... T risk management (ITRM) initiatives to increase the transparency of risk impacts to the firm, manage the Cyber risk register, issue log, facilitate the Risk Operating Committee (ROC), and support ...
... T risk management (ITRM) initiatives to increase the transparency of risk impacts to the firm, manage the Cyber risk register, issue log, facilitate the Risk Operating Committee (ROC), and support ...
Direct IT risk assessments, manage IT risk register, supplier security evaluations, penetration testing and assist with audits across operations * Partner with Legal, Privacy, Compliance, Information ...
Direct IT risk assessments, manage IT risk register, supplier security evaluations, penetration testing and assist with audits across operations * Partner with Legal, Privacy, Compliance, Information ...
NORC at the University of Chicago seeks Senior IT Risk and Compliance Analyst to join our DSS ... Risk Management Experience: Demonstrated experience in developing threat models and security risk ...
NORC at the University of Chicago seeks Senior IT Risk and Compliance Analyst to join our DSS ... Risk Management Experience: Demonstrated experience in developing threat models and security risk ...
Risk Manager, Endpoint Security
Mclean, VA ยท On-site
Technology & Data Risk Management (TDRM) is a small organization that packs a big punch. The ~200 TDRM professionals are trusted experts who oversee ~14,000 developers at Capital One. We raise the ...
Risk Manager, Endpoint Security
Mclean, VA ยท On-site
Technology & Data Risk Management (TDRM) is a small organization that packs a big punch. The ~200 TDRM professionals are trusted experts who oversee ~14,000 developers at Capital One. We raise the ...
Risk Manager, Endpoint Security
Mclean, VA ยท On-site
Technology & Data Risk Management (TDRM) is a small organization that packs a big punch. The ~200 TDRM professionals are trusted experts who oversee ~14,000 developers at Capital One. We raise the ...
Risk Manager, Endpoint Security
Mclean, VA ยท On-site
Technology & Data Risk Management (TDRM) is a small organization that packs a big punch. The ~200 TDRM professionals are trusted experts who oversee ~14,000 developers at Capital One. We raise the ...
Senior Associate, Cyber Risk Specialist Identity & Access Management | Retail Bank
Mclean, VA ยท On-site
... Management (IAM) processes ... You will be a strategic risk partner to business and technology stakeholders, directly shaping our ...
Senior Associate, Cyber Risk Specialist Identity & Access Management | Retail Bank
Mclean, VA ยท On-site
... Management (IAM) processes ... You will be a strategic risk partner to business and technology stakeholders, directly shaping our ...
Sr. Manager, Tech & Cyber Risk
Mclean, VA ยท On-site
You will leverage your analytical and risk management expertise to drive meaningful outcomes, influence corporate policies and standards, and ensure the resilience of our enterprise technology.
Sr. Manager, Tech & Cyber Risk
Mclean, VA ยท On-site
You will leverage your analytical and risk management expertise to drive meaningful outcomes, influence corporate policies and standards, and ensure the resilience of our enterprise technology.
Senior Associate, Cyber Risk Specialist Identity & Access Management | Retail Bank
Mclean, VA ยท On-site
... Management (IAM) processes ... You will be a strategic risk partner to business and technology stakeholders, directly shaping our ...
Senior Associate, Cyber Risk Specialist Identity & Access Management | Retail Bank
Mclean, VA ยท On-site
... Management (IAM) processes ... You will be a strategic risk partner to business and technology stakeholders, directly shaping our ...
Sr. Manager, Tech & Cyber Risk
Mclean, VA ยท On-site
You will leverage your analytical and risk management expertise to drive meaningful outcomes, influence corporate policies and standards, and ensure the resilience of our enterprise technology.
Sr. Manager, Tech & Cyber Risk
Mclean, VA ยท On-site
You will leverage your analytical and risk management expertise to drive meaningful outcomes, influence corporate policies and standards, and ensure the resilience of our enterprise technology.
IT Audit - Staff
Alexandria, VA ยท On-site
$65K - $80K/yr
IT Audit Staff Location: Alexandria, VA (on-site) Level: Staff Clearance: Secret *Candidates must ... Conduct research related to IT control frameworks, risk management standards, and security ...
Quick apply
IT Audit - Staff
Alexandria, VA ยท On-site
$65K - $80K/yr
IT Audit Staff Location: Alexandria, VA (on-site) Level: Staff Clearance: Secret *Candidates must ... Conduct research related to IT control frameworks, risk management standards, and security ...
Technical Risk Analyst
Vienna, VA ยท On-site
The ideal candidate will have experience working with IT security controls, risk management practices, compliance frameworks, or audit activities and possess strong analytical and documentation ...
Technical Risk Analyst
Vienna, VA ยท On-site
The ideal candidate will have experience working with IT security controls, risk management practices, compliance frameworks, or audit activities and possess strong analytical and documentation ...
Risk Management Analyst
Washington, DC ยท On-site +1
Bachelor's Degree in Business Administration, Project Management, Information Technology, Public Administration, or a related field. * Minimum of 5 years of experience in risk management, program ...
Risk Management Analyst
Washington, DC ยท On-site +1
Bachelor's Degree in Business Administration, Project Management, Information Technology, Public Administration, or a related field. * Minimum of 5 years of experience in risk management, program ...
Risk Management Analyst
Washington, DC ยท Remote
Bachelor's Degree in Business Administration, Project Management, Information Technology, Public Administration, or a related field. * Minimum of 5 years of experience in risk management, program ...
Quick apply
Risk Management Analyst
Washington, DC ยท Remote
Bachelor's Degree in Business Administration, Project Management, Information Technology, Public Administration, or a related field. * Minimum of 5 years of experience in risk management, program ...
Risk Management Analyst
Washington, DC ยท On-site
Bachelor's Degree in Business Administration, Project Management, Information Technology, Public Administration, or a related field. * Minimum of 5 years of experience in risk management, program ...
Risk Management Analyst
Washington, DC ยท On-site
Bachelor's Degree in Business Administration, Project Management, Information Technology, Public Administration, or a related field. * Minimum of 5 years of experience in risk management, program ...
Director Risk Management
Washington, DC ยท On-site
$125K/yr
... technology, legal, and executive leadership teams. This position may supervise Risk Management ... Patient Safety, Audit, or Quality support staff, as organizational structure evolves. Essential ...
Director Risk Management
Washington, DC ยท On-site
$125K/yr
... technology, legal, and executive leadership teams. This position may supervise Risk Management ... Patient Safety, Audit, or Quality support staff, as organizational structure evolves. Essential ...
Director Risk Management
Washington, DC ยท On-site
... technology, legal, and executive leadership teams. This position may supervise Risk Management ... Patient Safety, Audit, or Quality support staff, as organizational structure evolves. Essential ...
Director Risk Management
Washington, DC ยท On-site
... technology, legal, and executive leadership teams. This position may supervise Risk Management ... Patient Safety, Audit, or Quality support staff, as organizational structure evolves. Essential ...
Principal Associate, International Risk, Strategy & Technology Enablement- Enterprise Services Risk
Mclean, VA ยท On-site
$99K/yr
We operate at the forefront of risk management, providing support for novel and developing technologies, as well as critical business strategies. Diverse perspectives and experiences are valued as we ...
Principal Associate, International Risk, Strategy & Technology Enablement- Enterprise Services Risk
Mclean, VA ยท On-site
$99K/yr
We operate at the forefront of risk management, providing support for novel and developing technologies, as well as critical business strategies. Diverse perspectives and experiences are valued as we ...
Principal Associate, International Risk, Strategy & Technology Enablement- Enterprise Services Risk
Mclean, VA ยท On-site
$99K/yr
We operate at the forefront of risk management, providing support for novel and developing technologies, as well as critical business strategies. Diverse perspectives and experiences are valued as we ...
Principal Associate, International Risk, Strategy & Technology Enablement- Enterprise Services Risk
Mclean, VA ยท On-site
$99K/yr
We operate at the forefront of risk management, providing support for novel and developing technologies, as well as critical business strategies. Diverse perspectives and experiences are valued as we ...
Brand, Enterprise Supplier Management, Enterprise Products & Experience (EPX), Software, External Affairs, eData, Global Workplace Solutions, Emerging Payments, Ventures, and Tech. As the risk team ...
Brand, Enterprise Supplier Management, Enterprise Products & Experience (EPX), Software, External Affairs, eData, Global Workplace Solutions, Emerging Payments, Ventures, and Tech. As the risk team ...
Risk Management Analyst
Sterling, VA ยท On-site
$86K - $181K/yr
Risk Management Analyst Job Category ... Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with ...
Risk Management Analyst
Sterling, VA ยท On-site
$86K - $181K/yr
Risk Management Analyst Job Category ... Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with ...
Technology Risk Management information
See Washington, DC salary details
$49.1K - $61.8K
8% of jobs
$61.8K - $74.6K
14% of jobs
$80.4K is the 25th percentile. Wages below this are outliers.
$74.6K - $87.3K
6% of jobs
$87.3K - $100K
8% of jobs
$100K - $112.8K
11% of jobs
The median wage is $115.4K / yr.
$112.8K - $125.5K
13% of jobs
$125.5K - $138.2K
11% of jobs
$142.1K is the 75th percentile. Wages above this are outliers.
$138.2K - $151K
15% of jobs
$151K - $163.7K
8% of jobs
$163.7K - $176.4K
4% of jobs
$176.4K - $189.1K
2% of jobs
$49.1K
$117.1K
$189.1K
How much do technology risk management jobs pay per year?
What is a Technology Risk Management job?
A Technology Risk Management job involves identifying, assessing, and mitigating risks related to an organization's technology infrastructure, systems, and data. Professionals in this field develop policies, ensure compliance with regulatory requirements, and implement security controls to protect against cyber threats and operational failures. They collaborate with IT, security, and business teams to address vulnerabilities and enhance resilience. The role requires knowledge of risk assessment frameworks, regulatory standards, and emerging technology risks.
What are the key skills and qualifications needed to thrive in the Technology Risk Management position, and why are they important?
To excel in Technology Risk Management, you need a background in information security, risk assessment, and regulatory compliance, often supported by a relevant degree and experience in IT or cybersecurity. Familiarity with risk management frameworks (such as NIST or ISO 27001), governance, risk and compliance (GRC) tools, and certifications like CISA, CISSP, or CRISC are highly valued. Strong analytical thinking, communication skills, and the ability to influence and collaborate across departments are vital soft skills for this role. These competencies are crucial to effectively identify, mitigate, and communicate technology risks, helping organizations manage threats while ensuring business continuity and compliance.
What are the typical daily responsibilities for someone working in Technology Risk Management?
Professionals in Technology Risk Management are typically responsible for identifying and assessing potential technology-related risks, developing policies and controls to mitigate those risks, and monitoring compliance with internal and external regulations. Their day-to-day activities often include conducting risk assessments, coordinating with IT teams on security initiatives, preparing reports for senior management, and responding to incidents or audit findings. Collaboration with various departments such as IT, compliance, and business units is frequent to ensure comprehensive risk oversight. This role requires staying up-to-date on emerging threats and evolving regulatory requirements to proactively manage the organization's risk posture.

Full-time
Medical, Dental, Vision, Retirement, PTO
Posted 16 days ago
Job description
The Manager, Cybersecurity Governance and Risk will lead IT risk management (ITRM) initiatives to increase the transparency of risk impacts to the firm, manage the Cyber risk register, issue log, facilitate the Risk Operating Committee (ROC), and support the Governance and Risk team in identifying and implementing industry standards (e.g., NIST, ISO and COBIT) in accordance with applicable regulatory or client guidelines. The Manager will also assist in developing methodologies, policies, processes, and tools to support InfoSec and Governance and Risk initiatives. The role will contribute to evolving ITRM's oversight, reporting, governance, communications, and education efforts from an Information Security perspective. This position is 100% Onsite and not open for Remote.
Manager, Cybersecurity Governance and Risk Responsibilities:
- Assist with the development, implementation and management of the governance and risk strategic plan and roadmap, including evolving the reporting structure and frequency to InfoSec stakeholders.
- Serve as a key contributor in identifying, managing and communicating governance and risk across InfoSec policy domains, providing expertise to prioritize and manage risk, while facilitating the adoption in conjunction with the Controls Manager of IT Risk policies, standards and guidelines across the enterprise.
- In conjunction with the Controls and TPRM Managers, evolve, develop and manage the development, maintenance and evaluation of organizational InfoSec governance and risk procedures, processes and guidelines in accordance with Firm and Client requirements.
- Work with the Controls Manager and other stakeholders to identify, validate and document deficiencies in ITRM governance, processes and risk management practices, propose remediations, and enforce cross functional POAM initiatives and status reporting requirements in accordance with prioritization requirements.
- Manage the Cyber risk and issue registers and remediations, including supporting monthly ROC meetings (e.g., agenda, data calls, etc.), tracking and aggregating the risk registers and performing risk to policy domain to control(s) mapping to provide prioritization and transparency into control and policy domains requiring remediation.
- Evolve risk methodologies, as well as conduct and support risk assessments to support InfoSec the identification of risk across policy domains, identify opportunities for control enhancement and risk mitigation.
- Assist InfoSec's TPRM and Client InfoSec Assessments, including assessment activities (completion and quality control reviews), developing or revising control narratives and supporting reporting efforts to InfoSec leadership and stakeholders.
- Facilitate the definition and maintenance of InfoSec governance and risk measures and metrics; and handle additional related projects as assigned.
Manager, Cybersecurity Governance and Risk Qualifications:
- Bachelor's degree in information security, Information Assurance, Computer Science, Information Systems, or other related field (2 years of additional experience may be substituted for 2 years of college credits).
- At least 7 years of combined information technology, information security and risk management experience.
- Advanced awareness of current information security standards and developments (CSF, NIST, ISO), the COSO framework, as well as the emerging cyber threat landscape.
- Advanced understanding of risk management concepts, frameworks, and methodologies.
- Strong understanding of information security concepts and technologies.
- Strong project management skills and understanding of the technology and operational risks as related to technology solutions.
- Fundamental knowledge of the operation of law practices and advanced knowledge of MS Outlook, Word, Excel, Visio, and PowerPoint.
- Third party assessment experience, including the evaluation of SOC2 Type 2, SIG, Pen Test, etc., reports.
- Strong understanding of Operational Risk from a Technology perspective.
- Excellent analytical and problem-solving skills, inquisitive nature and comfort challenging current practices.
- Understanding of governance, risk and compliance (GRC) practices and technologies across governance, process and technical domains.
- Background in consulting preferred.
- Ability to develop and maintain solid working relationships across the departments, and high-level technical understanding of security applications, platforms and architectures.
- CISA, CISM, GSEC, CISSP, CRISC or other security-related certification preferred.
Benefits include medical insurance, retirement plan, Dental, Vision, PTO, etc.
Keywords: Washington DC Jobs, Manager, Cybersecurity Governance and Risk, Information Security, Risk Management, Methodologies, Outlook, Word, Excel, Visio, PowerPoint, Project Management, CFS, NIST, ISO, COSO Framework, GRC, Governance Risk and Compliance, SOC2 Type 2, SIG, Pen Test, CISA, CISM, GSEC, CISSP, CRISC, Washington DC Recruiters, Information Technology Jobs, IT Jobs, Washington DC Recruiting
Looking to hire for similar positions in Washington, DC or in other cities? Our IT recruiting agencies and staffing companies can help.
We help companies that are looking to hire Managers, Cybersecurity Governance and Risk for jobs in Washington, DC and in other cities too. Please contact our IT recruiting agencies and IT staffing companies today! Phone 630-428-0600 ext. 11 or email us at jobs@nextstepsystems.com.
Atlanta Georgia IT Recruiters, Austin TX IT Recruiters, Baltimore Executive Staffing, Boston IT Recruiters, Charlotte IT Recruiters, Chicago Recruiting Agency, Cincinnati Executive Search Firms, Cleveland Executive Tech Recruiting, Columbus Technical Recruiters, Dallas Recruiters for IT, Denver Technology Headhunters, Detroit IT Headhunters, Fort Lauderdale Information Technology Recruiters, Houston IT Recruiters, Indianapolis IT Recruiters, Jacksonville IT Recruiters, Kansas City IT Recruiters, Los Angeles IT Recruiters, Miami IT Recruiters, Minneapolis IT Recruiters, Nashville IT Recruiters, New Jersey Tech Recruiters, New York IT Recruiters, Phoenix IT Recruiters, Raleigh IT Recruiters, Salt Lake City IT Recruitment, San Antonio Information Technology Recruiters, San Diego Executive Staffing, San Francisco Executive Search Firms, San Jose Executive Tech Recruiting, Seattle Technical Recruiters, Silicon Valley Tech Recruiters, St. Louis Technology Headhunters, Tampa Technology Headhunters, Washington DC IT Recruiters
Home"Manager, Cybersecurity Governance and Risk
About Next Step Systems
Sourced by ZipRecruiter
Industry
It services
Company size
11 - 50 Employees
Headquarters location
Naperville, IL, US
Year founded
1995