1

It Risk Manager Jobs in Denver, CO (NOW HIRING)

Technology Risk Specialist Sr

Arvada, CO · On-site

$98K/yr

As a(n) Technology Risk Specialist Sr. within PNC's Technology organization, you will be based in ... that information in creating customized customer solutions. * Managing Risk - Assessing and ...

Risk Technology Consultant

Denver, CO · On-site

$29.81 - $48.08/hr

Analyze business, risk, compliance, audit, security, and technology processes to identify ... Evaluate technology processes such as change management, logical access, IT operations, system ...

Analyze business, risk, compliance, audit, security, and technology processes to identify ... Evaluate technology processes such as change management, logical access, IT operations, system ...

Analyze business, risk, compliance, audit, security, and technology processes to identify ... Evaluate technology processes such as change management, logical access, IT operations, system ...

The position partners closely with Technology, Information Security, Operational Risk, Audit, Compliance, Finance, and Enterprise Risk Management teams to develop and mature technology risk ...

IT Manager

Denver, CO · Remote

$97K - $119K/yr

Contribute to IT risk management, disaster recovery planning, and business continuity procedures. What We Are Looking For: * Bachelor's degree in information technology, Computer Science, or a ...

Our cutting-edge A-CAES technology is uniquely poised to revolutionize the energy landscape. Join ... This position plans, organizes, directs, performs, reviews and presents risk information and ...

Risk Manager

Denver, CO · On-site

$150 - $200/hr

Our cutting-edge A-CAES technology is uniquely poised to revolutionize the energy landscape. Join ... This position plans, organizes, directs, performs, reviews and presents risk information and ...

As a LOB Risk Specialist Senior, you will serve as a key member of the Technology Risk Management ... All information provided will be kept confidential and will be used only to the extent required to ...

LOB Risk Lead

Denver, CO · On-site

$125 - $150/hr

Experience with multiple disciplines of Information Technology Service Management (ITSM) and the ... ITIL, Tech Risk (ISACA), Cyber Security, AI. The LOB Risk Lead will be a senior role on the ...

Performing and/or managing Information Technology(IT) Audits (e.g., system development, incident ... associated risk assessment approaches. * Managing multiple client projects, and teams with ...

Understand the impact of key technology trends and workforce changes impacting our clients through ... Advanced proficiency in Microsoft Office (PowerPoint, Excel, Visio) Information for applicants with ...

Oversee information security risk management functions by leading initiatives with Information Technology, Corporate Security, Audit Services, Compliance, Operations and Operational Risk leadership ...

next page

Showing results 1-20

It Risk Manager information

See Denver, CO salary details

$53K

$114.8K

$175K

How much do it risk manager jobs pay per year?

As of Sep 7, 2026, the average yearly pay for it risk manager in Denver, CO is $114,822.00, according to ZipRecruiter salary data. Most workers in this role earn between $92,600.00 and $132,800.00 per year, depending on experience, location, and employer.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

What are popular job titles related to It Risk Manager jobs in Denver, CO?

For It Risk Manager jobs in Denver, CO, the most frequently searched job titles are:

What job categories do people searching It Risk Manager jobs in Denver, CO look for?

The top searched job categories for It Risk Manager jobs in Denver, CO are:

Infographic showing various It Risk Manager job openings in Denver, CO as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $114,822 per year, or $55.2 per hour.

Senior Technology & Business Risk Management

Biodesix, Inc.

Louisville, CO • On-site

$150 - $200/hr

Other

Medical, Dental, Vision, Life, PTO

Posted 17 days ago


Key responsibilities

  • Lead enterprise-wide risk identification, assessment, prioritization, mitigation, and reporting activities across technology and business domains.

  • Support risk‑informed decision‑making throughout technology and business initiatives.

  • Lead development and continuous improvement of the Business Continuity Program.


Job description

Every team member at Biodesix has the potential to impact our business and our patients, providers, and partners. Even our company logo includes a “thumbprint” – a visual reminder that encourages all team members to put their fingerprints on our future. Explore our openings below and see if your next role is here with Team Biodesix. Thank you for considering us in your search.

