1

Technology Risk Manager Jobs in Colorado (NOW HIRING)

LOB Risk Lead

Arvada, CO

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The position partners closely with Technology, Information Security, Operational Risk, Audit, Compliance, Finance, and Enterprise Risk Management teams to develop and mature technology risk ...

Position Overview The Director, Cyber Risk leads Asurion's cyber and technology risk management discipline and is accountable for a consistent, outcome-driven program the business can rely on for ...

Understand the impact of key technology trends and workforce changes impacting our clients through ... Credit Risk, Liquidity Risk, Market Risk, Capital Management/Stress Testing * Knowledge of ...

Program Risk Manager

Colorado Springs, CO ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

E&M Technologies, Inc. is currently seeking a Program Risk Manager to join our team in Colorado Springs, CO in support of the North American Aerospace Defense Command. NORAD is a United States and ...

Analyze business, risk, compliance, audit, security, and technology processes to identify ... Evaluate technology processes such as change management, logical access, IT operations, system ...

New

NISSC 3 Risk Manager

Colorado Springs, CO ยท On-site

$151K - $155K/yr

  • Medical

  • Retirement

  • PTO

Significant experience (senior level) in risk management for complex programs, preferably in DoD, cyber, or systems/IT environments. Demonstrated expertise in proactively identifying, assessing, and ...

NISSC 3 Risk Manager

Colorado Springs, CO ยท On-site

$151K - $155K/yr

  • Medical

  • Retirement

  • PTO

Significant experience (senior level) in risk management for complex programs, preferably in DoD, cyber, or systems/IT environments. Demonstrated expertise in proactively identifying, assessing, and ...

... technology innovation required by the business. Recruiting for this role ends on 12/31/2026. Work ... Work you'll do As an Insider Risk Manager on the Cyber team, you will be responsible for:

Cyber and Tech Risk UW SR

Denver, CO ยท On-site

$101K - $119K/yr

  • Medical

  • Life

  • Retirement

  • PTO

This role builds and manages strong broker relationships, provides market insight in a rapidly evolving cyber risk landscape, and positions the organization as a leader in the primary cyber market.

Cyber and Tech Risk UW SR

Arvada, CO ยท On-site +1

$100K - $119K/yr

  • Medical

  • Life

  • Retirement

  • PTO

... and technology risk. We combine underwriting expertise, cyber risk intelligence, and advanced ... Our cyber offerings are supported by proactive risk management services and data driven insights ...

Enterprise Risk Analyst

Denver, CO ยท On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the ... Background in startup, aerospace, defense technology, or SaaS companies operating in regulated ...

Assurance Digital delivers the technology that enables high quality external assurance engagements across the U.S. and the global network. The Manager of Risk & Compliance supports Assurance Digital ...

next page

Showing results 1-20

Technology Risk Manager information

See Colorado salary details

$54.2K

$117.3K

$178.8K

How much do technology risk manager jobs pay per year?

As of Aug 20, 2026, the average yearly pay for technology risk manager in Colorado is $117,303.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,600.00 and $135,600.00 per year, depending on experience, location, and employer.

What is a technology risk manager?

Technology Risk Managers are professionals responsible for identifying, assessing, and mitigating risks associated with information technology systems and processes within an organization. They ensure that IT operations comply with regulations and best practices while safeguarding data and technology assets from threats such as cyberattacks, data breaches, and system failures. Their work involves developing risk management strategies, conducting risk assessments, and collaborating with other departments to ensure the organization's technology infrastructure is secure and resilient.

What are some common challenges technology risk managers face when working across different departments?

Technology Risk Managers often encounter challenges in aligning risk management strategies with the priorities of various business units. Departments may have differing levels of risk tolerance, technical understanding, and resource availability, which can make establishing consistent policies and controls difficult. Success in the role relies on strong communication and negotiation skills, as well as the ability to educate stakeholders about the importance of risk mitigation while balancing business objectives. Building collaborative relationships and maintaining flexibility are key to overcoming these cross-departmental challenges.

What are the key skills and qualifications needed to thrive as a technology risk manager, and why are they important?

To thrive as a Technology Risk Manager, you need expertise in risk assessment, cybersecurity principles, and regulatory compliance, often supported by a degree in information security or related fields. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC (governance, risk, and compliance) tools, and certifications like CISM or CISSP are typically required. Strong analytical thinking, communication, and stakeholder management skills help you translate technical risks into business terms and coordinate mitigation efforts. These abilities are critical to proactively identifying threats and ensuring organizational resilience against evolving technology risks.

What is the difference between Technology Risk Manager vs Cybersecurity Analyst?

AspectTechnology Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISACISSP, CEH, Security+
Work EnvironmentRisk assessment, policy development, complianceMonitoring security threats, incident response, vulnerability analysis
Industry UsageFinancial, healthcare, technology firmsIT security teams, government agencies, corporations

The Technology Risk Manager focuses on identifying and mitigating overall technology risks and ensuring compliance, while the Cybersecurity Analyst concentrates on protecting systems from security threats and responding to incidents. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

What cities in Colorado are hiring for Technology Risk Manager jobs?

Cities in Colorado with the most Technology Risk Manager job openings:

Infographic showing various Technology Risk Manager job openings in Colorado as of August 2026, with employment types broken down into 87% Full Time, 11% Part Time, 1% Temporary, and 1% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $117,303 per year, or $56.4 per hour.

Senior Technology & Business Risk Manager

Biodesix, Inc.

Louisville, CO โ€ข On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 2 days ago

New


Job description

Senior Technology amp; Business Risk Manager
ABOUT US:
Biodesix is a leading diagnostic solutions company, driven to improve clinical care and outcomes for patients. Biodesix Diagnostic Tests support clinical decisions to expedite personalized care and improve outcomes for patients with lung disease. Biodesix Development Services enable the worldโ€™s leading biopharmaceutical, life sciences, and research institutions with scientific, technological, and operational capabilities that fuel the development of diagnostic tests, tools, and therapeutics.
Our Mission: Transform patient care and improve outcomes through personalized diagnostics that are timely, accessible, and address immediate clinical needs.
Our Vision: A world where patient diseases are conquered with the guidance of personalized diagnostics.
For more information, please visit www.biodesix.com.
LOCATION:
On-Site in Louisville, CO

THE ROLE:
The Senior Technology amp; Business Risk Manager is responsible for leading enterprise technology risk management, business continuity, governance, compliance coordination, and operational resilience activities across the organization. This role oversees risk assessment processes, business continuity planning, control governance, third-party risk management, audit readiness, and technology risk initiatives that support business operations, cybersecurity objectives, regulatory compliance, and organizational growth. The position partners closely with Infrastructure Engineering, Cybersecurity, Software Development, Business Intelligence, Compliance, Legal, Quality, and business stakeholders to ensure risks are identified, evaluated, communicated, and appropriately mitigated. This position is designed for a hands-on technology risk leader capable of assessing cybersecurity, infrastructure, operational, and business risks while helping mature enterprise governance, risk management, and operational resilience programs. The successful candidate must be comfortable operating in a highly technical environment and actively participating in risk assessments, audits, technology reviews, business continuity planning, vendor risk evaluations, control design discussions, and operational resilience initiatives.
WHAT YOU'LL DO:
Enterprise Risk Management amp; Governance
  • Lead enterprise-wide risk identification, assessment, prioritization, mitigation, and reporting activities across technology and business domains.
  • Maintain and continuously improve the enterprise risk register, risk methodologies, scoring models, and governance processes
  • Facilitate cross-functional risk assessments involving cybersecurity, infrastructure, applications, cloud technologies, data protection, operational processes, and third-party services
  • Establish risk metrics, key risk indicators (KRIs), dashboards, and executive reporting processes.
  • Coordinate risk review activities with business leaders and IT stakeholders to ensure risk ownership and mitigation accountability
  • Support risk-informed decision-making throughout technology and business initiatives
  • Partner with business leaders to identify, assess, and monitor operational, strategic, regulatory, and enterprise risks beyond traditional technology domains
  • Drive enterprise risk governance through regular risk reviews, executive reporting, and cross-functional governance committees
Technology Risk amp; Cybersecurity Governance
  • Partner with Infrastructure Engineering and Cybersecurity teams to evaluate technical risks, control effectiveness, and remediation strategies
  • Assess enterprise risks associated with emerging technologies, including Artificial Intelligence (AI), automation, cloud-native platforms, and evolving digital capabilities
  • Support governance activities aligned with NIST CSF, NIST RMF, ISO 27001, SOC 2, HIPAA, SOX and related frameworks
  • Assist with root cause analysis, risk investigations, control reviews, and corrective action planning
  • Conduct and lead technology risk assessments involving infrastructure, cloud services, enterprise applications, identity and access management, cybersecurity controls, endpoint technologies, and operational technology environments
  • Stay current with emerging cybersecurity threats, regulatory developments, risk management practices, and technology trends
Business Continuity amp; Operational Resilience
  • Lead development and continuous improvement of the Business Continuity Program
  • Conduct Business Impact Assessments (BIAs) and recovery planning activities across business functions
  • Coordinate tabletop exercises, continuity testing, and resilience validation activities
  • Partner with Infrastructure and Security teams to ensure Disaster Recovery capabilities support business recovery objectives
  • Evaluate operational resiliency risks involving critical business processes, vendors, and technology dependencies
  • Support incident response reviews and lessons-learned activities following significant operational disruptions
  • Coordinate responses to customer security questionnaires, technology due diligence activities, and third-party assurance requests
Compliance, Audit amp; Third-Party Risk
  • Coordinate readiness activities for internal and external audits including SOC 2, HIPAA, ISO 27001, SOX, and related assessments
  • Partner with business and IT teams to collect audit evidence, validate controls, and track remediation activities
  • Support vendor risk assessments, third-party reviews, and ongoing vendor monitoring activities
  • Assist with policy development, control governance, and risk-related training initiatives
  • Monitor evolving regulatory requirements impacting technology, cybersecurity, privacy, and operational risk programs
  • Maintain documentation supporting governance, compliance, continuity, and risk management activities
  • Partner with Finance, Internal Audit, and business stakeholders to support SOX IT General Controls (ITGCs), application controls, control testing, remediation activities, and audit readiness efforts
  • Evaluate technology, cybersecurity, and operational control effectiveness and recommend improvements to reduce organizational risk exposure
Operational Governance amp; Leadership
  • Drive maturity improvements across enterprise risk, business continuity, and governance programs
  • Develop and maintain risk management procedures, methodologies, standards, and documentation
  • Drive accountability through governance reviews, risk reporting, mitigation tracking, and issue escalation processes
  • Support audit readiness and control effectiveness activities within regulated environments
  • Provide enterprise leadership by influencing cross-functional teams, facilitating governance forums, and driving accountability for organizational risk management activities
  • Foster a collaborative, risk-aware, and business-focused culture across the organization
  • Oversee the enterprise technology policy governance process, including policy lifecycle management, periodic reviews, and alignment with regulatory and business requirements
WHAT YOU'LL BRING:
  • Bachelor's degree in Information Technology, Information Systems, Cybersecurity, Computer Science, Engineering, Risk Management, or related technical field
  • 8+ years of progressive experience in IT Risk Management, Cybersecurity Governance, Enterprise Risk Management, Information Security, Internal IT Audit, GRC, or related disciplines
  • 5+ years of leadership experience leading enterprise risk, cybersecurity governance, business continuity, compliance, or technology risk programs
  • Experience conducting enterprise technology risk assessments and control evaluations
  • Demonstrated experience assessing enterprise technology environments, including infrastructure, cloud platforms, cybersecurity technologies, identity and access management, endpoint technologies, and enterprise applications
  • Experience implementing or supporting frameworks such as NIST CSF, NIST RMF, ISO 27001, COBIT, SOX ITGC, HIPAA Security Rule, SOC 2, HITRUST, or similar frameworks
  • Demonstrated ability to lead enterprise risk management, business continuity, governance, or cybersecurity risk programs
  • Strong organizational skills and ability to balance strategic planning with hands-on execution
  • Experience influencing business and technology leaders regarding risk decisions
  • Strong analytical and problem-solving capabilities involving technology, cybersecurity, operational, and business risks
  • Demonstrated understanding of enterprise infrastructure, cloud platforms, identity and access management, endpoint technologies, data protection, and cybersecurity controls
  • Comfortable participating in technical reviews, architecture discussions, risk assessments, and remediation planning
  • Ability to evaluate technical control effectiveness and communicate risk implications to leadership
  • Strong written and verbal communication skills with executive-level presentation abilities
  • Ability to communicate technical risk concepts to both technical and non-technical audiences
  • Collaborative mindset with the ability to influence stakeholders across multiple business functions
  • Experience operating within regulated or compliance-focused environments
  • Familiarity with healthcare, laboratory, biotechnology, or highly regulated industry frameworks
  • Experience presenting risk assessments and recommendations to executive leadership
  • CISSP, CISM, CRISC, CGRC, CISA, CBCP, PMP, or equivalent certifications, preferred
  • Experience with ServiceNow GRC, Archer, AuditBoard, Drata, or similar platforms, preferred
  • Experience within healthcare, diagnostics, biotechnology, pharmaceutical, or regulated industries, preferred
  • Experience supporting AI governance, AI risk management, or emerging technology oversight, preferred
โ€‹WHAT YOU'LL GET:
  • Annual Base Salary Range $145,000 - $160,000
  • Discretionary Bonus opportunity
  • Comprehensive health coverage: Medical, Dental, and Vision
  • Insurance: Short/Long Term Disability and Life Insurance
  • Financial benefits: 401(k), Flex Spending Account
  • 120 hours of annual vacation
  • 72 hours of paid sick time off
  • 11 paid holidays + 3 floating holidays
  • Employee Assistance Program
  • Voluntary Benefits
  • Employee recognition program
WHAT TO EXPECT IN THE INTERVIEW PROCESS:

We want you to have a clear view of the IT Operations amp; End User Services Manager roleโ€”and we want to get to know the real you. Our interview process is designed to be thorough, transparent, and give you direct insight into what itโ€™s like to work here:

  1. Virtual Recruiter Screen โ€“ A conversation to understand your background, what motivates you, and where you're looking to grow.
  2. Hiring Manager Interview โ€“ A deeper discussion about your experience, skills, and approach.
  3. Final On-Site Interview โ€“ Tour our corporate headquarters; interview with additional members of the team to discuss alignment and fit.
Individual base compensation is based on various factors unique to each candidate, including skill set, experience, qualifications, and other job-related aspects.
Biodesix is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.