... control activities. * Information Security and Technology Risk Management * Conduct or facilitate risk assessments for applications, infrastructure, cloud services, Firm-critical legal-industry ...
... control activities. * Information Security and Technology Risk Management * Conduct or facilitate risk assessments for applications, infrastructure, cloud services, Firm-critical legal-industry ...
Senior Risk Management/Loss Control Consultant (Remote in Broward County / Palm Beach area)
Tampa, FL · Remote
Due to a retirement, we are recruiting for a Senior Risk Management/Loss Control Consultant to join our team. This is a field-based position that will sit remotely within the Broward County to Palm ...
Senior Risk Management/Loss Control Consultant (Remote in Broward County / Palm Beach area)
Tampa, FL · Remote
Due to a retirement, we are recruiting for a Senior Risk Management/Loss Control Consultant to join our team. This is a field-based position that will sit remotely within the Broward County to Palm ...
Senior Risk Management/Loss Control Consultant (Remote in Broward County / Palm Beach area)
Tampa, FL · On-site +1
Due to a retirement, we are recruiting for a Senior Risk Management/Loss Control Consultant to join our team. This is a field-based position that will sit remotely within the Broward County to Palm ...
Senior Risk Management/Loss Control Consultant (Remote in Broward County / Palm Beach area)
Tampa, FL · On-site +1
Due to a retirement, we are recruiting for a Senior Risk Management/Loss Control Consultant to join our team. This is a field-based position that will sit remotely within the Broward County to Palm ...
Senior Risk Management/Loss Control Consultant (Remote in Broward County / Palm Beach area)
Tampa, FL · Remote
Due to a retirement, we are recruiting for a Senior Risk Management/Loss Control Consultant to join our team. This is a field-based position that will sit remotely within the Broward County to Palm ...
Senior Risk Management/Loss Control Consultant (Remote in Broward County / Palm Beach area)
Tampa, FL · Remote
Due to a retirement, we are recruiting for a Senior Risk Management/Loss Control Consultant to join our team. This is a field-based position that will sit remotely within the Broward County to Palm ...
Proven ability to integrate security, risk, and control requirements into Agile, DevOps, platform operations, and service management practices. * Experience with asset governance, technology ...
Proven ability to integrate security, risk, and control requirements into Agile, DevOps, platform operations, and service management practices. * Experience with asset governance, technology ...
ServiceNow Platform Architect - Manager
Tampa, FL · On-site
$67.25 - $84.75/hr
... risk & control framework, content definition & standardization, training and end user enablement ... Defining CMDB and Common Service Data Model (CSDM) architecture strategies that support service ...
ServiceNow Platform Architect - Manager
Tampa, FL · On-site
$67.25 - $84.75/hr
... risk & control framework, content definition & standardization, training and end user enablement ... Defining CMDB and Common Service Data Model (CSDM) architecture strategies that support service ...
... risk/control environment and recruit and enhance quality individuals to be utilized in the various disciplines and fields of Brown and Brown. How You Will Contribute: * Manage the day-to-day ...
... risk/control environment and recruit and enhance quality individuals to be utilized in the various disciplines and fields of Brown and Brown. How You Will Contribute: * Manage the day-to-day ...
... risk/control environment and recruit and enhance quality individuals to be utilized in the various disciplines and fields of Brown and Brown. How You Will Contribute: * Manage the day-to-day ...
... risk/control environment and recruit and enhance quality individuals to be utilized in the various disciplines and fields of Brown and Brown. How You Will Contribute: * Manage the day-to-day ...
Model Validation 2nd LOD Lead Analyst
Tampa, FL · On-site
$153K - $153K/yr
Support the Model Risk Management Framework, including policy, processes, and procedures the firm uses to identify, measure, monitor, report, and control model risk across the firm. Develop and ...
Model Validation 2nd LOD Lead Analyst
Tampa, FL · On-site
$153K - $153K/yr
Support the Model Risk Management Framework, including policy, processes, and procedures the firm uses to identify, measure, monitor, report, and control model risk across the firm. Develop and ...
Model Validation 2nd LOD Lead Analyst
Tampa, FL · Hybrid
$153K - $153K/yr
Support the Model Risk Management Framework, including policy, processes, and procedures the firm uses to identify, measure, monitor, report, and control model risk across the firm Develop and ...
Model Validation 2nd LOD Lead Analyst
Tampa, FL · Hybrid
$153K - $153K/yr
Support the Model Risk Management Framework, including policy, processes, and procedures the firm uses to identify, measure, monitor, report, and control model risk across the firm Develop and ...
As a Lead Technical Program Manager in Corporate Investment Bank, you will drive the successful ... Support regulatory, operational, and control considerations by partnering with risk/control ...
As a Lead Technical Program Manager in Corporate Investment Bank, you will drive the successful ... Support regulatory, operational, and control considerations by partnering with risk/control ...
... control gaps, audit findings, vendor risk, and resilience needs, then connecting those priorities ... Forecast and manage the cyber and risk consulting pipeline, including opportunity sizing ...
... control gaps, audit findings, vendor risk, and resilience needs, then connecting those priorities ... Forecast and manage the cyber and risk consulting pipeline, including opportunity sizing ...
Markets Third Party Risk Senior. Analyst - C12
Tampa, FL · On-site
$87K - $130K/yr
Project management skills * Effective communication and presentation skills Responsibilities ... Work closely with business partners on findings resulting from control execution * Work with ...
Markets Third Party Risk Senior. Analyst - C12
Tampa, FL · On-site
$87K - $130K/yr
Project management skills * Effective communication and presentation skills Responsibilities ... Work closely with business partners on findings resulting from control execution * Work with ...
Markets Third Party Risk Senior. Analyst - C12
Tampa, FL · On-site
$87K - $130K/yr
... control environment and culture to minimize third party risk within the business. We are seeking a detail-oriented and proactive professional to join our Third Party Risk Management team as an ...
Markets Third Party Risk Senior. Analyst - C12
Tampa, FL · On-site
$87K - $130K/yr
... control environment and culture to minimize third party risk within the business. We are seeking a detail-oriented and proactive professional to join our Third Party Risk Management team as an ...
Risk Mitigation Specialist - Mid
Tampa, FL · On-site
$93K/yr
Serve as the primary security and risk advisor to leaders and managers of operational, technical ... Demonstrates in-depth knowledge and understanding of Foreign Ownership, Control, or Influence (FOCI ...
Risk Mitigation Specialist - Mid
Tampa, FL · On-site
$93K/yr
Serve as the primary security and risk advisor to leaders and managers of operational, technical ... Demonstrates in-depth knowledge and understanding of Foreign Ownership, Control, or Influence (FOCI ...
Risk Mitigation Specialist - Expert
Tampa, FL · On-site
$93K/yr
Serve as the primary security and risk advisor to leaders and managers of operational, technical ... Demonstrates in-depth knowledge and understanding of Foreign Ownership, Control, or Influence (FOCI ...
Risk Mitigation Specialist - Expert
Tampa, FL · On-site
$93K/yr
Serve as the primary security and risk advisor to leaders and managers of operational, technical ... Demonstrates in-depth knowledge and understanding of Foreign Ownership, Control, or Influence (FOCI ...
Risk Mitigation Specialist
Tampa, FL · On-site
$93K/yr
Serve as the primary security and risk advisor to leaders and managers of operational, technical ... Demonstrates in-depth knowledge and understanding of Foreign Ownership, Control, or Influence (FOCI ...
Risk Mitigation Specialist
Tampa, FL · On-site
$93K/yr
Serve as the primary security and risk advisor to leaders and managers of operational, technical ... Demonstrates in-depth knowledge and understanding of Foreign Ownership, Control, or Influence (FOCI ...
Serve as the primary security and risk advisor to leaders and managers of operational, technical ... Demonstrates in-depth knowledge and understanding of Foreign Ownership, Control, or Influence (FOCI ...
Serve as the primary security and risk advisor to leaders and managers of operational, technical ... Demonstrates in-depth knowledge and understanding of Foreign Ownership, Control, or Influence (FOCI ...
Cyber Security Governance, Risk, Compliance Manager - VP
Tampa, FL · Hybrid
$104K - $141K/yr
Assess control design, operating effectiveness, and sustainability in support of Information ... Lead discussions at all levels of the organization to incorporate and manage security risk elements ...
