1

It Risk Management Jobs (NOW HIRING)

The incumbent will execute and support day-to-day IT risk management activities for the Enterprise Product & Platform Engineering (EPPE) department, manage deadlines and stakeholder expectations, and ...

The incumbent will execute and support day-to-day IT risk management activities for the Enterprise Product & Platform Engineering (EPPE) department, manage deadlines and stakeholder expectations, and ...

IT Risk & Compliance Analyst

Andover, MA · On-site +1

$95K - $95K/yr

This position reports to the Manager, IT Risk & Compliance. This role is remote and may be based anywhere within the United States. Primary Job Duties and Responsibilities * Coordinate IT compliance, ...

Reporting to the Global IT SOX Risk Management Leader, you'll drive strategic SOX readiness projects and provide risk advisory expertise across many process areas to ensure compliance with SOX while ...

Senior IT Risk Analyst

Rosemont, IL · On-site

$98K - $110K/yr

Wintrust provides community and commercial banking, specialty finance and wealth management ... Position Overview The Senior IT Risk Analyst (Audit concentration) role supports IT Risk Leadership ...

Showing results 21-40

It Risk Management information

See salary details

$51.5K

$111.6K

$170K

How much do it risk management jobs pay per year?

As of Aug 7, 2026, the average yearly pay for it risk management in the United States is $111,556.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,000.00 and $129,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an IT risk management professional, and why are they important?

To thrive in IT Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance frameworks, typically supported by a degree in information technology, cybersecurity, or a related field. Familiarity with risk management tools (such as RSA Archer or MetricStream), knowledge of ISO 27001, and certifications like CISSP or CISM are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help in identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets, ensuring compliance, and enabling informed decision-making regarding technology risks.

What are some common challenges faced by IT risk management professionals, and how can they effectively address them?

IT Risk Management professionals often encounter challenges such as rapidly evolving cyber threats, balancing compliance with operational efficiency, and communicating technical risks to non-technical stakeholders. Staying updated with the latest security trends and regulations is essential for effective risk assessment. Building strong cross-departmental relationships can help ensure that risk mitigation strategies are both practical and well-understood across the organization. Continuous learning and leveraging risk management frameworks, like NIST or ISO 27001, can also provide a solid foundation for addressing these challenges.

What is the difference between It Risk Management vs Cybersecurity Analyst?

AspectIt Risk ManagementCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentFocus on risk assessment, compliance, and mitigation strategies across IT systemsFocus on monitoring, analyzing, and responding to security threats
Employer & Industry UsageUsed in organizations prioritizing risk management and complianceUsed in security operations centers and cybersecurity teams

While both roles involve IT security, It Risk Management emphasizes assessing and mitigating risks across IT systems, whereas Cybersecurity Analysts focus on detecting and responding to security threats. Understanding these differences helps organizations assign the right roles for their security needs.

What does an IT risk management do?

An IT risk management professional identifies, assesses, and prioritizes potential technology-related threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, ensuring data security and compliance with industry standards. This role often involves using risk assessment tools and maintaining awareness of emerging cybersecurity threats.

What is IT risk management?

IT Risk Management is the process of identifying, assessing, and mitigating risks related to information technology systems and data within an organization. This discipline aims to protect information assets from threats such as cyberattacks, data breaches, and system failures by implementing security controls and policies. Effective IT Risk Management helps organizations comply with regulations, minimize financial losses, and ensure business continuity. Professionals in this field continuously monitor and update risk strategies to adapt to evolving technological threats.

What are careers in it risk management?

Careers in IT risk management involve identifying, assessing, and mitigating technology-related security threats to protect organizational data and systems. Roles include IT risk analyst, cybersecurity manager, and compliance officer, often requiring knowledge of security frameworks, risk assessment tools, and relevant certifications like CISSP or CISM.
More about It Risk Management jobs
What cities are hiring for It Risk Management jobs? Cities with the most It Risk Management job openings:
What states have the most It Risk Management jobs? States with the most job openings for It Risk Management jobs include:
Infographic showing various It Risk Management job openings in the United States as of August 2026, with employment types broken down into 83% Full Time, 13% Part Time, 1% Temporary, and 3% Contract. Highlights an 88% Physical, 2% Hybrid, and 10% Remote job distribution, with an average salary of $111,556 per year, or $53.6 per hour.

Director IT Embedded Risk

DTCC

Coppell, TX • On-site

Other

Medical, Life, Retirement, PTO

Re-posted 26 days ago


Job description

Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.
Pay and Benefits:
  • Competitive compensation, including base pay and annual incentive
  • Comprehensive health and life insurance and well-being benefits, based on location
  • Pension / Retirement benefits
  • Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
  • DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).

The Impact you will have in this role:
Being a member of IT FinSight Delivery team, a IT ERM Director has primary responsibility for supporting and conducting targeted IT risk assessments, managing the risk profile of aligned IT capabilities, analyze and remediate risk items (e.g., issues, policy deviations), and for proactively identifying gaps in processes and controls.
The incumbent will execute and support day-to-day IT risk management activities for the Enterprise Product & Platform Engineering (EPPE) department, manage deadlines and stakeholder expectations, and lead or participate in projects within assigned areas of responsibility.
In carrying these responsibilities, the incumbent must work collaboratively with the IT Risk Management team (including Management Control Testing and Center of Excellence functions), other risk & control functions (e.g., Internal Audit, Technology Risk Management), as well as with IT line management (1st line).
Your Primary Responsibilities:
  • Proactively lead and support efforts to identify, assess, and mitigate risk within the Enterprise Product & Platform Engineering (EPPE) department
  • Develop, communicate, and ensure alignment to department risk policies, procedures and standard methodologies
  • Contribute to documentation of processes and controls across cloud, mainframe, network, and database technologies
  • Advise and periodically review inherent and residual risk assessments for supported IT capabilities for their impact on business and functional areas incorporating indicators of control environment strength (e.g., key metrics, issues)
  • Contribute to reviews, and validate the accuracy of, risk assessments conducted by the second line of defense (New Initiatives, Third Party Risk, Compliance)
  • Reassess existing processes and create new ones that most optimally anticipate, lead and reduce risk to DTCC and its participants
  • Cultivate an environment of regulatory awareness and ensure regulatory compliance
  • Demonstrate and embed the behaviors and proficiencies that build a risk management attitude in your organization
  • Support ongoing staff education; mentor and develop team members on technical capabilities and risk management concepts
  • Drive successful action plan and issue closures by assessing root causes of issues, defining appropriate action plans, and ensuring sustainability of implemented solutions
  • Support reviews of initiative portfolio risks with initiative sponsors, key stakeholders and the New Initiatives Office
  • Lead review of risk incidents, corresponding root cause analysis and remediation plan development. Proactively identify issues and trends resulting from risk incidents
  • Develop and strengthen relationships with IT partners and control evaluation functions across the 3 lines of defense

**NOTE: The Primary Responsibilities of this role are not limited to the above details**
Qualifications:
  • Minimum of 10 years of related experience
  • BA / BS and/or equivalent experience. Advanced degree preferred
  • Audit or Technical Certification preferred (CISA, CRISC, CISM, CISSP, etc)

Talents Needed for Success:
  • 10+ years' experience as a senior risk and control professional, preferably within technical auditing/ examination and focus in financial services industry (or other highly supervised industry)
  • Background in financial services information technology or Big 4 technical advisory services a plus
  • Highly motivated, detail-oriented, self-starter, who can set priorities, take initiative and work both independently and proactively in a diverse, multi-location team environment
  • Excellent analytical and problem-solving including for data identification, analysis, measurement and reporting
  • Excellent written and verbal communication skills; ability to tailor messaging to various levels of management including to risk committees
  • Demonstrated ability to oversee and own an IT risk team that serves as a decision-making tool for management
  • Strong planning and project management skills; ability to define, communicate and balance priorities across the team
  • Knowledge of the security markets, post-trade processing and clearing and settlement infrastructure preferred
  • Ability to lead technical, risk focused discussions with key stakeholders to analyze vulnerabilities and deviations from standards (e.g., security requirements)
  • Understanding and working knowledge of cloud technologies including cloud engineering, private cloud delivery, and server virtualization
  • Understanding and working knowledge of disaster recovery and infrastructure resiliency concepts including data center operations and rotation
  • Technical understanding of mainframe and network technologies including application of quantum computing readiness principles (encryption, key management)
  • Exposure to risk and control concepts including technical diagrams (network diagrams), risk and control identification, control evaluation (design and operating effectiveness), and related reporting

The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
About Us
With over 50 years of experience, DTCC is the premier post-trade market infrastructure for the global financial services industry. From 20 locations around the world, DTCC, through its subsidiaries, automates, centralizes, and standardizes the processing of financial transactions, mitigating risk, increasing transparency, enhancing performance and driving efficiency for thousands of broker/dealers, custodian banks and asset managers. Industry owned and governed, the firm innovates purposefully, simplifying the complexities of clearing, settlement, asset servicing, transaction processing, trade reporting and data services across asset classes, bringing enhanced resilience and soundness to existing financial markets while advancing the digital asset ecosystem. In 2024, DTCC's subsidiaries processed securities transactions valued at U.S. $3.7 quadrillion and its depository subsidiary provided custody and asset servicing for securities issues from over 150 countries and territories valued at U.S. $99 trillion. DTCC's Global Trade Repository service, through locally registered, licensed, or approved trade repositories, processes more than 25 billion messages annually. To learn more, please visit us at or connect with us on LinkedIn , X , YouTube , Facebook and Instagram .
DTCC proudly supports Flexible Work Arrangements favoring openness and gives people freedom to do their jobs well, by encouraging diverse opinions and emphasizing teamwork. When you join our team, you'll have an opportunity to make meaningful contributions at a company that is recognized as a thought leader in both the financial services and technology industries. A DTCC career is more than a good way to earn a living. It's the chance to make a difference at a company that's truly one of a kind.
Learn more about Clearance and Settlement by clicking here .