1

It Risk Manager Jobs in Virginia (NOW HIRING)

IT Audit - Senior

Alexandria, VA · On-site

$80K - $100K/yr

IT Audit - Senior Location: Alexandria, VA (on-site) Level: Senior Clearance: Secret *Candidates ... Knowledge of risk management, information security, and information assurance principles.

Risk Manager

Mclean, VA · On-site

$55 - $60/hr

Bachelor's degree in Information Technology or Risk Management (or equivalent professional qualification), Master's Degree desirable

The ideal candidate will have experience working with IT security controls, risk management practices, compliance frameworks, or audit activities and possess strong analytical and documentation ...

Manager, Cyber Risk & Analysis As a Manager, you will apply your technical expertise, risk ... Cybersecurity and technology risk certifications such as Certified Information Systems Security ...

next page

Showing results 1-20

It Risk Manager information

See Virginia salary details

$51.1K

$110.6K

$168.5K

How much do it risk manager jobs pay per year?

As of Jul 22, 2026, the average yearly pay for it risk manager in Virginia is $110,599.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,200.00 and $127,900.00 per year, depending on experience, location, and employer.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What is the highest salary for a risk manager?

The highest salary for an IT Risk Manager can exceed $150,000 annually, especially for those with extensive experience, advanced certifications like CRISC or CISSP, and working in large organizations or financial institutions. Senior risk managers or those in managerial or executive roles may earn even higher compensation, including bonuses and benefits.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

Is risk a good career?

A career as an IT Risk Manager is considered stable and in demand, as organizations prioritize cybersecurity and risk mitigation. The role requires strong analytical skills, knowledge of security frameworks, and often certifications like CISSP or CRISC. It offers opportunities for advancement and specialization in a growing field.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

How much does a risk manager get paid?

A risk manager's average salary varies by experience and location but typically ranges from $80,000 to $150,000 annually. Senior risk managers or those with specialized certifications like FRM or CRM can earn higher salaries, especially in large organizations or financial sectors.

What is the role of IT risk manager?

An IT risk manager is responsible for identifying, assessing, and mitigating information technology risks within an organization. They develop security policies, implement controls, and ensure compliance with industry standards to protect digital assets and infrastructure. Strong knowledge of cybersecurity, risk management frameworks, and relevant certifications like CISSP or CISM are often required.
What are popular job titles related to It Risk Manager jobs in Virginia? For It Risk Manager jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching It Risk Manager jobs in Virginia look for? The top searched job categories for It Risk Manager jobs in Virginia are:
What cities in Virginia are hiring for It Risk Manager jobs? Cities in Virginia with the most It Risk Manager job openings:
Infographic showing various It Risk Manager job openings in Virginia as of July 2026, with employment types broken down into 55% Full Time, and 45% Part Time. Highlights an 100% In-person job distribution, with an average salary of $110,599 per year, or $53.2 per hour.

IT Audit - Senior

Montcure, LLC

Alexandria, VA • On-site

$80K - $100K/yr

Full-time

Posted 9 days ago


Job description

IT Audit - Senior

Location: Alexandria, VA (on-site)
Level: Senior
Clearance: Secret

*Candidates must have the above clearance level and, at a minimum, be able to maintain this clearance during their employment with Montcure.


Montcure, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) founded with a vision to revolutionize consulting and advisory services through innovative, data-driven solutions. The Montcure team recognize the unique challenges faced by organizations and governments in today’s rapidly evolving business environment.


Job Summary

The IT Audit Senior Analyst supports Technology Risk and IT audit engagements within a Department of Defense or Government & Public Sector environment. This role leads the execution of IT audit procedures, oversees staff performing control testing, and ensures the quality and completeness of audit documentation. The Senior Analyst serves as a key liaison with client stakeholders and supports financial statement audits, attestation engagements, and IT control assessments. This position is ideal for candidates with 3–5 years of IT audit, information assurance, or technology risk experience, supporting DoD clients, including experience overseeing junior staff.

Key Responsibilities:

  • Lead execution of IT audit procedures supporting financial statement and attestation engagements.
  • Oversee testing of IT General Controls (ITGCs), including access controls, change management, and system operations.
  • Review testing of application controls, system interfaces, and automated processes.
  • Review and validate audit workpapers to ensure compliance with audit standards and quality expectations.
  • Identify IT control deficiencies, risks, and improvement opportunities.
  • Serve as a primary day-to-day contact for client personnel within assigned areas.
  • Support walkthroughs, client meetings, and audit status reporting.
  • Provide guidance, oversight, and mentorship to junior staff.

Required Qualifications:
Education:

  • Bachelor’s degree in Information Systems, Information Technology, Cybersecurity, Accounting (with IT focus), or related field.

Experience:

  • 3–5 years of experience in IT audit, information assurance, cybersecurity, or technology risk.
  • Experience overseeing or reviewing work performed by junior staff.
  • Experience supporting federal or DoD clients preferred.

Skills:

  • Strong understanding of IT General Controls and application controls.
  • Knowledge of risk management, information security, and information assurance principles.
  • Familiarity with control frameworks such as NIST, FISCAM, or ISO standards.
  • Experience reviewing audit documentation and providing feedback to staff.
  • Proficiency in Microsoft Excel, Word, and PowerPoint.
  • Strong analytical, problem-solving, and communication skills.
  • Ability to manage multiple priorities in a deadline-driven environment.


Preferred Qualifications

  • Experience supporting federal financial statement audits or IT audit engagements in a government environment.
  • Familiarity with federal IT control frameworks and security requirements.
  • Experience auditing with ERP systems or financial systems in a federal environment.
  • Professional certification such as CISA, Security+, CISSP, or progress toward certification.


Status: Contingency – This work is contingent upon award.

Salary Range: $80-$100k per year


Montcure, LLC is an Equal Opportunity Employer. Montcure, LLC does not discriminate on the basis of race, religion, color, sex, gender identity, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status or any other basis covered by appropriate law. All employment is decided on the basis of qualifications, merit, and business need.