1

It Risk Manager Jobs in Brooklyn, MD (NOW HIRING)

Lead and manage Cybersecurity and Information Security functions, including Security Engineering & Operations and IT Risk & Compliance. * Serve as a key advisor to senior leadership on matters of ...

Exposure to technology risk management frameworks. * Experience working within enterprise technology organizations. Preferred Certifications: * Certified Information Systems Auditor (CISA)

IT Manager

Silver Spring, MD · On-site

$85K - $90K/yr

IT Manager Silver Spring, MD | Full-Time | $85,000-$90,000 Who We Are: Santé Group Companies ... Security, Compliance & Risk Management * Implement cybersecurity best practices including MFA ...

... * IT Asset Management (ITAM) * Integrated Risk Management (IRM) * Security Operations (SecOps ... Third-Party Risk Management (TPRM) * 10+ years of demonstrated deep technical expertise in ...

Understand the impact of key technology trends and workforce changes impacting our clients through ... Advanced proficiency in Microsoft Office (PowerPoint, Excel, Visio) Information for applicants with ...

The ideal candidate will have experience in cybersecurity governance, risk management, compliance, IT audit, and security controls, along with exposure to ServiceNow and database environments. Key ...

New

next page

Showing results 1-20

It Risk Manager information

See Brooklyn, MD salary details

$48.1K

$104.3K

$158.9K

How much do it risk manager jobs pay per year?

As of Aug 14, 2026, the average yearly pay for it risk manager in Brooklyn, MD is $104,251.00, according to ZipRecruiter salary data. Most workers in this role earn between $84,100.00 and $120,600.00 per year, depending on experience, location, and employer.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

What cities near Brooklyn, MD are hiring for It Risk Manager jobs?

Cities near Brooklyn, MD with the most It Risk Manager job openings:

Senior Analyst, Technology Risk Oversight

T Rowe Price

Baltimore, MD • Hybrid

Full-time

Re-posted 10 days ago


T. Rowe Price rating

9.1

Company rating: 9.1 out of 10

Based on 21 frontline employees who took The Breakroom Quiz


Job description

Role Summary

We are looking for a seasoned Technology Risk Analyst with more than 5 years' experience in financial services and/or technology industry. The qualified candidate should be well versed in identifying, managing and monitoring technology risks across Technology Resiliency, Technology Change Management, Obsolescence, IT Asset Management, Cybersecurity, and Technology Risks related to Third parties. The position interacts with all levels of management and senior level executives in IT (ie. CTO, CIO, Chief Architect); therefore, exceptional interpersonal and communication skills are essential.

The successful candidate will report into the Global Head of ERM, who reports directly into the Chief Risk Officer and provide Second Line of Defense (SLoD) services to Global Technology Services First Line Organization. Experience with Cyber and Information Security, Cloud Risk Management (AWS, Azure), Enterprise Architecture is a plus.

Responsibilities

  • Risk Identification: Collaborate with IT leaders, Enterprise Process Owners, and First Line of Defense (FLOD) teams to proactively identify, assess, and monitor technology risks-including resiliency, change management, obsolescence, asset management, cybersecurity, and third-party risks-that may impact the organization's strategic objectives.
  • Oversight and Effective Challenge: Provide independent oversight and challenge of FLOD technology risk management activities, ensuring risks and non-compliance with internal and external standards are prudently managed. Advise on the prioritization of risks, mitigation alternatives, and compensating controls.
  • Assessment and Governance: Participate in risk governance forums, monitor technology risk appetite, escalate exceptions, and report breaches. Evaluate the adequacy and effectiveness of risk control and mitigation actions, recommending improvements to strengthen governance and enhance policies, routines, and interaction models.
  • Advisory and Strategic Leadership: Act as a trusted advisor to IT and FLOD leaders, providing expert guidance on technology risk posture, regulatory requirements, and best practices. Support regulatory exams and findings and foster integrated relationships between FLOD and Second Line of Defense (SLOD).
  • Framework Implementation: Drive the adoption and effective implementation of Enterprise Technology Risk Management (ETRM) policies, frameworks, tools, guidelines, and standards across the business, ensuring technology risks are identified and managed in alignment with industry and regulatory expectations.
  • Reporting and Communication: Draft regular updates to executive management and the Board Risk Committee on changes to the company's technology risk profile. Communicate risk management policies and outcomes to stakeholders at all levels.
  • Continuous Monitoring: Utilize enterprise risk and operational risk management tools (MRI, RCSA, KRIs, incident data, loss event data) to monitor the technology control environment, identify potential weaknesses, and address gaps in a timely manner.
  • Subject Matter Expertise: Serve as a subject matter expert in technology risk, controls, compliance, and best practices. Stay abreast of emerging technologies and their impact on the organization's risk profile.

Qualifications

Required

  • Bachelor's degree or the equivalent combination of education and relevant experience
  • 5+ years of relevant experience in risk management, financial services, or related field

Preferred:

  • 8+ years of experience in the financial, and or technology industries
  • This position requires interacting with "C" level suite, so superior communication, interpersonal, negotiation, presentation and intergroup skills are critical for success
  • Ability to translate technical issues into risk terms that business can understand is absolutely necessary
  • Strong understanding of how the use of Artificial Intelligence both introduces risks across a variety of risk categories, as well as provides opportunities for improved monitoring and reporting
  • Experience with regulatory exams and responses is strongly desired
  • Undergraduate in technology disciple or equivalent
  • Thought leadership around technology risks a must
  • Experience in risk management, compliance or audit, including but not limited to experience in design & implementation of control frameworks
  • Working knowledge of industry and regulatory risk and control standards and frameworks - FFIEC, DORA, NIST-CSF, 800-53, COBIT, CCM etc.
  • Collaborative, team player with the ability to navigate a complex organization and influence outcomes
  • Strong analytical, problem solving and critical thinking skills
  • High attention to detail and strong organizational skills

FINRA Requirements

FINRA licenses are not required and will not be supported for this role.

Work Flexibility

This role is eligible for hybrid work, with up to one day per week from home.


What T. Rowe Price employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom