1

It Risk And Compliance Jobs in Reston, VA (NOW HIRING)

A financial services organization in Virginia is seeking an IT Risk & Controls Analyst to join their team in Vienna. About the Opportunity: * Schedule: Monday to Friday * Hours: Standard business

IT Advisory Manager

Mclean, VA · On-site

$125 - $150/hr

**Job Family:**IT Risk & Controls Consulting**Travel Required:**Up to 10%**Clearance Required ... ongoing compliance with a baseline, and industry-accepted baselines such as DISA STIGs and CIS ...

The Counsel, AI Risk & Compliance serve at the intersection of legal, technology, risk management ... Partner closely with IT, Information Security, Procurement, Marketing and Business Development ...

Execute risk mitigation processes to ensure compliance with model and AI governance requirements ... Previous experience in IT audit, operational risk management, regulatory compliance, or a Big Four ...

next page

Showing results 1-20

It Risk And Compliance information

What is IT Risk and Compliance?

IT Risk and Compliance refers to the process of identifying, assessing, and managing risks associated with an organization's information technology systems, while ensuring that these systems adhere to relevant laws, regulations, and internal policies. Professionals in this field work to protect sensitive data, prevent security breaches, and ensure that the organization's IT practices are compliant with industry standards such as GDPR, HIPAA, or SOX. They often conduct risk assessments, implement controls, monitor compliance, and respond to audits. The goal is to minimize potential threats to IT infrastructure and maintain the trust of customers and stakeholders.

What are the key skills and qualifications needed to thrive as an IT Risk and Compliance professional?

To thrive as an IT Risk and Compliance professional, you need a solid understanding of IT governance, risk management frameworks, regulatory requirements, and a relevant degree such as in information technology, cybersecurity, or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, as well as certifications such as CISA, CRISC, or CISSP, is typically required. Strong analytical thinking, attention to detail, and effective communication help professionals excel in navigating complex regulations and collaborating with cross-functional teams. These skills and qualifications are crucial for ensuring organizational compliance, mitigating security risks, and maintaining trust with stakeholders.

How does an IT Risk and Compliance professional typically collaborate with other departments to ensure regulatory adherence?

IT Risk and Compliance professionals regularly work with teams across the organization—such as IT, legal, audit, and business operations—to identify risks, interpret regulations, and implement compliance controls. They facilitate training, conduct assessments, and coordinate responses to audits or incidents, ensuring that everyone understands their responsibilities. Effective communication and strong relationship-building skills are essential, as much of the role involves translating technical requirements into actionable steps for non-technical staff. This cross-functional collaboration helps maintain a culture of compliance and minimizes organizational risk.

What is the difference between It Risk And Compliance vs Cybersecurity Analyst?

AspectIt Risk And ComplianceCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, risk assessments, compliance auditsMonitoring security threats, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, financial institutions, government agencies

While both roles focus on protecting information, It Risk And Compliance emphasizes establishing policies, ensuring regulatory adherence, and managing overall risk frameworks. Cybersecurity Analysts primarily focus on identifying and mitigating security threats through technical measures. Understanding these differences helps organizations assign the right responsibilities and professionals for their security needs.

Is IT risk and compliance a good career?

IT risk and compliance is a growing field that involves managing cybersecurity threats, ensuring regulatory adherence, and implementing security controls. Professionals in this area often require certifications like CISSP or CISA and work in environments that demand strong analytical and technical skills. It offers opportunities for career advancement and job stability due to increasing regulatory requirements and cybersecurity concerns.

What cities near Reston, VA are hiring for It Risk And Compliance jobs?

Cities near Reston, VA with the most It Risk And Compliance job openings:

Infographic showing various It Risk And Compliance job openings in Reston, VA as of August 2026, with employment types broken down into 87% Full Time, 8% Part Time, and 5% Contract. Highlights an 95% In-person, and 5% Hybrid job distribution.

IT Risk Consulting Manager

Kearney & Company

Washington, DC • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 20 days ago


Job description

Kearney is seeking an IT Risk Consulting Manager to join our growing consulting practice. This role is responsible for partnering with federal clients to strengthen IT governance, improve technology risk management, modernize internal control environments, and support regulatory and compliance initiatives. The Manager will support consulting engagements focused on IT risk, financial systems controls, cybersecurity governance, compliance, and remediation while also supporting internal IT audit and control assessment activities when required.
This position requires a client-focused professional who can balance strategic advisory services with hands-on delivery, build trusted relationships, and lead teams in solving complex technology and compliance challenges.
Additional skills and responsibilities are defined below:
  • Support consulting engagements that help clients strengthen IT governance, risk management, and internal control environments across enterprise applications, cloud platforms, and business systems.
  • Advise clients on designing, implementing, and maturing IT controls that support regulatory compliance, operational effectiveness, and organizational objectives.
  • Perform and oversee IT control assessments, including IT General Controls (ITGCs), Business Process Application Controls (BPACs), internal IT audits, and OMB A-123 evaluations.
  • Assess technology risks and identify practical recommendations that improve security, compliance, operational efficiency, and business resilience.
  • Partner with client executives, business stakeholders, system owners, and implementation teams to develop sustainable solutions for identified control deficiencies.
  • Collaborate with system integrators and client leadership to develop actionable remediation strategies, Plans of Action and Milestones (POA&Ms), and long-term control improvements.
  • Review remediation activities and provide guidance to ensure corrective actions effectively address root causes and satisfy compliance requirements.
  • Support financial system modernization, ERP implementations, cloud migrations, and digital transformation initiatives by integrating governance, risk, and control considerations throughout the project lifecycle.
  • Facilitate workshops, walkthroughs, risk assessments, and client meetings to evaluate business processes, system controls, and technology risks.
  • Develop executive-ready presentations, assessment reports, and client deliverables that clearly communicate risks, recommendations, and implementation priorities.
  • Mentor seniors and staffing by providing technical guidance, quality reviews, coaching, and career development.
  • Support business development activities, including proposal development, client presentations, solution design, and identification of follow-on consulting opportunities.
  • Contribute to the continuous improvement of the firm's Governance, Risk, and Compliance (GRC) methodologies, templates, accelerators, and service offerings.

