1

Technology Risk Management Jobs in Washington, DC

The Risk Management Risk (RMR) Office is seeking a highly motivated Risk Advisor to apply their analytical, risk, communication, and project management skills in support of the Risk Tech and Product ...

The Risk Management Risk (RMR) Office is seeking a highly motivated Risk Advisor to apply their analytical, risk, communication, and project management skills in support of the Risk Tech and Product ...

The ideal candidate will possess a solid understanding and hands-on experience of risk management frameworks (such as NIST 800-53, NIST CSF), technology functions, and organizational structures.

next page

Showing results 1-20

Technology Risk Management information

See Washington, DC salary details

$49.3K

$117.5K

$189.8K

How much do technology risk management jobs pay per year?

As of Jun 29, 2026, the average yearly pay for technology risk management in Washington, DC is $117,493.00, according to ZipRecruiter salary data. Most workers in this role earn between $82,100.00 and $149,600.00 per year, depending on experience, location, and employer.

What is a Technology Risk Management job?

A Technology Risk Management job involves identifying, assessing, and mitigating risks related to an organization's technology infrastructure, systems, and data. Professionals in this field develop policies, ensure compliance with regulatory requirements, and implement security controls to protect against cyber threats and operational failures. They collaborate with IT, security, and business teams to address vulnerabilities and enhance resilience. The role requires knowledge of risk assessment frameworks, regulatory standards, and emerging technology risks.

What are the key skills and qualifications needed to thrive in the Technology Risk Management position, and why are they important?

To excel in Technology Risk Management, you need a background in information security, risk assessment, and regulatory compliance, often supported by a relevant degree and experience in IT or cybersecurity. Familiarity with risk management frameworks (such as NIST or ISO 27001), governance, risk and compliance (GRC) tools, and certifications like CISA, CISSP, or CRISC are highly valued. Strong analytical thinking, communication skills, and the ability to influence and collaborate across departments are vital soft skills for this role. These competencies are crucial to effectively identify, mitigate, and communicate technology risks, helping organizations manage threats while ensuring business continuity and compliance.

What does technology risk management do?

Technology risk management involves identifying, assessing, and mitigating risks related to information technology systems and infrastructure. Professionals in this field develop strategies to protect data, ensure compliance, and reduce the impact of cyber threats, often using tools like risk assessments and security frameworks. It requires knowledge of cybersecurity, IT controls, and industry standards such as ISO 27001 or NIST.

What is the highest paying risk management job?

In risk management, senior roles such as Chief Risk Officer (CRO) or Director of Risk typically have the highest salaries, often exceeding six figures annually. These positions require extensive experience, advanced certifications like FRM or CRM, and strong leadership skills within financial, insurance, or corporate environments.

Is risk management a good career?

Risk management is a valuable career path, especially in fields like technology risk management where professionals identify and mitigate cybersecurity threats, compliance issues, and operational risks. It often requires certifications such as CRISC or CISSP and involves analytical skills, attention to detail, and understanding of industry standards. The demand for risk management professionals is growing as organizations prioritize security and regulatory compliance.

What are the typical daily responsibilities for someone working in Technology Risk Management?

Professionals in Technology Risk Management are typically responsible for identifying and assessing potential technology-related risks, developing policies and controls to mitigate those risks, and monitoring compliance with internal and external regulations. Their day-to-day activities often include conducting risk assessments, coordinating with IT teams on security initiatives, preparing reports for senior management, and responding to incidents or audit findings. Collaboration with various departments such as IT, compliance, and business units is frequent to ensure comprehensive risk oversight. This role requires staying up-to-date on emerging threats and evolving regulatory requirements to proactively manage the organization's risk posture.

How much do technology risk consultants make?