Cyber Security Governance, Risk, Compliance Manager - VP
Tampa, FL · Hybrid
$104K - $141K/yr
Assess control design, operating effectiveness, and sustainability in support of Information ... Lead discussions at all levels of the organization to incorporate and manage security risk elements ...
Enterprise Data & Platform Security Analyst
Lutz, FL · Hybrid
$60K - $80K/yr
Sensitive data exposure Insider risk Control breakdowns Coordinate remediation strategies and ... Ability to manage multiple priorities in a fast-paced environment. Experience mentoring junior ...
Enterprise Data & Platform Security Analyst
Lutz, FL · Hybrid
$60K - $80K/yr
Sensitive data exposure Insider risk Control breakdowns Coordinate remediation strategies and ... Ability to manage multiple priorities in a fast-paced environment. Experience mentoring junior ...
Risk Control Manager information
See Spring Hill, FL salary details
$28.96 - $32.52
3% of jobs
$32.52 - $36.08
3% of jobs
$39.45 is the 25th percentile. Wages below this are outliers.
$36.08 - $39.64
20% of jobs
$39.64 - $43.20
14% of jobs
$43.20 - $46.76
9% of jobs
The median wage is $47.35 / hr.
$46.76 - $50.32
6% of jobs
$50.32 - $53.88
5% of jobs
$53.88 - $57.44
0% of jobs
$57.44 - $61
0% of jobs
$63.77 is the 75th percentile. Wages above this are outliers.
$61 - $64.56
19% of jobs
$64.56 - $68.12
21% of jobs
$28
$51
$68
How much do risk control manager jobs pay per hour?
What does a Risk Control Manager do?
What are the key skills and qualifications needed to thrive as a Risk Control Manager?
How does a Risk Control Manager typically collaborate with other departments to identify and mitigate risks?
What is the difference between Risk Control Manager vs Risk Analyst?
| Aspect | Risk Control Manager | Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRM, ARM, or CPCU often preferred | Certifications such as FRM or CRM may be beneficial |
| Work Environment | Oversees risk management strategies, collaborates with departments | Analyzes data, assesses risks, prepares reports |
| Industry Usage | Common in insurance, finance, and corporate sectors | Widely used in finance, insurance, and consulting firms |
While both roles focus on risk, the Risk Control Manager develops and implements risk mitigation strategies, whereas the Risk Analyst primarily assesses and analyzes risks through data. The manager has a broader strategic role, often supervising teams, while the analyst concentrates on detailed risk evaluation.
Do risk control managers make good money?
What cities near Spring Hill, FL are hiring for Risk Control Manager jobs?
Cities near Spring Hill, FL with the most Risk Control Manager job openings:

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 8 days ago
Key responsibilities
Support the development, review, and maintenance of information security and technology risk policies, standards, procedures, and guidance documents.
Conduct or facilitate risk assessments for applications, infrastructure, cloud services, and key business processes, and maintain the risk register.
Perform third-party security due diligence, review assurance artifacts, and coordinate security questionnaires and evidence collection.
Holland & Knight rating
8.3
Based on 8 frontline employees who took The Breakroom Quiz
18th of 35 rated law firms
Job description
We are a Firm where people truly believe in what they do and strive to achieve the highest standards of performance and success.
This position is based in the Firm's global operations center in Tampa, FL.
General Description:
We are seeking an IT Enterprise Risk Analyst to join our team. The IT Risk Analyst helps manage the Firm's GRC and IT risk programs, focusing on information security for client data, attorney work, and privileged communications. Reporting to the IT Enterprise Risk Management Manager, the role maintains policies, assesses risks and controls, coordinates third-party reviews, drafts responses for client guidelines, prepares evidence for cyber insurance, and supports audits. Responsibilities align with ISO/IEC 27001/27002, NIST CSF, CIS Controls, SOC 2, HIPAA, GLBA, GDPR, and state privacy laws (e.g., CCPA/CPRA).
Key Responsibilities and Essential Job Functions:
- Policy, Standards and Governance
- Support the development, review, and maintenance of information security and technology risk policies, standards, procedures, and guidance documents.
- Maintain the policy lifecycle process, including stakeholder reviews, approvals, publication, periodic review schedules, and version control.
