1

It Risk Jobs in Colorado (NOW HIRING)

As an IT Cybersecurity Specialist (INFOSEC), you will provide technical expertise and guidance to WAPA functional and project teams regarding cybersecurity technical issues, risk analyses, mitigation ...

Senior IT Auditor

Colorado Springs, CO · On-site

$83K - $110K/yr

Supports the execution of all phases of IT audits including planning, risk assessment, walkthroughs ... Supports IT audit engagements end-to-end (planning, fieldwork, reporting, and QA review) in ...

IT Staff Auditor II

Canon City, CO · On-site

$65K - $85K/yr

Perform risk-based testing over key IT processes, such as access management, change management, IT operations, and data integrity, to evaluate control effectiveness and identify potential control ...

Perform risk-based testing over key IT processes, such as access management, change management, IT operations, and data integrity, to evaluate control effectiveness and identify potential control ...

IT Staff Auditor II

Canon City, CO · On-site

$65K - $85K/yr

Perform risk-based testing over key IT processes, such as access management, change management, IT operations, and data integrity, to evaluate control effectiveness and identify potential control ...

IT Systems Administrator

Romeo, CO · On-site

$80 - $100/hr

Global Manager - Governance, Risk & Compliance Would you like to work for a company where ambitious spirits and creativity thrive? L&L Products offers a culture that grows talent and flourishes with ...

IT Program Analyst

Denver, CO · On-site

$60 - $80/hr

... risk management, budgeting, and cost analysis for IT program development and execution. Preferred Qualifications * Experience in a start-up and/or rapidly scaling company. * Experience supporting ...

IT Architect

Denver, CO · On-site

$100 - $125/hr

... value, reduce risk, and strengthen the reliability, scalability, and sustainability of the ... The Technology Services Department is seeking an IT Architect to help shape and advance the City ...

IT Architect

Denver, CO · Hybrid

$115K - $130K/yr

... value, reduce risk, and strengthen the reliability, scalability, and sustainability of the ... The Technology Services Department is seeking an IT Architect to help shape and advance the City ...

IT Architect

Denver, CO · On-site

$115K - $130K/yr

... value, reduce risk, and strengthen the reliability, scalability, and sustainability of the ... The Technology Services Department is seeking an IT Architect to help shape and advance the City ...

IT Project Manager

Westminster, CO · On-site

$60 - $70/hr

Job Title: Senior IT Project Manager Location: Broomfield, CO Location Type: Hybrid, Broomfield, CO ... Strong knowledge of project planning, governance, risk/issue management, change control, and ...

IT Architect

Denver, CO · Hybrid

$115K - $130K/yr

... value, reduce risk, and strengthen the reliability, scalability, and sustainability of the ... The Technology Services Department is seeking an IT Architect to help shape and advance the City ...

IT Architect

Denver, CO · Hybrid

$115K - $130K/yr

... value, reduce risk, and strengthen the reliability, scalability, and sustainability of the ... The Technology Services Department is seeking an IT Architect to help shape and advance the City ...

Senior IT Auditor

Denver, CO · On-site +1

$96K - $127K/yr

Document results within risk assessments and recommend changes to the multi-year audit plan as ... Compliance, Legal, Banking Regulatory, Information Technology, Information Security, Data Analytics ...

Showing results 41-60

It Risk information

See Colorado salary details

$15

$31

$77

How much do it risk jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for it risk in Colorado is $31.90, according to ZipRecruiter salary data. Most workers in this role earn between $20.48 and $40.67 per hour, depending on experience, location, and employer.

What is IT risk?

IT risk refers to the potential for losses or negative impacts to an organization resulting from the use of information technology. This includes threats such as data breaches, cyberattacks, system failures, and non-compliance with regulations. IT risk management involves identifying, assessing, and mitigating these risks to protect an organization’s information assets and ensure business continuity.

What are the key skills and qualifications needed to thrive as an IT risk professional, and why are they important?

To thrive as an IT Risk professional, you need a strong understanding of information security principles, risk management frameworks, and relevant regulations, typically supported by a degree in information technology or cybersecurity. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) systems, and certifications such as CISM or CISSP is highly valued. Analytical thinking, attention to detail, and effective communication are vital soft skills for identifying vulnerabilities and collaborating with stakeholders. These competencies are crucial for proactively managing threats and ensuring the organization's information assets remain secure and compliant.

What are some common challenges faced by IT risk professionals when working with cross-functional teams?

IT Risk professionals often collaborate with various departments such as IT, compliance, finance, and operations. A common challenge is effectively communicating technical risks in terms that non-technical stakeholders can understand, ensuring alignment on priorities and mitigation strategies. Navigating differing risk tolerances and balancing business needs with security requirements can also present difficulties. Building strong relationships and fostering ongoing dialogue are key to overcoming these challenges and ensuring successful risk management across the organization.

What is the difference between It Risk vs Cybersecurity Analyst?

AspectIt RiskCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentRisk management teams, compliance departmentsSecurity operations centers, IT departments
Employer & Industry UsageFinancial, healthcare, and large enterprisesTech firms, finance, government agencies

It Risk professionals focus on identifying, assessing, and mitigating risks related to IT systems and compliance. Cybersecurity Analysts primarily monitor and respond to security threats and incidents. While both roles require similar certifications and work in overlapping environments, It Risk emphasizes risk management strategies, whereas Cybersecurity Analysts concentrate on security operations and threat response.

Do IT risk analysts make good money?

IT risk analysts typically earn competitive salaries that vary by experience, location, and industry. Entry-level positions may start around $60,000 annually, while experienced analysts can earn over $100,000, especially with certifications like CISSP or CISA. The role often involves working with cybersecurity tools and risk assessment frameworks.

Is risk analyst an IT job?

A risk analyst in the IT field evaluates technology-related risks, such as cybersecurity threats and system vulnerabilities, often using data analysis tools and risk management frameworks. The role typically requires knowledge of IT systems, security protocols, and relevant certifications like CISSP or CRISC.

What are the most commonly searched types of It Risk jobs in Colorado?

The most popular types of It Risk jobs in Colorado are:

Infographic showing various It Risk job openings in Colorado as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 10% Part Time, and 3% Contract. Highlights an 86% Physical, 4% Hybrid, and 10% Remote job distribution, with an average salary of $66,350 per year, or $31.9 per hour.

IT Cybersecurity Specialist

Lakewood, CO • On-site

U.S. Department of Energy (DOE)
Public Administration • 10K+ employees

$106K/yr

Full-time

Posted 15 days ago


Key responsibilities

  • Provide technical expertise and guidance on cybersecurity issues, risk analyses, mitigation plans, and continuity of operations.

  • Analyze security events, develop threat models, and perform vulnerability assessments to identify and mitigate cybersecurity threats.

  • Design, develop, and manage cybersecurity architectures and systems to ensure compliance with federal and industry standards.


U.S. Department Of Energy rating

8.8

Company rating: 8.8 out of 10

Based on 10 frontline employees who took The Breakroom Quiz

151st of 858 rated public administrative organizations


Job description

As an IT Cybersecurity Specialist (INFOSEC), you will provide technical expertise and guidance to WAPA functional and project teams regarding cybersecurity technical issues, risk analyses, mitigation plans and continuity of operations planning.
**This is NOT A REMOTE POSITION. The selectee will be required to be physically present at one of the duty location(s) identified.**Qualifications:

QUALIFICATION REQUIRMENTS: To qualify for this position, you must meet the minimum qualification requirements as well as the specialized experience requirements outlined below:
MINIMUM REQUIREMENTS FOR GRADE 12 and Above (GS or Equivalent): The competencies listed in the "How You Will Be Evaluated" section will be used to evaluate whether or not you meet the minimum proficiency level established for the 2210 series
SPECIALIZED EXPERIENCE for Cybersecurity Infrastructure and Architecture (IA): A qualified candidate's online application and resume must demonstrate at least one (1) year of specialized experience equivalent in difficulty and responsibility to the next lower grade level GS-12 in the Federal service (obtained in either the public or private sectors). Specialized experience for this position is defined as having at least two (2) of the following:

  • Test, analyze, and/or implement existing and future systems to complement existing cybersecurity architectures; often leading Authority to Operate (ATO) job functions such as control testing and validation, Plan of Actions & Milestones (POAM) tracking or Risk Acceptance (RA).
  • Analyze security events, including threat model development and resulting security risk analysis of systems.
  • Design and develop security architecture to execute a company's cybersecurity program to meet Federal Information Security Modernization Act (FISMA), North American Electric Reliability (NERC), Critical Information Protection (CIP), or NIST 800-53 Controls.
  • Perform vulnerability management to include scans, assessments, and remediation in conjunction with other IT business units to reduce company-wide risk.

-OR-

SPECIALIZED EXPERIENCE for Cybersecurity Operations (Ops): A qualified candidate's online application and resume must demonstrate at least one (1) year of specialized experience equivalent in difficulty and responsibility to the next lower grade level GS-12 in the Federal service (obtained in either the public or private sectors). Specialized experience for this position is defined as having at least two (2) of the following:

  • Configure and manage and/or manage the lifecycle of at least 1 (one) of the following cybersecurity systems: Axonius, Carbon Black App Control, Carbon Black Endpoint Detection and Response (EDR), Corelight, Forescout, Splunk, and Tenable.
  • Apply the Risk Management Framework (RMF) and assess cybersecurity systems against federal and industry compliance standards, such as NIST SP 800-53, FISMA, or NERC CIP.
  • Conduct incident response activities, vulnerability assessments, and/or digital forensics, including analyzing security events to understand and mitigate active potential cybersecurity threats.
Education:

For this position, education cannot be substituted for experience.

Employment Type: OTHER

What U.S. Department Of Energy employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom