1

It Risk Manager Jobs in Vienna, VA (NOW HIRING)

Support critical third-party vendor risk management activities * Develop, enhance, and maintain ... Previous experience in IT audit, operational risk management, regulatory compliance, or a Big Four ...

Support critical third-party vendor risk management activities * Develop, enhance, and maintain ... Previous experience in IT audit, operational risk management, regulatory compliance, or a Big Four ...

The IT Risk and Controls Managing Consultant will support stakeholder engagement and technical delivery for efforts supporting a Department of Homeland Security (DHS) client with IT controls audit ...

The IT Risk and Controls Managing Consultant will support stakeholder engagement and technical delivery for efforts supporting a Department of Homeland Security (DHS) client with IT controls audit ...

The IT Risk and Controls Managing Consultant will support stakeholder engagement and technical delivery for efforts supporting a Department of Homeland Security (DHS) client with IT controls audit ...

IT Audit - Staff

Alexandria, VA ยท On-site

$65K - $80K/yr

IT Audit Staff Location: Alexandria, VA (on-site) Level: Staff Clearance: Secret *Candidates must ... Conduct research related to IT control frameworks, risk management standards, and security ...

IT Advisory Manager

Mclean, VA

$96K - $117K/yr

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

IT Advisory Manager

Chantilly, VA ยท On-site

$97K - $119K/yr

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

IT Advisory Manager

Chantilly, VA ยท On-site

$97K - $119K/yr

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

You will lead audit and exam requests for the Risk Tech and Product teams by partnering with ... Please note that this salary information is solely for candidates hired to perform work within one ...

Develop and deliver management reporting and insights to stakeholders on the model and AI ... Previous experience in IT audit, operational risk management, regulatory compliance, or a Big Four ...

Develop and deliver management reporting and insights to stakeholders on the model and AI ... Previous experience in IT audit, operational risk management, regulatory compliance, or a Big Four ...

next page

Showing results 1-20

It Risk Manager information

See Vienna, VA salary details

$51.7K

$112K

$170.6K

How much do it risk manager jobs pay per year?

As of Jul 27, 2026, the average yearly pay for it risk manager in Vienna, VA is $111,969.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,300.00 and $129,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What is the highest salary for a risk manager?

The highest salary for an IT Risk Manager can exceed $150,000 annually, especially for those with extensive experience, advanced certifications like CRISC or CISSP, and working in large organizations or financial institutions. Senior risk managers or those in managerial or executive roles may earn even higher compensation, including bonuses and benefits.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

Is risk a good career?

A career as an IT Risk Manager is considered stable and in demand, as organizations prioritize cybersecurity and risk mitigation. The role requires strong analytical skills, knowledge of security frameworks, and often certifications like CISSP or CRISC. It offers opportunities for advancement and specialization in a growing field.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

How much does a risk manager get paid?

A risk manager's average salary varies by experience and location but typically ranges from $80,000 to $150,000 annually. Senior risk managers or those with specialized certifications like FRM or CRM can earn higher salaries, especially in large organizations or financial sectors.

What is the role of IT risk manager?

An IT risk manager is responsible for identifying, assessing, and mitigating information technology risks within an organization. They develop security policies, implement controls, and ensure compliance with industry standards to protect digital assets and infrastructure. Strong knowledge of cybersecurity, risk management frameworks, and relevant certifications like CISSP or CISM are often required.
What job categories do people searching It Risk Manager jobs in Vienna, VA look for? The top searched job categories for It Risk Manager jobs in Vienna, VA are:
What cities near Vienna, VA are hiring for It Risk Manager jobs? Cities near Vienna, VA with the most It Risk Manager job openings:
Infographic showing various It Risk Manager job openings in Vienna, VA as of July 2026, with employment types broken down into 1% As Needed, 76% Full Time, 19% Part Time, and 4% Contract. Highlights an 94% Physical, 1% Hybrid, and 5% Remote job distribution, with an average salary of $111,969 per year, or $53.8 per hour.
IT Risk Consulting Manager

IT Risk Consulting Manager

Kearney & Company

Washington, DC โ€ข On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 8 days ago


Job description

Kearney is seeking an IT Risk Consulting Manager to join our growing consulting practice. This role is responsible for partnering with federal clients to strengthen IT governance, improve technology risk management, modernize internal control environments, and support regulatory and compliance initiatives. The Manager will support consulting engagements focused on IT risk, financial systems controls, cybersecurity governance, compliance, and remediation while also supporting internal IT audit and control assessment activities when required.
This position requires a client-focused professional who can balance strategic advisory services with hands-on delivery, build trusted relationships, and lead teams in solving complex technology and compliance challenges.
Additional skills and responsibilities are defined below:
  • Support consulting engagements that help clients strengthen IT governance, risk management, and internal control environments across enterprise applications, cloud platforms, and business systems.
  • Advise clients on designing, implementing, and maturing IT controls that support regulatory compliance, operational effectiveness, and organizational objectives.
  • Perform and oversee IT control assessments, including IT General Controls (ITGCs), Business Process Application Controls (BPACs), internal IT audits, and OMB A-123 evaluations.
  • Assess technology risks and identify practical recommendations that improve security, compliance, operational efficiency, and business resilience.
  • Partner with client executives, business stakeholders, system owners, and implementation teams to develop sustainable solutions for identified control deficiencies.
  • Collaborate with system integrators and client leadership to develop actionable remediation strategies, Plans of Action and Milestones (POA&Ms), and long-term control improvements.
  • Review remediation activities and provide guidance to ensure corrective actions effectively address root causes and satisfy compliance requirements.
  • Support financial system modernization, ERP implementations, cloud migrations, and digital transformation initiatives by integrating governance, risk, and control considerations throughout the project lifecycle.
  • Facilitate workshops, walkthroughs, risk assessments, and client meetings to evaluate business processes, system controls, and technology risks.
  • Develop executive-ready presentations, assessment reports, and client deliverables that clearly communicate risks, recommendations, and implementation priorities.
  • Mentor seniors and staffing by providing technical guidance, quality reviews, coaching, and career development.
  • Support business development activities, including proposal development, client presentations, solution design, and identification of follow-on consulting opportunities.
  • Contribute to the continuous improvement of the firm's Governance, Risk, and Compliance (GRC) methodologies, templates, accelerators, and service offerings.

Qualifications
Required Qualifications
โ€ข Bachelor's degree from an accredited college/university.
โ€ข Minimum of four years of experience in IT risk consulting, technology advisory, internal IT audit, IT compliance, or related consulting services.
โ€ข Experience advising clients on improving and maturing IT governance, risk management, and internal control environments.
โ€ข Experience leading IT control assessments, internal audits, or compliance evaluations involving enterprise applications, ERP systems, cloud technologies, or financial systems.
โ€ข Strong understanding of IT General Controls (ITGCs), application controls, technology risk management, and control frameworks.
โ€ข Experience working directly with client stakeholders, presenting recommendations, and managing consulting engagements.
โ€ข Excellent written and verbal communication skills with the ability to translate technical concepts into business-focused recommendations.
โ€ข Ability to manage multiple client engagements, priorities, and project teams in a consulting environment.
โ€ข Ability to work onsite at client locations throughout the Washington, DC metropolitan area.
โ€ข Ability to obtain and maintain a US Security Clearance (US Citizenship Required)
โ€ข Must have at least one professional certification such as CISA, CISSP, CRISC, CGEIT, Security+, CPA, or equivalent.
Preferred Qualifications
โ€ข Experience supporting OMB A-123 IT evaluations within federal agencies.
โ€ข Experience with Oracle, Oracle Cloud ERP, Oracle Federal Financials business applications.
โ€ข Experience supporting cloud governance and security within AWS, Azure, Oracle Cloud Infrastructure (OCI), or Google Cloud Platform.
โ€ข Experience implementing or administering Governance, Risk, and Compliance (GRC) platforms such as ServiceNow GRC, Diligent HighBond, or Archer.
โ€ข Experience supporting FISMA, NIST Cybersecurity Framework, NIST SP 800-53, FedRAMP, or related federal compliance initiatives.
โ€ข Bachelor's degree in information systems, Computer Science, Accounting, Business, Cybersecurity, or a related field from an accredited college/university.
Overview
Exclusively focused on the Government, Kearney & Company provides financial services, including auditing, consulting, and technology services. Our commitment to our employees and clients as well as to dedication and trust, critical values to our Firm, have led to Kearney's recognition as one of the leading accounting firms in the country. Based on our employees' feedback, we are also consistently rated a Best Place to Work. Employment at Kearney means a flexible, collaborative, and open-minded work environment. We hope it is your "first easy decision." Learn more at www.kearneyco.com/careers." ,"
The expected salary range for this position is between $77,000 and $125,000. This range is representative of base pay only and does not include straight time pay for hours worked over 40 per week, company contributions towards paid benefits, and/or bonuses. Actual compensation (meeting or exceeding the range) will be determined based on specific experience, education, work location, clearance level, and other factors permitted by law. This position is eligible for bonuses (when applicable).
We also offer a competitive benefits package that includes:
  • Medical, Dental, Vision, Life, AD&D, and Disability Insurance
  • 401(k) Retirement Plan and 529 Education Savings Plan
  • Flexible Spending & Health Savings Account
  • Accident, Critical Illness, Hospital Indemnity Insurances
  • Legal Insurance and Pet Insurance
  • Employee Assistance Program, fitness and wellness benefits, and other firm benefits.
  • Paid holidays, vacation, and sick time

EEO Notice
Applicants have rights under Federal Employment Laws
EEO Notice
Work location is subject to change based on client requirements.
Kearney & Company is an Equal Opportunity Employer and will consider all qualified applicants without regard to race, color, national origin, ethnicity, ancestry, genetic information, religion, sex, gender, gender identity, sexual orientation, marital status, pregnancy, childbirth, any medical condition related to pregnancy or childbirth, age, disability, protected veteran status, relationship or association to a protected veteran, or any other characteristic protected by local, state or federal laws, rules or regulation. Click here for more information on Kearney's EEO Policy.
If you would like to request a reasonable accommodation, regarding accessibility of our website, a modification or adjustment of the job application or interview process due to a disability, please call 703-236-2391 or email accommodations@kearneyco.com. Please be advised that this contact information is for accommodation requests only and cannot be used to inquire about the status of an application.
Family and Medical Leave Act (FMLA)
FMLA is designed to help employees balance their work and family responsibilities by allowing them to take reasonable unpaid leave for certain family and medical reasons. Kearney & Company provides eligible employees with up to 12 weeks of unpaid, job-protected leave per year. Military family leave is available for up to 26 weeks under FMLA. Click here to learn more.
Employee Polygraph Protection Act (EPPA)
The EPPA prohibits most private employers from using lie detector tests either for pre-employment screening or during the course of employment. Kearney & Company adheres all provisions of the EPPA. Click here to learn more.