- Map policies/standards to ISO, NIST, CIS Controls, SOC 2, HIPAA, GLBA, U.S. state privacy laws, and EU requirements, and to applicable client Outside Counsel Guidelines and contractual security addenda; maintain crosswalks and control documentation to support audit readiness.
- Administer policy exception and risk acceptance of workflows, ensuring justification, compensating controls, approvals, and defined expiration/renewal dates.
- Contribute to awareness materials and operational guidance to promote consistent implementation of requirements.
- Help maintain controls supporting ethical walls / information barriers, matter-level access restrictions, and legal hold obligations, under the direction of the Senior Analyst and in partnership with the Office of the General Counsel, Conflicts, and Records & Information Governance.
- Maintain awareness of the Firm's professional responsibility obligations, including ABA Model Rules 1.1 (technology competence) and 1.6 (confidentiality of information), and apply that awareness to policy implementation and control activities.
- Information Security and Technology Risk Management
- Conduct or facilitate risk assessments for applications, infrastructure, cloud services, Firm-critical legal-industry platforms (document management, time and billing, conflicts and new business intake, eDiscovery, and matter management), and key business processes; document risk statements, likelihood/impact, and control effectiveness.
- Maintain and update the risk register, including inherent and residual ratings, treatment plans, owners, milestones, and status updates.
- Partner with control owners to identify remediation actions, track progress, and validate closure with appropriate evidence.
- Support ongoing risk monitoring through key risk indicators (KRIs) and control health metrics, including indicators relevant to the legal sector (e.g., business email compromise and wire-fraud schemes, ransomware targeting law firms, and client-confidential data exposure).
- Draft and contribute to risk reporting and summaries for governance forums under the direction of the IT Enterprise Risk Management Manager, including content packaged for Firm leadership and Firm Management Committee audiences.
- Support incident response activities by gathering control and risk evidence, contributing to post-incident lessons learned, and helping ensure resulting control improvements are tracked in the risk register.
- Vendor/Third Party Risk Management (TPRM)
- Perform third party security due diligence based on vendor criticality and risk tiering (including third-industry parties such as co-counsel and local counsel, eDiscovery and document review providers, expert witnesses, court reporters and translators, legal-technology SaaS vendors, and managed-service providers handling client matter data); coordinate security questionnaires and evidence collection.
- Review assurance artifacts such as SOC reports, ISO certificates, penetration test summaries, security whitepapers, and privacy/security attestations.
- Identify gaps, document findings, recommend remediation/compensating controls, and track vendor action plans to closure.
- Partner with Procurement/Legal to ensure contracts include appropriate security and privacy requirements (e.g., breach notification, subcontractor controls, right-to-assess, data processing terms, and data residency as applicable).
- Support periodic vendor reassessments and reassessments triggered by scope changes, incidents, or material updates.
- Draft initial responses to inbound client security questionnaires and Outside Counsel Guideline (OCG) inquiries for Senior Analyst review; help maintain a controlled answer library and partner with the engagement attorney and Loss Prevention on follow-ups.
- Audit, Assurance and Compliance (ISO / NIST / CIS / SOC 2 / HIPAA / GLBA / EU)
- Support internal and external audits by coordinating evidence collection, control walkthroughs, and timely responses to audit requests.
- Assist with gap assessments and control testing against ISO 27001/27002, NIST CSF / SP 800-53 / 800-171, CIS Controls, SOC 2 Trust Services Criteria, GLBA Safeguards Rule, and HIPAA requirements.
- Support EU-aligned compliance activities where applicable (e.g., GDPR security measures and accountability documentation; NIS2-aligned operational practices).
- Track audit findings, corrective action plans (CAPs), and management responses; monitor remediation progress and validate closure evidence.
- Maintain audit artifacts including control matrices, evidence inventories, and standardized templates to improve repeatability and audit readiness.
- Support control activities related to handling Controlled Unclassified Information (CUI) and other regulated client data for the Firm's federal, defense, aerospace, and government-contracts practices, including evidence gathering and documentation aligned with NIST SP 800-171, CMMC Level 2 readiness, and ITAR/EAR data-handling requirements, under the direction of the Senior Analyst.
- Help compile control attestations and evidence packages for the Firm's annual cyber insurance application and renewal cycle, supporting responses to underwriter and broker inquiries under senior oversight.
- Expected to maintain a regular and predictable work schedule and full attention to and engagement in work activities on behalf of the firm during business hours unless otherwise approved or required by applicable law.
- Special projects and duties as assigned.
Required Skills:
- Strong written and verbal communication skills; ability to translate control requirements into clear documentation and actionable guidance.
- Strong organizational skills and attention to detail.
- Ability to manage multiple priorities and deadlines.
- Knowledge or ability to learn Microsoft Office Suite, or Microsoft 365.
Required Qualifications & Education:
- Bachelor's degree in information security, Information Technology, Risk Management, Business, or equivalent practical experience.
- 3+ years of experience in GRC, information security, technology risk management, compliance, internal audit, or third-party risk management.
- Working knowledge of ISO/IEC 27000 Family concepts, NIST CSF/SP 800-53/800-171, and HIPAA.
- Familiarity with EU information security and privacy requirements (e.g., GDPR security principles); familiarity with NIS2 is a plus where relevant.
- Experience collecting, organizing, and validating control evidence and supporting audits/assessments.
- Certifications - ISACA: CRISC (Certified in Risk and Information Systems Control) and/or CISA (Certified Information Systems Auditor).
Preferred Qualifications & Education:
- Prior exposure to GRC, IT risk, or information security work in a law firm, professional services firm, or other client-confidential environment is preferred.
- Familiarity with legal-industry technology (document management such as iManage or NetDocuments; time and billing such as 3E or Aderant; conflicts and new business intake such as Intapp; eDiscovery platforms such as Relativity) and with the data-sensitivity considerations they raise is a plus.
- Awareness of the ABA Model Rules of Professional Conduct (in particular Rules 1.1 and 1.6) and applicable state bar requirements relating to technology competence and client confidentiality is preferred.
- Familiarity with Controlled Unclassified Information (CUI) handling, NIST SP 800-171, CMMC, and ITAR/EAR data-handling concepts; prior exposure to federal, defense, or government-contracts client matters is a plus.
- Certifications -
- ISACA: COBIT Foundation, CDPSE, or CGEIT as applicable to governance, privacy, and enterprise risk responsibilities ISO/IEC 27001 Internal Auditor, Lead Implementer, or Lead Auditor.
- Cloud and platform risk certifications such as Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900), Azure Security Engineer Associate (AZ-500), or similar.
Physical Requirements:
- Ability to sit or stand for extended periods of time.
- Moderate or advanced keyboard usage.
Benefits: Our goal is to promote a work environment in which individuals have access to the resources they need to be their best both professionally and personally, which includes resources that encourage individuals to focus on their health and well-being.
Below are the benefits we offer: comprehensive medical (PPO and HDHPs), dental and vision plans including coverage for domestic partners; life and AD&D insurance; short and long term disability insurance; tax-advantaged accounts for health care expenses, including FSAs and HSAs; FSAs for dependent care; health advocacy services; behavioral health and counseling resources for all family members; 401(k); profit sharing; backup dependent care; senior care planning support; resources for individuals with development disabilities and their caregivers; and paid holidays and other paid time off, including paid leave for new parents.
Holland & Knight is an Equal Opportunity Employer and does not discriminate on the basis of race, color, religion, sex (including pregnancy, childbirth or related conditions, transgender status, and sexual orientation), national origin, age, disability, genetic information, veteran status or any other factor prohibited by law.
Applicants who are interested in applying for a position and require an accommodation during the process should contact ApplicantAccommodations@hklaw.com.
Personal Information collected from applicants will be used for the purpose of processing the application throughout any recruitment or employment process, as well as inclusion in a personnel file. Categories of data collected may include name, address, phone numbers, email, Social Security Number, and signature. Holland & Knight may collect further information if you consent to a background check. This includes criminal background, employment, and certifications. Please visit Legal Information Portal for Holland & Knight LLP's privacy policies.
What Holland & Knight employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Holland & Knight
Sourced by ZipRecruiter
Industry
Law firms
Company size
1,001 - 5,000 Employees
Headquarters location
Brandon, FL, US
Year founded
1968