Technology risk consultants typically earn between $70,000 and $130,000 annually, depending on experience, location, and certifications such as CISSP or CISA. Senior consultants or those in high-demand areas can earn higher salaries, often exceeding $150,000 with bonuses and benefits included.
What are the most commonly searched types of Technology Risk Management jobs in Washington, DC? The most popular types of Technology Risk Management jobs in Washington, DC are:
What are popular job titles related to Technology Risk Management jobs in Washington, DC? For Technology Risk Management jobs in Washington, DC, the most frequently searched job titles are:
What job categories do people searching Technology Risk Management jobs in Washington, DC look for? The top searched job categories for Technology Risk Management jobs in Washington, DC are:
Infographic showing various Technology Risk Management job openings in Washington, DC as of June 2026, with employment types broken down into 100% Full Time. Highlights an 93% In-person, and 7% Remote job distribution, with an average salary of $117,493 per year, or $56.5 per hour.
Principal IT Risk Management Analyst

Principal IT Risk Management Analyst

Strategic Education, Inc.

Herndon, VA • On-site, Remote

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 6 days ago


Strategic Education rating

8.8

Company rating: 8.8 out of 10

Based on 11 frontline employees who took The Breakroom Quiz

10th of 197 rated education and training


Job description

At Strategic Education Inc., our mission is to enable economic mobility through education. Through our portfolio of institutions and learning solutions, we serve working adult learners by improving affordability, engagement, and workforce readiness. This mission guides our approach to technology, cybersecurity, and risk management.
The Principal IT Risk Management Analyst is a senior leader responsible for advancing the organization's IT risk management program. This is not a compliance or audit role. The successful candidate will have deep experience identifying, assessing, quantifying, and managing technology risk, along with the technical understanding needed to evaluate security controls, identify technology risks, and engage effectively with cybersecurity, engineering, and architecture teams. While the role does not require designing technical solutions or interpreting detailed system configurations, it does require the ability to understand how technology decisions, vulnerabilities, and control weaknesses translate into organizational risk and business impact.
This role drives strategy, leads complex technology risk assessments, and partners across the enterprise to ensure technology risks are effectively identified, measured, managed, and communicated in alignment with organizational risk appetite and tolerance. Success in this role requires the ability to translate technical risk into meaningful business context for executive leadershi
Essential Duties & Responsibilities
Strategic Leadership
  • Lead and evolve the IT security risk management program in alignment with organizational goals, risk appetite, and risk tolerance

  • Partner with executive leadership to shape risk strategy and drive enterprise-wide adoption

  • Serve as a key advisor on risk posture, translating technical findings into strategic business decisions

Risk Assessment & Analysis
  • Identify, assess, and quantify technology risks by evaluating cybersecurity threats, operational vulnerabilities, and emerging technology risks using qualitative and quantitative methodologies

  • Conduct risk assessments using established frameworks, including NIST CSF and CIS Controls v8

  • Translate technical findings into clear, actionable business risk and support risk-based decision making

  • Manage and maintain the enterprise IT risk register, including risk ownership, scoring, and lifecycle tracking

Risk Mitigation & Governance
  • Design and implement IT security risk mitigation strategies and controls aligned with industry standards

  • Lead the risk exception management process, including evaluation, documentation, and risk acceptance decisions

  • Provide risk-informed guidance for complex technology initiatives, including emerging areas such as artificial intelligence and machine learning

  • Integrate IT security risk management practices into business and technology processes

  • Support the development and lifecycle management of information security policies and standards

Risk Reporting & Insights
  • Define and evolve risk metrics, key risk indicators (KRIs), and risk appetite thresholds

  • Develop dashboards and reporting that translate risk data into actionable insights for executive and board-level audiences

  • Communicate complex risk concepts clearly to both technical and non-technical stakeholders

Program Enablement & Continuous Improvement
  • Drive adoption of IT security risk platforms and workflow automation to improve efficiency and scalability

  • Identify and implement automation opportunities across risk management workflows

  • Continuously enhance risk methodologies, tools, and processes

  • Stay current on the evolving threat landscape, emerging technologies, and industry practices

Mentorship & Development
  • Mentor and guide junior team members in direct or matrixed reporting relationships

  • Lead or own workstreams while providing direction and support to junior analysts

Qualifications
Skills & Expertise
  • Strong leadership, analytical, and problem-solving skills with a risk-first mindset

  • Demonstrated team leadership through mentoring, coaching, or leading analysts

  • Ability to own workstreams and guide junior staff in a matrixed environment

  • Strong technical depth to identify risks, evaluate control effectiveness, and translate vulnerability and technical data into business risk

  • Deep knowledge of NIST CSF, CIS Controls v8, and related frameworks

  • Proven ability to build and manage an enterprise IT risk register and exception management program

  • Experience building and evolving risk metrics, KRIs, dashboards, and executive reporting

  • Hands-on experience with GRC platforms and workflow automation tools (e.g., Archer, ServiceNow GRC, OneTrust, Jira, Rapid7 Nexpose) and the ability to automate processes

  • Understanding of AI/ML risk domains, including model risk, data integrity, bias, and adversarial threats, with the ability to recommend controls

  • Experience drafting, reviewing, and improving information security policies and standards

  • Ability to communicate technical concepts and residual risk clearly to non-technical stakeholders

Work Experience
  • 5+ years of IT risk management experience, with a focus on risk assessment, quantification, and risk register ownership (not primarily compliance or audit)

  • 3+ years mentoring or leading team members

  • Demonstrated experience mentoring analysts while owning and delivering discrete risk workstreams or program components

  • Experience conducting risk assessments aligned to NIST CSF, CIS Controls v8, or similar frameworks

  • Experience managing an IT risk register, risk exception processes, and residual risk documentation

  • Experience developing risk metrics, dashboards, and executive reporting

  • Experience with GRC platforms and workflow automation in a risk context

  • Experience managing risks related to emerging technologies, including artificial intelligence

Education & Certifications
  • Bachelor's degree in a relevant discipline required; Master's degree preferred

Preferred certifications:
  • CRISC (ISACA)

  • CISSP (ISC²)

  • CISM (ISACA)

  • CompTIA Security+

  • CompTIA CySA+

  • CompTIA CASP+

  • CGEIT (ISACA)

Other:
  • Must be able to travel occasionally should a business need arise. For most roles travel would not be common. Travel may involve plane, car or metro. In accordance with ADA policies, reasonable accommodations regarding travel limitations can be provided. Travel will be more common for roles such as Account Executives (25 - 50%), senior leaders (10 - 20%) or Capella Core Faculty (5 - 10%).
  • Ability to work onsite in Corporate or Campus location (in a typical office environment) may be required based on role. If so, this would include being mobile within the office, including movement from floor-to-floor using elevators or stairs.
  • If offsite or hybrid role, must have access to work in setting which enables meeting all requirements of the role (including privacy, reliable internet access, phone, ability to video conference, etc.) at a remote location.
  • This role may require lifting, however reasonable accommodations will be provided in accordance with our ADA policies.
  • Must be able to meet critical thinking and problem solving aspects aligned to job duties, as well as effectively communicating with co-workers.
  • Must be able to work more than 40 hours per week when business needs warrant. Accommodations related to schedule may be considered.
  • Able to access information using a computer.
  • Other essential functions and marginal job functions are subject to modification.

#LI-JD1
SEI offers a comprehensive package of benefits to employees scheduled 30 hours or more per week. In addition to medical, dental, vision, life and disability plans, SEI employees may take advantage of well-being incentives, parental leave, paid time off, certain paid holidays, tax saving accounts (FSA, HSA), 401(k) retirement benefit, Employee Stock Purchase Plan, tuition assistance as well as entertainment and retail discounts. Non-exempt employees are eligible for overtime pay, if applicable.
Careers - Our Benefits, Strategic Education, Inc
SEI is an equal opportunity employer committed to fostering an inclusive and collaborative culture where individuals can grow their careers and contribute fully. We strive to attract talent with broad experiences, skills and perspectives. We welcome applications from all. While it is not typical for an individual to be hired at or near the top end of the pay range at SEI, we offer a competitive salary. The actual base pay offered to the successful candidate may vary depending on multiple factors including, but not limited to, job-related knowledge/skills, experience, business needs, geographical location, and internal pay equity. Our Talent Acquisition Team is ready to discuss your interest in joining SEI. The expected salary range for this position is below.
$119,300.00 - $178,900.00 - Salary
If you require reasonable accommodations to complete our application process, please contact our Human Resources Department at Careers@strategiced.com.

What Strategic Education employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom