1

It Risk Analyst Jobs in Washington (NOW HIRING)

ISACA IT Risk Fundamentals * NIST Cybersecurity Framework (NCSF) Practitioner * CISM Fundamentals ... Strong analytical, organizational, and critical-thinking skills. * Excellent written and verbal ...

SIMILAR CAREER TITLES Cybersecurity Analyst, Information Security Analyst, Security Engineer, Network Security Specialist, Security Administrator, IT Risk Analyst, Cyber Defense Specialist, Security ...

SIMILAR CAREER TITLES Cybersecurity Analyst, Information Security Analyst, Security Engineer, Network Security Specialist, Security Administrator, IT Risk Analyst, Cyber Defense Specialist, Security ...

SIMILAR CAREER TITLES Cybersecurity Analyst, Information Security Analyst, Security Engineer, Network Security Specialist, Security Administrator, IT Risk Analyst, Cyber Defense Specialist, Security ...

SIMILAR CAREER TITLES Cybersecurity Analyst, Information Security Analyst, Security Engineer, Network Security Specialist, Security Administrator, IT Risk Analyst, Cyber Defense Specialist, Security ...

The ideal candidate is an early-career information security or Governance, Risk, and Compliance (GRC) professional who possesses strong analytical, organizational, and communication skills, and is ...

Third-Party Risk Analyst

Mclean, VA · On-site

$45 - $47/hr

Bachelor's degree in Risk Management, Business Administration, Finance, Data Analytics, Project Management, Information Security, or related field. * 5+ years of experience in risk management or ...

Manager, Cyber Risk & Analysis As a Manager, you will apply your technical expertise, risk ... Cybersecurity and technology risk certifications such as Certified Information Systems Security ...

Showing results 41-60

It Risk Analyst information

See Washington salary details

$17

$45

$74

How much do it risk analyst jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for it risk analyst in Washington is $45.85, according to ZipRecruiter salary data. Most workers in this role earn between $33.75 and $55.82 per hour, depending on experience, location, and employer.

What does an IT Risk Analyst do?

An IT Risk Analyst is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They analyze potential threats, such as cyberattacks or data breaches, and develop strategies to minimize these risks. Their role involves working closely with other IT professionals to ensure compliance with security policies and regulatory requirements, as well as preparing risk reports and recommending improvements. Ultimately, IT Risk Analysts help organizations protect sensitive information and maintain secure, reliable IT operations.

What are some common challenges IT Risk Analysts face when collaborating with other departments?

IT Risk Analysts often work closely with various departments such as IT, compliance, and operations to identify and mitigate risks. One common challenge is translating technical risk information into terms that non-technical stakeholders can understand. Additionally, balancing the need for rigorous security measures with business objectives can sometimes lead to conflicting priorities. Effective communication and building strong relationships across teams are key to overcoming these challenges and ensuring that risk controls are both practical and effective.

What are the key skills and qualifications needed to thrive as an IT Risk Analyst, and why are they important?

To thrive as an IT Risk Analyst, you need a strong understanding of risk management frameworks, cybersecurity principles, and regulatory compliance—often supported by a degree in information technology or a related field. Familiarity with tools such as risk assessment software, vulnerability scanners, and certifications like CISSP or CISA is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills that distinguish top performers in this role. These competencies are crucial for accurately identifying risks, ensuring regulatory compliance, and effectively communicating findings to stakeholders.

What is the difference between It Risk Analyst vs Cybersecurity Analyst?

AspectIt Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentFinancial, healthcare, corporate sectors focusing on risk managementIT security teams, cybersecurity firms, tech companies
Employer & Industry UsageFinancial institutions, large corporations, consulting firmsTech companies, government agencies, security firms

While both roles focus on protecting information, the It Risk Analyst primarily assesses and manages overall IT risks within organizations, emphasizing compliance and risk mitigation strategies. In contrast, the Cybersecurity Analyst concentrates on defending systems from cyber threats and attacks. Both roles often collaborate but serve distinct functions in an organization's security framework.

How much do IT risk analysts get paid?

IT risk analysts typically earn a median annual salary of around $80,000 to $100,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. Salaries also vary based on industry and company size.

Is an IT risk analyst a hard job?

An IT risk analyst's job involves assessing and managing cybersecurity threats, which requires strong analytical skills, attention to detail, and knowledge of security tools and frameworks. The role can be challenging due to the evolving nature of cyber threats and the need for continuous learning and certification, such as CISSP or CISA. Overall, it can be demanding but is manageable with proper training and experience.

What job categories do people searching It Risk Analyst jobs in Washington look for?

The top searched job categories for It Risk Analyst jobs in Washington are:

What cities in Washington are hiring for It Risk Analyst jobs?

Cities in Washington with the most It Risk Analyst job openings:

Infographic showing various It Risk Analyst job openings in Washington as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $95,375 per year, or $45.9 per hour.

Jr. GRC Analyst

System One

Rockville, MD • On-site

Contractor

Posted 24 days ago


Job description

JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION Overview:
  • The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ServiceNow Integrated Risk Management (IRM).
Working under the guidance of Information Security leadership, the analyst will apply established risk assessment methodologies, workflows, and reporting processes to support enterprise cybersecurity governance and risk management initiatives. This role provides hands-on experience in information security governance, risk analysis, policy exception management, enterprise risk management, and ServiceNow IRM. Key Responsibilities: Policy Exception Management
  • Review policy exception requests for completeness and required documentation.
  • Validate business justifications and request additional information as needed.
  • Maintain exception records and track approvals in ServiceNow.
  • Monitor expiration dates, coordinate renewals, and produce status reports.
Risk Analysis
  • Conduct risk evaluations using established methodologies and templates.
  • Assess business impact, likelihood, and overall risk.
  • Identify compensating controls and document risk analyses.
  • Prepare risk-based recommendations for management review.
  • Maintain analysis records in ServiceNow.
Enterprise Risk Register Administration
  • Create, update, and maintain risk records.
  • Track risks identified through assessments, penetration tests, vulnerability scans, security incidents, and other approved sources.
  • Monitor mitigation activities, due dates, and risk status.
  • Maintain supporting documentation and generate reports.
ServiceNow IRM Administration
  • Process policy exceptions.
  • Maintain risk register records.
  • Track approvals and workflows.
  • Generate reports and dashboards.
Stakeholder Support
  • Communicate with IT staff, business stakeholders, system owners, managers, and security teams.
  • Provide professional customer service and clear written and verbal communication.
Education
  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Business Information Systems, or a related field.
Preferred Certifications - at least one
  • CompTIA Security+
  • ISACA IT Risk Fundamentals
  • NIST Cybersecurity Framework (NCSF) Practitioner
  • CISM Fundamentals
  • Cybersecurity, audit, or compliance-related certifications
Experience: Required
  • One (1) year of experience in Information Security, IT Governance, Risk Management, Compliance, Audit, Information Technology, or a related field; or
  • Recent graduate with relevant internship or equivalent experience.
Preferred
  • ServiceNow experience
  • Microsoft 365 proficiency
  • GRC program experience
  • Technical documentation experience
  • Customer service and project coordination experience
Knowledge & Skills:
  • Basic understanding of cybersecurity, risk management, information security, NIST Cybersecurity Framework, and compliance concepts.
  • Strong analytical, organizational, and critical-thinking skills.
  • Excellent written and verbal communication skills.
  • Attention to detail and ability to manage multiple priorities.
  • Ability to work independently and learn new technologies quickly.
Deliverables:
  • Policy exception reviews and tracking records
  • Risk analyses and recommendations
  • Risk register entries and updates
  • Monthly metrics and quarterly reports
  • Executive dashboards
  • ServiceNow documentation and reporting artifacts
#M1 #LI-CB3 Ref: #851-Rockville-S1


System One logo

About System One

Sourced by ZipRecruiter

System One helps employers get work done more efficiently and economically without compromising quality. Over our 35+ year history, we've helped connect thousands of talented people with innovative companies. The excitement of a perfect fit motivates us every single day.

Industry

Business consulting services and recruiting and staffing services

Company size

5,001 - 10,000 Employees

Headquarters location

Pittsburgh, PA, US