1

It Risk Jobs in Virginia (NOW HIRING)

IT Risk and Controls Manager

Springfield, VA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Ability to Obtain Public Trust What You Will Do: The IT Risk and Controls Managing Consultant will support ...

IT Risk and Controls Manager

Mclean, VA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Ability to Obtain Public Trust What You Will Do: The IT Risk and Controls Managing Consultant will support ...

IT Audit - Staff

Alexandria, VA · On-site

$65K - $80K/yr

As a member of the Technology Risk (IT Audit) team, this role contributes to the delivery of high-quality services supporting financial statement audits, attestation engagements, and IT control ...

IT Advisory Manager

Mclean, VA · On-site

$110 - $150/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

**Job Family:**IT Risk & Controls Consulting**Travel Required:**Up to 10%**Clearance Required:**Active Top Secret SCI with Polygraph**What You Will Do:**The IT Advisory Manager will lead stakeholder ...

IT Advisory Manager

Chantilly, VA · On-site

$97K - $119K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

IT Advisory Manager

Chantilly, VA · On-site

$97K - $119K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

IT Advisory Manager

Mclean, VA

$96K - $117K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

IT Advisory Manager

Chantilly, VA

$97K - $119K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

IT Audit Manager

Mclean, VA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

Previous experience in IT audit, operational risk management, regulatory compliance, or a Big Four consulting * Relevant professional certications such as CISA, CISSP, CISM, CPA, CIA Security+, or ...

IT Audit - Senior

Alexandria, VA · On-site

$80K - $100K/yr

Job Summary The IT Audit Senior Analyst supports Technology Risk and IT audit engagements within a Department of Defense or Government & Public Sector environment. This role leads the execution of ...

IT Audit Senior

Alexandria, VA · On-site

$100K - $132K/yr

IT Audit Senior Are you ready to take the next step in your IT audit career? Join Castro amp ... Identify and Communicate Risk : Analyze IT environments, pinpoint control gaps, and clearly present ...

Identify and quantify IT risk factors for EHR application security and related infrastructure. * Working knowledge and experience with Keystone Edge, Microsoft OS, MS Office, DocuSign, Panda. * Apply ...

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...

next page

Showing results 1-20

It Risk information

See Virginia salary details

$14

$30

$73

How much do it risk jobs pay per hour?

As of Aug 18, 2026, the average hourly pay for it risk in Virginia is $30.08, according to ZipRecruiter salary data. Most workers in this role earn between $19.33 and $38.37 per hour, depending on experience, location, and employer.

What is IT risk?

IT risk refers to the potential for losses or negative impacts to an organization resulting from the use of information technology. This includes threats such as data breaches, cyberattacks, system failures, and non-compliance with regulations. IT risk management involves identifying, assessing, and mitigating these risks to protect an organization’s information assets and ensure business continuity.

What are the key skills and qualifications needed to thrive as an IT risk professional, and why are they important?

To thrive as an IT Risk professional, you need a strong understanding of information security principles, risk management frameworks, and relevant regulations, typically supported by a degree in information technology or cybersecurity. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) systems, and certifications such as CISM or CISSP is highly valued. Analytical thinking, attention to detail, and effective communication are vital soft skills for identifying vulnerabilities and collaborating with stakeholders. These competencies are crucial for proactively managing threats and ensuring the organization's information assets remain secure and compliant.

What are some common challenges faced by IT risk professionals when working with cross-functional teams?

IT Risk professionals often collaborate with various departments such as IT, compliance, finance, and operations. A common challenge is effectively communicating technical risks in terms that non-technical stakeholders can understand, ensuring alignment on priorities and mitigation strategies. Navigating differing risk tolerances and balancing business needs with security requirements can also present difficulties. Building strong relationships and fostering ongoing dialogue are key to overcoming these challenges and ensuring successful risk management across the organization.

What is the difference between It Risk vs Cybersecurity Analyst?

AspectIt RiskCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentRisk management teams, compliance departmentsSecurity operations centers, IT departments
Employer & Industry UsageFinancial, healthcare, and large enterprisesTech firms, finance, government agencies

It Risk professionals focus on identifying, assessing, and mitigating risks related to IT systems and compliance. Cybersecurity Analysts primarily monitor and respond to security threats and incidents. While both roles require similar certifications and work in overlapping environments, It Risk emphasizes risk management strategies, whereas Cybersecurity Analysts concentrate on security operations and threat response.

Do IT risk analysts make good money?

IT risk analysts typically earn competitive salaries that vary by experience, location, and industry. Entry-level positions may start around $60,000 annually, while experienced analysts can earn over $100,000, especially with certifications like CISSP or CISA. The role often involves working with cybersecurity tools and risk assessment frameworks.

Is risk analyst an IT job?

A risk analyst in the IT field evaluates technology-related risks, such as cybersecurity threats and system vulnerabilities, often using data analysis tools and risk management frameworks. The role typically requires knowledge of IT systems, security protocols, and relevant certifications like CISSP or CRISC.

What are the most commonly searched types of It Risk jobs in Virginia?

The most popular types of It Risk jobs in Virginia are:

What cities in Virginia are hiring for It Risk jobs?

Cities in Virginia with the most It Risk job openings:

Infographic showing various It Risk job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 16% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $62,558 per year, or $30.1 per hour.

IT Risk and Controls Manager

Guidehouse

Springfield, VA • On-site

Full-time

Medical, Dental, Vision, Life, Retirement

This job post has expired 1 day ago. Applications are no longer accepted.


Guidehouse rating

7.7

Company rating: 7.7 out of 10

Based on 27 frontline employees who took The Breakroom Quiz

42nd of 72 rated business consultants


Job description

Job Family:

IT Risk & Controls Consulting


Travel Required:

Up to 10%


Clearance Required:

Ability to Obtain Public Trust

What You Will Do:

The IT Risk and Controls Managing Consultant will support stakeholder engagement and technical delivery for efforts supporting a Department of Homeland Security (DHS) client with IT controls audit/assessments, remediation, and other related support. The client is responsible for coordinating and monitoring internal controls for the organization, including performing assessments in accordance with OMB Circular A-123, the FISCAM, and assisting other program offices with remediation and other related internal controls tasks. This is an ideal role for someone with an IT audit background who is looking to utilize their skills to support clients internally as a consultant rather than as an external auditor.

The IT Risk and Controls Managing Consultant will have a role in working directly with clients and other organizational stakeholders to support IT internal control efforts, including audits/assessments, remediation, and other ad-hoc efforts.

Day-to-day tasks include some or all of the following:

  • Managing and performing rigorous audits/assessments of IT controls using industry-standard guidance and leading practices

  • Managing and performing walkthrough interviews and maintaining communication with a variety of client stakeholders, including system personnel such as system and database administrators

  • Requesting, obtaining, reviewing, and analyzing a variety of artifacts to assist in executing IT controls testing such as security plans, SOPs, system screenshots, and system configuration settings.

  • Evaluating the design and operating effectiveness of IT controls using provided artifacts, industry-standard guidance, leading practices, and professional judgment.

  • Professionally documenting the results of IT controls test work in a consistent and high-quality manner that would allow a reviewer to repeat the test and reach the same conclusion.

  • Summarizing and communicating IT controls assessment results to a variety of client stakeholders, including senior leadership personnel

  • Planning, executing, and managing day-to-day activities of IT controls assessments individually and for the team.

  • Working with client personnel to understand and analyze known IT control weaknesses, identify root causes, and develop detailed, robust remediation plans.

  • Providing subject matter expertise to client personnel on all matters relating to IT controls and responding to ad-hoc IT controls requests from client personnel

  • Developing documents to support internal control assessment planning decisions and control identification.

  • Supporting the development of corrective action plans to resolve material weaknesses, significant deficiencies, and control deficiencies.

  • Reviewing financial system modernization production environment functionality and application controls to provide input regarding audit readiness.

  • Assessing incremental financial system modernization efforts as well as in-production and in-development environments with regards to audit readiness and future risks

  • Preparing presentations, briefing materials, standard operating procedures, frequently asked questions, guides, and white papers that effectively support organizational efforts to promote awareness and understanding of OMB A-123 and internal controls.

What You Will Need:

  • US Citizenship and must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY are preferred.

  • Bachelor's Degree

  • SIX (6) or more years' experience in IT controls, audit, assessment, and/or remediation.


What Would Be Nice To Have:

  • Master's Degree

  • Certified Information Systems Auditor (CISA) certification

  • Demonstrates knowledge and experience in IT risk and controls through IT audits, IT control assessments, and IT security reviews.

  • Demonstrates a working knowledge of IT audit, the FISCAM, and other relevant federal information assurance laws, regulations, and guidance.

  • Experience supporting an internal control program.

  • Experience managing and performing IT audits, OMB Circular A-123 or similar internal control assessments, and/or remediating and implementing IT controls is preferable.

  • Experience testing or remediating some or all of the following IT controls topic areas is preferable:

    • Access and account management, including authorization, provisioning, recertification, and separation.

    • Segregation of duties, including identifying and defining segregation of duties risks and conflicts, preventive and detective segregation of duties controls, and understanding the difference between segregation of duties and least privilege

    • Technical account management controls, such as password length, complexity, and expiration

    • Audit logging and monitoring, including generation of audit logs, use of audit log aggregation and analysis tools, and audit log monitoring and review.

    • Configuration management, including configuration baseline concepts, baseline deviations, baseline maintenance, monitoring for ongoing compliance with a baseline, and industry-accepted baselines such as DISA STIGs and CIS benchmarks.

    • Change management, including authorization, development, testing, and deployment of changes.

    • Contingency planning, including backups, testing of backups, and alternate sites

#LI-DNI


What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:

  • Medical, Rx, Dental & Vision Insurance

  • Personal and Family Sick Time & Company Paid Holidays

  • Position may be eligible for a discretionary variable incentive bonus

  • Parental Leave and Adoption Assistance

  • 401(k) Retirement Plan

  • Basic Life & Supplemental Life

  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts

  • Short-Term & Long-Term Disability

  • Student Loan PayDown

  • Tuition Reimbursement, Personal Development & Learning Opportunities

  • Skills Development & Certifications

  • Employee Referral Program

  • Corporate Sponsored Events & Community Outreach

  • Emergency Back-Up Childcare Program

  • Mobility Stipend

About Guidehouse

Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.


What Guidehouse employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom