... operations. * Develop guidance, templates, other tools, and advice to the program offices to ... Provide risk management and information security continuous monitoring program implementation ...
... operations. * Develop guidance, templates, other tools, and advice to the program offices to ... Provide risk management and information security continuous monitoring program implementation ...
Risk Manager
Riverdale, MD · On-site
Overview The Risk Manager is responsible for leading the project's risk management program and ... Identify operational, contractual, insurance, and safety-related risks affecting the project.
Risk Manager
Riverdale, MD · On-site
Overview The Risk Manager is responsible for leading the project's risk management program and ... Identify operational, contractual, insurance, and safety-related risks affecting the project.
Director, Risk Management
Mclean, VA · On-site
Certified Business Continuity Professional (CBCP/MBCP)Certified in Risk and Information Systems Control (CRISC)Certified Information Security Manager (CISM)Other operational risk or resilience ...
Director, Risk Management
Mclean, VA · On-site
Certified Business Continuity Professional (CBCP/MBCP)Certified in Risk and Information Systems Control (CRISC)Certified Information Security Manager (CISM)Other operational risk or resilience ...
Partner effectively with specialized teams across the enterprise-including Operational Risk Management, Enterprise Risk Management, Compliance, Business Risk Offices, Information Technology, Basel ...
Partner effectively with specialized teams across the enterprise-including Operational Risk Management, Enterprise Risk Management, Compliance, Business Risk Offices, Information Technology, Basel ...
Certified Business Continuity Professional (CBCP/MBCP)Certified in Risk and Information Systems Control (CRISC)Certified Information Security Manager (CISM)Other operational risk or resilience ...
Certified Business Continuity Professional (CBCP/MBCP)Certified in Risk and Information Systems Control (CRISC)Certified Information Security Manager (CISM)Other operational risk or resilience ...
Lead Risk Specialist
Mclean, VA · On-site
$99K/yr
Audit-Ready Operations: Foster a culture of proactive risk awareness, helping manage horizontal routines to ensure the business is continuously audit-ready. * Cross-Functional Collaboration: Partner ...
Lead Risk Specialist
Mclean, VA · On-site
$99K/yr
Audit-Ready Operations: Foster a culture of proactive risk awareness, helping manage horizontal routines to ensure the business is continuously audit-ready. * Cross-Functional Collaboration: Partner ...
Lead Risk Specialist
Mclean, VA · On-site
$99K/yr
Audit-Ready Operations: Foster a culture of proactive risk awareness, helping manage horizontal routines to ensure the business is continuously audit-ready. * Cross-Functional Collaboration: Partner ...
Lead Risk Specialist
Mclean, VA · On-site
$99K/yr
Audit-Ready Operations: Foster a culture of proactive risk awareness, helping manage horizontal routines to ensure the business is continuously audit-ready. * Cross-Functional Collaboration: Partner ...
Manager, Data Risk Governance - Global Payment Network As a Manager on the Global Payment Network (GPN) Data Governance team, you will work with a team of professionals dedicated to ensuring that GPN ...
Manager, Data Risk Governance - Global Payment Network As a Manager on the Global Payment Network (GPN) Data Governance team, you will work with a team of professionals dedicated to ensuring that GPN ...
Technical Risk Manager
Washington, DC · Remote
Company Description ProSidian is a Management and Operations Consulting Services firm that delivers ... Risk, Compliance & Independent Certification Support [DOE0023023] for Program Support on a Exempt ...
Quick apply
Technical Risk Manager
Washington, DC · Remote
Company Description ProSidian is a Management and Operations Consulting Services firm that delivers ... Risk, Compliance & Independent Certification Support [DOE0023023] for Program Support on a Exempt ...
Senior Associate, Risk Manager
Mclean, VA · On-site
Partner effectively with specialized teams across the enterprise-including Operational Risk Management, Enterprise Risk Management, Compliance, Business Risk Offices, Information Technology, Internal ...
Senior Associate, Risk Manager
Mclean, VA · On-site
Partner effectively with specialized teams across the enterprise-including Operational Risk Management, Enterprise Risk Management, Compliance, Business Risk Offices, Information Technology, Internal ...
Collaborate effectively across multiple organizations such as Operational Risk Management, Enterprise Risk Management, Compliance, Business Risk Offices, Operational Risk Sub-Steward organizations ...
Collaborate effectively across multiple organizations such as Operational Risk Management, Enterprise Risk Management, Compliance, Business Risk Offices, Operational Risk Sub-Steward organizations ...
GBU Risk Manager
Reston, VA · On-site
Our services span from initial planning and investment, through start-up and operations. Core to ... The GBU Project Risk Manager is responsible for the support and guidance to Project Risk Management ...
GBU Risk Manager
Reston, VA · On-site
Our services span from initial planning and investment, through start-up and operations. Core to ... The GBU Project Risk Manager is responsible for the support and guidance to Project Risk Management ...
GBU Risk Manager
Reston, VA · On-site
Our services span from initial planning and investment, through start-up and operations. Core to ... The GBU Project Risk Manager is responsible for the support and guidance to Project Risk Management ...
GBU Risk Manager
Reston, VA · On-site
Our services span from initial planning and investment, through start-up and operations. Core to ... The GBU Project Risk Manager is responsible for the support and guidance to Project Risk Management ...
Learn how to identify, evaluate, and prioritize business, operational, regulatory, and technology ... Credit Risk, Liquidity Risk, Market Risk, Capital Management/Stress Testing * Knowledge of ...
Learn how to identify, evaluate, and prioritize business, operational, regulatory, and technology ... Credit Risk, Liquidity Risk, Market Risk, Capital Management/Stress Testing * Knowledge of ...
... Operations, and Finance. Risk Policy Development & Governance * Lead drafting and iteration of risk ... management policies and standards supporting the non-prime installment product, including: * Credit ...
... Operations, and Finance. Risk Policy Development & Governance * Lead drafting and iteration of risk ... management policies and standards supporting the non-prime installment product, including: * Credit ...
Partner effectively with specialized teams across the enterprise-including Operational Risk Management, Enterprise Risk Management, Compliance, Business Risk Offices, Information Technology, Basel ...
Partner effectively with specialized teams across the enterprise-including Operational Risk Management, Enterprise Risk Management, Compliance, Business Risk Offices, Information Technology, Basel ...
Risk Manager, Senior
Arlington, VA · On-site
The Risk Manager identifies, assesses, and mitigates potential threats to an organization's assets, operations, finances, and reputation by developing and implementing risk management strategies ...
Risk Manager, Senior
Arlington, VA · On-site
The Risk Manager identifies, assesses, and mitigates potential threats to an organization's assets, operations, finances, and reputation by developing and implementing risk management strategies ...
... Operations, and Finance. Risk Policy Development & Governance * Lead drafting and iteration of risk ... management policies and standards supporting the non-prime installment product, including: * Credit ...
Quick apply
... Operations, and Finance. Risk Policy Development & Governance * Lead drafting and iteration of risk ... management policies and standards supporting the non-prime installment product, including: * Credit ...
Director, Sourcing and Operational Risk Management
Washington, DC · On-site
$175K - $210K/yr
Director, Sourcing and Operational Risk Management Location: Charlotte, NC, Dallas, TX, Knoxville ... A Certified Purchasing Manager (CPM) or Certified Professional in Supply Management (CPSM) would be ...
Director, Sourcing and Operational Risk Management
Washington, DC · On-site
$175K - $210K/yr
Director, Sourcing and Operational Risk Management Location: Charlotte, NC, Dallas, TX, Knoxville ... A Certified Purchasing Manager (CPM) or Certified Professional in Supply Management (CPSM) would be ...
Senior Associate, Data Scientist - Operational Risk Management Data is at the center of everything we do. As a startup, we disrupted the credit card industry by individually personalizing every ...
Senior Associate, Data Scientist - Operational Risk Management Data is at the center of everything we do. As a startup, we disrupted the credit card industry by individually personalizing every ...
Operational Risk Manager information
See Alexandria, VA salary details
$50.3K - $68.8K
5% of jobs
$80K is the 25th percentile. Wages below this are outliers.
$68.8K - $87.3K
33% of jobs
The median wage is $103.6K / yr.
$87.3K - $105.8K
14% of jobs
$105.8K - $124.3K
14% of jobs
$124.3K - $142.7K
5% of jobs
$155.8K is the 75th percentile. Wages above this are outliers.
$142.7K - $161.2K
6% of jobs
$161.2K - $179.7K
7% of jobs
$179.7K - $198.2K
5% of jobs
$198.2K - $216.7K
2% of jobs
$216.7K - $235.2K
8% of jobs
$235.2K - $253.7K
0% of jobs
$50.3K
$129.2K
$253.7K
How much do operational risk manager jobs pay per year?
What does an operational risk manager do?
An operational risk manager works to identify and limit the risk associated with a company’s operations. As an operational risk manager, your responsibilities involve assessing business operations, identifying issues, and creating reports on your findings. You then help develop policies and implement changes to lessen operational risks. Other duties include continually monitoring the business to find potential new threats and ensuring company compliance with laws and regulations.
What are some common challenges faced by operational risk managers in maintaining effective risk controls across different departments?
What are the key skills and qualifications needed to thrive as an operational risk manager, and why are they important?
What is the difference between Operational Risk Manager vs Risk Analyst?
| Aspect | Operational Risk Manager | Risk Analyst |
|---|---|---|
| Certifications | CFA, FRM, or similar | CFA, FRM, or similar |
| Work Environment | Financial institutions, banks, insurance companies | Financial firms, consulting, corporate risk teams |
| Responsibilities | Identify, assess, and mitigate operational risks; develop risk frameworks | Analyze risk data, support risk assessments, prepare reports |
The Operational Risk Manager focuses on managing and mitigating operational risks within organizations, often holding certifications like CFA or FRM. In contrast, Risk Analysts primarily analyze risk data and support risk management processes. Both roles are vital in financial sectors and share similar credentials, but the Operational Risk Manager has a broader responsibility for risk mitigation strategies.

Job description
CVP is seeking an Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program. The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency’s CIO and CISO in cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security reporting; and other information security-related tasks.
- Identify, evaluate, and develop strategies for handling risks to reduce information security and privacy risk across the agency.
- Provide recommendations, guidance, planning, and implementation support for agency risk management activities and tools, and provide support as needed to enhance the agency’s Information Security Program related to governance, optimizations, automation, and supporting tools.
- Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for Information Systems and Organizations and SP 800-39, Managing Information Security Risk (as revised).
- Conducting an enterprise risk assessment and developing an agency Information Security Risk Assessment Report that addresses all findings from the assessment
- Developing an agency Privacy and Security Roadmap that recommends privacy and information security capabilities based on risks identified in the agency’s Information Security Risk Assessment Report
- Developing an agency Information Security Risk Management Plan that addresses how the agency will implement and perform risk management activities regarding risk tolerance, risk assessment, risk response, risk monitoring, and risk capabilities
- Providing risk management guidance to the agency offices for A&A activities as required, ensuring continuous risk monitoring of information security control implementation effectiveness and required information security compliance requirements
- Support the Information Security and Assurance Office (ISAO) in implementing and overseeing the organization’s information security risk management and security assessment and authorization (A&A) activities.
- Advise the agency on how best to tailor the revised A&A process to handle non-traditional technologies including, but not limited to, cloud, mobile, and Internet of Things.
- Provide the agency recommendations on how it can continuously monitor and assess the security posture of agency information systems over time and alert agency decision makers when an information system presents an increased risk or eminent threat to agency data and/or operations.
- Develop guidance, templates, other tools, and advice to the program offices to support their risk management and ATO activities.
- Provide risk management and information security continuous monitoring program implementation recommendations to program offices
- Track and review Plans of Actions and Milestones (POA&Ms) agency-wide to identify areas of risk as a result of unimplemented POA&Ms, a buildup of risk-based decisions, or other cross-cutting issues observed as a result of its risk management support.
- Track the A&A status for all divisions and programs that have information systems to validate they meet the requirements to protect the agency’s data and operations.
- Develop the required artifacts to complete security accreditation packages for OCIO information systems and perform any required assessments, as requested. The Contractor shall provide oversight and advisory support to agency program office personnel for completion of information system A&A packages, as requested.
- Follow NIST Federal Information Processing Standards (FIPS) and Special Publications (SPs) to include, but not limited to, FIPS 199 and 200, SP 800-39, SP 800-37, SP 800-137, SP 800-60, SP 800-53, SP 800-53A, SP 800-34, SP 800-30, and SP 800-18. The Contractor shall comply with all agency IT security and Privacy policies and standards including, and the agency Privacy Impact Assessment (PIA) requirements and associated templates.
- Minimum of six years’ experience in cybersecurity. 10+ years’ experience is preferred.
- Minimum of six years' experience leading and delivering in FISMA-based and FedRAMP Assessment and Authorization (A&A) programs for comparably sized federal agencies and programs. Seven plus years’ experience is preferred.
- Shall have at least one of the following industry-recognized certifications:
- Certified Information System Security Professional (CISSP)
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- Familiarity with Information Technology Infrastructure Library (ITIL) Foundation Compliance (GRC) tool, continuous monitoring, and vulnerability management tools or services. Note: NIH currently uses CSAM.
- Demonstrated experience managing cybersecurity teams including personnel, workload, priorities, scheduling, and risks.
- Proven experience bringing innovative approaches to help reduce the FISMA workload and time to authorization/reauthorization through such methods as boundary consolidation, common control identification and re-use, automation, assessment readiness reviews, and digital transformation.
Desired Skills
- PMP Certification
- CISSP Certification
- Experience with Security Assessment Tools (Tenable Nessus, DBProtect, Wireshark, WebInspect)
- NIH/HHS experience
Location
- Rockville, MD (Hybrid)
Salary Band: $155-165k (Depending on experience)
About CVP
CVP is an award-winning healthcare and next-gen technology and consulting services firm solving critical problems for healthcare, national security, and public sector clients. We help organizations achieve lasting transformation.
CVP is an Equal Opportunity Employer dedicated to actively recruiting individuals and providing advancement opportunities based on merit and legitimate job qualifications. We ensure that all associates receive equal opportunities based on their personal qualifications and job requirements. CVP strictly prohibits any form of discrimination or harassment.
At CVP, we cultivate a work environment that encourages fairness, teamwork, and respect among all associated. We are committed to maintaining a workplace where everyone can grow both personally and professionally.
About Customer Value Partners
Sourced by ZipRecruiter
Company size
51 - 200 Employees
Headquarters location
Fairfax, VA, US
Year founded
2002