1

It Risk Manager Jobs (NOW HIRING)

IT Risk and Compliance Analyst

New York, NY ยท On-site

$90K - $115K/yr

Reporting Relationships: * IT Risk and Compliance Manager Key Contacts: * Works closely with the Legal and Business Unit stakeholders. * This role will work with the clients in response to security ...

Reporting Relationships: * IT Risk and Compliance Manager Key Contacts: * Works closely with the Legal and Business Unit stakeholders. * This role will work with the clients in response to security ...

IT Program Project Manager

Santa Clara, CA ยท Hybrid

$114K - $135K/yr

Governance Risk and Compliance GRC and IT Risk Management, Project Planning, Pursuit/ Proposal Management, Risk/Crisis Management We are seeking an accomplished IT Program Project Manager with deep ...

IT Audit - Staff

Alexandria, VA ยท On-site

$65K - $80K/yr

IT Audit Staff Location: Alexandria, VA (on-site) Level: Staff Clearance: Secret *Candidates must ... Conduct research related to IT control frameworks, risk management standards, and security ...

next page

Showing results 1-20

It Risk Manager information

See salary details

$51.5K

$111.6K

$170K

How much do it risk manager jobs pay per year?

As of Jun 19, 2026, the average yearly pay for it risk manager in the United States is $111,556.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,000.00 and $129,000.00 per year, depending on experience, location, and employer.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

Do risk managers make good money?

Risk managers typically earn competitive salaries that vary based on experience, industry, and location. According to industry data, median annual pay ranges from $80,000 to over $130,000, with higher earnings possible for those with certifications like FRM or CRM and extensive experience. They often work in corporate environments, analyzing and mitigating financial, operational, or cybersecurity risks.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

How much does a risk manager get paid?

Risk managers typically earn a median annual salary of around $100,000, with salaries ranging from approximately $70,000 to over $150,000 depending on experience, industry, and location. Professionals often hold certifications like CRM or FRM and work in finance, insurance, or corporate sectors.

Are risk managers in high demand?

Risk managers are in high demand across various industries due to increasing concerns about cybersecurity, compliance, and operational risks. Employers seek professionals with skills in risk assessment, mitigation strategies, and certifications like FRM or CRM, making it a growing field with strong job prospects.

What is the role of IT risk manager?

An IT risk manager is responsible for identifying, assessing, and mitigating information technology risks within an organization. They develop security policies, implement controls, and ensure compliance with industry standards to protect digital assets and infrastructure. Strong knowledge of cybersecurity, risk management frameworks, and relevant certifications like CISSP or CISM are often required.
More about It Risk Manager jobs
What cities are hiring for It Risk Manager jobs? Cities with the most It Risk Manager job openings:
What states have the most It Risk Manager jobs? States with the most job openings for It Risk Manager jobs include:
Infographic showing various It Risk Manager job openings in the United States as of June 2026, with employment types broken down into 89% Full Time, 3% Part Time, and 8% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $111,556 per year, or $53.6 per hour.

IT Risk and Compliance Analyst

Thinkbrg

New York, NY โ€ข On-site

$90K - $115K/yr

Full-time

Posted 19 days ago


Job description

We do Consulting Differently

Job Summary:

The IT Risk and Compliance Analyst position is a highly visible, client facing role which works closely with the Legal and Business Unit stakeholders and reports to the IT Risk and Compliance Manager. This role is responsible for providing assistance in evaluating, assessing, and monitoring the firm's risk and compliance with applicable information security standards and frameworks, industry best practices, and applicable laws and regulations. This role will also help coordinate and maintain the firm's Information Security Management Program and assist in implementing security policy objectives in ways that align with business and mission objectives.

Reporting Relationships:

  • IT Risk and Compliance Manager

Key Contacts:

  • Works closely with the Legal and Business Unit stakeholders.
  • This role will work with the clients in response to security assessments and due diligence questionnaires covering a broad range of business disciplines and industries (i.e., Healthcare, Financial Services, Construction, Government Contracts, Insurance, Real Estate, et al).
  • This role will work in conjunction with the IT Security and Infrastructure Team.

Major Responsibilities/ Job Functions:

  • Provide IT security, risk, and compliance advice to business units on an ongoing basis.
  • Analyze and address gaps in operations to ensure integrity of processes, controls, and policies.
  • Assist in maintaining and updating Information Security Program policies and procedures as needed, also completing a yearly review to ensure all documentation is properly updated.
  • Provide governance for participation in the information security incident response process by ensuring that the process is being followed and documented.
  • Respond to escalated security events and drive the security incident response process.
  • Participate in the evaluation, development and implementation of security standards, procedures and guidelines for multiple platforms and diverse systems environments.
  • Works with internal and external auditors to demonstrate and provide evidence for controls that are in place. May conduct additional testing to validate that items found during testing have been remediated.
  • Responsible for completion of client security questionnaires and working with the business units to assist with RFI responses related to IT security.
  • Assists in vendor vetting to ensure our vendors, business partners, or suppliers are using the same or higher security practices.
  • Assists in conducting Risk Assessments and annual reviews for any new or current vendors, business partners, or suppliers.
  • Assists with complex security assessments that require both analytical and technical skills across a broad range of Information Technology topics (e.g., Identity and Access Management,

Security Architecture, Physical and Environmental, etc.).

  • Assists with evaluating, testing, documenting, and maintaining the firmwide DR and BCP policies, processes, and standards.
  • Assists with the Security Awareness Training program initiatives related to phishing campaigns and coordinate with HR to deliver ongoing employee training.

Requirements:

  • Associate Degree or equivalent work experience
  • 3 years of experience in two or more major information technology functions (infrastructure, operations, datacenter, application support, etc.)
  • 3 years IT security, IT compliance, or IT risk management experience desired.
  • 3 years of experience involving ISO27001 annual surveillance audits and full recertification audits.
  • Familiarity with industry frameworks and standards such as SOC2, HIPAA, HITRUST is a plus.
  • Familiarity with GDPR and CCPA.
  • Familiarity using GRC tools.
  • Knowledge of application and network security, information security risk and industry best practice (how to best manage risk).
  • Experience with building, executing, and maintaining DR and BCP program.
  • Ability to effectively prioritize and execute tasks in a high-pressure environment.
  • Excellent written/verbal communication skills and time management skills.
  • Strong troubleshooting, problem-solving and analytical skills.
  • Position may require traveling for short periods. Trips will sometimes extend to 5 working days and could on rare occasions extend beyond 5 business days. All travel expenses will be reimbursed.

Salary Range: $90,000-$115,000

Candidate must be able to submit verification of his/her legal right to work in the U.S., without company sponsorship.

#LI-SJ1

About BRG

BRG combines world-leading academic credentials with world-tested business expertise and purpose-built emerging technologies. Our culture centers on agility and connectivity which sets us apart and gets you ahead.

At BRG, our professionals include specialist consultants, industry experts, renowned academics, and leading-edge data scientists. Together, they bring a diversity of real-world experience, data, and human and artificial intelligence, to economics, disputes, and investigations; corporate finance; and performance improvement services that address the most complex challenges facing organizations across the globe.

Our unique structure nurtures the interdisciplinary relationships that give us the edge, laying the groundwork for more informed insights and more original, incisive thinking. When paired with our global reach and resources, our diverse perspectives and technical capabilities make us uniquely capable to address our clients' challenges. We get results because we know how to apply our thinking to your world.

At BRG, we don't just show you what's possible. We're built to help you make it happen.


BRG is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, religion, color, sex, gender, national origin, age, United States military veteran status, ancestry, sexual orientation, marital status, family structure, medical condition including genetic characteristics or information, veteran status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law.