1

It Risk Jobs in Kentucky (NOW HIRING)

Bachelor's degree in Information Systems or related field. * Required: CISA, CISM, CISSP ... technology audit, IT risk management, or information security, with at least 4 years in a ...

$41.75 - $55.75/hr

The IT Governance/Risk/Compliance Analyst position offers a dynamic opportunity for an experienced analyst to help shape the future of our governance, risk, and compliance initiatives. In this role ...

Partner with technology teams, application owners, information security teams, and risk organizations to identify and mitigate risks.* Facilitate risk reviews, issue management activities, and ...

$69K - $69K/yr

Risk & Vendor Management Conduct risk assessments for new technologies, vendors, and operational changes; maintain the IT risk register and drive mitigation plans to closure. Perform security ...

$66K - $91K/yr

Lead Risk Assessments that inform the annual IT audit plan, identifying where the company ... technology exposure sits and what needs attention this year * Develop and execute audits focused on ...

$135K - $155K/yr

Lead and execute IT Risk-Based Audit engagements from end-to-end, including planning, execution and reporting. * Partner with operational audit team members to test ITGCs and key IT risks over key ...

We decode risk to unlock opportunity, helping our clients navigate uncertainty with clarity, speed ... technologies and IT infrastructure platforms, including cloud environments (AWS, Azure, GCP ...

We decode risk to unlock opportunity, helping our clients navigate uncertainty with clarity, speed ... technologies and IT infrastructure platforms, including cloud environments (AWS, Azure, GCP ...

$78K - $106K/yr

... IT risk assessments and recommended mitigating solutions. There are three (3) Assignment Levels within this classification. All personnel perform related work. Assignment Levels 2 and 3 may supervise ...

Governance, Risk, and Compliance Senior Associate, IT Controls & Assurance Job Category : Advisory Requisition Number : GOVER003160 * Posted : August 18, 2026 * Full-Time Locations Showing 1 location ...

$195K - $217K/yr

Primary Purpose of Position The Director, IT Internal Audit provides strategic risk leadership for the Company's technology and cybersecurity assurance program and serves as a key risk advisor on ...

Cybersecurity and technology risk certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified in Risk and Information ...

$85K - $100K/yr

SC&H's Advisory Services Practice provides risk, and control services to assist organizations in independently assessing security, information technology, operational and financial risks. Work with ...

New

$95K - $165K/yr

Morgan Stanley is seeking a Risk professional to join the Cyber, Technology and Information Security (CTIS) Standards team within the Non-Financial Risk Organization in Alpharetta or Baltimore at the ...

Advise executive leadership on technology investments, cybersecurity risk management, and emerging technologies. * Establish and enforce IT governance policies, cybersecurity standards, and best ...

Advise executive leadership on technology investments, cybersecurity risk management, and emerging technologies. * Establish and enforce IT governance policies, cybersecurity standards, and best ...

Showing results 21-40

It Risk information

See Kentucky salary details

$12

$26

$64

How much do it risk jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for it risk in Kentucky is $26.35, according to ZipRecruiter salary data. Most workers in this role earn between $16.92 and $33.61 per hour, depending on experience, location, and employer.

What is IT risk?

IT risk refers to the potential for losses or negative impacts to an organization resulting from the use of information technology. This includes threats such as data breaches, cyberattacks, system failures, and non-compliance with regulations. IT risk management involves identifying, assessing, and mitigating these risks to protect an organization’s information assets and ensure business continuity.

What are the key skills and qualifications needed to thrive as an IT risk professional, and why are they important?

To thrive as an IT Risk professional, you need a strong understanding of information security principles, risk management frameworks, and relevant regulations, typically supported by a degree in information technology or cybersecurity. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) systems, and certifications such as CISM or CISSP is highly valued. Analytical thinking, attention to detail, and effective communication are vital soft skills for identifying vulnerabilities and collaborating with stakeholders. These competencies are crucial for proactively managing threats and ensuring the organization's information assets remain secure and compliant.

What are some common challenges faced by IT risk professionals when working with cross-functional teams?

IT Risk professionals often collaborate with various departments such as IT, compliance, finance, and operations. A common challenge is effectively communicating technical risks in terms that non-technical stakeholders can understand, ensuring alignment on priorities and mitigation strategies. Navigating differing risk tolerances and balancing business needs with security requirements can also present difficulties. Building strong relationships and fostering ongoing dialogue are key to overcoming these challenges and ensuring successful risk management across the organization.

What is the difference between It Risk vs Cybersecurity Analyst?

