1

Information Technology Risk Manager Jobs (NOW HIRING)

The incumbent will execute and support day-to-day IT risk management activities (such as risk and controls assessments), manage deadlines and stakeholder expectations, and lead or participate in ...

You will work with organizations to evaluate not only the effectiveness of their IT controls and risk management programs, but also the technology infrastructure that supports business operations and ...

You will work with organizations to evaluate not only the effectiveness of their IT controls and risk management programs, but also the technology infrastructure that supports business operations and ...

IT Risk & Compliance Analyst

Andover, MA · On-site +1

$95K - $95K/yr

This position reports to the Manager, IT Risk & Compliance. This role is remote and may be based anywhere within the United States. Primary Job Duties and Responsibilities * Coordinate IT compliance, ...

Company Overview Symetra Investment Management ("SIM") is a SEC-registered investment advisory firm ... About the role The Senior IT Risk and Security Analyst (RSA) is a critical member of the ...

The role manages the firm's GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications. Key Responsibilities * Policy, Standards and ...

Senior IT Risk Analyst

Rosemont, IL · Hybrid

$98K - $110K/yr

Wintrust provides community and commercial banking, specialty finance and wealth management ... Position Overview The Senior IT Risk Analyst (Audit concentration) role supports IT Risk Leadership ...

Showing results 41-60

Information Technology Risk Manager information

See salary details

$65K

$144.7K

$262.5K

How much do information technology risk manager jobs pay per year?

As of Sep 10, 2026, the average yearly pay for information technology risk manager in the United States is $144,712.00, according to ZipRecruiter salary data. Most workers in this role earn between $87,000.00 and $174,000.00 per year, depending on experience, location, and employer.

What is the difference between Information Technology Risk Manager vs Cybersecurity Analyst?

AspectInformation Technology Risk ManagerCybersecurity Analyst
CertificationsCISA, CISSP, CRISCCISSP, CEH, Security+
Work EnvironmentRisk assessment, policy development, complianceMonitoring security threats, incident response, vulnerability analysis
Industry UsageFinancial, healthcare, large enterprisesIT security firms, corporate IT departments

While both roles focus on protecting information assets, the Information Technology Risk Manager primarily assesses and manages overall IT risks and compliance, whereas the Cybersecurity Analyst concentrates on identifying and mitigating security threats and vulnerabilities. The Risk Manager develops policies and strategies, while the Analyst implements security measures and responds to incidents.

What cities are hiring for Information Technology Risk Manager jobs?

Cities with the most Information Technology Risk Manager job openings:

What states have the most Information Technology Risk Manager jobs?

States with the most job openings for Information Technology Risk Manager jobs include:

What are popular job titles related to Information Technology Risk Manager jobs?

For Information Technology Risk Manager jobs, the most frequently searched job titles are:

Infographic showing various Information Technology Risk Manager job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 73% Full Time, 23% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $144,712 per year, or $69.6 per hour.

Associate Director IT Embedded Risk

On-site

Depository Trust & Clearing Corporation
Securities, Commodity Contracts, and Financial Investments • 5 - 10K employees

Other

Medical, Life, Retirement, PTO

Posted 8 days ago


Key responsibilities

  • Support and conduct targeted IT risk assessments and analyze risk items including policy deviations, risk acceptances, issues, and actions.

  • Maintain and enhance the IT risk management framework, including tools and processes for risk identification, monitoring, and escalation.

  • Provide risk and control consultation, evaluate control effectiveness, and liaise with risk management functions and IT management.


Job description

Are you ready to make an impact at DTCC? Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve. The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.

Pay and Benefits:
  • Competitive compensation, including base pay and annual incentive
  • Comprehensive health and life insurance and well-being benefits, based on location
  • Pension / Retirement benefits
  • Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
  • DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
The Impact you will have in this role:

Being a member of IT FinSight Delivery team, An IT ERM Associate Director has primary responsibility of supporting and conducting targeted IT risk assessments as well as the analysis and remediation of risk items including policy deviations, risk acceptances, issues and actions.

The incumbent will execute and support day-to-day IT risk management activities (such as risk and controls assessments), manage deadlines and stakeholder expectations, and lead or participate in projects within assigned areas of responsibility.

In carrying these responsibilities, the incumbent must work collaboratively with the IT Risk Management team (including Management Control Testing and Center of Excellence functions), other risk & control functions (e.g., Internal Audit, Technology Risk Management), as well as with IT line management (1st line).

Your Primary Responsibilities:

DTCC’s Information Technology (IT) Risk Management program is designed to identify, manage, measure and mitigate risks in all IT Capabilities.

  • Maintaining and enhancing IT risk management framework. The framework is comprised of tools and processes to help DTCC:
  • Identify new risks, changes in risk, or relationships between risks
  • Monitor and elevate key matters of risk and control.
  • Support IT management in maintaining a complete and accurate Process, Risk, and Control library
  • Formulating, disseminating and administering IT risk management policy and procedures;
  • Providing risk and control consultation and evaluations of control effectiveness to support/ evidence management awareness of the effectiveness of the control environment (i.e., assist management in issue self-identification)
  • Liaising with Technology Risk, Information Security, Technology Centers of Excellence and with other subject matter experts within the organization to ensure that risks and appropriate mitigants are identified and communicated throughout the organization.

**NOTE: The Primary Responsibilities of this role are not limited to the details above. **

Qualifications:
  • Minimum of 8 years of related experience
  • Bachelor's degree preferred and/or equivalent experience
Talents Needed for Success:
  • 8+ years of experience in risk management/ analysis and/or technical auditing/ examination
  • Demonstrated experience leading and executing IT Risk and Control Self‑Assessments (RCSAs), including risk identification, inherent and residual risk assessment, control design evaluation, and challenge of risk ratings.
  • Strong experience producing IT quarterly risk reporting for senior management, including aggregation of risk themes, trend analysis, key risk indicators (KRIs), and concise executive‑level commentary.
  • Proven ability to define, analyze, and interpret IT risk metrics, with solid quantitative and analytical skills to assess control effectiveness, risk trends, and out‑of‑tolerance conditions.
  • Deep understanding of core IT processes and technologies (e.g., application development, infrastructure, cloud, cybersecurity, resiliency, change management) and how process failures translate into operational and regulatory risk.
  • Experience designing and executing risk assessments across complex IT environments, including scoping, evidence evaluation, stakeholder interviews, and synthesis of findings into actionable risk insights.
  • Strong business acumen, with the ability to understand supported business areas, critical services, and client impacts, and to align IT risk assessments to business priorities and outcomes.
  • Hands‑on experience analyzing IT asset inventories (applications, infrastructure, platforms, data assets) and extrapolating risk findings across portfolios, capabilities, and business lines to identify systemic issues.
  • Demonstrated expertise in incident analysis and root cause analysis, including evaluation of technology incidents, control failures, and near‑misses to inform risk assessments, corrective actions, and risk reporting.
  • Ability to challenge effectively and independently, partnering with IT, risk, and business stakeholders while maintaining strong governance, documentation standards, and audit readiness.

The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

#J-18808-Ljbffr