1

It Risk Manager Jobs in Pennsylvania (NOW HIRING)

IT Support Specialist

Greenville, PA · On-site

$400/day

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

HIPAA IT Risk Assessment and Security Management Services * Enterprise Reporting and Dashboards Location Prelude's corporate office is located in Mechanicsburg, PA. This position works onsite 5 days ...

... technology innovation required by the business. Recruiting for this role ends on 12/31/2026. Work ... Information and Event Management, User and Entity Behavior Analytics, and Data Loss Prevention ...

Manager, IT Delivery

Malvern, PA · On-site

$93K - $114K/yr

We are seeking a Manager, IT Delivery to join our Conversation Channels group in PiTech. In this ... You'll partner across product, engineering, security/risk, analytic and operations to improve ...

Manager, IT Delivery

Malvern, PA

$93K - $114K/yr

We are seeking a Manager, IT Delivery to join our Conversation Channels group inPiTech. In this ... You'll partner across product, engineering, security/risk, analytic and operations to improve ...

IT Staff Auditor (Hybrid)

Pittsburgh, PA · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

This role evaluates the design and operating effectiveness of IT controls across key domains, including governance, risk management, access controls, change management, computer and system operations ...

Showing results 41-60

It Risk Manager information

See Pennsylvania salary details

$51.6K

$111.8K

$170.4K

How much do it risk manager jobs pay per year?

As of Aug 20, 2026, the average yearly pay for it risk manager in Pennsylvania is $111,824.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,200.00 and $129,300.00 per year, depending on experience, location, and employer.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

What are popular job titles related to It Risk Manager jobs in Pennsylvania?

For It Risk Manager jobs in Pennsylvania, the most frequently searched job titles are:

What cities in Pennsylvania are hiring for It Risk Manager jobs?

Cities in Pennsylvania with the most It Risk Manager job openings:

Infographic showing various It Risk Manager job openings in Pennsylvania as of August 2026, with employment types broken down into 82% Full Time, 17% Part Time, and 1% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $111,824 per year, or $53.8 per hour.

Senior Technology Risk Auditor

Dick's Sporting Goods

Coraopolis, PA • On-site

$77K - $94K/yr

Full-time

Re-posted 14 days ago


Dick's Sporting Goods rating

6.5

Company rating: 6.5 out of 10

Based on 1,149 frontline employees who took The Breakroom Quiz

15th of 39 rated national retailers


Job description

At DICK'S Sporting Goods, we believe in how positively sports can change lives. On our team, everyone plays a critical role in creating confidence and excitement by personally equipping all athletes to achieve their dreams. We are committed to creating an inclusive and diverse workforce, reflecting the communities we serve.
If you are ready to make a difference as part of the world's greatest sports team, apply to join our team today!
OVERVIEW:
As Dick's Sporting Goods continues to grow and invest in its technology ecosystem, we're expanding our Internal Audit team with several new Technology Internal Audit roles. These positions are part of our ongoing focus on strengthening our partnership with Technology to provide assurance and insights as they build for what's next.
The Senior Technology Risk Auditor will be a key member of the Internal Audit department and will be responsible for evaluating the effectiveness of internal processes and controls to mitigate technology, security, and business risks.
Job Duties and Responsibilities
Technology and Integrated Audits
  • Performs general technology and integrated audits, with a focus on infrastructure, cloud environments, application audits, application controls, and/or interface controls, as applicable to each audit
  • Responsible for performing risk assessments and documenting processes for audit areas. Performs risk assessments to identify relevant risks to the applicable audit and determine the extent of testing procedures to be performed
  • Where applicable, partners with auditees to document process and data flows for areas under audit to use as a validation tool with the auditee to confirm understanding of the process and to document risks, control points, and scoping decisions
  • Schedules and holds walk through meetings with auditees.
  • Drafts request lists for audits and manages requests to account for turnaround time and potential follow-up requests; monitors requests for completion and reviews received requests in a timely manner to ensure it meets the audit objectives.
  • Executes audit fieldwork to consider inherent risks of the processes audited. Assists team in root cause analyses and exposure checks for issues identified
  • Communicates with audit contacts on requests, follow-up questions, and discusses observations identified through fieldwork with Technology Internal Audit Manager, Senior Manager, and/or Director prior to discussing with auditee.
  • Uses audit engagement to develop or strengthen relationships with auditees.
  • Communicate audit results and recommendations for improvement to Management through formal audit reports and presentations that consider root causes, impact/exposure, and both near and long-term recommendations/solutions

Implementation Audits
  • Performs the activities above for system Implementations and technology modernization programs, with a focus on agile development methodologies, to evaluate development, program management, integration, data conversion/validation, and testing controls

Sarbanes-Oxley (SOX) and Internal Control Testing
  • Interact with auditees to gain an understanding of the technology processes and internal controls.
  • Execute defined test steps to evaluate the controls, including technology general controls, application/interface, entity-level, and enterprise risk management.
  • Adequately prepares exception support and examples for findings and improvement opportunities.
  • Perform detailed audit testing, including root cause analyses, and assess any exposure or residual risk
  • Communicate audit results and recommendations for improvement to Management through formal audit reports and presentations

On-Site Store and Distribution Center Audits
  • Perform on-site physical inventory observations and other audit procedures at various stores
  • Assist financial/operational audit team in performing Distribution Center audits
  • Communicate audit findings and recommendations for improvement to Management via audit reports and closing meetings

QUALIFICATIONS:
  • Bachelor's Degree in Information Systems Management, Data Science, Cybersecurity, or Audit
  • 3-5 years experience, including 3+ years of technology audit, cybersecurity, or risk experience required; public accounting or consulting experience preferred
  • Understanding of Technology Risk Assessment, SOX, general technology controls, system implementation risks/controls, data governance, cybersecurity controls, and privacy risks
  • Auditing in various technology environments: Azure, Windows, Unix, Oracle, SQL Server Database, and/or iSeries
  • Technical audit knowledge of infrastructure, cloud,application controls, interface controls, control frameworks (e.g., PCI DSS, NIST, COSO), and development methodologies
  • Ability to perform root cause analysis and understand risk exposure
  • Proven ability to adapt to change
  • Excellent relationship-building skills with a strong client-service focus
  • Ability to travel up to 15% of time

#LI-JD1
VIRTUAL REQUIREMENTS:
At DICK'S, we thrive on innovation and authenticity. That said, to protect the integrity and security of our hiring process, we ask that candidates do not use AI tools (like ChatGPT or others) during interviews or assessments.
To ensure a smooth and secure experience, please note the following:
  • Cameras must be on during all virtual interviews.
  • AI tools are not permitted to be used by the candidateduring any part of the interview process.
  • Offers are contingent upon a satisfactory background check which may include ID verification.

If you have any questions or need accommodations, we're here to help. Thanks for helping us keep the process fair and secure for everyone!

What Dick's Sporting Goods employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom