1

It Risk Management Jobs in Tennessee (NOW HIRING)

... IT strategy and operations is required. * Minimum 5 years experience building high-performing teams, establishing technology governance, managing enterprise technology risk, vendor relationships ...

2027 TRC Fall Internship

Nashville, TN · On-site

$14.50 - $19.25/hr

... IT Audit Managers and clients, you will gain an understanding of the client's IT systems, infrastructure, and control environment. You will apply that understanding to a variety of IT risk and ...

next page

Showing results 1-20

It Risk Management information

See Tennessee salary details

$46.7K

$101.3K

$154.3K

How much do it risk management jobs pay per year?

As of Aug 28, 2026, the average yearly pay for it risk management in Tennessee is $101,250.00, according to ZipRecruiter salary data. Most workers in this role earn between $81,700.00 and $117,100.00 per year, depending on experience, location, and employer.

What is IT risk management?

IT Risk Management is the process of identifying, assessing, and mitigating risks related to information technology systems and data within an organization. This discipline aims to protect information assets from threats such as cyberattacks, data breaches, and system failures by implementing security controls and policies. Effective IT Risk Management helps organizations comply with regulations, minimize financial losses, and ensure business continuity. Professionals in this field continuously monitor and update risk strategies to adapt to evolving technological threats.

What are the key skills and qualifications needed to thrive as an IT risk management professional, and why are they important?

To thrive in IT Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance frameworks, typically supported by a degree in information technology, cybersecurity, or a related field. Familiarity with risk management tools (such as RSA Archer or MetricStream), knowledge of ISO 27001, and certifications like CISSP or CISM are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help in identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets, ensuring compliance, and enabling informed decision-making regarding technology risks.

What are some common challenges faced by IT risk management professionals, and how can they effectively address them?

IT Risk Management professionals often encounter challenges such as rapidly evolving cyber threats, balancing compliance with operational efficiency, and communicating technical risks to non-technical stakeholders. Staying updated with the latest security trends and regulations is essential for effective risk assessment. Building strong cross-departmental relationships can help ensure that risk mitigation strategies are both practical and well-understood across the organization. Continuous learning and leveraging risk management frameworks, like NIST or ISO 27001, can also provide a solid foundation for addressing these challenges.

What is the difference between It Risk Management vs Cybersecurity Analyst?

AspectIt Risk ManagementCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentFocus on risk assessment, compliance, and mitigation strategies across IT systemsFocus on monitoring, analyzing, and responding to security threats
Employer & Industry UsageUsed in organizations prioritizing risk management and complianceUsed in security operations centers and cybersecurity teams

While both roles involve IT security, It Risk Management emphasizes assessing and mitigating risks across IT systems, whereas Cybersecurity Analysts focus on detecting and responding to security threats. Understanding these differences helps organizations assign the right roles for their security needs.

What are careers in it risk management?

Careers in IT risk management involve identifying, assessing, and mitigating technology-related security threats to protect organizational data and systems. Roles include IT risk analyst, cybersecurity manager, and compliance officer, often requiring knowledge of security frameworks, risk assessment tools, and relevant certifications like CISSP or CISM.

What does an IT risk management do?

An IT risk management professional identifies, assesses, and prioritizes potential technology-related threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, ensuring data security and compliance with industry standards. This role often involves using risk assessment tools and maintaining awareness of emerging cybersecurity threats.

What are popular job titles related to It Risk Management jobs in Tennessee?

For It Risk Management jobs in Tennessee, the most frequently searched job titles are:

What job categories do people searching It Risk Management jobs in Tennessee look for?

The top searched job categories for It Risk Management jobs in Tennessee are:

Infographic showing various It Risk Management job openings in Tennessee as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $101,250 per year, or $48.7 per hour.

Director, IT Risk and Controls - Remote Position

Memphis, TN • Remote

Full-time

This job post has expired 2 days ago. Applications are no longer accepted.


Job description

By joining Sedgwick, you'll be part of something truly meaningful. It's what our 33,000 colleagues do every day for people around the world who are facing the unexpected. We invite you to grow your career with us, experience our caring culture, and enjoy work-life balance. Here, there's no limit to what you can achieve.

Newsweek Recognizes Sedgwick as America's Greatest Workplaces National Top Companies

Certified as a Great Place to Work

Fortune Best Workplaces in Financial Services & Insurance

Director, IT Risk and Controls - Remote Position

PRIMARY PURPOSE OF THE ROLE: The Director IT Risk and Controls leads Sedgwick's IT risk and control governance activities, including SOX-related technology controls, IT General Controls (ITGCs), and broader technology risk and control processes. The role provides subject matter expertise, guidance, and oversight to support a consistent and sustainable control environment while partnering with Technology, Finance, Risk, Compliance, and Audit stakeholders to identify risks, strengthen controls, and support regulatory and governance requirements.

ESSENTIAL RESPONSIBILITIES MAY INCLUDE

  • Leads the enterprise IT risk and control governance program, encompassing SOX, ITGCs, and broader technology risk and control activities, including IT risk assessments, control scoping and design, framework governance, and management reporting.
  • Directs governance operations, including risk assessments, control documentation, issue management processes, governance reporting, control inventories, repositories, and executive reporting to support effective program administration and leadership decision-making.
  • Serves as the senior subject matter expert for IT SOX compliance, ITGCs, automated controls, key reports, interfaces, end-user computing controls, third-party dependencies, and other technology controls supporting business and financial reporting objectives.
  • Owns and maintains risk and control governance documentation, including narratives, RCMs, control descriptions, policies, standards, evidence requirements, control-owner guidance, and system inventories.
  • Advises control owners and Technology leaders on risk identification, control design, segregation of duties, evidence requirements, compensating controls, and sustainable control execution.
  • Partners with the IT Compliance function by providing program context, documentation, reporting, and management input while maintaining appropriate separation from independent assurance, testing, and remediation oversight activities.
  • Monitors and reports on control effectiveness using attestations, operational metrics, continuous monitoring results, and assurance inputs; identifies trends, recurring risk themes, and matters requiring leadership attention.
  • Maintains governance visibility of control deficiencies, risk exposures, and related remediation activities for reporting and management awareness while independent oversight and validation remain the responsibility of the IT Compliance function.

SUPERVISORY RESPONSIBILITIES

  • Provides support, guidance, leadership and motivation to promote maximum performance.
  • Administers company personnel policies in all areas and follows company staffing standards and training recommendations.
  • Interviews, hires and establishes colleague performance development plans; conducts colleague performance discussions.

QUALIFICATIONS

Advanced degree in Accounting, Finance, Information Systems, Business or a related field, from an accredited college or university preferred. CISA certification strongly preferred. Additional certifications such as CPA, CRISC, CIA, CISSP, or equivalent are beneficial.

Ten (10) years of related, progressive experience in IT risk management, IT controls, IT SOX compliance, technology governance, or IT audit, including significant leadership of enterprise risk and control activities in a complex organization or equivalent combination of education and experience required. Demonstrated experience assessing technology risks; scoping systems and dependencies; and designing or advising on ITGCs, automated controls, key reports, interfaces, third-party controls, and other risk-mitigating controls highly preferred.

Skills & Knowledge

  • Advanced knowledge of SOX requirements, IT General Controls, technology risk management practices, and governance frameworks, including COSO and COBIT.
  • Proven ability to evaluate control design and effectiveness information, identify risk themes, develop well-supported governance recommendations, and communicate implications to senior management and control stakeholders
  • Ability to partner effectively with IT Compliance, Internal Audit, External Audit, Enterprise Risk, Finance, Security, and Technology teams in complex, multi-system, and/or global operating environments
    Strong command of risk assessment, control design, control execution, evidence expectations, control-effectiveness reporting, issue classification, and sustainable control ownership
  • Ability to translate complex technical risks and control-effectiveness information into clear business, operational, and financial reporting implications
  • Executive-level written and verbal communication skills, including the ability to explain and support well-reasoned risk and control positions with senior leaders and assurance stakeholders
  • Ability to influence without direct authority, establish accountability, and drive cross-functional decisions across a broad technology risk and control environment
  • Advanced analytical, problem-solving, and professional judgment skills with a high degree of integrity, objectivity, and attention to detail
  • Working knowledge of governance, risk, and compliance platforms, control-management tools, workflow automation, and continuous monitoring solutions
  • Ability to manage multiple priorities and lead a year-round IT risk and control governance program in a fast-paced environment
  • Ability to work in a team environment
  • Ability to meet or exceed Performance Competencies

WORK ENVIRONMENT

When applicable and appropriate, consideration will be given to reasonable accommodations.

Mental: Clear and conceptual thinking ability; excellent judgment, troubleshooting, problem solving, analysis, and discretion; ability to handle work-related stress; ability to handle multiple priorities simultaneously; and ability to meet deadlines

Physical: Computer keyboarding, travel as required

Auditory/Visual: Hearing, vision and talking

The statements contained in this document are intended to describe the general nature and level of work being performed by a colleague assigned to this description. They are not intended to constitute a comprehensive list of functions, duties, or local variances. Management retains the discretion to add or to change the duties of the position at any time.

#LI-TS1 #remote

Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers, the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, the San Diego Fair Chance Ordinance, the San Francisco Fair Chance Ordinance, the California Fair Chance Act, and all other applicable laws.

Sedgwickis an Equal Opportunity Employer and a Drug-Free Workplace.

If you're excited about this role but your experience doesn't align perfectly with every qualification in the job description, consider applying for it anyway! Sedgwick is building a diverse, equitable, and inclusive workplace and recognizes that each person possesses a unique combination of skills, knowledge, and experience. You may be just the right candidate for this or other roles.