1

It Risk Manager Jobs in Virginia (NOW HIRING)

The IT Risk and Controls Managing Consultant will support stakeholder engagement and technical delivery for efforts supporting a Department of Homeland Security (DHS) client with IT controls audit ...

The IT Risk and Controls Managing Consultant will support stakeholder engagement and technical delivery for efforts supporting a Department of Homeland Security (DHS) client with IT controls audit ...

IT Audit - Staff

Alexandria, VA · On-site

$65K - $80K/yr

IT Audit Staff Location: Alexandria, VA (on-site) Level: Staff Clearance: Secret *Candidates must ... Conduct research related to IT control frameworks, risk management standards, and security ...

IT Advisory Manager

Mclean, VA

$96K - $117K/yr

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

IT Advisory Manager

Chantilly, VA

$97K - $119K/yr

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

IT Advisory Manager

Chantilly, VA · On-site

$97K - $119K/yr

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

You will lead audit and exam requests for the Risk Tech and Product teams by partnering with ... Please note that this salary information is solely for candidates hired to perform work within one ...

You will lead audit and exam requests for the Risk Tech and Product teams by partnering with ... Please note that this salary information is solely for candidates hired to perform work within one ...

You will lead audit and exam requests for the Risk Tech and Product teams by partnering with ... Please note that this salary information is solely for candidates hired to perform work within one ...

next page

Showing results 1-20

It Risk Manager information

See Virginia salary details

$51.1K

$110.6K

$168.5K

How much do it risk manager jobs pay per year?

As of Jun 29, 2026, the average yearly pay for it risk manager in Virginia is $110,599.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,200.00 and $127,900.00 per year, depending on experience, location, and employer.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

Do risk managers make good money?

Risk managers typically earn competitive salaries that vary based on experience, industry, and location. According to industry data, median annual pay ranges from $80,000 to over $130,000, with higher earnings possible for those with certifications like FRM or CRM and extensive experience. They often work in corporate environments, analyzing and mitigating financial, operational, or cybersecurity risks.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

How much does a risk manager get paid?

Risk managers typically earn a median annual salary of around $100,000, with salaries ranging from approximately $70,000 to over $150,000 depending on experience, industry, and location. Professionals often hold certifications like CRM or FRM and work in finance, insurance, or corporate sectors.

Are risk managers in high demand?

Risk managers are in high demand across various industries due to increasing concerns about cybersecurity, compliance, and operational risks. Employers seek professionals with skills in risk assessment, mitigation strategies, and certifications like FRM or CRM, making it a growing field with strong job prospects.

What is the role of IT risk manager?

An IT risk manager is responsible for identifying, assessing, and mitigating information technology risks within an organization. They develop security policies, implement controls, and ensure compliance with industry standards to protect digital assets and infrastructure. Strong knowledge of cybersecurity, risk management frameworks, and relevant certifications like CISSP or CISM are often required.
What are popular job titles related to It Risk Manager jobs in Virginia? For It Risk Manager jobs in Virginia, the most frequently searched job titles are:
What cities in Virginia are hiring for It Risk Manager jobs? Cities in Virginia with the most It Risk Manager job openings:
Infographic showing various It Risk Manager job openings in Virginia as of June 2026, with employment types broken down into 81% Full Time, 5% Part Time, and 14% Contract. Highlights an 94% Physical, 1% Hybrid, and 5% Remote job distribution, with an average salary of $110,599 per year, or $53.2 per hour.
Technology Risk Manager

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 4 days ago


Job description

Position OverviewHarris Williams will not provide sponsorship for employment visas or participate in STEM OPT for this position.Job Description

Title: Technology Risk Manager

We are a global investment bank specializing in M&A and private capital advisory services. Clients worldwide rely on us to help unlock value in their business and turn ambitious goals into reality. We approach every engagement with boundless collaboration, pooling expertise and relationships across industries, service offerings, and geographies. For over 30 years, our clients have trusted us to think strategically, execute precisely, and deliver premium outcomes to help them grow.

We are ambitious in our goals and steadfast in the belief that clients deserve our very best. To achieve our highest aspiration, we invest in world-class, team-oriented individuals who are smart, driven, and principled - those who are eager to be part of something bigger than themselves. When you join Harris Williams, you are welcomed into a collegial environment where every individual has the opportunity to make an impact in a powerful and significant way. We invite you to learn more about careers at Harris Williams.

The Role:

Within Harris Williams Compliance and Risk team,the Technology Risk Manager will be an integral member of the IT security team, with one direct report, the Technology Risk Analyst, focused on key programs and initiatives that enable us to effectively identify and reduce risk to the firm. This role will leverage depth in technology risk management to partner across multiple organizations, developing and supporting risk solutions that protect our firm, our clients and our ability to remain a market leader.

Why This Role is Unique

  • Opportunity to own and mature the technology risk program within a growing, highly visible platform
  • Direct exposure to senior leadership and parent company stakeholders (PNC)
  • Ability to shape risk strategy across emerging areas such as AI, data governance, and vendor risk
  • A role that blends strategy, execution, and influence-with meaningful impact on how the firm operates

Core Responsibilities:
Technology risk and compliance management:

  • Primary lead for all Harris Williams Technology risk and compliance efforts and initiatives, supporting the CTO, CCO and their designees in successful management of the IT risk portfolio and identified priorities.
  • Manage and track a consolidated program for all interactions between Harris Williams IT/Security and PNC teams (meetings, control schedule, KRIs, assessments, etc.). Outline strategic roadmap for the Technology Risk program (platforms, people, processes).
  • Develop deep familiarity with parent company structure, as a liaison with all lines of defense to organize compliance cycles, execute controls and measure performance towards subsidiary risk management objectives. Continually seek to identify opportunities for improvement and efficiency.
  • Function as Subject Matter Expert around technology risk and the proper application of technical and procedural risk principles to enterprise IT environments and practices.
  • Coordinate and lead the firm's response for IT assessments and inquiries, prepare agendas and materials, record and track action items to closure with Harris Williams IT, parent company counterparts, auditors and regulators.
  • Evaluate and consult on the risks associated with strategic priorities or major programs and projects, formulating targeted recommendations and guidance.
  • Collaborate and partner with the business and key stakeholders in creating recommendations to ensure alignment with defined priorities.
  • Regularly prepare and deliver comprehensive program updates regarding portfolio prioritization, progress, trends and effectiveness.
  • Establish and maintain technology risk register and related security and compliance maturity frameworks. Lead the identification, assessment, and prioritization of technology risks across the organization's IT landscape.
  • Own and lead the lifecycle for IT policy and procedure inventory management. Focus efforts on key areas of primary broker dealer risks, including security and privacy of firm, employee and client information, data classification, vendors, and AI.
  • Primary IT risk owner for ensuring all new and renewing vendors are successfully processed through the firm's vendor risk process.
  • Partner with the Risk Manager to build a cohesive and effective risk program.
  • Manage, mentor, and develop the Technology Risk Analyst, providing day-to-day direction, oversight, and professional growth to ensure consistent delivery against program priorities.

Job Specific Competencies, Education and Experience:

  • Degree in information systems, business or related experience.
  • A clear understanding of requirements, controls, and testing methodologies.
  • Experience developing an effective control environment related to financial services or technology products and services.
  • Relevant professional, compliance and/or security certifications (CISA, CRISC, ITIL, CGEIT, PMP).
  • Ability to work across matrixed teams to effectively balance risks and opportunity costs through prioritization to effectively execute assigned tasks.
  • 5+ years' experience in IT security and compliance best practices and frameworks (NIST CSF, ISO 27001/9001, COBIT / SOx, PCI, HIPAA).
  • 5+ years' experience in designing, implementing and managing enterprise-wide risk programs.
  • Experience developing, coaching, and mentoring junior risk or compliance staff.
  • High degree of professionalism, organization, proactivity and curiosity.
  • Excellent interpersonal communication skills and the ability to influence and effectively tailor messages to a variety of audiences.
  • Passion for technology, operational excellence and a keen focus on ensuring an exceptional client experience.

Our Culture & Growth

When you join Harris Williams, you step into a highly collaborative, high-expectations environment where individuals are empowered to take ownership and make a visible impact. We value curiosity, accountability, and a strong team-first mindset.

This is an environment where you will be expected to lean in, contribute meaningfully, and grow quickly, working alongside passionate colleagues who are committed to excellence and continuous improvement.

Additional Information

  • This is a hybrid role based in Richmond, VA, with an expectation of three days per week in the office.
  • Candidates must be authorized to work in the U.S. without sponsorship
  • This description reflects the core responsibilities of the role but is not intended to be all-inclusive. Responsibilities and focus areas may evolve based on business needs.

Disclaimer: Harris Williams will not accept unsolicited resumes from contingency recruiters. Any such resumes received will not be considered as legitimate submissions, and Harris Williams will not pay for the placement of a candidate resulting from the receipt of an unsolicited resume. Furthermore, Harris Williams strictly forbids any contingency recruiter from representing the firm in the market without prior consent

Base Salary: $160,000 - $220,000

  • Salaries may vary within the range based on geographic location, market data and on individual skills, experience, and education.
  • Role is incentive eligible with the payment based upon company, business and/or individual performance.
  • Application Window: Generally, this opening is expected to be posted for 48 business hours from 05/26/2026, although longer with business discretion.
Qualifications

Successful candidates must demonstrate appropriate knowledge, skills, and abilities for a role. Listed below are skills, competencies, work experience, education, and required certifications/licensures needed to be successful in this position.

Preferred SkillsAccess Control (AC), Building Architecture, Customer Solutions, Disaster Recovery Planning, Information Security, Network Security, Physical Security, Risk Assessments, Security TechnologiesCompetenciesInformation Assurance, Information Security Audits, Information Security Management, Information Security Technologies, IT Environment, IT Standards, Procedures & Policies, Knowledge of Organization, Planning: Tactical, StrategicWork ExperienceRoles at this level typically require a university / college degree. Higher level education such as a Masters degree, PhD, or certifications is desirable. Industry experience is typically 8+ years. At least 5 years of prior management experience is typically required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered.EducationBachelorsCertificationsNo Required Certification(s)LicensesNo Required License(s)Pay TransparencyBase Salary: $123,200.00 - $228,800.00Salaries may vary based on geographic location, market data and on individual skills, experience, and education.Application WindowGenerally, this opening is expected to be posted for two business days from 05/26/2026, although it may be longer with business discretion.BenefitsPNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives.In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service.

To learn more about these and other programs, including benefits for full time and part-time employees, visitpncthrive.com.

Disability Accommodations Statement

If an accommodation is required to participate in the application process, please contact us via email at AccommodationRequest@pnc.com. Please include "accommodation request" in the subject line title and be sure to include your name, the job ID, and your preferred method of contact in the body of the email. Emails not related to accommodation requests will not receive responses. Applicants may also call 877-968-7762 and say "Workday" for accommodation assistance. All information provided will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.


At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions.

Equal Employment Opportunity (EEO)


PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law.

This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage Licensing Act of 2008 (SAFE Act) and/or the Financial Industry Regulatory Authority (FINRA), which prohibit the hiring of individuals with certain criminal history.

California Residents

Refer to the California Consumer Privacy Act Privacy Notice to gain understanding of how PNC may use or disclose your personal information in our hiring practices.