1

It Risk Manager Jobs in Minneapolis, MN (NOW HIRING)

Risk Manager

Bloomington, MN · Hybrid

$93K - $122K/yr

As an established technology and innovation leader, we are continuously evolving to meet the ... information which is subject to the export control regulations of the United States. Hiring ...

Risk Manager

Maple Grove, MN · On-site

$150K/yr

... and Risk Management programs as an opportunity for long-term enterprise value. The successful ... information, pregnancy, or any other protected characteristic as outlined by federal, state, or ...

Lead and manage Cybersecurity and Information Security functions, including Security Engineering & Operations and IT Risk & Compliance. * Serve as a key advisor to senior leadership on matters of ...

Performing risk assessments, information management reviews, and control evaluations for audit technology platforms, including generative artificial intelligence and agentic artificial intelligence ...

Showing results 21-40

It Risk Manager information

See Minneapolis, MN salary details

$53.8K

$116.5K

$177.5K

How much do it risk manager jobs pay per year?

As of Aug 6, 2026, the average yearly pay for it risk manager in Minneapolis, MN is $116,454.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,000.00 and $134,700.00 per year, depending on experience, location, and employer.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

What are popular job titles related to It Risk Manager jobs in Minneapolis, MN? For It Risk Manager jobs in Minneapolis, MN, the most frequently searched job titles are:
What job categories do people searching It Risk Manager jobs in Minneapolis, MN look for? The top searched job categories for It Risk Manager jobs in Minneapolis, MN are:
Infographic showing various It Risk Manager job openings in Minneapolis, MN as of August 2026, with employment types broken down into 84% Full Time, 12% Part Time, and 4% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $116,454 per year, or $56 per hour.

VP of Cybersecurity & Information Security

Mariner Finance

Eagan, MN • On-site

$160K - $225K/yr

Full-time

Posted 28 days ago


Mariner Finance rating

7.5

Company rating: 7.5 out of 10

Based on 37 frontline employees who took The Breakroom Quiz

116th of 150 rated financial services


Job description

USD $160,000.00 - USD $225,000.00 /Yr.

Since 1927, the Mariner Finance family of companies has provided customers with creative, flexible, and convenient lending options. Headquartered in Baltimore, Mariner Finance operates coast-to-coast with physical locations in over half the states. With a growing number of employees, superior customer service remains the cornerstone of our business, and we pride ourselves in delivering a variety of loans with an enhanced focus on exceptional service. We work with customers to find options that are beneficial to their specific needs, which is why we are recognized by our customers as one of the community’s consumer finance companies of choice.

Benefits:


For information regarding our benefits, please visit: https://www.marinerfinance.com/careers/benefits/ 

All full time employees are provided with a generous benefits package in addition to their monetary compensation. Learn more about it today.


In this role, you will...

Be responsible for leading the organization’s Cybersecurity and Information Security functions, including Security Engineering & Operations and IT Risk & Compliance. Provide strategic and operational leadership to protect enterprise systems, data, identities, cloud environments, platforms, and business processes while ensuring the company’s security program aligns with business priorities, risk appetite, regulatory requirements, and the evolving threat landscape.

Build and lead a metric-driven security organization focused on risk reduction, control effectiveness, incident response, identity security, cloud and platform security, regulatory compliance, automation, and continuous improvement. Oversee security technologies, threat monitoring, identity and access controls, cloud security architecture, audits, remediation efforts, vendor performance, and executive reporting while partnering across IT, engineering, development, platform, and business functions to embed secure-by-design practices into systems, processes, product delivery, and business decision-making.

Responsibilities and Duties:

  • Lead and manage Cybersecurity and Information Security functions, including Security Engineering & Operations and IT Risk & Compliance.
  • Serve as a key advisor to senior leadership on matters of strategic and operational security importance, influencing decision-making and driving proactive initiatives that strengthen the company’s security posture, risk management practices, regulatory compliance, and business resilience.
  • Develop and execute Cybersecurity and Information Security strategies aligned with business goals, risk appetite, regulatory requirements, and the evolving threat landscape.
  • Build and operate a metric-driven Cybersecurity and Information Security organization, defining KPIs that measure risk reduction, control effectiveness, operational performance, incident response, identity security, cloud security, and compliance posture.
  • Oversee security engineering teams responsible for security platforms, tooling, architecture, and integrations across endpoint, network, cloud, identity, and platform environments.
  • Manage security operations, including threat monitoring, event detection, incident response, investigations, and continuous improvement of detection and response capabilities.
  • Oversee identity security capabilities, including identity and access management, privileged access management, identity governance, Zero Trust initiatives, and privileged access controls.
  • Oversee cloud and platform security capabilities, including cloud security architecture, DevSecOps enablement, infrastructure-as-code security, container/runtime security, and partnership on cloud governance.
  • Partner with enterprise engineering, development, platform, and technology teams to integrate security into the software development lifecycle, enable secure engineering practices, support shared platform governance, and drive secure-by-design delivery.
  • Stay abreast of the evolving threat landscape, emerging attack vectors, and advancements in security technologies, continuously adapting the organization’s security posture.
  • Advise technology, development, engineering, and business partners on security best practices, architectural patterns, and risk-based decision-making, providing ongoing oversight and guidance.
  • Establish and operate a risk-based cybersecurity program aligned to business priorities, regulatory expectations, and the evolving threat landscape.
  • Oversee the IT Risk function, including coordination of security audits, penetration testing, third-party assessments, control validation, and remediation tracking.
  • Manage the end-to-end audit lifecycle, including planning, scheduling, execution, findings management, remediation tracking, and reporting.
  • Ensure compliance with regulatory and industry standards, including PCI DSS and ISO 27001, with ownership of audits, control validation, and remediation efforts.
  • Oversee annual reporting, regulatory submissions, partner security attestations, and related cybersecurity and information security documentation.
  • Drive timely and effective remediation of vulnerabilities, audit findings, control gaps, identity risks, cloud security risks, and security issues across the enterprise.
  • Establish and maintain security policies, standards, control frameworks, and governance practices that support business, regulatory, technology, and risk management objectives.
  • Implement and enhance continuous monitoring, detection, response, and reporting capabilities to proactively identify and address security risks.
  • Lead continual optimization of security technologies, tooling, platforms, and resource utilization to improve effectiveness and reduce cost.
  • Drive a bias toward automation and technology-first solutions, reducing manual processes and increasing scalability across Cybersecurity and Information Security functions.
  • Leverage automation and AI capabilities to enhance threat detection, accelerate response, improve risk analysis, strengthen security operations, and scale security program capabilities.
  • Manage security vendor relationships, contracts, service performance, and cost optimization across tools, services, and third-party providers.
  • Provide executive-level reporting on security posture, risks, incidents, identity security, cloud security, control effectiveness, remediation progress, and compliance status.
  • Develop and manage the Cybersecurity and Information Security budget, including tools, services, staffing, and vendor spend, optimizing cost efficiency while maintaining or improving program effectiveness.
  • Establish strong, business-oriented partnerships across functions, ensuring Cybersecurity and Information Security enables and protects business outcomes and priorities.
  • Share knowledge, mentor, and educate stakeholders with regard to the company’s Cybersecurity and Information Security initiatives, opportunities, risks, and challenges.
  • Promote the professional growth and development of team members by sharing knowledge, mentoring, and providing consistent, actionable feedback.
  • Responsible for managerial matters such as performance appraisals and goal setting, promotions, salary recommendations, and staffing in accordance with the company hiring process, personnel policies, and budget requirements.
  • Perform additional duties as assigned to support evolving business needs.

Required Qualifications:

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field; applicable years of experience may be substituted for a bachelor’s degree.
  • Twelve (12) years of experience in the Information Technology field with significant leadership experience in cybersecurity, information security, or related security functions.
  • Three (3) years of managerial experience leading or overseeing Security Operations, Security Engineering, IT Risk, Compliance, Identity Security, Cloud Security, DevSecOps, or related cybersecurity and information security functions, working in capacities with decision-making authority and responsibility for coordinating, delegating, and managing operational activities.
  • CISSP, CISM, or an equivalent information security certification.
  • Extensive experience managing security technologies, including SIEM, EDR, IAM, PAM, vulnerability management, cloud security, and network security tools.
  • Demonstrated experience with identity security capabilities, including identity and access management, privileged access management, identity governance, Zero Trust, and privileged access controls.
  • Demonstrated experience with cloud and platform security capabilities, including cloud security architecture, DevSecOps enablement, infrastructure-as-code security, container/runtime security, and cloud governance partnership.
  • Demonstrated ability to partner with enterprise engineering, development, platform, and technology teams to integrate security into the software development lifecycle, support engineering enablement, strengthen shared platform governance, and promote secure-by-design delivery.
  • Demonstrated success managing audits, penetration testing programs, and enterprise remediation efforts.
  • Experience building and operating incident response and investigation capabilities.
  • Proven ability to align cybersecurity and information security strategies, programs, and initiatives with business priorities, risk appetite, regulatory requirements, and measurable outcomes.
  • Strong experience with regulatory frameworks and compliance standards, including PCI DSS and ISO 27001.
  • Demonstrated financial discipline in managing operational budgets, vendor costs, resource utilization, and cost optimization initiatives.
  • Demonstrated success building metric-driven security programs with measurable improvements in risk posture and operational performance.
  • Proven ability to support and enhance team performance, promote engagement, and cultivate the professional development of team members.
  • Demonstrated proficiency in leading through change, executing on major initiatives, and leading cross-departmental work.
  • Strong experience managing vendors, contracts, third parties, service performance, and costs across Cybersecurity, Information Security, and IT Risk functions.
  • Ability to work effectively, manage complex projects, and multitask successfully in a dynamic, fast-paced, and complex business environment.
  • Strong decision-making and negotiation skills with the ability to use expertise to influence on matters of strategic importance.
  • Ability to foster strong relationships, influence, coach, and partner with all levels across the organization.
  • Ability to articulate complex information in understandable terms to various audiences. Comfortable presenting data to all levels of leadership and across business functions.
  • Highly proficient with Microsoft Office Suite.
  • Strong analytical and problem-solving skills, with the ability to evaluate security risk, threat trends, identity risk, cloud security posture, control performance, compliance obligations, and business impacts to guide decisions, address complex challenges, and strengthen the enterprise security program.
  • Demonstrated high level of reliability, flexibility, and dedication with the ability to adapt quickly to changing priorities and timelines.
  • Excellent interpersonal skills necessary to communicate professionally and effectively, verbally and in writing, with regulatory agencies, vendors, customers, and all levels of company staff.

Preferred Qualifications:

  • Experience in financial services or other highly regulated industries.
  • Experience implementing advanced security capabilities, including Zero Trust, SASE, identity-centric security models, identity governance, and privileged access management.
  • Familiarity with cloud security architectures across AWS, Azure, or GCP.
  • Experience with cloud and platform security practices, including infrastructure-as-code security, container/runtime security, cloud governance, and shared platform security
  • Experience with GRC platforms and automation of compliance processes.
  • Track record of integrating security into DevOps, SDLC, engineering workflows, or shared platform governance through DevSecOps practices.
  • Certifications:
    • CISA, CRISC (for risk and compliance focus).
    • Cloud security certifications (e.g., CCSP, AWS/Azure Security Specialty).
    • PCI QSA or ISO 27001 Lead Implementer/Auditor.
    • ISO 42001 implementation/certification experience.

Hours of Work:

Work hours will depend on the business hours of the time zone serviced.

To the extent permitted by law, the Company may, in its sole discretion, change the work schedule to address business needs.

Physical Demands:

While performing the duties of this job, the employee is frequently required to sit for extended periods; reach with hands and arms; and talk or hear. The employee is occasionally required to move about. The employee must occasionally lift and/or move up to twenty (20) pounds. Specific vision abilities required by this job include close vision and the ability to adjust focus.

EEO:

Mariner Finance is an Equal Opportunity Employer and does not discriminate on the basis of race, color, religion, creed, sex, gender, gender identity or expression, marital status, age, religion, national origin, sexual orientation, familial or caregiver status, citizenship status, status as a victim of domestic violence, medical condition, genetic information, pregnancy, physical or mental disability, or status as a disabled or Vietnam era veteran. Employee must be able to perform the essential duties/functions of the position satisfactorily and, if requested, reasonable accommodations will be made


What Mariner Finance employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom