1

It Risk Analyst Jobs in Maryland (NOW HIRING)

Enterprise Architect (IT)

Hagerstown, MD · On-site +1

$68.50 - $88.25/hr

Provide visibility into technology risk, technical debt, platform health, lifecycle obsolescence ... Bachelor's degree in computer science, Information Technology, Engineering, Business, or a related ...

Enterprise Architect (IT)

Hagerstown, MD · On-site +1

$102K - $208K/yr

Provide visibility into technology risk, technical debt, platform health, lifecycle obsolescence ... Bachelor's degree in computer science, Information Technology, Engineering, Business, or a related ...

SIMILAR CAREER TITLES Information Security Auditor, IT Security Auditor, Cybersecurity Auditor, Compliance Analyst, Risk Assessment Specialist, Security Risk Auditor, Internal IT Auditor, Information ...

Information Technology Analyst - Mid ***This position requires a Top-Secret clearance *** The ... risk mitigation in the future. Communicate technical concepts and insights to both technical and ...

Sr. IT Auditor

Bethesda, MD · On-site

$90K - $120K/yr

You'll asse risk across applications, infrastructure, cloud environments, and operational ... Excellent analytical, communication, and stakeholder-management skills A Successful Candidate ...

You'll asse risk across applications, infrastructure, cloud environments, and operational ... Excellent analytical, communication, and stakeholder-management skills A Successful Candidate ...

Showing results 21-40

It Risk Analyst information

See Maryland salary details

$14

$39

$63

How much do it risk analyst jobs pay per hour?

As of Aug 15, 2026, the average hourly pay for it risk analyst in Maryland is $39.29, according to ZipRecruiter salary data. Most workers in this role earn between $28.94 and $47.84 per hour, depending on experience, location, and employer.

Is an IT Risk Analyst a hard job?

An IT Risk Analyst role involves assessing and managing cybersecurity threats, which requires strong analytical skills, knowledge of IT systems, and familiarity with risk management frameworks. The job can be challenging due to the evolving nature of cyber threats and the need for attention to detail, but it is manageable with proper training and experience.

What does an IT Risk Analyst do?

An IT Risk Analyst is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They analyze potential threats, such as cyberattacks or data breaches, and develop strategies to minimize these risks. Their role involves working closely with other IT professionals to ensure compliance with security policies and regulatory requirements, as well as preparing risk reports and recommending improvements. Ultimately, IT Risk Analysts help organizations protect sensitive information and maintain secure, reliable IT operations.

What are the key skills and qualifications needed to thrive as an IT Risk Analyst, and why are they important?

To thrive as an IT Risk Analyst, you need a strong understanding of risk management frameworks, cybersecurity principles, and regulatory compliance—often supported by a degree in information technology or a related field. Familiarity with tools such as risk assessment software, vulnerability scanners, and certifications like CISSP or CISA is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills that distinguish top performers in this role. These competencies are crucial for accurately identifying risks, ensuring regulatory compliance, and effectively communicating findings to stakeholders.

What are some common challenges IT Risk Analysts face when collaborating with other departments?

IT Risk Analysts often work closely with various departments such as IT, compliance, and operations to identify and mitigate risks. One common challenge is translating technical risk information into terms that non-technical stakeholders can understand. Additionally, balancing the need for rigorous security measures with business objectives can sometimes lead to conflicting priorities. Effective communication and building strong relationships across teams are key to overcoming these challenges and ensuring that risk controls are both practical and effective.

What is the difference between It Risk Analyst vs Cybersecurity Analyst?

AspectIt Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentFinancial, healthcare, corporate sectors focusing on risk managementIT security teams, cybersecurity firms, tech companies
Employer & Industry UsageFinancial institutions, large corporations, consulting firmsTech companies, government agencies, security firms

While both roles focus on protecting information, the It Risk Analyst primarily assesses and manages overall IT risks within organizations, emphasizing compliance and risk mitigation strategies. In contrast, the Cybersecurity Analyst concentrates on defending systems from cyber threats and attacks. Both roles often collaborate but serve distinct functions in an organization's security framework.

How much do IT risk analysts get paid?

IT risk analysts typically earn a median annual salary of around $80,000 to $100,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. Salaries also vary based on industry and company size.

What are popular job titles related to It Risk Analyst jobs in Maryland?

For It Risk Analyst jobs in Maryland, the most frequently searched job titles are:

What cities in Maryland are hiring for It Risk Analyst jobs?

Cities in Maryland with the most It Risk Analyst job openings:

Infographic showing various It Risk Analyst job openings in Maryland as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution, with an average salary of $81,729 per year, or $39.3 per hour.

Director, Technology Risk & Digital Enablement

McCormick & Company

Hunt Valley, MD • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 27 days ago


McCormick & Company rating

8.2

Company rating: 8.2 out of 10

Based on 45 frontline employees who took The Breakroom Quiz

72nd of 438 rated food and drinks producers


Job description

You may know McCormick as a leader in herbs, spices, seasonings, and condiments - and we're only getting started. At McCormick, we're always looking for new people to bring their unique flavor to our team.
McCormick employees - all 14,000 of us across the world - are what makes this company a great place to work.
We are looking to hire a Director, Technology Risk & Digital Enablement to join the Global Risk and Audit Management (GRAM) team based at our Global Headquarters in Hunt Valley, Maryland. The position is hybrid eligible (50% onsite per month).
What We Bring To The Table:
The best people deserve the best rewards. In addition to the benefits you'd expect from a global leader (401k, health insurance, paid time off, etc.) we also offer:
• Competitive compensation
• Career growth opportunities
• Flexibility and Support for Diverse Life Stages and Choices
• Wellbeing programs including Physical, Mental and Financial wellness
• Tuition assistance
We have embarked on an exciting journey to transform and integrate our Enterprise Risk and Internal Audit capabilities and align with McCormick's strategic priorities. Director, Technology Risk & Digital Enablement is a key leadership role reporting to the Chief Risk & Audit Officer (CRAO), and responsible for owning and advancing the full technology risk agenda within GRAM. This individual serves as the strategic leader in advancing global technology and cyber risk coverage while simultaneously acting as the function's digital transformation champion - driving the adoption of analytics, automation, and emerging technologies to make audit activities smarter, faster, and more impactful.
This is a dual-mandate role: one foot firmly in risk and assurance, the other driving innovation. The successful candidate will be as comfortable presenting technology risk insights to the Audit Committee as they are building a data analytics roadmap with audit teams.
Responsibilities
Technology Risk & Audit Leadership
  • Lead and own all GRAM workstreams related to global Technology Risk Universe, ensuring comprehensive coverage of IT, cyber, data, cloud, AI, and third-party technology risks.
  • Lead the planning, execution, and reporting of all technology advisory and assurance initiatives across infrastructure, applications, cybersecurity, data governance, and emerging technology.
  • Serve as GRAM function's primary interface with the Technology leadership team incl. CTO, CISO, and others.
  • Serve as the in-house expert on all Technology matters related to Sarbanes-Oxley (SOX), corporate governance and enterprise risks and provide expert opinion on technology risk matters to the CARO, Audit Committee, and senior management, translating complex technical risks into clear business language.
  • Collaborate closely with other members of GRAM leadership team to ensure that risk management activities are well-defined, coordinated, risk-based, and executed
  • Stay current with the evolving technology risk landscape (e.g., cloud, AI/ML risk, ransomware, third-party digital risk) and ensure risk mitigation and audit plans remain relevant and forward-looking.
  • Oversee quality assurance on technology audit engagements, ensuring findings are well-evidenced, rated consistently, and linked to business impact.

Digital Enablement & Innovation
  • Champion the adoption of digital tools and capabilities within Internal Audit, including data analytics, automation/AI-assisted audit techniques, and continuous monitoring.
  • Define and execute a multi-year Digital Enablement Roadmap for the GRAM function, with measurable milestones and efficiency outcomes.
  • Partner with Data & Analytics, IT, and external vendors to build and sustain function-specific data pipelines, dashboards, and automated testing capabilities.
  • Identify and pilot emerging technologies (e.g., natural language processing for document review, anomaly detection, GRC platform enhancements).
  • Embed data-driven risk management techniques into engagements, helping teams move from sample-based testing to population-level analysis.
  • Track and report on digital enablement ROI - efficiency gains, risk coverage expansion, and quality improvements.