AspectIt RiskCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentRisk management teams, compliance departmentsSecurity operations centers, IT departments
Employer & Industry UsageFinancial, healthcare, and large enterprisesTech firms, finance, government agencies

It Risk professionals focus on identifying, assessing, and mitigating risks related to IT systems and compliance. Cybersecurity Analysts primarily monitor and respond to security threats and incidents. While both roles require similar certifications and work in overlapping environments, It Risk emphasizes risk management strategies, whereas Cybersecurity Analysts concentrate on security operations and threat response.

Do IT risk analysts make good money?

IT risk analysts typically earn competitive salaries that vary by experience, location, and industry. Entry-level positions may start around $60,000 annually, while experienced analysts can earn over $100,000, especially with certifications like CISSP or CISA. The role often involves working with cybersecurity tools and risk assessment frameworks.

Is risk analyst an IT job?

A risk analyst in the IT field evaluates technology-related risks, such as cybersecurity threats and system vulnerabilities, often using data analysis tools and risk management frameworks. The role typically requires knowledge of IT systems, security protocols, and relevant certifications like CISSP or CRISC.

What are the most commonly searched types of It Risk jobs in Kentucky?

The most popular types of It Risk jobs in Kentucky are:

Infographic showing various It Risk job openings in Kentucky as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 6% Part Time, 7% Temporary, and 2% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $54,804 per year, or $26.3 per hour.

Director, Technology Risk & Digital Enablement

On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 20 days ago


Key responsibilities

  • Lead and own all workstreams related to the global Technology Risk Universe, including IT, cyber, data, cloud, AI, and third-party technology risks.

  • Plan, execute, and report on technology advisory and assurance initiatives across infrastructure, applications, cybersecurity, data governance, and emerging technology.

  • Define and execute a multi-year Digital Enablement Roadmap, partnering with teams to build data pipelines, dashboards, and automate testing capabilities.


McCormick & Company rating

8.2

Company rating: 8.2 out of 10

Based on 45 frontline employees who took The Breakroom Quiz

70th of 445 rated food and drinks producers


Job description

Select how often (in days) to receive an alert:

Director, Technology Risk & Digital Enablement

HUNT VALLEY, MD, US, 21031

You may know McCormick as a leader in herbs, spices, seasonings, and condiments – and we’re only getting started. At McCormick, we’re always looking for new people to bring their unique flavor to our team.

McCormick employees – all 14,000 of us across the world – are what makes this company a great place to work.

We are looking to hire a Director, Technology Risk & Digital Enablement to join the Global Risk and Audit Management (GRAM) team based at our Global Headquarters in Hunt Valley, Maryland. The position is hybrid eligible (50% onsite per month).

What We Bring To The Table:

The best people deserve the best rewards. In addition to the benefits you’d expect from a global leader (401k, health insurance, paid time off, etc.) we also offer:

  • Career growth opportunities
  • Flexibility and Support for Diverse Life Stages and Choices
  • Wellbeing programs including Physical, Mental and Financial wellness

We have embarked on an exciting journey to transform and integrate our Enterprise Risk and Internal Audit capabilities and align with McCormick's strategic priorities. Director, Technology Risk & Digital Enablement is a key leadership role reporting to the Chief Risk & Audit Officer (CRAO), and responsible for owning and advancing the full technology risk agenda within GRAM. This individual serves as the strategic leader in advancing global technology and cyber risk coverage while simultaneously acting as the function's digital transformation champion – driving the adoption of analytics, automation, and emerging technologies to make audit activities smarter, faster, and more impactful.

This is a dual-mandate role: one foot firmly in risk and assurance, the other driving innovation. The successful candidate will be as comfortable presenting technology risk insights to the Audit Committee as they are building a data analytics roadmap with audit teams.

Responsibilities Technology Risk & Audit Leadership
  • Lead and own all GRAM workstreams related to global Technology Risk Universe, ensuring comprehensive coverage of IT, cyber, data, cloud, AI, and third-party technology risks.
  • Lead the planning, execution, and reporting of all technology advisory and assurance initiatives across infrastructure, applications, cybersecurity, data governance, and emerging technology.
  • Serve as GRAM function's primary interface with the Technology leadership team incl. CTO, CISO, and others.
  • Serve as the in-house expert on all Technology matters related to Sarbanes-Oxley (SOX), corporate governance and enterprise risks and provide expert opinion on technology risk matters to the CARO, Audit Committee, and senior management, translating complex technical risks into clear business language.
  • Collaborate closely with other members of GRAM leadership team to ensure that risk management activities are well-defined, coordinated, risk-based, and executed
  • Stay current with the evolving technology risk landscape (e.g., cloud, AI/ML risk, ransomware, third-party digital risk) and ensure risk mitigation and audit plans remain relevant and forward-looking.
  • Oversee quality assurance on technology audit engagements, ensuring findings are well-evidenced, rated consistently, and linked to business impact.
  • Champion the adoption of digital tools and capabilities within Internal Audit, including data analytics, automation/AI-assisted audit techniques, and continuous monitoring.
  • Define and execute a multi-year Digital Enablement Roadmap for the GRAM function, with measurable milestones and efficiency outcomes.
  • Partner with Data & Analytics, IT, and external vendors to build and sustain function-specific data pipelines, dashboards, and automated testing capabilities.
  • Identify and pilot emerging technologies (e.g., natural language processing for document review, anomaly detection, GRC platform enhancements).
  • Embed data-driven risk management techniques into engagements, helping teams move from sample-based testing to population-level analysis.
  • Track and report on digital enablement ROI - efficiency gains, risk coverage expansion, and quality improvements.
People Leadership & Capability Building
  • Recruit and retain top technology risk talent, building a team that blends deep technical expertise with strong business acumen.
  • Lead, mentor, and develop a team of technology risk professionals (in-house and co-source provider), fostering a culture of continuous learning and innovation.
  • Build digital literacy and data analytics skills across the broader audit function through training, coaching, and hands-on engagement.
  • Act as a role model for intellectual curiosity and agile ways of working within a traditionally structured audit environment.
Candidate profile
  • Bachelor's degree in Information Systems or related field.
  • Required: CISA, CISM, CISSP certification or equivalent. Preferred CIA, CPA or equivalent.
  • 10+ years of progressive experience in technology audit, IT risk management, or information security, with at least 4 years in a leadership role, including interaction with senior management.
  • Experience managing cross-regional or multi-country audit programs, with specific exposure to emerging markets with regions.
  • Strong track record of leading high-performing audit teams and developing talent at all levels.
  • Exceptional communication, influencing, and executive presence skills - ability to present complex risk and audit topics to C-suite and Board audiences.
  • Proficiency with audit management and GRC technology platforms (e.g., Optro, Workiva, Archer, or equivalent).
  • Large, multi-brand, global, public company experience preferred.
  • M&A experience preferred.
  • Thorough knowledge of IT Operational Functions including IAM, Asset Management, Cybersecurity, Data Privacy.
  • Demonstrated experience leading or materially contributing to a digital transformation or data analytics program within an audit or risk function.
  • Thorough understanding of internal auditing standards, PCAOB auditing standards, COSO, SOX, US GAAP and risk assessment practice.
  • Robust understanding of regulatory and external requirements as they relate to IT, privacy and cybersecurity for regulations such as GDPR, NERC-CIP and SOX.
  • Proven track-record of implementing technology enablers such as data analytics, AI, etc. to modernize risk & audit capabilities.
  • Proven ability to handle scale, change agenda, pace and overall complexity.
  • Experience implementing and managing change within an organization, taking steps to remove barriers or to accelerate its pace.
  • Track record of working alongside business leaders, positioning internal audit as a strategic partner, identifying and helping mitigate risk.
  • Superior business acumen; ability to build strong relationships and trust with company leadership and business process owners.
  • Broad understanding of the inter-dependency between operational, technological, strategic and reputational risks as well as general compliance standards.
  • Professional, self-starter, solution-minded, results oriented and approachable.
  • Strong analytical and problem-solving skills with attention to detail and customer focus.
  • Excellent organizational, time management and prioritization skills.
  • Commitment to maintaining a high degree of discretion and confidentiality.

#LI-DNI

Base salary compensation will be determined based on factors such as geographic location, skills, education, experience for this role, and/or internal equity of our current employees as part of any final offer. This position is also eligible to participate in McCormick's Incentive Bonus (MIB) Plan/ McCormick's Sales Incentive Bonus (SIB) Plan/ McCormick's Dividend Program. In addition to a competitive compensation package, permanent employees of McCormick are eligible for our extensive Total Rewards programs that include:

  • Comprehensive health plans covering medical, vision, dental, life and disability benefits
  • Family-friendly benefits such as paid parental leave, fertility benefits, Employee Assistance Program, and caregiver support
  • Retirement and investment programs including 401(k) and profit-sharing plans

McCormick & Company is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.

As a general policy, McCormick does not offer employment visa sponsorships upon hire or in the future.

#LI-DNI

WHY WORK AT MCCORMICK?

As a McCormick employee you’ll be empowered to focus on more than your individual responsibilities. You’ll have the opportunity to be part of something bigger than yourself—to have a say in where the company is going and how it’s growing.

Between our passion for flavor, our 130-year history of leadership and integrity, the competitive and comprehensive benefits we offer, and our culture, which is built on respect and opportunities for growth, there are many reasons to join us at McCormick.

#J-18808-Ljbffr

What McCormick & Company employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom