1

It Risk Manager Jobs in Washington, DC (NOW HIRING)

Title: IT Audit Manager KBR is seeking an experienced IT Audit Manager to join the Internal Audit ... Develop and maintain risk-based testing strategies and audit plans covering IT General Controls ...

Manager, Cyber Risk & Analysis As a Manager, you will apply your technical expertise, risk ... Cybersecurity and technology risk certifications such as Certified Information Systems Security ...

Manager, Cyber Risk & Analysis As a Manager, you will apply your technical expertise, risk ... Cybersecurity and technology risk certifications such as Certified Information Systems Security ...

Showing results 41-60

It Risk Manager information

See Washington, DC salary details

$58.3K

$126.3K

$192.5K

How much do it risk manager jobs pay per year?

As of Aug 16, 2026, the average yearly pay for it risk manager in Washington, DC is $126,301.00, according to ZipRecruiter salary data. Most workers in this role earn between $101,900.00 and $146,100.00 per year, depending on experience, location, and employer.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

What are popular job titles related to It Risk Manager jobs in Washington, DC?

For It Risk Manager jobs in Washington, DC, the most frequently searched job titles are:

What job categories do people searching It Risk Manager jobs in Washington, DC look for?

The top searched job categories for It Risk Manager jobs in Washington, DC are:

Infographic showing various It Risk Manager job openings in Washington, DC as of August 2026, with employment types broken down into 82% Full Time, 16% Part Time, and 2% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $126,348 per year, or $60.7 per hour.

Technology Risk - Risk Management - Principal

Fanniemae

Reston, VA

Full-time

Medical, Life

Posted 6 days ago


Job description

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home.

Job Description

In this highly influential role, you will help shape the strategic direction of Third Party Risk Management (TPRM) capabilities, policies, governance, and operating practices. You will work across business, technology, cybersecurity, operational resilience, legal, procurement, and risk functions to address complex third-party and fourth-party risk matters and strengthen enterprise resilience.

This role requires more than deep risk expertise. You will anticipate emerging risks and stakeholder needs, advise senior leaders on complex risk decisions, influence enterprise-wide approaches, and lead high-impact initiatives without relying on direct authority. Your ability to connect business objectives, regulatory expectations, and enterprise risk considerations will help Fannie Mae make informed decisions and continue advancing the maturity and effectiveness of its Third Party Risk Management program.

The Way You Will Make a Difference
  • Shape the strategic direction of Third Party Risk Management capabilities, policies, governance, and operating models by anticipating emerging risks, industry trends, and evolving stakeholder needs.
  • Influence enterprise third-party risk strategy by evaluating business objectives, regulatory expectations, and risk considerations and recommending strategic tradeoffs, governance enhancements, and sustainable solutions.
  • Lead highly complex, cross-functional risk initiatives involving stakeholders across business, technology, cybersecurity, operational resilience, legal, procurement, and risk functions.
  • Serve as a strategic advisor to senior leadership by providing forward-looking perspectives and recommendations on complex third-party and fourth-party risk matters.
  • Exercise independent judgment to identify, assess, escalate, and support mitigation of material third-party risks that could affect business operations, regulatory compliance, security, reputation, financial success, or enterprise resilience.
  • Build alignment across organizations by navigating competing priorities, influencing stakeholders, and helping establish consistent approaches to Third Party Risk Management across the enterprise.
  • Drive continuous improvement in Third Party Risk Management governance, data, automation, analytics, processes, and risk management practices to strengthen program effectiveness and maturity.
  • Strengthen organizational risk capability by sharing expertise, mentoring peers, influencing best practices, and helping teams apply effective approaches to complex risk decisions.
Minimum Required Qualifications
  • Bachelor's Degree or Equivalent
  • 8 years of relevant professional experience.
  • Demonstrated experience assessing and managing complex technology, third-party, or enterprise risk matters.
  • Experience providing strategic risk advice and recommendations that support significant business or enterprise decisions.
  • Demonstrated ability to lead complex, cross-functional initiatives and influence outcomes across multiple stakeholder groups without direct authority.
  • Experience evaluating risk and control considerations and developing well-supported recommendations for management.
  • Ability to exercise independent judgment when evaluating complex or potentially material risk matters.
  • Strong communication and stakeholder-management capabilities, including the ability to translate complex risk considerations into clear, actionable recommendations.
  • Shows curiosity and adaptability in learning and responsibly applying new technologies, including artificial intelligence, to reimagine how we work.
Desired Experience
  • Significant experience in Third Party Risk Management, third-party technology risk; or a closely related risk discipline
  • Experience operating within a highly regulated or similarly complex business environment.
  • Experience advising senior leaders on complex risk matters and influencing decisions across organizational boundaries.
  • Experience leading enterprise-level risk initiatives involving multiple business, technology, cybersecurity, procurement, legal, operational resilience, or risk stakeholders.
  • Experience improving risk management governance, processes, data, analytics, automation, or operating practices.
  • Experience mentoring colleagues, sharing subject-matter expertise, and influencing risk management best practices.

#LI - TW1 - Hybrid

Qualifications

Active Directory (AD), Active Directory (AD), Amazon Web Services (AWS), Artificial Intelligence (AI), Atlassian JIRA, Authentication Management, Backup and Recovery (Software), Business Insight Skills, Business Process Management Skills, Calendar and Scheduling Tools, Cleaning and Transforming Data, Cloud Technology, Collaborating Cross-Functionally, Communicating in Technical Writing, Communicating Technical Information, Communication, Configuration Management (CM), Conflict Resolution, Coordination, Customer and Market Insights, Customer Relationship Management (CRM), CyberArk, Cybersecurity Analysis, Data Analysis, Data Analysis Interpretation {+ 60 more}

Education:

Bachelor's Level Degree (Required)

The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers.

For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote.


Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form.

The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here.

Requisition compensation:

175000

to

239000