The Senior Cyber and Technology Risk Analyst provides subject-matter expertise, guidance and ... Bachelor's degree in Information Security, Computer Science, Information Management, Business or ...
The Senior Cyber and Technology Risk Analyst provides subject-matter expertise, guidance and ... Bachelor's degree in Information Security, Computer Science, Information Management, Business or ...
The Senior Cyber and Technology Risk Analyst provides subject-matter expertise, guidance and ... Bachelor's degree in Information Security, Computer Science, Information Management, Business or ...
The Senior Cyber and Technology Risk Analyst provides subject-matter expertise, guidance and ... Bachelor's degree in Information Security, Computer Science, Information Management, Business or ...
Sr. Technology & Operations Risk Manager (UT, TX, AZ, CA, CO, ID, NV, OR, WA, WY)
Midvale, UT · On-site
Qualifications: * 10+ years in 1st or 2nd Line Risk Management or IT Audit, with expertise in at least two areas: cybersecurity, technology, cloud risk, or emerging technologies (e.g., GenAI, Quantum)
Sr. Technology & Operations Risk Manager (UT, TX, AZ, CA, CO, ID, NV, OR, WA, WY)
Midvale, UT · On-site
Qualifications: * 10+ years in 1st or 2nd Line Risk Management or IT Audit, with expertise in at least two areas: cybersecurity, technology, cloud risk, or emerging technologies (e.g., GenAI, Quantum)
Sr. Technology & Operations Risk Manager (UT, TX, AZ, CA, CO, ID, NV, OR, WA, WY)
Midvale, UT · On-site
Qualifications: * 10+ years in 1st or 2nd Line Risk Management or IT Audit, with expertise in at least two areas: cybersecurity, technology, cloud risk, or emerging technologies (e.g., GenAI, Quantum)
Sr. Technology & Operations Risk Manager (UT, TX, AZ, CA, CO, ID, NV, OR, WA, WY)
Midvale, UT · On-site
Qualifications: * 10+ years in 1st or 2nd Line Risk Management or IT Audit, with expertise in at least two areas: cybersecurity, technology, cloud risk, or emerging technologies (e.g., GenAI, Quantum)
Sr. Technology & Operations Risk Manager (UT, TX, AZ, CA, CO, ID, NV, OR, WA, WY)
Midvale, UT · On-site
Qualifications: * 10+ years in 1st or 2nd Line Risk Management or IT Audit, with expertise in at least two areas: cybersecurity, technology, cloud risk, or emerging technologies (e.g., GenAI, Quantum)
Sr. Technology & Operations Risk Manager (UT, TX, AZ, CA, CO, ID, NV, OR, WA, WY)
Midvale, UT · On-site
Qualifications: * 10+ years in 1st or 2nd Line Risk Management or IT Audit, with expertise in at least two areas: cybersecurity, technology, cloud risk, or emerging technologies (e.g., GenAI, Quantum)
IT Specialist (INFOSEC)
Layton, UT · On-site
... Risk Management Framework (RMF). • Manage change control processes. • Ensure the 75 ABW/SC Wing Cybersecurity Office's delivery of cost-effective and efficient IT services for Hill AFB and its ...
IT Specialist (INFOSEC)
Layton, UT · On-site
... Risk Management Framework (RMF). • Manage change control processes. • Ensure the 75 ABW/SC Wing Cybersecurity Office's delivery of cost-effective and efficient IT services for Hill AFB and its ...
IT Specialist (INFOSEC)
Layton, UT · On-site
$89K - $138K/yr
You will support the certification and accreditation of information technology through the implementation of the Risk Management Framework (RMF), manage change control processes, and ensure the 75 ...
IT Specialist (INFOSEC)
Layton, UT · On-site
$89K - $138K/yr
You will support the certification and accreditation of information technology through the implementation of the Risk Management Framework (RMF), manage change control processes, and ensure the 75 ...
Risk Manager
Brigham City, UT · On-site
$75K - $85K/yr
Risk Manager DEPARTMENT: County Attorney EFFECTIVE DATE: June 2026 GENERAL PURPOSE The Risk Manager ... Advanced technology skills including Microsoft Office, Google Workspace, learning management ...
Risk Manager
Brigham City, UT · On-site
$75K - $85K/yr
Risk Manager DEPARTMENT: County Attorney EFFECTIVE DATE: June 2026 GENERAL PURPOSE The Risk Manager ... Advanced technology skills including Microsoft Office, Google Workspace, learning management ...
Senior Risk Manager
Salt Lake City, UT · On-site
The Sr. Risk Manager provides expertise in insurance & risk management; loss prevention; claims ... From the IT professional who develops an app that sends the gospel message worldwide, to the ...
Senior Risk Manager
Salt Lake City, UT · On-site
The Sr. Risk Manager provides expertise in insurance & risk management; loss prevention; claims ... From the IT professional who develops an app that sends the gospel message worldwide, to the ...
The Sr. Risk Manager provides expertise in insurance & risk management; loss prevention; claims ... From the IT professional who develops an app that sends the gospel message worldwide, to the ...
The Sr. Risk Manager provides expertise in insurance & risk management; loss prevention; claims ... From the IT professional who develops an app that sends the gospel message worldwide, to the ...
Senior Risk Manager
Salt Lake City, UT · On-site
The Sr. Risk Manager provides expertise in insurance & risk management; loss prevention; claims ... From the IT professional who develops an app that sends the gospel message worldwide, to the ...
Senior Risk Manager
Salt Lake City, UT · On-site
The Sr. Risk Manager provides expertise in insurance & risk management; loss prevention; claims ... From the IT professional who develops an app that sends the gospel message worldwide, to the ...
Senior Risk Manager
Salt Lake City, UT · On-site
The Sr. Risk Manager provides expertise in insurance & risk management; loss prevention; claims ... From the IT professional who develops an app that sends the gospel message worldwide, to the ...
Senior Risk Manager
Salt Lake City, UT · On-site
The Sr. Risk Manager provides expertise in insurance & risk management; loss prevention; claims ... From the IT professional who develops an app that sends the gospel message worldwide, to the ...
The IT Solution Architecture Manager provides managerial and technical leadership for enterprise ... Risk Ensures IT solution architectures support compliance with CLIA, CAP, HIPAA, and applicable ...
The IT Solution Architecture Manager provides managerial and technical leadership for enterprise ... Risk Ensures IT solution architectures support compliance with CLIA, CAP, HIPAA, and applicable ...
Job Summary This role is designed for students who have recently graduated from a university program who are interested in understanding how IT risk management, governance frameworks, and internal ...
Job Summary This role is designed for students who have recently graduated from a university program who are interested in understanding how IT risk management, governance frameworks, and internal ...
The IT Solution Architecture Manager provides managerial and technical leadership for enterprise ... Risk Ensures IT solution architectures support compliance with CLIA, CAP, HIPAA, and applicable ...
The IT Solution Architecture Manager provides managerial and technical leadership for enterprise ... Risk Ensures IT solution architectures support compliance with CLIA, CAP, HIPAA, and applicable ...
IT Internal Audit Intern - Post-Graduate (6 Month Duration)
Sandy, UT · On-site
$14.25 - $19/hr
Job Summary This role is designed for students who have recently graduated from a university program who are interested in understanding how IT risk management, governance frameworks, and internal ...
IT Internal Audit Intern - Post-Graduate (6 Month Duration)
Sandy, UT · On-site
$14.25 - $19/hr
Job Summary This role is designed for students who have recently graduated from a university program who are interested in understanding how IT risk management, governance frameworks, and internal ...
The IT Solution Architecture Manager provides managerial and technical leadership for enterprise ... Risk Ensures IT solution architectures support compliance with CLIA, CAP, HIPAA, and applicable ...
The IT Solution Architecture Manager provides managerial and technical leadership for enterprise ... Risk Ensures IT solution architectures support compliance with CLIA, CAP, HIPAA, and applicable ...
Technology Governance Manager
Midvale, UT · Hybrid
Establish and oversee SDLC governance and thirdparty technology risk practices to ensure vendor ... Bachelor's degree in information technology, computer science, or a related field, or equivalent ...
Technology Governance Manager
Midvale, UT · Hybrid
Establish and oversee SDLC governance and thirdparty technology risk practices to ensure vendor ... Bachelor's degree in information technology, computer science, or a related field, or equivalent ...
Senior Technology Auditor
Sandy, UT · Hybrid
$89K - $117K/yr
Partner with business, IT, Risk Management, and Compliance teams to enhance alignment across the Three Lines model. * Serve as a trusted advisor while maintaining auditor independence and objectivity.
Senior Technology Auditor
Sandy, UT · Hybrid
$89K - $117K/yr
Partner with business, IT, Risk Management, and Compliance teams to enhance alignment across the Three Lines model. * Serve as a trusted advisor while maintaining auditor independence and objectivity.
Risk Management - Maintain the enterprise risk register. Conduct regular risk assessments ... Bachelor's degree in Cybersecurity, Information Systems, Risk Management, IT, or equivalent ...