Position:

Senior Technology & Business Risk Manager

Location:

Louisville, CO

Job Id:

863-090051

# of Openings:

1

Senior Technology & Business Risk Manager

Biodesix is a leading diagnostic solutions company, driven to improve clinical care and outcomes for patients. Biodesix Diagnostic Tests support clinical decisions to expedite personalized care and improve outcomes for patients with lung disease. Biodesix Development Services enable the world’s leading biopharmaceutical, life sciences, and research institutions with scientific, technological, and operational capabilities that fuel the development of diagnostic tests, tools, and therapeutics.

Our Mission:

Transform patient care and improve outcomes through personalized diagnostics that are timely, accessible, and address immediate clinical needs.

Our Vision:

A world where patient diseases are conquered with the guidance of personalized diagnostics.

The Senior Technology & Business Risk Manager is responsible for leading enterprise technology risk management, business continuity, governance, compliance coordination, and operational resilience activities across the organization. This role oversees risk assessment processes, business continuity planning, control governance, third‑party risk management, audit readiness, and technology risk initiatives that support business operations, cybersecurity objectives, regulatory compliance, and organizational growth. The position partners closely with Infrastructure Engineering, Cybersecurity, Software Development, Business Intelligence, Compliance, Legal, Quality, and business stakeholders to ensure risks are identified, evaluated, communicated, and appropriately mitigated. This position is designed for a hands‑on technology risk leader capable of assessing cybersecurity, infrastructure, operational, and business risks while helping mature enterprise governance, risk management, and operational resilience programs. The successful candidate must be comfortable operating in a highly technical environment and actively participating in risk assessments, audits, technology reviews, business continuity planning, vendor risk evaluations, control design discussions, and operational resilience initiatives.

