1

It Risk Analyst Jobs (NOW HIRING)

LRS Consulting is on the hunt for an IT Audit & Risk Analyst to support third party risk management, ITGC testing, vendor assessments, and audit readiness. This role blends IT auditing, process ...

About the role The Senior IT Risk and Security Analyst (RSA) is a critical member of the Information Security Officer's (ISO's) team. The RSA's role is to act as an interface between IT, Audit ...

About the role The Senior IT Risk and Security Analyst (RSA) is a critical member of the Information Security Officer's (ISO's) team. The RSA's role is to act as an interface between IT, Audit ...

What you'll do The IT Risk Senior Analyst is a strategic advisor responsible for integrating IT risk management and compliance into enterprise technology transformation initiatives. This role ensures ...

What you'll do The IT Risk Senior Analyst is a strategic advisor responsible for integrating IT risk management and compliance into enterprise technology transformation initiatives. This role ensures ...

What you'll do The IT Risk Senior Analyst is a strategic advisor responsible for integrating IT risk management and compliance into enterprise technology transformation initiatives. This role ensures ...

What you'll do The IT Risk Senior Analyst is a strategic advisor responsible for integrating IT risk management and compliance into enterprise technology transformation initiatives. This role ensures ...

Showing results 41-60

It Risk Analyst information

See salary details

$15

$40

$65

How much do it risk analyst jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for it risk analyst in the United States is $40.49, according to ZipRecruiter salary data. Most workers in this role earn between $29.81 and $49.28 per hour, depending on experience, location, and employer.

What does an IT Risk Analyst do?

An IT Risk Analyst is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They analyze potential threats, such as cyberattacks or data breaches, and develop strategies to minimize these risks. Their role involves working closely with other IT professionals to ensure compliance with security policies and regulatory requirements, as well as preparing risk reports and recommending improvements. Ultimately, IT Risk Analysts help organizations protect sensitive information and maintain secure, reliable IT operations.

What are some common challenges IT Risk Analysts face when collaborating with other departments?

IT Risk Analysts often work closely with various departments such as IT, compliance, and operations to identify and mitigate risks. One common challenge is translating technical risk information into terms that non-technical stakeholders can understand. Additionally, balancing the need for rigorous security measures with business objectives can sometimes lead to conflicting priorities. Effective communication and building strong relationships across teams are key to overcoming these challenges and ensuring that risk controls are both practical and effective.

What are the key skills and qualifications needed to thrive as an IT Risk Analyst, and why are they important?

To thrive as an IT Risk Analyst, you need a strong understanding of risk management frameworks, cybersecurity principles, and regulatory complianceβ€”often supported by a degree in information technology or a related field. Familiarity with tools such as risk assessment software, vulnerability scanners, and certifications like CISSP or CISA is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills that distinguish top performers in this role. These competencies are crucial for accurately identifying risks, ensuring regulatory compliance, and effectively communicating findings to stakeholders.

What is the difference between It Risk Analyst vs Cybersecurity Analyst?

AspectIt Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentFinancial, healthcare, corporate sectors focusing on risk managementIT security teams, cybersecurity firms, tech companies
Employer & Industry UsageFinancial institutions, large corporations, consulting firmsTech companies, government agencies, security firms

While both roles focus on protecting information, the It Risk Analyst primarily assesses and manages overall IT risks within organizations, emphasizing compliance and risk mitigation strategies. In contrast, the Cybersecurity Analyst concentrates on defending systems from cyber threats and attacks. Both roles often collaborate but serve distinct functions in an organization's security framework.

How much do IT risk analysts get paid?

IT risk analysts typically earn a median annual salary of around $80,000 to $100,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. Salaries also vary based on industry and company size.

Is an IT risk analyst a hard job?

An IT risk analyst's job involves assessing and managing cybersecurity threats, which requires strong analytical skills, attention to detail, and knowledge of security tools and frameworks. The role can be challenging due to the evolving nature of cyber threats and the need for continuous learning and certification, such as CISSP or CISA. Overall, it can be demanding but is manageable with proper training and experience.
More about It Risk Analyst jobs

What cities are hiring for It Risk Analyst jobs?

Cities with the most It Risk Analyst job openings:

What states have the most It Risk Analyst jobs?

States with the most job openings for It Risk Analyst jobs include:

What are popular job titles related to It Risk Analyst jobs?

For It Risk Analyst jobs, the most frequently searched job titles are:

Infographic showing various It Risk Analyst job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 82% Physical, 4% Hybrid, and 14% Remote job distribution, with an average salary of $84,210 per year, or $40.5 per hour.

IT Risk & Compliance Analyst

Manhattan, NY β€’ On-site

$126K - $157K/yr

Other

Posted 12 days ago


Key responsibilities

  • Manage cybersecurity risk, regulatory compliance, and business continuity programs.

  • Coordinate the development, review, and maintenance of security policies, risk assessments, and threat mitigation plans.

  • Lead the end-to-end response to security incidents and support security monitoring activities.


Job description

New York City
76 Trinity Pl
New York, NY 10006, USA

The IT Risk & Compliance Analyst plays a critical role in safeguarding Trinity’s technology environment by managing cybersecurity risk, regulatory compliance, and business continuity programs. In addition to ensuring compliance with standards such as PCI DSS and overseeing disaster recovery planning, this role monitors Trinity’s IT environment for emerging cyber threats and coordinates incident response efforts.

As a hybrid security and compliance role, the Analyst supports the development and enforcement of security policies, manages security assessments and remediation, and maintains documentation for internal governance and external audits. The role also provides hands‑on technical oversight of log reviews, vulnerability scans, and threat monitoring activities. By promoting a security‑aware culture and enabling continuous improvement, the IT Risk & Compliance Analyst strengthens the organization’s resilience and readiness in the face of evolving threats.

The annual salary range for this position is $126,100 to $157,900.

Essential Duties and Responsibilities Governance
  • Develop and coordinate vendor risk management frameworks, policies and processes within a broader enterprise, operational and IT risk management model.
  • Compile metrics for reporting threats, risks, and success of operating controls to leadership.
  • Coordinate creation, approval, maintenance and updating of security policies.
  • Coordinate periodic access reviews.
  • Develop and maintain a methodology to identify and prioritize internal and external threats, quantify the risk to the organization, and recommend methods to mitigate or remediate risk. Work with risk owners to develop appropriate risk response plans; monitor plans to closure.
  • Develop and maintain a risk register. Coordinate periodic management reviews and manage exception requests.
  • Research emerging threats and vulnerabilities to aid in the identification of network incidents.
Third-Party Risk Management
  • Coordinate management of vendor, supplier and other third-party risk.
  • Facilitate assessments of new and existing third-parties. Evaluate statements of work from partners to ensure that adequate security protections are in place. Assess provider documentation (e.g., security assessment questionnaire responses, SOC 1 or SOC 2 audit reports, or other sources).
  • As risks are identified, report risks to management and vendor management teams; work with third-parties to develop appropriate risk response plans; and monitor plans to closure.
Security Awareness and Training
  • Coordinate, maintain and continuously improve security awareness and role‑based security training programs, to mitigate human risks.
  • Educate stakeholders on cybersecurity‑related matters to increase awareness and improve culture.
  • Create and coordinate plans for role‑based security training.
Audit and Compliance
  • Work with Legal to maintain an understanding of internal and external regulatory compliance requirements.
  • Assist in responding to findings from external audits, penetration tests and vulnerability assessments.
  • Conduct security control gap assessments of internal systems, third‑party and internally‑developed applications, and IT infrastructure. Work with technical teams as they develop remediation plans and track approved plans to completion.
Security Monitoring and Incident Response
  • Serve as the designated backup Incident Manager when the primary manager is unavailable. Lead the end to end response to security incidents, coordinating with external partners as needed (such as cyber insurance carriers, digital forensics teams, and root cause analysis specialists). When activated, initiate and direct the security incident response process and exercise decision making authority within the scope of the role to ensure timely and effective resolution.
Required Knowledge, Skills, and Activities
  • Strong understanding of IT risk frameworks, compliance requirements, and security standards (e.g., PCI DSS, NIST, ISO 27001).
  • Experience supporting internal audits, managing risk registers, and working with external compliance assessors.
  • Excellent communication and interpersonal skills with both technical and non-technical stakeholders.
  • Highly organized with attention to detail, especially in documenting controls and producing reports.
  • Knowledge of disaster recovery planning and operational resilience practices.
  • Strong communications and interpersonal skills with a customer-service orientation, including listening, written, and verbal communication
  • Strong informal or formal project management skills with a proven history of getting projects done and meeting project goals utilizing teams
  • Familiarity with threat detection platforms, endpoint security, vulnerability scanning tools, and log analysis.
  • Ability to conduct root cause analysis and support containment, eradication, and recovery efforts.
  • Strong ability to effectively prioritize work
  • Must be able to work independently
  • Distinctive blend of business, IT, financial and communication skills, because this is a highly visible position with substantial impact
  • Knowledge of project management methodology and experience or familiarity with major, defined program management approaches.
  • Knowledge of project planning/scheduling tools, with a solid track record of practical application.
  • Effective influencing and negotiating skills in an environment in which this role may not directly control resources
  • Strong knowledge and understanding of business needs, with the ability to establish and maintain a high level of customer trust and confidence
  • Ability to communicate ideas in both technical and user-friendly language.
  • Good analytical and problem-solving abilities.
  • Highly self-motivated and directed.
  • Experience working in a team-oriented, collaborative environment.
  • Additional working hours as required
Required and Preferred Education, Experience, and Credentials

Required

Candidates will be evaluated primarily upon their ability to demonstrate the competencies required to be successful in the role, as described above. For reference, the typical work experience and educational background of candidates in this role are as follows:

  • Bachelor’s degree in Cybersecurity, Information Systems, or a related field, or equivalent experience.
  • Minimum 3–5 years of experience in IT risk management, information security, cybersecurity operations, or IT audit.
  • Experience supporting disaster recovery planning and regulatory compliance efforts.

Preferred

  • Background in security architecture is a plus.
  • Preferred certifications: CISA, CRISC, CISSP, or equivalent.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

#J-18808-Ljbffr