1

It Risk Manager Jobs in Maryland (NOW HIRING)

Sr. IT Auditor

Bethesda, MD ยท On-site

$90K - $120K/yr

As a Sr. IT Auditor , you'll be the trusted expert ensuring our IT systems, cybersecurity posture, and technology-enabled processes stand up to the highest standards of governance, risk management ...

As a Sr. IT Auditor , you'll be the trusted expert ensuring our IT systems, cybersecurity posture, and technology-enabled processes stand up to the highest standards of governance, risk management ...

Lead and manage Cybersecurity and Information Security functions, including Security Engineering & Operations and IT Risk & Compliance. * Serve as a key advisor to senior leadership on matters of ...

Exposure to technology risk management frameworks. * Experience working within enterprise technology organizations. Preferred Certifications: * Certified Information Systems Auditor (CISA)

Showing results 21-40

It Risk Manager information

See Maryland salary details

$50K

$108.3K

$165K

How much do it risk manager jobs pay per year?

As of Aug 8, 2026, the average yearly pay for it risk manager in Maryland is $108,270.00, according to ZipRecruiter salary data. Most workers in this role earn between $87,300.00 and $125,200.00 per year, depending on experience, location, and employer.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

What are popular job titles related to It Risk Manager jobs in Maryland? For It Risk Manager jobs in Maryland, the most frequently searched job titles are:
What cities in Maryland are hiring for It Risk Manager jobs? Cities in Maryland with the most It Risk Manager job openings:
Infographic showing various It Risk Manager job openings in Maryland as of August 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 86% Physical, 2% Hybrid, and 12% Remote job distribution, with an average salary of $108,270 per year, or $52.1 per hour.

Information Technology Compliance Manager

MSD

Rockville, MD โ€ข On-site

$116K - $177K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 23 days ago


Job description

POSITION SUMMARY
This position is responsible for design, implementation, and ongoing maintenance of the Information Technology (IT) Compliance Program. This includes both internal controls definition, interpretation, and adherence efforts as well as supporting our customer's information security requirements. The successful candidate will also be responsible for helping keep the compliance program current with all applicable US and international IT regulations and guidelines and advising leadership on IT compliance matters.
DUTIES AND RESPONSIBILITIES
โ€ข Information Technology Controls Development
o Lead in the development of IT controls using best practice frameworks.
o Evaluate the effectiveness and applicability of IT controls
o Drive the adherence of IT controls and best practices.
o Keeping current on cyber best practices, strategies, and concepts.
o Holding technical teams accountable for security and compliance deliverables.
  • Compliance Reporting

    • Conduct compliance reviews and assessments.
    • Craft reports and dashboards which show the current compliance condition and track relevant goals.
    • Continually evaluate and baseline internal information security practices against nationally and internationally recognized frameworks.
    • Support the Cybersecurity maturity program through tracking milestones and, programs, and initiatives.
    • Work with Quality, Regulatory Affairs, and auditors to provide needed data or materials in the support of audits.
    • Assist in the delivery of Third Party Risk Management (TPRM) attestations to customers

  • Enterprise Compliance Maintenance

    • Serves as the FedRAMP Program Manager
    • Work with various IT groups to ensure that IT systems adhere to corporate standards
    • Interact with various technology teams to confirm findings and mitigation.
    • Assist in the execution of the Vulnerability Management Program
    • Support IT Risk, Security, and Compliance certifications activities.

EXPERIENCE AND QUALIFICATIONS
  • Bachelor's degree in a related field
  • Minimum of five years of experience in managing complex IT compliance requirements.
  • Experience with Information Technology and Information Security Concepts
  • Experience in both U.S. and international data protection and privacy regulatory requirements, such as GDPR, CCPA, etc. (strongly preferred)
  • Experience managing a FedRAMP program including developing the support deliverables for reauthorization as well as the monthly continuous monitoring standards and criteria.
  • Experience as an auditor for a complex compliance regime such as ISO 27000, NIST 800-53, NIST 800-171, etc.
  • Experience leading, managing, and mentoring individuals including direct reports, matrixed reports, and project assigned staff.
  • The following audit or compliance certifications are preferred, but not required;

    • CISA - Certified Information System Auditor
    • CRISC - Certified in Risk and Information Systems Controls
    • SSCP - Systems Security Certified Professional
    • CSA CCSK - Certificate of Cloud Security Knowledge
    • CSA CCAK - Certificate of Cloud Auditing Knowledge

KNOWLEDGE, SKILLS AND ABILITIES
  • Strong problem solving, decision-making, reporting, communication and management skills.
  • Strong organization, analytical and project management skills.
  • Strong planning, implementation and negotiation skills.
  • Effective interpersonal communication skills.
  • Proficient computer skills, especially Microsoft Office applications.
  • Ability to multi-task and track many simultaneous initiatives.
  • Communication and Technical writing skills.
  • Must work effectively with a team and individually
  • Ability to evaluate regulatory documents and determine appropriate action
  • Strong understanding of risk management concepts and the ability to apply them to a business environment.
  • Familiarity with compliance certification regimes such as SOC 2, ISO 27001, and PCI. (Preferred)
  • Understanding of the compliance inner workings and challenges of Amazon Web Services (AWS (Preferred)
  • Expert level understanding of the following IT Compliance frameworks and regulations and how they apply in the commercial environment;

    • ISO 27000 (27001 and 27017)
    • Nist 800-53 or NIST 800-171
    • FedRAMP
    • SOC 2 (Preferred)
    • GDPR or CCPA (Preferred)
    • HIPAA or HiTrust (Preferred)
    • 21 CFR Part 11 (Preferred)

PHYSICAL DEMANDS
This position requires the ability to work standing up in data centers, data closets and other secure environments, along with the ability to lift moderately heavy equipment when required.
WORK ENVIRONMENT
Office based with some travel between office sites.
COMPENSATION SUMMARY:
The annual base salary for this position ranges from $116,600 to $177,800. This salary range represents a general guideline as MSD considers other factors when presenting an offer of employment, such as scope and responsibilities of the position, external market factors, and the candidate's knowledge, skills, abilities, education and experience. Employees may qualify for a discretionary or non-discretionary bonus in addition to their base salary. These annual bonuses are intended to recognize individual performance and enable employees to benefit from the Company's overall success.
BENEFITS SUMMARY:
At MSD, we offer a comprehensive benefits package to support our employees' well-being and financial security. In addition to competitive salaries, our benefits include medical, dental, and vision coverage, along with prescription benefits. We provide a 401(k) plan with company matching, flexible spending accounts, and company-paid short- and long-term disability insurance as well as group life and accidental death and dismemberment insurance. Our offerings also encompass paid vacation, paid sick leave, paid holidays, and paid parental leave, along with an employee assistance program. Additional voluntary perks include a fitness club membership contribution, pet insurance, identity theft protection, home and auto insurance discounts, and optional supplemental life insurance.
EEO/AA STATEMENT:
MSD is an Equal Opportunity/Affirmative Action Employer. We are committed to fostering a diverse and inclusive workplace where all individuals are treated with respect and dignity. We welcome applications from all qualified candidates, making employment decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, genetic information, marital status, national origin, age, protected veteran status, pregnancy, disability status, or any other protected characteristic. For our full EEO/AA and Pay Transparency statement, please click on the following link: https://www.mesoscale.com/en/our_company/careers/equal_employment_opportunity_statement. Meso Scale Diagnostics uses E-Verify to validate the work eligibility of candidates.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.