WHAT YOU'LL DO :
  • Lead enterprise-wide risk identification, assessment, prioritization, mitigation, and reporting activities across technology and business domains.
  • Maintain and continuously improve the enterprise risk register, risk methodologies, scoring models, and governance processes
  • Facilitate cross-functional risk assessments involving cybersecurity, infrastructure, applications, cloud technologies, data protection, operational processes, and third‑party services
  • Establish risk metrics, key risk indicators (KRIs), dashboards, and executive reporting processes.
  • Coordinate risk review activities with business leaders and IT stakeholders to ensure risk ownership and mitigation accountability
  • Support risk‑informed decision‑making throughout technology and business initiatives
  • Partner with business leaders to identify, assess, and monitor operational, strategic, regulatory, and enterprise risks beyond traditional technology domains
  • Drive enterprise risk governance through regular risk reviews, executive reporting, and cross‑functional governance committees
Technology Risk & Cybersecurity Governance
  • Partner with Infrastructure Engineering and Cybersecurity teams to evaluate technical risks, control effectiveness, and remediation strategies
  • Assess enterprise risks associated with emerging technologies, including Artificial Intelligence (AI), automation, cloud‑native platforms, and evolving digital capabilities
  • Support governance activities aligned with NIST CSF, NIST RMF, ISO 27001, SOC 2, HIPAA, SOX and related frameworks
  • Assist with root cause analysis, risk investigations, control reviews, and corrective action planning
  • Conduct and lead technology risk assessments involving infrastructure, cloud services, enterprise applications, identity and access management, cybersecurity controls, endpoint technologies, and operational technology environments
  • Stay current with emerging cybersecurity threats, regulatory developments, risk management practices, and technology trends
Business Continuity & Operational Resilience
  • Lead development and continuous improvement of the Business Continuity Program
  • Conduct Business Impact Assessments (BIAs) and recovery planning activities across business functions
  • Coordinate tabletop exercises, continuity testing, and resilience validation activities
  • Partner with Infrastructure and Security teams to ensure Disaster Recovery capabilities support business recovery objectives
  • Evaluate operational resiliency risks involving critical business processes, vendors, and technology dependencies
  • Support incident response reviews and lessons‑learned activities following significant operational disruptions
  • Coordinate responses to customer security questionnaires, technology due diligence activities, and third‑party assurance requests
Compliance, Audit & Third‑Party Risk
  • Coordinate readiness activities for internal and external audits including SOC 2, HIPAA, ISO 27001, SOX, and related assessments
  • Partner with business and IT teams to collect audit evidence, validate controls, and track remediation activities
  • Support vendor risk assessments, third‑party reviews, and ongoing vendor monitoring activities
  • Assist with policy development, control governance, and risk‑related training initiatives
  • Monitor evolving regulatory requirements impacting technology, cybersecurity, privacy, and operational risk programs
  • Maintain documentation supporting governance, compliance, continuity, and risk management activities
  • Partner with Finance, Internal Audit, and business stakeholders to support SOX IT General Controls (ITGCs), application controls, control testing, remediation activities, and audit readiness efforts
  • Evaluate technology, cybersecurity, and operational control effectiveness and recommend improvements to reduce organizational risk exposure
Operational Governance & Leadership
  • Drive maturity improvements across enterprise risk, business continuity, and governance programs
  • Develop and maintain risk management procedures, methodologies, standards, and documentation
  • Drive accountability through governance reviews, risk reporting, mitigation tracking, and issue escalation processes
  • Support audit readiness and control effectiveness activities within regulated environments
  • Provide enterprise leadership by influencing cross‑functional teams, facilitating governance forums, and driving accountability for organizational risk management activities
  • Foster a collaborative, risk‑aware, and business‑focused culture across the organization
  • Oversee the enterprise technology policy governance process, including policy lifecycle management, periodic reviews, and alignment with regulatory and business requirements
WHAT YOU'LL BRING :
  • Bachelor's degree in Information Technology, Information Systems, Cybersecurity, Computer Science, Engineering, Risk Management, or related technical field
  • 8+ years of progressive experience in IT Risk Management, Cybersecurity Governance, Enterprise Risk Management, Information Security, Internal IT Audit, GRC, or related disciplines
  • 5+ years of leadership experience leading enterprise risk, cybersecurity governance, business continuity, compliance, or technology risk programs
  • Experience conducting enterprise technology risk assessments and control evaluations
  • Demonstrated experience assessing enterprise technology environments, including infrastructure, cloud platforms, cybersecurity technologies, identity and access management, endpoint technologies, and enterprise applications
  • Experience implementing or supporting frameworks such as NIST CSF, NIST RMF, ISO 27001, COBIT, SOX ITGC, HIPAA Security Rule, SOC 2, HITRUST, or similar frameworks
  • Demonstrated ability to lead enterprise risk management, business continuity, governance, or cybersecurity risk programs
  • Strong organizational skills and ability to balance strategic planning with hands‑on execution
  • Experience influencing business and technology leaders regarding risk decisions
  • Strong analytical and problem‑solving capabilities involving technology, cybersecurity, operational, and business risks
  • Demonstrated understanding of enterprise infrastructure, cloud platforms, identity and access management, endpoint technologies, data protection, and cybersecurity controls
  • Comfortable participating in technical reviews, architecture discussions, risk assessments, and remediation planning
  • Ability to evaluate technical control effectiveness and communicate risk implications to leadership
  • Strong written and verbal communication skills with executive‑level presentation abilities
  • Ability to communicate technical risk concepts to both technical and non‑technical audiences
  • Collaborative mindset with the ability to influence stakeholders across multiple business functions
  • Experience operating within regulated or compliance‑focused environments
  • Familiarity with healthcare, laboratory, biotechnology, or highly regulated industry frameworks
  • Experience presenting risk assessments and recommendations to executive leadership
  • CISSP, CISM, CRISC, CGRC, CISA, CBCP, PMP, or equivalent certifications, preferred
  • Experience with ServiceNow GRC, Archer, AuditBoard, Drata, or similar platforms , preferred
  • Experience within healthcare, diagnostics, biotechnology, pharmaceutical, or regulated industries , preferred
  • Experience supporting AI governance, AI risk management, or emerging technology oversight , preferred
WHAT YOU'LL GET:
  • Annual Base Salary Range $145,000 - $160,000
  • Discretionary Bonus opportunity
  • Comprehensive health coverage: Medical, Dental, and Vision
  • Insurance: Short/Long Term Disability and Life Insurance
  • 120 hours of annual vacation
  • 72 hours of paid sick time off
  • 11 paid holidays + 3 floating holidays
  • Employee Assistance Program
  • Voluntary Benefits
  • Employee recognition program

Individual base compensation is based on various factors unique to each candidate, including skill set, experience, qualifications, and other job‑related aspects.

Biodesix is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Biodesix is proud to be an Equal Opportunity Employer

We are committed to ensuring an inclusive workplace environment, and welcome people of different backgrounds, experiences, abilities and perspectives. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Accommodation Notice

If you are an individual with a disability and require a reasonable accommodation to use our online system to search and/or apply for a position, please send us an email atcareers@biodesix.com.

#J-18808-Ljbffr