1

It Risk Analyst Jobs in Seattle, WA (NOW HIRING)

About the role The Senior IT Risk and Security Analyst (RSA) is a critical member of the Information Security Officer's (ISO's) team. The RSA's role is to act as an interface between IT, Audit ...

Senior IT Auditor, Technology Risk

Seattle, WA · On-site

$107K - $140K/yr

Use data and analytical thinking to identify trends, validate controls, and support risk ... You have worked in roles involving IT audit, risk, security, engineering, or similar, ideally in ...

Senior IT Auditor, Technology Risk

Seattle, WA · On-site

$107K - $140K/yr

Use data and analytical thinking to identify trends, validate controls, and support risk ... You have worked in roles involving IT audit, risk, security, engineering, or similar, ideally in ...

Senior IT Auditor, Technology Risk

Seattle, WA · On-site

$107K - $140K/yr

Use data and analytical thinking to identify trends, validate controls, and support risk ... You have worked in roles involving IT audit, risk, security, engineering, or similar, ideally in ...

Use data and analytical thinking to identify trends, validate controls, and support risk ... You have worked in roles involving IT audit, risk, security, engineering, or similar, ideally in ...

Senior IT Auditor, Technology Risk

Seattle, WA · On-site

$107K - $140K/yr

Use data and analytical thinking to identify trends, validate controls, and support risk ... You have worked in roles involving IT audit, risk, security, engineering, or similar, ideally in ...

Senior IT Auditor, Technology Risk

Seattle, WA · On-site

$107K - $140K/yr

Use data and analytical thinking to identify trends, validate controls, and support risk ... You have worked in roles involving IT audit, risk, security, engineering, or similar, ideally in ...

This role offers the chance to apply technical expertise, risk assessment, and data analytics ... We are seeking an experienced IT Audit Manager to join our Devices, Advertising, and Media ...

This role offers the chance to apply technical expertise, risk assessment, and data analytics ... We are seeking an experienced IT Audit Manager to join our Devices, Advertising, and Media ...

This role offers the chance to apply technical expertise, risk assessment, and data analytics ... We are seeking an experienced IT Audit Manager to join our Devices, Advertising, and Media ...

Perform regular risk analysis and risk management. Be aware of IT audit requirements and prepare. Ensure HIPAA and Data Stewardship compliance per UW Medicine Security and Privacy policies.

next page

Showing results 1-20

It Risk Analyst information

See Seattle, WA salary details

$17

$46

$74

How much do it risk analyst jobs pay per hour?

As of Aug 26, 2026, the average hourly pay for it risk analyst in Seattle, WA is $46.10, according to ZipRecruiter salary data. Most workers in this role earn between $33.94 and $56.11 per hour, depending on experience, location, and employer.

What does an IT Risk Analyst do?

An IT Risk Analyst is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They analyze potential threats, such as cyberattacks or data breaches, and develop strategies to minimize these risks. Their role involves working closely with other IT professionals to ensure compliance with security policies and regulatory requirements, as well as preparing risk reports and recommending improvements. Ultimately, IT Risk Analysts help organizations protect sensitive information and maintain secure, reliable IT operations.

What are some common challenges IT Risk Analysts face when collaborating with other departments?

IT Risk Analysts often work closely with various departments such as IT, compliance, and operations to identify and mitigate risks. One common challenge is translating technical risk information into terms that non-technical stakeholders can understand. Additionally, balancing the need for rigorous security measures with business objectives can sometimes lead to conflicting priorities. Effective communication and building strong relationships across teams are key to overcoming these challenges and ensuring that risk controls are both practical and effective.

What are the key skills and qualifications needed to thrive as an IT Risk Analyst, and why are they important?

To thrive as an IT Risk Analyst, you need a strong understanding of risk management frameworks, cybersecurity principles, and regulatory compliance—often supported by a degree in information technology or a related field. Familiarity with tools such as risk assessment software, vulnerability scanners, and certifications like CISSP or CISA is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills that distinguish top performers in this role. These competencies are crucial for accurately identifying risks, ensuring regulatory compliance, and effectively communicating findings to stakeholders.

What is the difference between It Risk Analyst vs Cybersecurity Analyst?

AspectIt Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentFinancial, healthcare, corporate sectors focusing on risk managementIT security teams, cybersecurity firms, tech companies
Employer & Industry UsageFinancial institutions, large corporations, consulting firmsTech companies, government agencies, security firms

While both roles focus on protecting information, the It Risk Analyst primarily assesses and manages overall IT risks within organizations, emphasizing compliance and risk mitigation strategies. In contrast, the Cybersecurity Analyst concentrates on defending systems from cyber threats and attacks. Both roles often collaborate but serve distinct functions in an organization's security framework.

How much do IT risk analysts get paid?

IT risk analysts typically earn a median annual salary of around $80,000 to $100,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. Salaries also vary based on industry and company size.

Is an IT risk analyst a hard job?

An IT risk analyst's job involves assessing and managing cybersecurity threats, which requires strong analytical skills, attention to detail, and knowledge of security tools and frameworks. The role can be challenging due to the evolving nature of cyber threats and the need for continuous learning and certification, such as CISSP or CISA. Overall, it can be demanding but is manageable with proper training and experience.
Infographic showing various It Risk Analyst job openings in Seattle, WA as of August 2026, with employment types broken down into 58% Full Time, and 42% Contract. Highlights an 100% In-person job distribution, with an average salary of $95,887 per year, or $46.1 per hour.

Sr IT Risk Security Analyst

Bellevue, WA • On-site


Symetra
Insurance Services • 5 - 10K employees

8.4

Company rating: 8.4 out of 10

Based on 17 frontline employees who took The Breakroom Quiz

109th of 312 rated insurance

People enjoy working here

Good employer

Recommended by parents


Other

Retirement, PTO

This job post has expired 2 days ago. Applications are no longer accepted.


Job description

Company Overview

Symetra Investment Management ("SIM") is a SEC-registered investment advisory firm with approximately $78 billion in assets under management as of March 31, 2025. Symetra Financial Corporation ("SFC"), a diversified financial services company with $68.4 billion in assets as of December 31, 2024, headquartered in Bellevue, Washington is the sole shareholder of SIM. SFC is also the holding company of Symetra Life Insurance Company ("Symetra Life"), which was founded in 1957, and has insurer financial strength ratings of 'A' by A.M. Best and Standard & Poor's and 'A1' by Moody's. Symetra Life is among the top 40 largest life insurance companies in the United States (based on statutory admitted assets as of December 31, 2024) and has approximately 2.3 million customers and over 2,600 employees nationwide. SFC is a wholly owned subsidiary of Sumitomo Life Insurance Company, a mutual life insurance company with head offices in Osaka and Tokyo, Japan. Founded in 1907, Sumitomo is one of the largest life insurance companies in Japan with $327 billion of assets as of March 31, 2025. SIM currently has recently begun marketing its investment management services to third-party institutional investors.

About the role

The Senior IT Risk and Security Analyst (RSA) is a critical member of the Information Security Officer's (ISO's) team. The RSA's role is to act as an interface between IT, Audit Services and the business for overall IT risk management. The RSA must be able to understand our current IT Control environment including IT General Controls and ISO 27001 Information Security Critical Controls while improving our risk posture. The RSA coordinates with several stakeholders including business, audit services, and IT to manage, evaluate and remediate issues.

What you will do

  • Serve as a trusted advisor to IT and business teams by identifying technology, security, and operational risks, recommending effective controls, and ensuring risks are properly assessed, documented, and mitigated.
  • Lead enterprise IT risk management activities, including annual risk assessments, risk committee facilitation, risk reporting, policy development, risk register management, and continuous improvement of the organization's risk management framework.
  • Support third-party technology risk management across the vendor lifecycle, including risk tiering, pre-contract due diligence, security assessments, and periodic monitoring. Evaluate SOC reports, ISO 27001 certifications, security questionnaires, penetration tests, external security ratings, encryption and data-handling practices, AI usage, contractual controls, and business continuity capabilities; document risk ratings and findings, drive remediation, and escalate unresolved risks in partnership with Procurement, Legal, business owners, and security teams.
  • Manage and enhance IT audit and compliance programs, including SOX IT General Controls (ITGCs), ISO 27001 security controls, regulatory requirements, and internal/external audit activities to ensure controls are designed and operating effectively.
  • Partner with control owners, auditors, and business stakeholders to track audit findings, drive remediation efforts, provide training, and ensure sustainable compliance across technology and business functions.
  • Evaluate third-party vendors, emerging technologies, and business initiatives to identify security and operational risks, implement monitoring controls, and support disaster recovery and business continuity planning efforts.
  • Develop executive-level reporting and dashboards that communicate risk exposure, audit results, compliance status, and remediation progress to senior leadership and governance committees.
  • Conduct reviews of information systems, business applications, infrastructure, and operational processes to assess security posture, control effectiveness, and alignment with company objectives.
  • Maintain ownership of risk management tools and processes, ensuring accurate documentation, reporting, workflow management, and ongoing program maturity.

Who You Are

  • You're an analytical problem solver with a strong understanding of information security, IT risk management, audit methodologies, compliance frameworks, and internal controls.
  • You have experience managing complex risk assessments, audit programs, and compliance initiatives, with the ability to translate technical risks into business-focused recommendations.
  • You're an effective communicator who can confidently collaborate with executives, auditors, IT leaders, business stakeholders, and external vendors to influence positive outcomes.
  • You thrive working independently while also serving as a trusted advisor, mentor, and subject matter expert for colleagues and cross-functional teams.
  • You possess strong organizational skills and attention to detail, enabling you to manage multiple priorities, maintain accurate documentation, and deliver high-quality results in a fast-paced environment.

Nice to Haves

  • Bachelor's degree in information systems, Cybersecurity, Computer Science, Accounting, Business, or related field, or equivalent combination of education and experience.
  • 5-8 years of experience in IT risk management, information security, IT audit, cybersecurity governance, compliance, or related disciplines.
  • Professional certifications such as CISA, CISSP, CRISC, CISM, CIA, ISO 27001 Lead Implementer/Auditor, or other relevant credentials.
  • Experience with SOX ITGCs, ISO 27001, IT risk assessment methodologies, vendor risk management, security governance, and audit lifecycle management.
  • Demonstrated ability to influence stakeholders, lead initiatives, and communicate complex technical concepts to both technical and non-technical audiences.

Why Work at Symetra

Here's what some of our employees have to say about why they work at Symetra:

"Symetra is a great place if you are looking for the opportunity to contribute, to grow, to be seen and valued." Vernell K. - Auditor

"We're big enough to make an impact on the country, but small enough to care and know who you are and what you're contributing to the organization. All new ideas are welcome!" Stephanie F. - VP Customer Service & Operations

What we offer you

Benefits and Perks

We don't take a "one-size-fits-all" approach when it comes to our employees. Our programs are designed to make your life better both at work and at home.

  • Flexible full-time or hybrid telecommuting arrangements
  • Plan for your future with our 401(k) plan and take advantage of immediate vesting and company matching up to 6%
  • Paid time away including vacation and sick time, flex days and ten paid holidays
  • Give back to your community and double your impact through our company matching
  • Want more details? Check out our Symetra Benefits Overview

Compensation

Salary Range: $79,900 - $133,200 plus eligibility for annual bonus program

Please review Symetra's Remote Network Minimum Requirements:

As a remote-first organization committed to providing a positive experience for both employees and customers, Symetra has the following standards for employees' internet connection:

  • Minimum Internet Speed:100 Mbps download and 20 Mbps upload, in alignment with the FCC's definition of "broadband."
  • Internet Type:Fiber, Cable (e.g., Comcast, Spectrum), or DSL.
  • Not Permissible:Satellite (e.g., Starlink), cellular broadband (hotspot or otherwise), any other wireless technology, or wired dial-up.

When applying to jobs at Symetra you'll be asked to test your internet speed and confirm that your internet connection meets or exceeds Symetra's standard as outlined above.

Identity Verification

Symetra is committed to fair and secure hiring practices. For all roles, candidates will be required (after the initial phone screen) to be on video for all interviews. Symetra will take affirmative steps at key points in the process to verify that a candidate is not seeking employment fraudulently, e.g. through use of a false identity.

Failure to comply with verification procedures may result in:

  • Disqualification from the recruitment process
  • Withdrawal of a job offer
  • Termination of employment and other criminal and/or civil remedies, if fraud is discovered

We empower inclusion

At Symetra, we aspire to be the most inclusive insurance company in the country. We're building a place where every employee feels valued, respected, and has opportunities to contribute.

Inclusion is about recognizing our assumptions, considering multiple perspective, and removing barriers. We accept and celebrate diverse experiences, identities, and perspectives, because lifting each other up fuels thought and builds a stronger, more innovative company. We invite you to learn more about our efforts here.

Creating a world where more people have access to financial freedom

Symetra is a national financial services company dedicated to helping people achieve their financial goals and feel confident about the future. In our daily work, we're guided by the principles of Value, Transparency and Sustainability. This means we provide products and services people need at a competitive price, we communicate clearly and openly so people understand what they're buying, and we design products-and operate our company-to stand the test of time. We're committed to showing up for our communities, lifting up our employees, and standing up for diversity, equity and inclusion (DEI). Join our team and help us create a world where more people have access to financial freedom.

For more information about our careers visit https://symetra.eightfold.ai/careers

Work Authorization

Employer work visa sponsorship and support are not provided for this role. Applicants must be currently authorized to work in the United States at hire and must maintain authorization to work in the United States throughout their employment with our company.

#LI-NW1

#LI-Remote



What Symetra employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom