1

It Risk Management Jobs in Maryland (NOW HIRING)

Enterprise Architect (IT)

Hagerstown, MD · On-site +1

$68.50 - $88.25/hr

Partner with cybersecurity, technology risk, compliance, infrastructure, application, data, and operations teams to support holistic IT risk management. * Facilitate alignment across application ...

Enterprise Architect (IT)

Hagerstown, MD · On-site +1

$102K - $208K/yr

Partner with cybersecurity, technology risk, compliance, infrastructure, application, data, and operations teams to support holistic IT risk management. * Facilitate alignment across application ...

next page

Showing results 1-20

It Risk Management information

See Maryland salary details

$50K

$108.3K

$165K

How much do it risk management jobs pay per year?

As of Aug 28, 2026, the average yearly pay for it risk management in Maryland is $108,270.00, according to ZipRecruiter salary data. Most workers in this role earn between $87,300.00 and $125,200.00 per year, depending on experience, location, and employer.

What is IT risk management?

IT Risk Management is the process of identifying, assessing, and mitigating risks related to information technology systems and data within an organization. This discipline aims to protect information assets from threats such as cyberattacks, data breaches, and system failures by implementing security controls and policies. Effective IT Risk Management helps organizations comply with regulations, minimize financial losses, and ensure business continuity. Professionals in this field continuously monitor and update risk strategies to adapt to evolving technological threats.

What are the key skills and qualifications needed to thrive as an IT risk management professional, and why are they important?

To thrive in IT Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance frameworks, typically supported by a degree in information technology, cybersecurity, or a related field. Familiarity with risk management tools (such as RSA Archer or MetricStream), knowledge of ISO 27001, and certifications like CISSP or CISM are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help in identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets, ensuring compliance, and enabling informed decision-making regarding technology risks.

What are some common challenges faced by IT risk management professionals, and how can they effectively address them?

IT Risk Management professionals often encounter challenges such as rapidly evolving cyber threats, balancing compliance with operational efficiency, and communicating technical risks to non-technical stakeholders. Staying updated with the latest security trends and regulations is essential for effective risk assessment. Building strong cross-departmental relationships can help ensure that risk mitigation strategies are both practical and well-understood across the organization. Continuous learning and leveraging risk management frameworks, like NIST or ISO 27001, can also provide a solid foundation for addressing these challenges.

What is the difference between It Risk Management vs Cybersecurity Analyst?

AspectIt Risk ManagementCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentFocus on risk assessment, compliance, and mitigation strategies across IT systemsFocus on monitoring, analyzing, and responding to security threats
Employer & Industry UsageUsed in organizations prioritizing risk management and complianceUsed in security operations centers and cybersecurity teams

While both roles involve IT security, It Risk Management emphasizes assessing and mitigating risks across IT systems, whereas Cybersecurity Analysts focus on detecting and responding to security threats. Understanding these differences helps organizations assign the right roles for their security needs.

What are careers in it risk management?

Careers in IT risk management involve identifying, assessing, and mitigating technology-related security threats to protect organizational data and systems. Roles include IT risk analyst, cybersecurity manager, and compliance officer, often requiring knowledge of security frameworks, risk assessment tools, and relevant certifications like CISSP or CISM.

What does an IT risk management do?

An IT risk management professional identifies, assesses, and prioritizes potential technology-related threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, ensuring data security and compliance with industry standards. This role often involves using risk assessment tools and maintaining awareness of emerging cybersecurity threats.

What are popular job titles related to It Risk Management jobs in Maryland?

For It Risk Management jobs in Maryland, the most frequently searched job titles are:

Infographic showing various It Risk Management job openings in Maryland as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 15% Part Time, and 2% Contract. Highlights an 84% Physical, 2% Hybrid, and 14% Remote job distribution, with an average salary of $108,270 per year, or $52.1 per hour.

Senior Analyst, Technology Risk Oversight

Baltimore, MD • Hybrid


T Rowe Price
Funds, Trusts and Financial Programs • 5 - 10K employees

9.1

Company rating: 9.1 out of 10

Based on 21 frontline employees who took The Breakroom Quiz

Great coworkers

People enjoy working here

Good employer


Full-time

Re-posted 23 days ago


Job description

Role Summary

We are looking for a seasoned Technology Risk Analyst with more than 5 years' experience in financial services and/or technology industry. The qualified candidate should be well versed in identifying, managing and monitoring technology risks across Technology Resiliency, Technology Change Management, Obsolescence, IT Asset Management, Cybersecurity, and Technology Risks related to Third parties. The position interacts with all levels of management and senior level executives in IT (ie. CTO, CIO, Chief Architect); therefore, exceptional interpersonal and communication skills are essential.

The successful candidate will report into the Global Head of ERM, who reports directly into the Chief Risk Officer and provide Second Line of Defense (SLoD) services to Global Technology Services First Line Organization. Experience with Cyber and Information Security, Cloud Risk Management (AWS, Azure), Enterprise Architecture is a plus.

Responsibilities

  • Risk Identification: Collaborate with IT leaders, Enterprise Process Owners, and First Line of Defense (FLOD) teams to proactively identify, assess, and monitor technology risks-including resiliency, change management, obsolescence, asset management, cybersecurity, and third-party risks-that may impact the organization's strategic objectives.
  • Oversight and Effective Challenge: Provide independent oversight and challenge of FLOD technology risk management activities, ensuring risks and non-compliance with internal and external standards are prudently managed. Advise on the prioritization of risks, mitigation alternatives, and compensating controls.
  • Assessment and Governance: Participate in risk governance forums, monitor technology risk appetite, escalate exceptions, and report breaches. Evaluate the adequacy and effectiveness of risk control and mitigation actions, recommending improvements to strengthen governance and enhance policies, routines, and interaction models.
  • Advisory and Strategic Leadership: Act as a trusted advisor to IT and FLOD leaders, providing expert guidance on technology risk posture, regulatory requirements, and best practices. Support regulatory exams and findings and foster integrated relationships between FLOD and Second Line of Defense (SLOD).
  • Framework Implementation: Drive the adoption and effective implementation of Enterprise Technology Risk Management (ETRM) policies, frameworks, tools, guidelines, and standards across the business, ensuring technology risks are identified and managed in alignment with industry and regulatory expectations.
  • Reporting and Communication: Draft regular updates to executive management and the Board Risk Committee on changes to the company's technology risk profile. Communicate risk management policies and outcomes to stakeholders at all levels.
  • Continuous Monitoring: Utilize enterprise risk and operational risk management tools (MRI, RCSA, KRIs, incident data, loss event data) to monitor the technology control environment, identify potential weaknesses, and address gaps in a timely manner.
  • Subject Matter Expertise: Serve as a subject matter expert in technology risk, controls, compliance, and best practices. Stay abreast of emerging technologies and their impact on the organization's risk profile.

Qualifications

Required

  • Bachelor's degree or the equivalent combination of education and relevant experience
  • 5+ years of relevant experience in risk management, financial services, or related field

Preferred:

  • 8+ years of experience in the financial, and or technology industries
  • This position requires interacting with "C" level suite, so superior communication, interpersonal, negotiation, presentation and intergroup skills are critical for success
  • Ability to translate technical issues into risk terms that business can understand is absolutely necessary
  • Strong understanding of how the use of Artificial Intelligence both introduces risks across a variety of risk categories, as well as provides opportunities for improved monitoring and reporting
  • Experience with regulatory exams and responses is strongly desired
  • Undergraduate in technology disciple or equivalent
  • Thought leadership around technology risks a must
  • Experience in risk management, compliance or audit, including but not limited to experience in design & implementation of control frameworks
  • Working knowledge of industry and regulatory risk and control standards and frameworks - FFIEC, DORA, NIST-CSF, 800-53, COBIT, CCM etc.
  • Collaborative, team player with the ability to navigate a complex organization and influence outcomes
  • Strong analytical, problem solving and critical thinking skills
  • High attention to detail and strong organizational skills

FINRA Requirements

FINRA licenses are not required and will not be supported for this role.

Work Flexibility

This role is eligible for hybrid work, with up to one day per week from home.



What T. Rowe Price employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom