1

Technology Risk Manager Jobs in Pennsylvania (NOW HIRING)

The Country Risk Manager (CRM) supports the Head of Country Risk in leading the enterprise country ... Every day, our teams harness cutting-edge AI and breakthrough technologies to collaborate with ...

The Trust Risk Manager needs to have lived, practical experience to guide incremental program ... Basic understanding of cloud hosting, infrastructure technologies, SaaS, and cloud services (e.g ...

Showing results 21-40

Technology Risk Manager information

See Pennsylvania salary details

$51.6K

$111.8K

$170.4K

How much do technology risk manager jobs pay per year?

As of Aug 25, 2026, the average yearly pay for technology risk manager in Pennsylvania is $111,824.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,200.00 and $129,300.00 per year, depending on experience, location, and employer.

What is a technology risk manager?

Technology Risk Managers are professionals responsible for identifying, assessing, and mitigating risks associated with information technology systems and processes within an organization. They ensure that IT operations comply with regulations and best practices while safeguarding data and technology assets from threats such as cyberattacks, data breaches, and system failures. Their work involves developing risk management strategies, conducting risk assessments, and collaborating with other departments to ensure the organization's technology infrastructure is secure and resilient.

What are some common challenges technology risk managers face when working across different departments?

Technology Risk Managers often encounter challenges in aligning risk management strategies with the priorities of various business units. Departments may have differing levels of risk tolerance, technical understanding, and resource availability, which can make establishing consistent policies and controls difficult. Success in the role relies on strong communication and negotiation skills, as well as the ability to educate stakeholders about the importance of risk mitigation while balancing business objectives. Building collaborative relationships and maintaining flexibility are key to overcoming these cross-departmental challenges.

What are the key skills and qualifications needed to thrive as a technology risk manager, and why are they important?

To thrive as a Technology Risk Manager, you need expertise in risk assessment, cybersecurity principles, and regulatory compliance, often supported by a degree in information security or related fields. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC (governance, risk, and compliance) tools, and certifications like CISM or CISSP are typically required. Strong analytical thinking, communication, and stakeholder management skills help you translate technical risks into business terms and coordinate mitigation efforts. These abilities are critical to proactively identifying threats and ensuring organizational resilience against evolving technology risks.

What is the difference between Technology Risk Manager vs Cybersecurity Analyst?

AspectTechnology Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISACISSP, CEH, Security+
Work EnvironmentRisk assessment, policy development, complianceMonitoring security threats, incident response, vulnerability analysis
Industry UsageFinancial, healthcare, technology firmsIT security teams, government agencies, corporations

The Technology Risk Manager focuses on identifying and mitigating overall technology risks and ensuring compliance, while the Cybersecurity Analyst concentrates on protecting systems from security threats and responding to incidents. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

What cities in Pennsylvania are hiring for Technology Risk Manager jobs?

Cities in Pennsylvania with the most Technology Risk Manager job openings:

Infographic showing various Technology Risk Manager job openings in Pennsylvania as of August 2026, with employment types broken down into 82% Full Time, 17% Part Time, and 1% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $111,824 per year, or $53.8 per hour.

Information Technology Enterprise Risk Manager

Pittsburgh, PA

Northwest
51 - 200 employees

Full-time

Posted 12 days ago


Job description

OH0713 NW Bancshares HQ, PA0728 Pittsburgh Business Office

Job Description

The Information Technology Enterprise Risk Manager within the Risk Management organization is responsible for supporting the execution and oversight of Northwest's Operational Risk framework as it relates to information technology, information security and data risks. This role will adapt previous experience and industry leading practices to identify, assess, monitor, and report key technology risks, helping to embed risk awareness into strategic and operational decision-making. This role will help to support activities including, but not limited to, Risk and Control Self-Assessments (RCSA), risk management training, issues management, risk management and policy and procedure governance.
Essential Functions
Provide oversight of the Risk and Control Self-Assessment (RCSA) activities within technology-related processes, performing credible challenge of the conclusions derived from the RCSA, and monitoring routines
Independently assess risks and drive actions to address the root causes that persistently lead to significant residual operational risk by challenging both historical and proposed practices
Validate the first line's control testing and independently test the first line's information technology, information security and data controls to verify the design and operational effectiveness
Leverage the current Enterprise Risk Management framework and partner with IT, IS and Data teams to further mature the second line of defense technology and information security risk assessments, document controls, identify gaps, and create action plans for critical IT processes, including validation and testing to ensure IT risk programs are implemented and executed appropriately
Provide support to key risk assessments and perform credible challenge of methodologies and results, including the annual Gramm-Leach-Bliley Act (GLBA) Assessment, Authentication and Access Assessments, Payment Card Industry Data Security Standard assessment and HIPAA compliance
Consult with the first line on the creation of issues to address control gaps/failures and monitor the progress of remediation, ensuring timely and accurate mitigation, and providing credible challenge to support the timely closure of issues
Support the establishment of metrics to quantify and measure technology risks and provide review and challenge to the action plans of deficient metrics
Perform oversight of the front-line's management of IT/IS/Data activities and exception handling, including the documentation of IT changes, end-of-life technology, resiliency enhancements and testing, business impact analysis, vulnerability management, completion of action items related to addressing technology failures and disruptions, CDEs and data rules
Provide credible challenge of the first line's IT/IS/Data policies and standards ensuring compliance under Northwest's corporate governance requirements
Analyze losses in the Business associated with IT failures, disruptions and errors to understand how losses were incurred, determined lessons learned, identify root causes and developing recommendations for future risk avoidance
Additional Essential Functions
Ensure compliance with Northwest's policies and procedures, and Federal/State regulations
Navigate Microsoft Office Software, computer applications, and software specific to the department in order to maximize technology tools and gain efficiency
Work as part of a team
Work with on-site equipment
What You Bring to the Team
Additional job duties as assigned by management
QUALIFICATIONS
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education
Bachelor's Degree Degree in Management Information Systems, Cybersecurity, or Business Administration
Work Experience
8 - 12 years Cybersecurity/information technology experience And
6 - 8 years Prior financial institution experience
Additional Knowledge, Skills and Abilities
Deep understanding of information technology, information security and data principles and best practices
Proficient in risk management methodologies, frameworks, and execution of the Risk and Control Self-Assessment (RCSA)
Knowledge of relevant compliance regulations and standards (e.g., NIST CSF, GLBA, PCI DSS, HIPAA)
Experience with vulnerability scanning and penetration testing tools
Strong analytical and problem-solving skills
Excellent communication and reporting abilities
Deep understanding of information technology and information security principles and best practices
Proficient in risk management methodologies and frameworks
Knowledge of relevant compliance regulations and standards (e.g., NIST CSF, GLBA, PCI DSS, HIPAA)
Experience with vulnerability scanning and penetration testing tools
Strong analytical and problem-solving skills
Excellent communication and reporting abilities
Licenses and Certifications
Infrastructure Library (ITIL)
Certified Information System Auditor
Certified Information Security Manager (CISM)
Certified Risk and Information Systems Control
Certified Information Systems Security Professional (CISSP)

Northwest is an equal opportunity employer. We are committed to creating an inclusive environment for all employees.