1

It Risk Manager Jobs in Phoenix, AZ (NOW HIRING)

Reporting to the Global IT SOX Risk Management Leader, you'll drive strategic SOX readiness projects and provide risk advisory expertise across many process areas to ensure compliance with SOX while ...

Job#: 3042542 Position Summary The Risk Manager is responsible for identifying, assessing, and ... Everforth Apex is a world-class IT services company that serves thousands of clients across the ...

Kforce has a client in Tempe, AZ that is seeking an IT Audit Manager. Overview The client is ... Experience performing risk assessments and managing remediation programs * Experience mentoring ...

Senior IT Internal Auditor

Scottsdale, AZ · On-site

$93K - $123K/yr

The Senior IT Auditor plays a key role in evaluating the design and operating effectiveness of IT controls supporting financial reporting, operational systems, and enterprise risk management. This ...

next page

Showing results 1-20

It Risk Manager information

See Phoenix, AZ salary details

$51.1K

$110.8K

$168.8K

How much do it risk manager jobs pay per year?

As of Jul 20, 2026, the average yearly pay for it risk manager in Phoenix, AZ is $110,765.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,400.00 and $128,100.00 per year, depending on experience, location, and employer.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What is the highest salary for a risk manager?

The highest salary for an IT Risk Manager can exceed $150,000 annually, especially for those with extensive experience, advanced certifications like CRISC or CISSP, and working in large organizations or financial institutions. Senior risk managers or those in managerial or executive roles may earn even higher compensation, including bonuses and benefits.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

Is risk a good career?

A career as an IT Risk Manager is considered stable and in demand, as organizations prioritize cybersecurity and risk mitigation. The role requires strong analytical skills, knowledge of security frameworks, and often certifications like CISSP or CRISC. It offers opportunities for advancement and specialization in a growing field.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

How much does a risk manager get paid?

A risk manager's average salary varies by experience and location but typically ranges from $80,000 to $150,000 annually. Senior risk managers or those with specialized certifications like FRM or CRM can earn higher salaries, especially in large organizations or financial sectors.

What is the role of IT risk manager?

An IT risk manager is responsible for identifying, assessing, and mitigating information technology risks within an organization. They develop security policies, implement controls, and ensure compliance with industry standards to protect digital assets and infrastructure. Strong knowledge of cybersecurity, risk management frameworks, and relevant certifications like CISSP or CISM are often required.
What cities near Phoenix, AZ are hiring for It Risk Manager jobs? Cities near Phoenix, AZ with the most It Risk Manager job openings:
Infographic showing various It Risk Manager job openings in Phoenix, AZ as of July 2026, with employment types broken down into 1% As Needed, 78% Full Time, 17% Part Time, and 4% Contract. Highlights an 94% Physical, 1% Hybrid, and 5% Remote job distribution, with an average salary of $110,765 per year, or $53.3 per hour.
Sr It Risk Manager

Full-time

Posted 6 days ago


Job description

Sr. IT Risk Manager

The Sr. IT Risk Manager will play a key role in the ongoing technology transformation journey of the Bank. This position will be responsible for overall assurance of the compliance of enterprise platforms with established security, risk and governance requirements of the Bank. Streamlining existing processes and maximizing automation is a major responsibility for this role, and it includes developing and operationalization programmatic guardrails in collaboration with owners and architects of established and emerging enterprise platforms.

In this role you will interact directly with a cross-functional team of multiple stakeholders across the bank including leadership teams of enterprise Cloud, API and DevSecOps platforms as well as overall enterprise platform governance leadership.

Once here you will:

  • Assess existing control frameworks and implementations within enterprise platforms against the security, risk and compliance requirements of the bank
  • Design Controls framework and Controls library for Cloud, API and DevSecOps platforms meeting Industry standards and best practices
  • Provide subject matter expertise to strength controls design and implementation effectiveness
  • Communicate platform control gaps and remediation plan to internal and external stakeholders
  • Implement processes for continuous compliance of enterprise technology platforms against control framework across people, process and technology
  • Partner with technical leadership and architects of enterprise platforms to continuously improve and maximize automation of the controls within the framework
  • Partner with product managers of enterprise platforms to ensure control gap remediation are incorporated into platform delivery roadmaps and prioritized
  • Engage with teams leveraging the platforms to ensure understanding of the risk mitigation provided by controls within the framework and what additionally is required by adopting teams
  • Develop metrics and reporting to provide visibility to leadership and stakeholders on maturity of adoption of the controls framework across enterprise platforms
  • Manage stakeholders and their expectations
  • Effectively communicate ideas and information with peers, management, and customers
  • Serve as a Change Agent and contribute to a culture of continuous compliance
  • Liaison with 1st, 2nd and 3rd Risk LOD
  • Liaison with Modern Platform owners and Application owners to ensure compliance

What you'll bring:

  • 10+ years of overall industry experience, specifically around cybersecurity, IT risk management, IT audit or compliance
  • 4+ years working experience with cloud platforms (AWS) and DevOps
  • Passion for achieving excellence in delivery, solving complex problems, and taking ownership
  • Expertise in IT operations and security control domains (including application security, change management, disaster recovery, data center operations, information security and networking)
  • Knowledge of, and experience with, financial services regulatory frameworks such as PCI, SOX, FFIEC, CIS20, GDPR, GLBA, CCPA
  • At least one of the following security certifications: CISSP, CISM, PCI-QSA certifications, or Certified ISO27001 Lead Implementer
  • Experience with enterprise IT management frameworks (e.g. COBIT, ITIL)
  • Excellent technical, analytical, problem solving, multitasking, and time management skills with consistent attention to detail
  • Ability to effectively learn, communicate and use new processes, concepts, tools, and methodology to support the needs of the business
  • Strong interpersonal skills, with the ability to work across functional lines and at many levels
  • Excellent presentation (written and verbal) communication skills. Ability to effectively communicate technical issues and solutions to all levels of business

Ability to effectively share technical information and train and mentor less experienced or knowledgeable team members