Information Risk Manager focuses on identifying, assessing, and managing overall information risks and compliance strategies, while a Cybersecurity Analyst primarily handles security monitoring, threat detection, and incident response. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

What cities near Houston, TX are hiring for Information Risk Manager jobs?

Cities near Houston, TX with the most Information Risk Manager job openings:

Sr. Manager, Information Risk & Controls

Houston, TX • Hybrid

Full-time

Medical, Retirement, PTO

Re-posted 10 days ago


Invesco rating

9.7

Company rating: 9.7 out of 10

Based on 5 frontline employees who took The Breakroom Quiz


Job description

About Invesco

As one of the world's leading independent global investment firms, Invesco is dedicated to rethinking possibilities for our clients. By delivering the combined power of our distinctive investment management capabilities, we provide a wide range of investment strategies and vehicles to our clients around the world. If you're looking for challenging work, intelligent colleagues, and exposure across a global footprint, come explore your potential at Invesco.

What's in it for you?

Our people are at the very core of our success. Invesco employees get more out of life through our comprehensive compensation and benefit offerings including:

  • Flexible paid time off

  • Hybrid work schedule

  • 401(K) matching of 100% up to the first 6% with a discretionary supplemental contribution

  • Health & wellbeing benefits

  • Parental Leave benefits

  • Employee stock purchase plan

Job Description

About the Department/Team:

At Invesco, we value focusing on clients, purposeful interactions, and teamwork. Within Enterprise Risk, you can expect to draw from your existing skills to drive value while finding opportunities to expand your talent and career.

Invesco Enterprise Risk Management (ERM) is evolving its capabilities and is looking for new Team members. Enterprise Risk is a global Second Line of Defense function that engages with Invesco Business teams to facilitate delivery and oversight of the risk management framework and provide a consistent, aligned approach to risk management across the firm.

The Enterprise Risk Management team, comprised of dynamic, diverse, and highly collaborative members, drives value to Invesco by delivering a comprehensive and standardized view of risk, integrated and underpinned by data and metrics. At the heart of the Invesco Enterprise Risk framework is the foundation for strong analytics, capable of responding to emerging threats and opportunities and adapting to evolving market trends and conditions.

Whether you want to extend your existing experience to Enterprise Risk or leverage Risk Management expertise to evolve Invesco's Enterprise Risk Management capability, we've got exciting opportunities.

About the Role:

Invesco is adopting new technologies, strengthening its data strategy, expanding its use of third parties and evolving its operating model to serve clients better. These changes raise the importance of two risk domains in particular: Business Resilience and Data Governance. The Sr. Manager of Information Risk and Controls is the second-line lead for these two domains. Supporting the Global Head of Information Risk and Controls, this individual provides independent oversight and challenge of how the first line identifies, assesses, controls, reports and responds to resilience and data risk, and turns that oversight into clear findings, appetite positions and escalations for senior risk committees. The role works day to day with the Chief Data Office, the Business Resilience and Incident& Crisis management functions, Compliance and Internal Audit, and coordinates with cybersecurity, privacy, technology risk and operational risk specialists, business users, architects and other subject matter experts where a risk crosses functional boundaries. Partnering with a team of subject matter experts, a key strategic focus will be to strengthen the overall risk posture, enhance risk management measures and support independent governance that let the firm evidence its resilience and data risk posture to its management and regulators.

Responsibilities of the Role:

  • Business Resilience oversight: Lead second-line oversight of Business Resilience across the firm, including its regulatory operational resilience obligations. Challenge the design and effectiveness of resilience capabilities, recovery arrangements, testing and remediation, and escalate exposures that remain outside appetite.

  • Data Governance oversight: Lead second-line oversight of data risk. Challenge the effectiveness of the firm's data governance framework, its adoption across the business and the progress of remediation and oversee data risks arising from new technology and AI use in coordination with privacy, cybersecurity and model risk specialists and with the business users, architects and other subject matter experts closest to that use.

  • Incident & Crisis management Advisory: Review material incidents affecting resilience or data for root cause, control failure and adequacy of response; advise the first line and senior management on lessons learned and remediation; provide independent second-line commentary to management and risk committees; and contribute to the continuing improvement of the firm's incident & crisis management practices.

  • Risk Management Activities: Lead the second-line role in the annual risk and control self-assessment for both domains and produce the rating recommendation for committee. Oversee the risk appetite measures and enhance key risk indicators for both domains, challenging coverage, thresholds and escalation.

  • Risk Reporting & Governance: Provide independent review of Business Resilience and Data risk reporting before risk committee submission, present a clear second-line opinion, and challenge risk acceptances, policy exceptions and issue remediation timelines that materially affect either domain.

  • Policy, regulatory and industry engagement: Lead the development and periodic review of ERM policies, standards, taxonomy and reporting guidance for the two domains, ensuring appropriate risk oversight and reporting against regional regulatory requirements. Support regulatory engagement on resilience and data governance matters, including examinations and information requests. Engage with industry networks and peers to track developments in resilience and data risk management and bring relevant practice back to the firm.

  • Leadership and collaboration: Provide strategic leadership to the analysts supporting both domains, setting priorities, developing capability and remaining accountable for the quality of second-line conclusions. Partner with first-line risk owners, the Chief Data Office, Business Resilience, Compliance and Internal Audit, and with the wider operational & enterprise risk management community, so that oversight of the two domains is coordinated across the three lines and the firm's risk culture in these areas is strengthened

Requirements for the Role:

  • Risk management experience: Typically 8 or more years of relevant risk, control, data governance or assurance experience, including substantial experience in either operational resilience or data governance with demonstrated working capability in the other, gained within or advising regulated financial services institutions. Asset management experience is preferred.

  • Business resilience expertise: Demonstrated experience applying operational resilience and business continuity requirements in a regulated environment, including familiarity with current regulatory resilience regimes.

  • Data governance expertise: Demonstrated experience assessing or implementing data governance operating models, including accountability, stewardship, classification, data quality, lineage and critical data. Familiarity with recognized data governance or risk data aggregation principles is desirable.

  • Incident management experience: Experience reviewing significant incidents, assessing root cause and control failure, and advising on remediation and lessons learned.

  • Second-line assessment experience: Experience independently challenging risk and control self-assessments and remediation evidence, and designing or challenging key risk indicators and their thresholds.

  • Committee and regulatory reporting: Experience preparing, reviewing and defending risk reporting for senior committees and forming a clear second-line opinion. Experience supporting regulatory examinations or information requests is desirable.

  • Communication and influence: Communicates material findings clearly to senior stakeholders, supports conclusions with evidence and secures accountable management responses; provides independent, constructive challenge and proportionate escalation while maintaining effective working relationships.

  • Analytical ability: Root-cause thinking on control failures and remediation, distinguishing symptom closure from remediation; comfortable using risk management platforms and analytical tools to assess complex information.

  • Leadership: Experience directing or coaching risk professionals, setting priorities and maintaining the quality of team conclusions.

  • Emerging technology: Can assess how cloud dependencies, automation and AI-enabled data use affect resilience, data quality, accountability and control effectiveness.

  • Education: An undergraduate degree is required; an MBA or master's degree in a relevant field is preferred.

  • Professional qualifications: A relevant professional qualification in resilience, risk, audit or data governance is desirable (for example CBCI/MBCI, CRISC, CISA, CDMP, CISM).

Full Time / Part TimeFull timeWorker TypeEmployeeJob Exempt (Yes / No)YesWorkplace Model

Pursuant to Invesco's Workplace Policy, employees are expected to comply with the firm's most current workplace model, which as of October 1, 2025, includes spending at least four full days each week working in an Invesco office. This reflects our belief that spending time together in the office helps us build stronger relationships, collaborate more easily, and support each other's growth and development.

The above information on this description has been designed to indicate the general nature and level of work performed by employees within this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job. The job holder may be required to perform other duties as deemed appropriate by their manager from time to time.

Invesco's culture of inclusivity and its commitment to diversity in the workplace are demonstrated through our people practices. We are proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, creed, color, religion, sex, gender, gender identity, sexual orientation, marital status, national origin, citizenship status, disability, age, or veteran status. Our equal opportunity employment efforts comply with all applicable U.S. state and federal laws governing non-discrimination in employment.


What Invesco employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom