1

It Risk Analyst Jobs in Baltimore, MD (NOW HIRING)

... and IT Risk & Compliance. Provide strategic and operational leadership to protect enterprise ... Strong analytical and problem-solving skills, with the ability to evaluate security risk, threat ...

The IT team at Eurotech delivers technology solutions to internal and external customers, enabling ... Strong analytical skills with demonstrated problem solving ability. * Energized by working with a ...

The IT team at Eurotech delivers technology solutions to internal and external customers, enabling ... Strong analytical skills with demonstrated problem solving ability. * Energized by working with a ...

Working collaboratively with IT application teams, end users, business leadership, corporate IT, and third-party IT service providers * Identify and implement process automation to reduce manual ...

New

Working collaboratively with IT application teams, end users, business leadership, corporate IT, and third-party IT service providers * Identify and implement process automation to reduce manual ...

New

Responsible for the IT Asset Management program for the organization. ESSENTIAL FUNCTIONS: * IT Support - * Monitor ticketing system to document, assign and resolve end user technical problems ...

Showing results 41-60

It Risk Analyst information

See Baltimore, MD salary details

$15

$40

$65

How much do it risk analyst jobs pay per hour?

As of Aug 8, 2026, the average hourly pay for it risk analyst in Baltimore, MD is $40.23, according to ZipRecruiter salary data. Most workers in this role earn between $29.62 and $48.94 per hour, depending on experience, location, and employer.

Is an IT Risk Analyst a hard job?

An IT Risk Analyst role involves assessing and managing cybersecurity threats, which requires strong analytical skills, knowledge of IT systems, and familiarity with risk management frameworks. The job can be challenging due to the evolving nature of cyber threats and the need for attention to detail, but it is manageable with proper training and experience.

What does an IT Risk Analyst do?

An IT Risk Analyst is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They analyze potential threats, such as cyberattacks or data breaches, and develop strategies to minimize these risks. Their role involves working closely with other IT professionals to ensure compliance with security policies and regulatory requirements, as well as preparing risk reports and recommending improvements. Ultimately, IT Risk Analysts help organizations protect sensitive information and maintain secure, reliable IT operations.

What are the key skills and qualifications needed to thrive as an IT Risk Analyst, and why are they important?

To thrive as an IT Risk Analyst, you need a strong understanding of risk management frameworks, cybersecurity principles, and regulatory compliance—often supported by a degree in information technology or a related field. Familiarity with tools such as risk assessment software, vulnerability scanners, and certifications like CISSP or CISA is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills that distinguish top performers in this role. These competencies are crucial for accurately identifying risks, ensuring regulatory compliance, and effectively communicating findings to stakeholders.

What are some common challenges IT Risk Analysts face when collaborating with other departments?

IT Risk Analysts often work closely with various departments such as IT, compliance, and operations to identify and mitigate risks. One common challenge is translating technical risk information into terms that non-technical stakeholders can understand. Additionally, balancing the need for rigorous security measures with business objectives can sometimes lead to conflicting priorities. Effective communication and building strong relationships across teams are key to overcoming these challenges and ensuring that risk controls are both practical and effective.

What is the difference between It Risk Analyst vs Cybersecurity Analyst?

AspectIt Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentFinancial, healthcare, corporate sectors focusing on risk managementIT security teams, cybersecurity firms, tech companies
Employer & Industry UsageFinancial institutions, large corporations, consulting firmsTech companies, government agencies, security firms

While both roles focus on protecting information, the It Risk Analyst primarily assesses and manages overall IT risks within organizations, emphasizing compliance and risk mitigation strategies. In contrast, the Cybersecurity Analyst concentrates on defending systems from cyber threats and attacks. Both roles often collaborate but serve distinct functions in an organization's security framework.

How much do IT risk analysts get paid?

IT risk analysts typically earn a median annual salary of around $80,000 to $100,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. Salaries also vary based on industry and company size.
What are popular job titles related to It Risk Analyst jobs in Baltimore, MD? For It Risk Analyst jobs in Baltimore, MD, the most frequently searched job titles are:
What job categories do people searching It Risk Analyst jobs in Baltimore, MD look for? The top searched job categories for It Risk Analyst jobs in Baltimore, MD are:
Infographic showing various It Risk Analyst job openings in Baltimore, MD as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution, with an average salary of $83,674 per year, or $40.2 per hour.

VP of Cybersecurity

Mariner Finance, LLC

Baltimore, MD • On-site

Other

Posted 26 days ago


Mariner Finance rating

7.5

Company rating: 7.5 out of 10

Based on 37 frontline employees who took The Breakroom Quiz

114th of 150 rated financial services


Job description

In this role, you will...

Be responsible for leading the organization’s Cybersecurity and Information Security functions, including Security Engineering & Operations and IT Risk & Compliance. Provide strategic and operational leadership to protect enterprise systems, data, identities, cloud environments, platforms, and business processes while ensuring the company’s security program aligns with business priorities, risk appetite, regulatory requirements, and the evolving threat landscape.

Build and lead a metric-driven security organization focused on risk reduction, control effectiveness, incident response, identity security, cloud and platform security, regulatory compliance, automation, and continuous improvement. Oversee security technologies, threat monitoring, identity and access controls, cloud security architecture, audits, remediation efforts, vendor performance, and executive reporting while partnering across IT, engineering, development, platform, and business functions to embed secure-by-design practices into systems, processes, product delivery, and business decision-making.

Responsibilities and Duties:

  • Lead and manage Cybersecurity and Information Security functions, including Security Engineering & Operations and IT Risk & Compliance.
  • Serve as a key advisor to senior leadership on matters of strategic and operational security importance, influencing decision-making and driving proactive initiatives that strengthen the company’s security posture, risk management practices, regulatory compliance, and business resilience.
  • Develop and execute Cybersecurity and Information Security strategies aligned with business goals, risk appetite, regulatory requirements, and the evolving threat landscape.
  • Build and operate a metric-driven Cybersecurity and Information Security organization, defining KPIs that measure risk reduction, control effectiveness, operational performance, incident response, identity security, cloud security, and compliance posture.
  • Oversee security engineering teams responsible for security platforms, tooling, architecture, and integrations across endpoint, network, cloud, identity, and platform environments.
  • Manage security operations, including threat monitoring, event detection, incident response, investigations, and continuous improvement of detection and response capabilities.
  • Oversee identity security capabilities, including identity and access management, privileged access management, identity governance, Zero Trust initiatives, and privileged access controls.
  • Oversee cloud and platform security capabilities, including cloud security architecture, DevSecOps enablement, infrastructure-as-code security, container/runtime security, and partnership on cloud governance.
  • Partner with enterprise engineering, development, platform, and technology teams to integrate security into the software development lifecycle, enable secure engineering practices, support shared platform governance, and drive secure-by-design delivery.
  • Stay abreast of the evolving threat landscape, emerging attack vectors, and advancements in security technologies, continuously adapting the organization’s security posture.
  • Advise technology, development, engineering, and business partners on security best practices, architectural patterns, and risk-based decision-making, providing ongoing oversight and guidance.
  • Establish and operate a risk-based cybersecurity program aligned to business priorities, regulatory expectations, and the evolving threat landscape.
  • Oversee the IT Risk function, including coordination of security audits, penetration testing, third-party assessments, control validation, and remediation tracking.
  • Manage the end-to-end audit lifecycle, including planning, scheduling, execution, findings management, remediation tracking, and reporting.
  • Ensure compliance with regulatory and industry standards, including PCI DSS and ISO 27001, with ownership of audits, control validation, and remediation efforts.
  • Oversee annual reporting, regulatory submissions, partner security attestations, and related cybersecurity and information security documentation.
  • Drive timely and effective remediation of vulnerabilities, audit findings, control gaps, identity risks, cloud security risks, and security issues across the enterprise.
  • Establish and maintain security policies, standards, control frameworks, and governance practices that support business, regulatory, technology, and risk management objectives.
  • Implement and enhance continuous monitoring, detection, response, and reporting capabilities to proactively identify and address security risks.
  • Lead continual optimization of security technologies, tooling, platforms, and resource utilization to improve effectiveness and reduce cost.
  • Drive a bias toward automation and technology-first solutions, reducing manual processes and increasing scalability across Cybersecurity and Information Security functions.
  • Leverage automation and AI capabilities to enhance threat detection, accelerate response, improve risk analysis, strengthen security operations, and scale security program capabilities.
  • Manage security vendor relationships, contracts, service performance, and cost optimization across tools, services, and third-party providers.
  • Provide executive-level reporting on security posture, risks, incidents, identity security, cloud security, control effectiveness, remediation progress, and compliance status.
  • Develop and manage the Cybersecurity and Information Security budget, including tools, services, staffing, and vendor spend, optimizing cost efficiency while maintaining or improving program effectiveness.
  • Establish strong, business-oriented partnerships across functions, ensuring Cybersecurity and Information Security enables and protects business outcomes and priorities.
  • Share knowledge, mentor, and educate stakeholders with regard to the company’s Cybersecurity and Information Security initiatives, opportunities, risks, and challenges.
  • Promote the professional growth and development of team members by sharing knowledge, mentoring, and providing consistent, actionable feedback.
  • Responsible for managerial matters such as performance appraisals and goal setting, promotions, salary recommendations, and staffing in accordance with the company hiring process, personnel policies, and budget requirements.
  • Perform additional duties as assigned to support evolving business needs.

Required Qualifications:

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field; applicable years of experience may be substituted for a bachelor’s degree.
  • Twelve (12) years of experience in the Information Technology field with significant leadership experience in cybersecurity, information security, or related security functions.
  • Three (3) years of managerial experience leading or overseeing Security Operations, Security Engineering, IT Risk, Compliance, Identity Security, Cloud Security, DevSecOps, or related cybersecurity and information security functions, working in capacities with decision-making authority and responsibility for coordinating, delegating, and managing operational activities.
  • CISSP, CISM, or an equivalent information security certification.
  • Extensive experience managing security technologies, including SIEM, EDR, IAM, PAM, vulnerability management, cloud security, and network security tools.
  • Demonstrated experience with identity security capabilities, including identity and access management, privileged access management, identity governance, Zero Trust, and privileged access controls.
  • Demonstrated experience with cloud and platform security capabilities, including cloud security architecture, DevSecOps enablement, infrastructure-as-code security, container/runtime security, and cloud governance partnership.
  • Demonstrated ability to partner with enterprise engineering, development, platform, and technology teams to integrate security into the software development lifecycle, support engineering enablement, strengthen shared platform governance, and promote secure-by-design delivery.
  • Demonstrated success managing audits, penetration testing programs, and enterprise remediation efforts.
  • Experience building and operating incident response and investigation capabilities.
  • Proven ability to align cybersecurity and information security strategies, programs, and initiatives with business priorities, risk appetite, regulatory requirements, and measurable outcomes.
  • Strong experience with regulatory frameworks and compliance standards, including PCI DSS and ISO 27001.
  • Demonstrated financial discipline in managing operational budgets, vendor costs, resource utilization, and cost optimization initiatives.
  • Demonstrated success building metric-driven security programs with measurable improvements in risk posture and operational performance.
  • Proven ability to support and enhance team performance, promote engagement, and cultivate the professional development of team members.
  • Demonstrated proficiency in leading through change, executing on major initiatives, and leading cross-departmental work.
  • Strong experience managing vendors, contracts, third parties, service performance, and costs across Cybersecurity, Information Security, and IT Risk functions.
  • Ability to work effectively, manage complex projects, and multitask successfully in a dynamic, fast-paced, and complex business environment.
  • Strong decision-making and negotiation skills with the ability to use expertise to influence on matters of strategic importance.
  • Ability to foster strong relationships, influence, coach, and partner with all levels across the organization.
  • Ability to articulate complex information in understandable terms to various audiences. Comfortable presenting data to all levels of leadership and across business functions.
  • Highly proficient with Microsoft Office Suite.
  • Strong analytical and problem-solving skills, with the ability to evaluate security risk, threat trends, identity risk, cloud security posture, control performance, compliance obligations, and business impacts to guide decisions, address complex challenges, and strengthen the enterprise security program.
  • Demonstrated high level of reliability, flexibility, and dedication with the ability to adapt quickly to changing priorities and timelines.
  • Excellent interpersonal skills necessary to communicate professionally and effectively, verbally and in writing, with regulatory agencies, vendors, customers, and all levels of company staff.

Preferred Qualifications:

  • Experience in financial services or other highly regulated industries.
  • Experience implementing advanced security capabilities, including Zero Trust, SASE, identity-centric security models, identity governance, and privileged access management.
  • Familiarity with cloud security architectures across AWS, Azure, or Google Cloud Platform.
  • Experience with cloud and platform security practices, including infrastructure-as-code security, container/runtime security, cloud governance, and shared platform security
  • Experience with GRC platforms and automation of compliance processes.
  • Track record of integrating security into DevOps, SDLC, engineering workflows, or shared platform governance through DevSecOps practices.
  • Certifications:
    • CISA, CRISC (for risk and compliance focus).
    • Cloud security certifications (e.g., CCSP, AWS/Azure Security Specialty).
    • PCI QSA or ISO 27001 Lead Implementer/Auditor.
    • ISO 42001 implementation/certification experience.

Hours of Work:

Work hours will depend on the business hours of the time zone serviced.

To the extent permitted by law, the Company may, in its sole discretion, change the work schedule to address business needs.

Physical Demands:

While performing the duties of this job, the employee is frequently required to sit for extended periods; reach with hands and arms; and talk or hear. The employee is occasionally required to move about. The employee must occasionally lift and/or move up to twenty (20) pounds. Specific vision abilities required by this job include close vision and the ability to adjust focus.

EEO:

Mariner Finance is an Equal Opportunity Employer and does not discriminate on the basis of race, color, religion, creed, sex, gender, gender identity or expression, marital status, age, religion, national origin, sexual orientation, familial or caregiver status, citizenship status, status as a victim of domestic violence, medical condition, genetic information, pregnancy, physical or mental disability, or status as a disabled or Vietnam era veteran. Employee must be able to perform the essential duties/functions of the position satisfactorily and, if requested, reasonable accommodations will be made to enable employees with disabilities to perform the essential duties/functions of their job, absent undue hardship. Drug/Alcohol/Smoke-free workplace. 

This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee. Duties, responsibilities, and activities may change or new ones may be assigned at any time or without notice.


What Mariner Finance employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom