1

It Risk Manager Jobs (NOW HIRING)

... manage risk and drive growth. Our solutions automate key processes and allow our customers to ... Abrigo is seeking a Senior IT Audit & Assurance Analyst to join our IT Risk & Assurance team ...

New

IT Risk Management VP

New York, NY

$171.80K - $215K/yr

Company Description A Major International Bank in Midtown Manhattan is seeking IT Risk Management VP in their HQ NYC office. The incumbent will be responsible for the day-to-day operation of the Bank ...

Foundational understanding of technology risk, IT controls, and governance concepts. * Basic knowledge of cybersecurity and technology risk management. * Familiarity with NIST, COBIT, and/or ISO ...

The position requires the ability to manage multiple project priorities related to a variety of tasks such as performance of IT risk assessments, physical risk assessments and sensitive ...

Reporting Relationships: * IT Risk and Compliance Manager Key Contacts: * Works closely with the Legal and Business Unit stakeholders. * This role will work with the clients in response to security ...

Reporting Relationships: * IT Risk and Compliance Manager Key Contacts: * Works closely with the Legal and Business Unit stakeholders. * This role will work with the clients in response to security ...

Reporting Relationships: * IT Risk and Compliance Manager Key Contacts: * Works closely with the Legal and Business Unit stakeholders. * This role will work with the clients in response to security ...

Technology Risk Analyst

Ware, MA · On-site

$60K - $75K/yr

This position supports the risk management and information security functions to ensure compliance with the Bank's Vendor Management Program, IT Risk Management Program, and Information Technology ...

next page

Showing results 1-20

It Risk Manager information

See salary details

$51.5K

$111.6K

$170K

How much do it risk manager jobs pay per year?

As of May 30, 2026, the average yearly pay for it risk manager in the United States is $111,556.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,000.00 and $129,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

More about It Risk Manager jobs
What cities are hiring for It Risk Manager jobs? Cities with the most It Risk Manager job openings:
What states have the most It Risk Manager jobs? States with the most job openings for It Risk Manager jobs include:
Infographic showing various It Risk Manager job openings in the United States as of May 2026, with employment types broken down into 1% As Needed, 77% Full Time, 21% Part Time, and 1% Contract. Highlights an 96% Physical, 2% Hybrid, and 2% Remote job distribution, with an average salary of $111,556 per year, or $53.6 per hour.
Senior IT Audit & Assurance Analyst

Senior IT Audit & Assurance Analyst

Abrigo

Raleigh, NC • On-site, Remote

Full-time

Medical, Retirement, PTO

Posted 2 days ago


Job description

At Abrigo, we provide market-leading compliance, credit risk and lending software solutions that financial institutions use to manage risk and drive growth. Our solutions automate key processes and allow our customers to maintain compliance, fight financial crime, process loans quicker, and leverage data to strengthen their portfolio.

Abrigo is seeking a Senior IT Audit & Assurance Analyst to join our IT Risk & Assurance team, leading the execution of SOC audit engagements, IT internal audit coordination, IT internal control testing and monitoring, and risk assessment activities for a fast-paced fintech SaaS company serving community financial institutions nationwide.

This position is remote-primary based in Raleigh, NC, with quarterly on-site team engagements (three days each) and periodic on-site visits during external audit fieldwork (up to three weeks annually). This role reports to leadership within the IT Risk & Assurance Team, within an organization that operates under a security-first model under the Chief Information Security Officer.

What You’ll Do:

SOC & External Audit Engagement Management:

  • Serve as a primary point of contact for external audit firms conducting enterprise SOC 1 and SOC 2 audit engagements, managing the engagement lifecycle from annual renewal and kickoff through final report issuance
  • Manage ad-hoc SOC 1 and SOC 2 audit engagements for newly acquired products not yet in scope of the enterprise SOC reports
  • Coordinate document requests, evidence collection timelines, and walkthrough scheduling with internal control owners across the organization
  • Evaluate audit artifacts for completeness and accuracy before submission to external auditors
  • Communicate preliminary audit findings to management and assist in drafting management responses

IT Internal Audit Coordination:

  • Serve as the primary liaison with the external IT internal audit firm, managing document requests, walkthrough scheduling, and audit status reporting for audits aligned with FFIEC IT Handbook standards
  • Perform walkthroughs with product teams and internal control owners to assess the IT internal control environment and recommend IT internal controls based on SOC and IT internal audit requirements
  • Proactively identify control gaps and recommend remediation strategies to control owners

Risk Finding Management & Control Monitoring:

  • Own the full lifecycle of the IT risk finding register, from opening findings through remediation closure, including escalation of overdue findings to management
  • Document and process risk acceptance based on control owner feedback
  • Perform ongoing monitoring of specific IT internal controls to ensure SOC and IT internal audit readiness throughout the year
  • Perform periodic IT internal control testing to validate control design and operating effectiveness
  • Conduct periodic risk finding reviews to verify findings were closed appropriately with supporting remediation evidence

Risk Assessments & Policy Coordination:

  • Lead annual updates to IT risk assessments, including the FFIEC Cybersecurity Assessment Tool (CAT), NIST CSF control mappings, and CIS Controls risk assessments
  • Lead the annual business impact analysis update, evaluating likelihood and impact of potential disruptions to the technology environment
  • Coordinate the annual policy update cycle with policy owners, including documenting changes, presenting to the IT Steering Committee, and coordinating management and Board approval
  • Perform additional IT risk and assurance duties as assigned to support the team's evolving needs

What You’ll Need:

  • Bachelor's degree in Information Systems, Accounting, Computer Science, or related discipline; equivalent professional experience may be substituted in lieu of a degree
  • 3–6 years of experience in IT audit, IT risk, or IT compliance, such as advisory services at a CPA or consulting firm, IT internal audit at a financial institution, or GRC at a technology company
  • Hands-on experience managing or significantly contributing to SOC 1/SOC 2 audit engagements, including evidence collection and walkthrough coordination
  • Working knowledge of IT general controls and their application to SOC trust services criteria and/or FFIEC IT Handbook examination standards
  • Demonstrated experience performing IT internal control testing and evaluating control effectiveness
  • Experience maintaining risk finding registers and managing risk remediation lifecycles
  • Familiarity with IT risk assessment frameworks such as FFIEC CAT, NIST CSF, or CIS Controls
  • Strong written and verbal communication skills with the ability to interact effectively with external auditors, internal control owners, and management
  • Strong organizational skills and the ability to independently manage multiple audit and assurance workstreams in a remote-first environment
  • Must be available for quarterly on-site team engagements in Raleigh, NC and periodic on-site visits during external audit fieldwork

Preferred:

  • CISA (Certified Information Systems Auditor) or CRISC (Certified in Risk and Information Systems Control)
  • Experience in the financial services, banking, or fintech industry
  • Experience with FFIEC regulatory examinations or bank/credit union technology audit programs
  • Experience with SaaS/cloud environments (AWS, Azure) and understanding of shared responsibility models
  • Experience coordinating with outsourced or co-sourced internal audit functions

What You’ll Get:

  • Market competitive total rewards package
  • To be part of the Heart & SOUL of a winning company with an inspiring mission
  • The opportunity to Make Big Things Happen
  • Competitive salary along with full health benefits with an HSA option
  • Flexible PTO and bank holidays
  • 401(k) plan and company match

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, age, genetic trait, sexual orientation, national origin, disability status, or any other characteristic protected by law.  Abrigo is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at careers@abrigo.com with the subject line accommodation.