People Leadership & Capability Building
  • Recruit and retain top technology risk talent, building a team that blends deep technical expertise with strong business acumen.
  • Lead, mentor, and develop a team of technology risk professionals (in-house and co-source provider), fostering a culture of continuous learning and innovation.
  • Build digital literacy and data analytics skills across the broader audit function through training, coaching, and hands-on engagement.
  • Act as a role model for intellectual curiosity and agile ways of working within a traditionally structured audit environment.

Candidate profile
  • Bachelor's degree in Information Systems or related field.
  • Required: CISA, CISM, CISSP certification or quivalent. Preferred CIA, CPA or equivalent.
  • 10+ years of progressive experience in technology audit, IT risk management, or information security, with at least 4 years in a leadership role, including interaction with senior management.
  • Experience managing cross-regional or multi-country audit programs, with specific exposure to emerging markets with regions.
  • Strong track record of leading high-performing audit teams and developing talent at all levels.
  • Exceptional communication, influencing, and executive presence skills - ability to present complex risk and audit topics to C-suite and Board audiences.
  • Proficiency with audit management and GRC technology platforms (e.g., Optro, Workiva, Archer, or equivalent).
  • Large, multi-brand, global, public company experience preferred.
  • M&A experience preferred.
  • Thorough knowledge of IT Operational Functions including IAM, Asset Management, Cybersecurity, Data Privacy.
  • Demonstrated experience leading or materially contributing to a digital transformation or data analytics program within an audit or risk function.
  • Thorough understanding of internal auditing standards, PCAOB auditing standards, COSO, SOX, US GAAP and risk assessment practice.
  • Robust understanding of regulatory and external requirements as they relate to IT, privacy and cybersecurity for regulations such as GDPR, NERC-CIP and SOX.
  • Proven track-record of implementing technology enablers such as data analytics, AI, etc. to modernize risk & audit capabilities.
  • Proven ability to handle scale, change agenda, pace and overall complexity.
  • Experience implementing and managing change within an organization, taking steps to remove barriers or to accelerate its pace.
  • Track record of working alongside business leaders, positioning internal audit as a strategic partner, identifying and helping mitigate risk.
  • Superior business acumen; ability to build strong relationships and trust with company leadership and business process owners.
  • Broad understanding of the inter-dependency between operational, technological, strategic and reputational risks as well as general compliance standards.
  • Professional, self-starter, solution-minded, results oriented and approachable.
  • Strong analytical and problem-solving skills with attention to detail and customer focus.
  • Excellent organizational, time management and prioritization skills.
  • Commitment to maintaining a high degree of discretion and confidentiality.

#LI-DNI
Base Salary: $140,610-253,080
Base salary compensation will be determined based on factors such as geographic location, skills, education, experience for this role, and/or internal equity of our current employees as part of any final offer. This position is also eligible to participate in McCormick's Incentive Bonus (MIB) Plan/ McCormick's Sales Incentive Bonus (SIB) Plan/ McCormick's Dividend Program. In addition to a competitive compensation package, permanent employees of McCormick are eligible for our extensive Total Rewards programs that include:
- Comprehensive health plans covering medical, vision, dental, life and disability benefits
- Family-friendly benefits such as paid parental leave, fertility benefits, Employee Assistance Program, and caregiver support
- Retirement and investment programs including 401(k) and profit-sharing plans
McCormick & Company is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.
As a general policy, McCormick does not offer employment visa sponsorships upon hire or in the future.
#LI-DNI
WHY WORK AT MCCORMICK?
As a McCormick employee you'll be empowered to focus on more than your individual responsibilities. You'll have the opportunity to be part of something bigger than yourself-to have a say in where the company is going and how it's growing.
Between our passion for flavor, our 130-year history of leadership and integrity, the competitive and comprehensive benefits we offer, and our culture, which is built on respect and opportunities for growth, there are many reasons to join us at McCormick.

What McCormick & Company employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom