1

Security Risk Manager Jobs in Washington, DC (NOW HIRING)

Professional security or risk management certifications, such as Certified Information Systems Auditor (CISA), or Certified Risk & Information Systems Control (CRISC) At this time, Capital One will ...

Professional security or risk management certifications, such as Certified Information Systems Auditor (CISA), or Certified Risk & Information Systems Control (CRISC) At this time, Capital One will ...

next page

Showing results 1-20

Security Risk Manager information

See Washington, DC salary details

$15

$29

$59

How much do security risk manager jobs pay per hour?

As of Jul 22, 2026, the average hourly pay for security risk manager in Washington, DC is $29.42, according to ZipRecruiter salary data. Most workers in this role earn between $20.67 and $33.22 per hour, depending on experience, location, and employer.

How much does a risk manager get paid?

A Security Risk Manager's average salary in the United States ranges from $80,000 to $130,000 annually, depending on experience, certifications, and industry. Senior roles or those with specialized skills can earn higher salaries, often exceeding $150,000. Compensation may also include bonuses and benefits related to security and risk management tools.

What is the difference between Security Risk Manager vs Security Analyst?

AspectSecurity Risk ManagerSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP (optional)
Work EnvironmentStrategic, managerial, policy-focusedOperational, monitoring, incident response
Employer & Industry UsageOrganizations with risk management frameworksIT departments, cybersecurity teams

The Security Risk Manager focuses on identifying, assessing, and mitigating security risks at a strategic level, often managing policies and frameworks. In contrast, the Security Analyst handles day-to-day security monitoring, incident response, and vulnerability assessments. Both roles require cybersecurity certifications, but the Risk Manager's role is more strategic, while the Analyst's role is more technical and operational.

What are some common challenges Security Risk Managers face when implementing new security policies within an organization?

Security Risk Managers often encounter challenges such as resistance to change from employees, balancing security needs with business operations, and ensuring compliance with industry regulations. Gaining buy-in from various stakeholders requires strong communication and education efforts, as some team members may perceive new protocols as disruptive. Additionally, Security Risk Managers must continuously assess evolving threats while adapting policies to keep the organization protected without hindering productivity.

What are the key skills and qualifications needed to thrive as a Security Risk Manager, and why are they important?

To thrive as a Security Risk Manager, you need a solid understanding of risk assessment, security protocols, and regulatory compliance, typically supported by a degree in cybersecurity, information security, or a related field. Familiarity with risk management frameworks (like ISO 27001 or NIST), security information and event management (SIEM) systems, and certifications such as CISSP or CISM are commonly required. Strong analytical thinking, communication, and leadership skills help you effectively identify vulnerabilities and collaborate with stakeholders. These competencies are crucial for proactively managing threats, ensuring organizational resilience, and maintaining regulatory compliance.

What is the highest salary for a risk manager?

The highest salary for a Security Risk Manager can exceed $150,000 annually, especially for those with extensive experience, advanced certifications like CISSP or CISM, and leadership roles in large organizations. Salaries vary based on industry, location, and the complexity of security environments managed.

What does a security risk manager do?

A security risk manager assesses and identifies potential security threats to an organization’s information systems and physical assets. They develop strategies, implement policies, and oversee security measures to mitigate risks, often using tools like risk assessment frameworks and security audits. Strong analytical skills and relevant certifications such as CISSP or CISM are typically required.

Can I make $200,000 a year in cyber security?

Security Risk Managers with extensive experience, advanced certifications, and specialized skills can potentially earn $200,000 or more annually, especially in high-demand industries or senior roles. Salary levels depend on factors such as location, company size, and individual expertise, with senior positions often offering higher compensation.
Infographic showing various Security Risk Manager job openings in Washington, DC as of July 2026, with employment types broken down into 89% Full Time, 10% Part Time, and 1% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $61,202 per year, or $29.4 per hour.
Manager, Risk Advisor

Manager, Risk Advisor

Capital One

Mclean, VA • On-site

Full-time

Posted 28 days ago


Job description

Manager, Risk Advisor

Do you want to be part of an organization that's dedicated to helping Capital One identify, manage and effectively mitigate risk? Can you build relationships and employ innovative risk management solutions? As a Risk Manager at Capital One, you'll be responsible for working with business partners and various stakeholders to identify and mitigate potential risks. Risk Managers at Capital One are the front line of defense to ensure our Company remains stable and profitable.

The Risk Management Risk (RMR) Office is seeking a highly motivated Risk Advisor to apply their analytical, risk, communication, and project management skills in support of the Risk Tech and Product organizations. In this role, you will oversee several work streams supporting the Risk Tech and Product organizations, including periodic risk assessments and controls testing. You will lead audit and exam requests for the Risk Tech and Product teams by partnering with stakeholders to draft responses, provide evidence, and also perform a quality check over both. You will advise on policy adherence and support end to end remediation activities. As the Business Continuity Lead for Risk Tech, you will facilitate tabletop exercises to support disaster readiness and response efforts and ensure compliance with business continuity requirements.

RMR Risk Advisors combine technical knowledge with the ability to manage and assess risks across cloud-native software platforms. Successful performance of this role includes fostering accountability and collaboration across all stakeholders, both technical and non-technical. You must be comfortable asking tough questions, challenging assumptions, and providing clear, actionable recommendations to ensure risks are properly managed without unnecessary delays. At the same time, you will exercise problem solving and critical thinking skills to continuously improve the risk posture of Risk Tech and Product.

Other Responsibilities Include:

  • Develop, nurture, and maintain collaborative relationships with our Risk Tech and Risk Product partners and key stakeholders

  • Set direction, manage expectations and lead cross-functional teams via influence

  • Manage internal audits and exams directed to and/or impacting Risk Tech / Risk Product

  • Manage Business Continuity activities for Risk Tech, including Business Continuity Plan updates and tabletop exercises

  • Monitor issue remediation, tracking, and closure

  • Communicate technical issues and risks to both technical and non-technical stakeholders in clear, concise language

  • Engage in routine Risk Assessments, including Process Level Assessments, driving influential outcomes

  • Maintain a proactive stance in escalating risks when necessary and ensure alignment with organizational goals

  • Analyze data within managed work streams to proactively identify risks, trends, and process improvements

  • Provide MBR and other metric inputs as required

Basic Qualifications:

  • Bachelor's Degree or military experience

  • At least 5 years of experience working in technical audits or technical risk management

  • At least 3 years of experience interacting with internal audit, business continuity, or centralized risk and compliance teams


Preferred Qualifications:

  • 6+ years of experience working in technical audits or technology risk management

  • 4+ years of experience interacting with or engaging with internal audit, business continuity, or centralized risk and compliance teams

  • 3+ years of Process Management or Project Management

  • Robust critical thinking skills

  • Excellent problem-solving, written, and verbal communication skills

  • AWS Cloud Practitioner certification

  • Professional security or risk management certifications, such as Certified Information Systems Auditor (CISA), or Certified Risk & Information Systems Control (CRISC)

At this time, Capital One will not sponsor a new applicant for employment authorization for this position.

The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.

McLean, VA: $151,900 - $173,400 for Risk Manager


Richmond, VA: $138,100 - $157,700 for Risk Manager


Riverwoods, IL: $138,100 - $157,700 for Risk Manager









Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.

This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.

Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at theCapital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to Careers@capitalone.com

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).