1

It Risk Analyst Jobs in Washington (NOW HIRING)

A financial services organization in Virginia is seeking an IT Risk & Controls Analyst to join their team in Vienna. About the Opportunity: * Schedule: Monday to Friday * Hours: Standard business

IT Audit Senior

Alexandria, VA Β· On-site

$100K - $132K/yr

IT Audit Senior Are you ready to take the next step in your IT audit career? Join Castro amp ... Identify and Communicate Risk : Analyze IT environments, pinpoint control gaps, and clearly present ...

... effective IT infrastructure solutions, review reusable components, and develop technical ... Required Skill and Experience The ideal candidate is a highly organized Risk Analyst with strong ...

IT Advisory Manager

Mclean, VA Β· On-site

$96K - $117K/yr

... analyze IT control weaknesses, identify root causes, and develop remediation plans. Responsibilities include some or all of the following: * Leading a team of IT security auditors performing IT risk ...

IT Advisory Manager

Chantilly, VA Β· On-site

$97K - $119K/yr

... analyze IT control weaknesses, identify root causes, and develop remediation plans. Responsibilities include some or all of the following: * Leading a team of IT security auditors performing IT risk ...

IT Advisory Manager

Chantilly, VA Β· On-site

$97K - $119K/yr

... analyze IT control weaknesses, identify root causes, and develop remediation plans. Responsibilities include some or all of the following: * Leading a team of IT security auditors performing IT risk ...

Job Title: Risk Analyst Location: Vienna, VA - 3 days onsite, 2 days remote Type: Contract ... genetic information, veteran status, marital status, or any other characteristic protected by ...

Job Title: Risk Analyst Location: Vienna, VA - 3 days onsite, 2 days remote Type: Contract ... genetic information, veteran status, marital status, or any other characteristic protected by ...

Job Title: Risk Analyst Location: Vienna, VA - 3 days onsite, 2 days remote Type: Contract ... genetic information, veteran status, marital status, or any other characteristic protected by ...

next page

Showing results 1-20

It Risk Analyst information

See Washington salary details

$17

$45

$74

How much do it risk analyst jobs pay per hour?

As of Sep 14, 2026, the average hourly pay for it risk analyst in Washington is $45.85, according to ZipRecruiter salary data. Most workers in this role earn between $33.75 and $55.82 per hour, depending on experience, location, and employer.

What does an IT Risk Analyst do?

An IT Risk Analyst is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They analyze potential threats, such as cyberattacks or data breaches, and develop strategies to minimize these risks. Their role involves working closely with other IT professionals to ensure compliance with security policies and regulatory requirements, as well as preparing risk reports and recommending improvements. Ultimately, IT Risk Analysts help organizations protect sensitive information and maintain secure, reliable IT operations.

What are some common challenges IT Risk Analysts face when collaborating with other departments?

IT Risk Analysts often work closely with various departments such as IT, compliance, and operations to identify and mitigate risks. One common challenge is translating technical risk information into terms that non-technical stakeholders can understand. Additionally, balancing the need for rigorous security measures with business objectives can sometimes lead to conflicting priorities. Effective communication and building strong relationships across teams are key to overcoming these challenges and ensuring that risk controls are both practical and effective.

What are the key skills and qualifications needed to thrive as an IT Risk Analyst, and why are they important?

To thrive as an IT Risk Analyst, you need a strong understanding of risk management frameworks, cybersecurity principles, and regulatory complianceβ€”often supported by a degree in information technology or a related field. Familiarity with tools such as risk assessment software, vulnerability scanners, and certifications like CISSP or CISA is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills that distinguish top performers in this role. These competencies are crucial for accurately identifying risks, ensuring regulatory compliance, and effectively communicating findings to stakeholders.

What is the difference between It Risk Analyst vs Cybersecurity Analyst?

AspectIt Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentFinancial, healthcare, corporate sectors focusing on risk managementIT security teams, cybersecurity firms, tech companies
Employer & Industry UsageFinancial institutions, large corporations, consulting firmsTech companies, government agencies, security firms

While both roles focus on protecting information, the It Risk Analyst primarily assesses and manages overall IT risks within organizations, emphasizing compliance and risk mitigation strategies. In contrast, the Cybersecurity Analyst concentrates on defending systems from cyber threats and attacks. Both roles often collaborate but serve distinct functions in an organization's security framework.

How much do IT risk analysts get paid?

IT risk analysts typically earn a median annual salary of around $80,000 to $100,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. Salaries also vary based on industry and company size.

Is an IT risk analyst a hard job?

An IT risk analyst's job involves assessing and managing cybersecurity threats, which requires strong analytical skills, attention to detail, and knowledge of security tools and frameworks. The role can be challenging due to the evolving nature of cyber threats and the need for continuous learning and certification, such as CISSP or CISA. Overall, it can be demanding but is manageable with proper training and experience.

What job categories do people searching It Risk Analyst jobs in Washington look for?

The top searched job categories for It Risk Analyst jobs in Washington are:

What cities in Washington are hiring for It Risk Analyst jobs?

Cities in Washington with the most It Risk Analyst job openings:

Infographic showing various It Risk Analyst job openings in Washington as of August 2026, with employment types broken down into 58% Full Time, and 42% Contract. Highlights an 100% In-person job distribution, with an average salary of $95,375 per year, or $45.9 per hour.

IT Risk & Controls Analyst

Vienna, VA β€’ On-site

Other

Posted 18 days ago


Job description



A financial services organization in Virginia is seeking an IT Risk & Controls Analyst to join their team in Vienna.


About the Opportunity:




  • Schedule: Monday to Friday




  • Hours: Standard business




  • Setting: Hybrid (3 days onsite)




Responsibilities:




  • Plan and scope IT and Information Security control assessments, including communications, risk and control matrices, scope documents, and supporting materials




  • Conduct walkthroughs with business partners to identify actual versus expected controls




  • Develop and execute testing strategies to evaluate control effectiveness




  • Document testing procedures, results, issues, and assessment conclusions




  • Prepare final assessment reports and present findings to leadership and other stakeholders




Qualifications:




  • Experience performing control testing, audit, risk assessments, or related functions




  • Experience with IT and/or Information Security risk assessments




  • Knowledge of financial services regulations, standards, and frameworks, including FFIEC, NIST, ISO, NCUA, and GLBA




  • Familiarity with NIST Cybersecurity Framework and 800 Series, ISO 27001/27002, SANS/CIS, and PCI DSS




  • Bachelor's degree in Business, Information Systems, or a related field, or equivalent work or military experience




  • Strong research, analytical, problem-solving, planning, and organizational skills




  • Strong written, verbal, interpersonal, and technical writing skills




  • Ability to clearly communicate assessment findings, conclusions, and recommendations to leadership




  • Experience working effectively with staff, management, business stakeholders, and third parties




  • Ability to build effective relationships through rapport, trust, diplomacy, and tact




  • Strong proficiency with word processing and spreadsheet applications




Desired Skills:





  • Information Security certification, such as CISSP, CISA, CCSP, or CRISC





  • Experience working within Audit, Enterprise Risk Management (ERM), or First Line of Defense functions




  • Experience working in an Agile environment