Qualifications
Required Qualifications
• Bachelor's degree from an accredited college/university.
• Minimum of four years of experience in IT risk consulting, technology advisory, internal IT audit, IT compliance, or related consulting services.
• Experience advising clients on improving and maturing IT governance, risk management, and internal control environments.
• Experience leading IT control assessments, internal audits, or compliance evaluations involving enterprise applications, ERP systems, cloud technologies, or financial systems.
• Strong understanding of IT General Controls (ITGCs), application controls, technology risk management, and control frameworks.
• Experience working directly with client stakeholders, presenting recommendations, and managing consulting engagements.
• Excellent written and verbal communication skills with the ability to translate technical concepts into business-focused recommendations.
• Ability to manage multiple client engagements, priorities, and project teams in a consulting environment.
• Ability to work onsite at client locations throughout the Washington, DC metropolitan area.
• Ability to obtain and maintain a US Security Clearance (US Citizenship Required)
• Must have at least one professional certification such as CISA, CISSP, CRISC, CGEIT, Security+, CPA, or equivalent.
Preferred Qualifications
• Experience supporting OMB A-123 IT evaluations within federal agencies.
• Experience with Oracle, Oracle Cloud ERP, Oracle Federal Financials business applications.
• Experience supporting cloud governance and security within AWS, Azure, Oracle Cloud Infrastructure (OCI), or Google Cloud Platform.
• Experience implementing or administering Governance, Risk, and Compliance (GRC) platforms such as ServiceNow GRC, Diligent HighBond, or Archer.
• Experience supporting FISMA, NIST Cybersecurity Framework, NIST SP 800-53, FedRAMP, or related federal compliance initiatives.
• Bachelor's degree in information systems, Computer Science, Accounting, Business, Cybersecurity, or a related field from an accredited college/university.
Overview
Exclusively focused on the Government, Kearney & Company provides financial services, including auditing, consulting, and technology services. Our commitment to our employees and clients as well as to dedication and trust, critical values to our Firm, have led to Kearney's recognition as one of the leading accounting firms in the country. Based on our employees' feedback, we are also consistently rated a Best Place to Work. Employment at Kearney means a flexible, collaborative, and open-minded work environment. We hope it is your "first easy decision." Learn more at www.kearneyco.com/careers." ,"
The expected salary range for this position is between $77,000 and $125,000. This range is representative of base pay only and does not include straight time pay for hours worked over 40 per week, company contributions towards paid benefits, and/or bonuses. Actual compensation (meeting or exceeding the range) will be determined based on specific experience, education, work location, clearance level, and other factors permitted by law. This position is eligible for bonuses (when applicable).
We also offer a competitive benefits package that includes:
  • Medical, Dental, Vision, Life, AD&D, and Disability Insurance
  • 401(k) Retirement Plan and 529 Education Savings Plan
  • Flexible Spending & Health Savings Account
  • Accident, Critical Illness, Hospital Indemnity Insurances
  • Legal Insurance and Pet Insurance
  • Employee Assistance Program, fitness and wellness benefits, and other firm benefits.
  • Paid holidays, vacation, and sick time

EEO Notice
Applicants have rights under Federal Employment Laws
EEO Notice
Work location is subject to change based on client requirements.
Kearney & Company is an Equal Opportunity Employer and will consider all qualified applicants without regard to race, color, national origin, ethnicity, ancestry, genetic information, religion, sex, gender, gender identity, sexual orientation, marital status, pregnancy, childbirth, any medical condition related to pregnancy or childbirth, age, disability, protected veteran status, relationship or association to a protected veteran, or any other characteristic protected by local, state or federal laws, rules or regulation. Click here for more information on Kearney's EEO Policy.
If you would like to request a reasonable accommodation, regarding accessibility of our website, a modification or adjustment of the job application or interview process due to a disability, please call 703-236-2391 or email accommodations@kearneyco.com. Please be advised that this contact information is for accommodation requests only and cannot be used to inquire about the status of an application.
Family and Medical Leave Act (FMLA)
FMLA is designed to help employees balance their work and family responsibilities by allowing them to take reasonable unpaid leave for certain family and medical reasons. Kearney & Company provides eligible employees with up to 12 weeks of unpaid, job-protected leave per year. Military family leave is available for up to 26 weeks under FMLA. Click here to learn more.
Employee Polygraph Protection Act (EPPA)
The EPPA prohibits most private employers from using lie detector tests either for pre-employment screening or during the course of employment. Kearney & Company adheres all provisions of the EPPA. Click here to learn more.