Quick apply
Risk Management - Maintain the enterprise risk register. Conduct regular risk assessments ... Bachelor's degree in Cybersecurity, Information Systems, Risk Management, IT, or equivalent ...
It Risk Manager information
See Utah salary details
$46.9K - $56.7K
4% of jobs
$56.7K - $66.5K
6% of jobs
$66.5K - $76.3K
11% of jobs
$80K is the 25th percentile. Wages below this are outliers.
$76.3K - $86.1K
11% of jobs
The median wage is $93.9K / yr.
$86.1K - $95.9K
23% of jobs
$95.9K - $105.7K
13% of jobs
$112.2K is the 75th percentile. Wages above this are outliers.
$105.7K - $115.5K
12% of jobs
$115.5K - $125.3K
8% of jobs
$125.3K - $135.1K
6% of jobs
$135.1K - $145K
4% of jobs
$145K - $154.8K
2% of jobs
$46.9K
$101.6K
$154.8K
How much do it risk manager jobs pay per year?
What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?
Do risk managers make good money?
What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?
What does an IT Risk Manager do?
What is the difference between It Risk Manager vs Cybersecurity Analyst?
| Aspect | It Risk Manager | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CISSP, Security+, CEH |
| Work Environment | Oversees risk management strategies across IT systems | Monitors and responds to security threats and incidents |
| Industry Usage | Used in organizations with complex IT infrastructures | Common in security-focused roles across industries |
The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.
How much does a risk manager get paid?
Are risk managers in high demand?
What is the role of IT risk manager?
Full-time
Posted 15 days ago
Job description
If you need assistance with filling out our application form or during any phase of the application, interview, or employment process, please notify our Human Resources Team at 801-366-6947 option 1 or email macurecruiting@macu.com and every reasonable effort will be made to accommodate your needs in a timely manner.
Job SummaryThe Senior Cyber and Technology Risk Analyst serves as a member of the Cyber and Technology Risk Management team in our second line of defense. This role participates in the design and implementation and maturity of our cyber and technology risk management program. The Senior Cyber and Technology Risk Analyst provides subject-matter expertise, guidance and monitoring of the first line Cybersecurity and Technology control environment and teams to support effective management of cyber, technology, and data risk within the Credit Union's risk appetite. This role operates with established risk frameworks and governance structures and guidance from senior team leaders. Complex or enterprise level decisions remain subject to leadership review and approval.Job DescriptionLOCATION
Mountain America Center - Hybrid
9800 S Monroe St
Sandy, UT 84070
SCHEDULE
Full Time; this is a hybrid schedule with some weekly in office expectation, based on business need.
To be effective, an individual must be able to perform each job duty successfully.
- Contribute to strategic direction and participate in the execution of roadmap to enhance MACU's cybersecurity and technology risk management capabilities. Help shape priorities, sequencing, and success measures for assigned program areas.
- Actively assist leadership in developing project plans, roadmaps and status reporting for risk assessments, control testing, standards and training documentation, and other risk management activities.
- Develop and implement testing approaches and strategies to assess the design and operating effectiveness of controls. Lead the design, conduct, and document tests of controls, process walkthroughs, and risk assessments to evaluate design and effectiveness.
- Intake, triage, analyze, and rate (inherent/residual) cybersecurity and technology risks in collaboration with subject matter experts and risk owners. Facilitate alignment and drive completion of risk treatment decisions. Coordinate and perform continuous monitoring of risk treatment activities.
- Assess risk and control gaps of IT systems, processes, and procedures. Ensure control gaps and other risk issues are documented and reported. Review remediation plans and provide feedback to ensure plans are sufficient to ensure sustainable remediation. Monitor remediation progress, identify blockers, and escalate concerns when risk reduction is not on track.
- Evaluate and provide guidance to first line of defense Cybersecurity and Technology teams related to their standards, processes, controls, and risk exceptions.
- Research, understand, and interpret regulations and frameworks that relate to cybersecurity, technology, privacy, and data. Stay aware of changes and educate key stakeholders regarding changes to existing and new regulations and recommended response considerations for MACU. Work closely with the risk owners and Legal, Risk Management, and Compliance teams to ensure compliance with applicable laws and regulations.
- Develop and maintain procedures and training related to risk frameworks, standards, and roles and responsibilities for first line Cybersecurity and Technology teams to ensure effective identification of risks, implementation of controls, monitoring of controls, and reporting on the control environment and any corresponding issues or risks. Improve adoption by translating expectations into actionable guidance and job aids.
- Actively identify and lead implementation of process improvements and efficiencies.
- Support regular and ad-hoc reporting on findings, metrics, and recommend mitigations to first and second line of defense leadership. This includes ad-hoc and scheduled meetings with leadership and risk owners.
- Coordinate and oversee third-party independent risks assessments as necessary to improve the IT risk program and control environment. Define scope, evaluate outputs, and ensure recommendations are actionable.
- Review and provide guidance and quality control for technology and security related Key Risk Indicators (KRIs). Improve the reliability, definition, and thresholds so KRIs drive decisions and action.
- Lead special projects and perform other duties as assigned.
The requirements listed are representative of the knowledge, skills, and/or abilities required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential job functions.
Education and Experience
- Bachelor's degree in Information Security, Computer Science, Information Management, Business or related field or equivalent combination of education and work experience. Advanced degree or equivalent work experience preferred.
- 5+ years of similar or related experience in first or second-line of defense cybersecurity, technology, or data risk management and/or IT audit or related consulting or professional services.
- Experience in leading the evaluation of security and technology controls against cyber, technology, and privacy regulations, standards and frameworks (e.g., FFIEC, ISO 27001, NIST CSF, NIST AI RMF, COBIT, SOC2, PCI, ITIL, DORA, FAIR, etc.).
- Experience leading the development and documentation of IT processes and controls.
- Experience with Archer or other GRC automation tools preferred.
- Experience working in banking, financial services, or other regulated environment preferred.
- Working knowledge of major regulatory/legal frameworks (US/international) driving requirements across technology organizations preferred.
- Working knowledge of risk/control issues in relation to evolving technology (e.g., blockchain, AI/Machine Learning, cloud, quantum computing, etc.) preferred.
Licenses, Certifications, Registrations
- Certification from recognized security, technology, or risk management body (e.g., CISSP,CEH, CISA/CISM, CRISC, GIAC, FAIR, etc.) is preferred.
Knowledge & Skills
- Advanced understanding of the purpose, application, and integration of enterprisewide cybersecurity and technology risk concepts. Demonstrated ability to analyze technology and security risk solutions, independently scope and execute risk assessments, and assess complex risk scenarios across domains such as vulnerability management, resilience, SDLC, infrastructure, cloud, data governance, and AI governance.
- Strong working knowledge and applied experience with cyber, technology, and privacy regulations, standards, and frameworks (e.g., FFIEC, ISO 27001, NIST CSF, NIST AI RMF, COBIT, SOC 2, PCI, CCPA, ITIL, DORA, FAIR). Applies subject-matter expertise to interpret regulatory intent, assess applicability, identify gaps, and translate requirements into practical expectations for first line teams.
- Proven ability to independently manage and prioritize work in a fastpaced environment with competing demands. Demonstrates sound judgment when navigating ambiguity, balancing risk, regulatory expectations, and business objectives, and proactively identifying when to escalate or recalibrate priorities.
- Excellent written and verbal communication skills, with demonstrated experience drafting and reviewing policies, standards, procedures, control documentation, and risk assessments. Ability to clearly articulate risk, control gaps, and recommendations to technical teams, business partners, and senior management in a concise, actionable manner.
- Demonstrated initiative and continuous learning mindset, with the ability to apply new knowledge, emerging risks, and evolving best practices to improve program maturity. Willingness to take on stretch assignments and lead problemsolving efforts for complex or novel risk topics relevant to MACU.
- Strong collaborative problemsolving and stakeholder engagement skills. Demonstrated ability to gather and synthesize information from diverse sources, exercise independent judgment, and support and drive resolution of issues through influence rather than authority, while maintaining a strong customerservice orientation.
- Consistently strong contributor to team effectiveness and quality outcomes. Understands how individual work connects to broader enterprise risk objectives and strategic priorities. Provides informal mentorship, peer review, and knowledge sharing to elevate overall team capability and consistency.
- Proficient in Microsoft Office tools, including Copilot, with the ability to leverage technology to improve analysis, documentation quality, efficiency, and reporting.
Physical Demands
Ability to sit, talk and hear consistently
Vision Requirements
Close vision (clear vision at 20 inches or less)
Distance vision (clear vision at 20 feet or more)
Color vision (ability to identify and distinguish colors)
Weight Lifted or Force Exerted
Ability to lift up to 10 pounds frequently and up to 25 pounds occasionally
Environmental
There are no unusual environmental factors (such as a typical office)
Noise Environment
Moderate noise (business office with computers and printers, light traffic)
***This Job is not eligible to be performed in Colorado or Connecticut, either remotely or in-person.***
Mountain America Credit Union is an EEO/AA/ADA/Veterans employer.