1

It Risk Jobs in Virginia (NOW HIRING)

IT Risk Manager #W0115

Richmond, VA · On-site

$121K - $130K/yr

IT Risk Manager #W0115 Apply now Job no: 5109791 Work type: Full-Time (Salaried) Location: Richmond (City), Virginia Categories: Information Technology Title: IT Risk Manager #W0115 State Role Title:

A financial services organization in Virginia is seeking an IT Risk & Controls Analyst to join their team in Vienna. About the Opportunity: * Schedule: Monday to Friday * Hours: Standard business

IT Advisory Manager

Mclean, VA · On-site

$125 - $150/hr

**Job Family:**IT Risk & Controls Consulting**Travel Required:**Up to 10%**Clearance Required:**Active Top Secret SCI with Polygraph**What You Will Do:**The IT Advisory Manager will lead stakeholder ...

IT Advisory Manager

Chantilly, VA · On-site

$97K - $119K/yr

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

IT Advisory Manager

Chantilly, VA · On-site

$97K - $119K/yr

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

IT Advisory Manager

Mclean, VA · On-site

$96K - $117K/yr

Job Family: IT Risk & Controls Consulting Travel Required: Up to 10% Clearance Required: Active Top Secret SCI with Polygraph What You Will Do: The IT Advisory Manager will lead stakeholder ...

Previous experience in IT audit, operational risk management, regulatory compliance, or a Big Four consulting * Relevant professional certications such as CISA, CISSP, CISM, CPA, CIA Security+, or ...

IT Audit Senior

Alexandria, VA · On-site

$100K - $132K/yr

IT Audit Senior Are you ready to take the next step in your IT audit career? Join Castro amp ... Identify and Communicate Risk : Analyze IT environments, pinpoint control gaps, and clearly present ...

LoD2: Technology Risk Specialist

Richmond, VA · On-site

$97K/yr

Specific activities may change from time to time. 1. Provides independent risk oversight (i.e ... Expertise in hosting platforms (on-premise and cloud, open systems, mainframe), IT operations, and ...

Identify and quantify IT risk factors for EHR application security and related infrastructure. * Working knowledge and experience with Keystone Edge, Microsoft OS, MS Office, DocuSign, Panda. * Apply ...

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...

Principal Risk Specialist

Richmond, VA · On-site

$97K/yr

At least 3 years of Information Systems Risk Management, IT Audit, or IT Compliance Experience Preferred Qualifications: * 4+ years of Information Systems Risk Management, IT Audit, or IT Compliance ...

Principal Risk Specialist

Mclean, VA · On-site

$125 - $150/hr

At least 3 years of Information Systems Risk Management, IT Audit, or IT Compliance Experience Preferred Qualifications * 4+ years of Information Systems Risk Management, IT Audit, or IT Compliance ...

At least 3 years of Information Systems Risk Management, IT Audit, or IT Compliance Experience Preferred Qualifications: * 4+ years of Information Systems Risk Management, IT Audit, or IT Compliance ...

At least 3 years of Information Systems Risk Management, IT Audit, or IT Compliance Experience Preferred Qualifications: * 4+ years of Information Systems Risk Management, IT Audit, or IT Compliance ...

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...

next page

Showing results 1-20

It Risk information

See Virginia salary details

$14

$30

$73

How much do it risk jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for it risk in Virginia is $30.08, according to ZipRecruiter salary data. Most workers in this role earn between $19.33 and $38.37 per hour, depending on experience, location, and employer.

What is IT risk?

IT risk refers to the potential for losses or negative impacts to an organization resulting from the use of information technology. This includes threats such as data breaches, cyberattacks, system failures, and non-compliance with regulations. IT risk management involves identifying, assessing, and mitigating these risks to protect an organization’s information assets and ensure business continuity.

What are the key skills and qualifications needed to thrive as an IT risk professional, and why are they important?

To thrive as an IT Risk professional, you need a strong understanding of information security principles, risk management frameworks, and relevant regulations, typically supported by a degree in information technology or cybersecurity. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) systems, and certifications such as CISM or CISSP is highly valued. Analytical thinking, attention to detail, and effective communication are vital soft skills for identifying vulnerabilities and collaborating with stakeholders. These competencies are crucial for proactively managing threats and ensuring the organization's information assets remain secure and compliant.

What are some common challenges faced by IT risk professionals when working with cross-functional teams?

IT Risk professionals often collaborate with various departments such as IT, compliance, finance, and operations. A common challenge is effectively communicating technical risks in terms that non-technical stakeholders can understand, ensuring alignment on priorities and mitigation strategies. Navigating differing risk tolerances and balancing business needs with security requirements can also present difficulties. Building strong relationships and fostering ongoing dialogue are key to overcoming these challenges and ensuring successful risk management across the organization.

What is the difference between It Risk vs Cybersecurity Analyst?

AspectIt RiskCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentRisk management teams, compliance departmentsSecurity operations centers, IT departments
Employer & Industry UsageFinancial, healthcare, and large enterprisesTech firms, finance, government agencies

It Risk professionals focus on identifying, assessing, and mitigating risks related to IT systems and compliance. Cybersecurity Analysts primarily monitor and respond to security threats and incidents. While both roles require similar certifications and work in overlapping environments, It Risk emphasizes risk management strategies, whereas Cybersecurity Analysts concentrate on security operations and threat response.

Do IT risk analysts make good money?

IT risk analysts typically earn competitive salaries that vary by experience, location, and industry. Entry-level positions may start around $60,000 annually, while experienced analysts can earn over $100,000, especially with certifications like CISSP or CISA. The role often involves working with cybersecurity tools and risk assessment frameworks.

Is risk analyst an IT job?

A risk analyst in the IT field evaluates technology-related risks, such as cybersecurity threats and system vulnerabilities, often using data analysis tools and risk management frameworks. The role typically requires knowledge of IT systems, security protocols, and relevant certifications like CISSP or CRISC.

What are the most commonly searched types of It Risk jobs in Virginia?

The most popular types of It Risk jobs in Virginia are:

What cities in Virginia are hiring for It Risk jobs?

Cities in Virginia with the most It Risk job openings:

Infographic showing various It Risk job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 10% Part Time, and 3% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $62,558 per year, or $30.1 per hour.

IT Risk Manager #W0115

Richmond, VA • On-site

State of Virginia
Executive Offices and Legislative Bodies • 10K+ employees

$121K - $130K/yr

Full-time

Medical, Life, Retirement, PTO

Posted 12 days ago


State Of Virginia rating

8.0

Company rating: 8.0 out of 10

Based on 33 frontline employees who took The Breakroom Quiz

11th of 50 rated states


Job description

IT Risk Manager #W0115

Apply now Job no: 5109791
Work type: Full-Time (Salaried)
Location: Richmond (City), Virginia
Categories: Information Technology

Title: IT Risk Manager #W0115

State Role Title: Info Technology Specialist III

Hiring Range: $121,000 - $130,000 per year (salary commensurate with experience)

Pay Band: 6

Agency: Department of Social Services

Location: DSS HOME OFFICE

Agency Website: https://www.dss.virginia.gov/

Recruitment Type: General Public - G

Job Duties

At the Virginia Department of Social Services, we put people at the center of everything we do. We believe that every Virginian can live a life of dignity and that all voices, ideas and experiences contribute greatly to our pursuit of excellence. Inspired by continuous improvement, we commit ourselves to listening, learning and cultivating environments of trust, respect and positive engagement. Together, we are mission-driven, eager to achieve, and passionate about bringing the best of who we are to those we serve.
We design and deliver high-quality human services that help Virginians achieve safety, independence and overall well-being. We are a $2 billion agency - one of the largest in the Commonwealth of Virginia - partnering with 120 local departments of social services and 31 community action agencies, along with faith-based and non-profit organizations, to promote the well-being of children, adults, and families statewide. We proudly serve alongside 1,650 (state) and 12,200 (local) human services professionals throughout the Social Services System, who ensure that thousands of Virginia's most vulnerable citizens have easy access to the services and benefits available to them.
The IT Risk Manager is responsible for implementing the VDSS Risk Management Framework and the VITA Information Technology Risk Standard SEC520. The position provides VDSS Information Security and Risk Management leadership, strategic direction and consultation on information security risk and compliance. The IT Risk Manager leads and facilitates Data Classification with Business Owners, System Owners and the Business Continuity Manager to determine application sensitivity and performs IT Risk Assessments for the all sensitive DSS applications, coordinating with Business Owners, System Owners, and System Administrators to develop a risk-based assessment in accordance with VITA SEC520. The IT Risk Manager coordinates quarterly Risk Treatment Plans with System Owners and VITA Commonwealth Security and Risk Management. Further, the IT Risk Manager is responsible for conducting Control Assessments and System Security Plans for each VDSS application. The IT Risk Manager serves as an agency point of contact for internal and external entities regarding IT Risk Management for VDSS. The position provides VDSS Information Security and Risk Management leadership, strategic direction and consultation on information security risk and compliance and oversees Information Technology and Risk Management staff, including the IT Risk Analysts.

Minimum Qualifications

Comprehensive, advanced, demonstrated, and supervisory experience in Information Systems, business, or related IT risk management fields.
Comprehensive, advanced, demonstrated, and supervisory experience in applying complex federal and state statutes, regulations, policies and procedures governing the area of compliance.
Advanced experience in evaluating and testing security controls within computer applications
Advanced experience in reviewing and/or writing reports, policies and procedures.
Comprehensive experience in working on and/or leading projects and teams.
Comprehensive and advanced experience performing IT Risk Assessments
Experience in building and implementing software tools
Experience using or implementing AI-driven governance, risk, and compliance (GRC) tools, or automated risk analytics platforms.
KSA's and/or Competencies required to successfully perform the work:
1. Technical and Functional Expertise - Possess a thorough understanding of over SEC530 and other NIST related information security standard security controls across Agency, State, and Federal security frameworks. Experience with developing and updating Risk Assessments, Data Classifications, System Security Plans, Control Assessments, and coordinating Authorities to Operate. Experience or knowledge of system design principles. Ability to gather data from automated and manual sources and through interviews with staff to make risk determinations. Ability to understand state and federal security controls (NIST 800-53A, IRS 1075, CMS MARS-E, SSA, etc.) and determine compliance with those controls.
2. Understanding Business - Understand the overlapping uses of Information Systems to support VDSS and to provide assurance on core business processes in risk management and governance.
3. Results Focused - Issue Data Classifications, Security Impact Analyses, Risk Assessments, System Security Plans, Internal Controls Weakness, Control Assessment evaluations for applications.
4. Interpersonal Communication - Demonstrated ability to communicate effectively both orally and in writing with diverse groups of organizations and people. Ability to translate complex technical risks into clear, actionable information for leadership.
5. Technical and Functional Expertise - High degree of independent judgement. Become proficient in other members security office duties for contingency operations
6. Personal Effectiveness - Willingness to be very flexible, ability to maintain the highest professional standards, and competence to be accurate, thorough, and productive with all work.
7. Project Organization - Experience in planning and organization projects through Jira.
8. Tool adoption - Experience utilizing AI-driven risk management tools to provide solutions to automate risk detection, analyze trends, perform predictive risk modeling, and improve the accuracy and speed of assessments.

Additional Considerations

Current Security Credentials like CISA, CISM, CISSP, CRISC, etc.
Experience in state government related to IT risk management, technology governance, audit, or cybersecurity.

Special Instructions

You will be provided a confirmation of receipt when your application and/or resume is submitted successfully. Please refer to "Your Application" in your account to check the status of your application for this position.

Selected candidate(s) must successfully pass a fingerprint-based criminal history background check. A record of criminal history does not automatically bar an applicant from consideration. Employment verification will be conducted to include current/previous supervisory employment reference checks.
VDSS will record information from each new employee's Form I-9 (Employment Eligibility Verification) into the Federal E-Verify system to confirm identity and work authorization.
To be considered for this position, you must submit a Commonwealth of Virginia application or resume through the on-line "Virginia Jobs" (PageUp) employment site no later than 11:55 p.m. on the closing date listed. Each application is reviewed for documentation that shows the applicant meets the minimum and additional considerations as stated in the job announcement. The decision to interview an applicant is based on the information provided. Multiple positions may be filled from this recruitment within 90 days of the closing date.
In addition to a rewarding work experience, VDSS offers excellent health and life insurance benefits, pre-tax spending accounts, state funded Short and Long Term Disability, paid holidays, vacation, tuition assistance, free wellness programs, and a state retirement plan with options for tax-deferred retirement savings including employer matching - Employee Benefits.
The Virginia Department of Social Services (VDSS) is an Equal Opportunity Employer and encourages diversity within its workforce.
VDSS does not provide sponsorship.
This position may be eligible for telework opportunities; availability, hours, and duration will be in accordance with the Commonwealth's Teleworking policy.
VDSS is an official certified state agency that values the service and experience of our Veterans. As such, Veterans are encouraged to apply and receive preference in the hiring process. AmeriCorps, Peace Corps and other national service alumni also are encouraged to apply. Reasonable accommodations are available to applicants, if requested, during the application and/or interview process.
If you have been affected by Policy 1.30 Layoff as a state employee and possess a valid Interagency Placement Screening Form (Yellow Form) or a Preferential Hiring Card (Blue Card), you must submit this document through the "Virginia Jobs" (PageUp) employment site when you apply.

Contact Information

Name: VDSS - Division of Human Resources

Phone: dssrecruitment@dss.virginia.gov

Email: dssrecruitment@dss.virginia.gov

In support of the Commonwealth's commitment to inclusion, we are encouraging individuals with disabilities to apply through the Commonwealth Alternative Hiring Process. To be considered for this opportunity, applicants will need to provide their AHP Letter (formerly COD) provided by the Department for Aging & Rehabilitative Services (DARS), or the Department for the Blind & Vision Impaired (DBVI). Service-Connected Veterans are encouraged to answer Veteran status questions and submit their disability documentation, if applicable, to DARS/DBVI to get their AHP Letter. Requesting an AHP Letter can be found at AHP Letter or by calling DARS at 800-552-5019.

Note: Applicants who received a Certificate of Disability from DARS or DBVI dated between April 1, 2022- February 29, 2024, can still use that COD as applicable documentation for the Alternative Hiring Process.

Advertised: 27 Aug 2026 Eastern Daylight Time
Applications close:

Back to search results Apply now Refer a friend

Whatsapp Facebook LinkedIn Email App

What State Of Virginia employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom