1

Technology Risk Manager Jobs in Baltimore, MD (NOW HIRING)

Build risk register management capabilities: creation, tracking, scoring, mitigation planning, and ... As the world's leading mission capability integrator and transformative enterprise IT provider, we ...

Build risk register management capabilities: creation, tracking, scoring, mitigation planning, and ... As the world's leading mission capability integrator and transformative enterprise IT provider, we ...

Build risk register management capabilities: creation, tracking, scoring, mitigation planning, and ... As the world's leading mission capability integrator and transformative enterprise IT provider, we ...

Supports security authorization activities in compliance with National Institute of Standards and Technology Risk Management Framework (NIST RMF). (U) The Information Systems Security Officer (ISSO ...

ISSO

Annapolis Junction, MD · On-site

$100K - $240K/yr

Supports security authorization activities in compliance with National Institute of Standards and Technology Risk Management Framework (NIST RMF). Salary range: $100k - $240k Salary for this position ...

next page

Showing results 1-20

Technology Risk Manager information

See Baltimore, MD salary details

$51.2K

$110.8K

$168.9K

How much do technology risk manager jobs pay per year?

As of May 30, 2026, the average yearly pay for technology risk manager in Baltimore, MD is $110,846.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,400.00 and $128,200.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Technology Risk Manager, and why are they important?

To thrive as a Technology Risk Manager, you need expertise in risk assessment, cybersecurity principles, and regulatory compliance, often supported by a degree in information security or related fields. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC (governance, risk, and compliance) tools, and certifications like CISM or CISSP are typically required. Strong analytical thinking, communication, and stakeholder management skills help you translate technical risks into business terms and coordinate mitigation efforts. These abilities are critical to proactively identifying threats and ensuring organizational resilience against evolving technology risks.

What are some common challenges Technology Risk Managers face when working across different departments?

Technology Risk Managers often encounter challenges in aligning risk management strategies with the priorities of various business units. Departments may have differing levels of risk tolerance, technical understanding, and resource availability, which can make establishing consistent policies and controls difficult. Success in the role relies on strong communication and negotiation skills, as well as the ability to educate stakeholders about the importance of risk mitigation while balancing business objectives. Building collaborative relationships and maintaining flexibility are key to overcoming these cross-departmental challenges.

What are Technology Risk Managers?

Technology Risk Managers are professionals responsible for identifying, assessing, and mitigating risks associated with information technology systems and processes within an organization. They ensure that IT operations comply with regulations and best practices while safeguarding data and technology assets from threats such as cyberattacks, data breaches, and system failures. Their work involves developing risk management strategies, conducting risk assessments, and collaborating with other departments to ensure the organization's technology infrastructure is secure and resilient.

What is the difference between Technology Risk Manager vs Cybersecurity Analyst?

AspectTechnology Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISACISSP, CEH, Security+
Work EnvironmentRisk assessment, policy development, complianceMonitoring security threats, incident response, vulnerability analysis
Industry UsageFinancial, healthcare, technology firmsIT security teams, government agencies, corporations

The Technology Risk Manager focuses on identifying and mitigating overall technology risks and ensuring compliance, while the Cybersecurity Analyst concentrates on protecting systems from security threats and responding to incidents. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

What cities near Baltimore, MD are hiring for Technology Risk Manager jobs? Cities near Baltimore, MD with the most Technology Risk Manager job openings:
Infographic showing various Technology Risk Manager job openings in Baltimore, MD as of May 2026, with employment types broken down into 100% Full Time. Highlights an 89% In-person, and 11% Remote job distribution, with an average salary of $110,846 per year, or $53.3 per hour.
Cyber Engineer 4 - Annapolis Junction, MD

Cyber Engineer 4 - Annapolis Junction, MD

M.C. Dean, Inc

Annapolis, MD • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 26 days ago


M.C. Dean rating

7.5

Company rating: 7.5 out of 10

Based on 42 frontline employees who took The Breakroom Quiz

221st of 350 rated engineering


Job description

Overview
About M.C. Dean
M.C. Dean is Building Intelligence. We design, build, operate, and maintain cyber-physical solutions for the nation's most mission-critical facilities, secure environments, complex infrastructure, and global enterprises. With over 7,000 employees, our capabilities span electrical, electronic security, telecommunications, life safety, automation and controls, audiovisual, and IT systems. Headquarters in Tysons, Virginia, M.C. Dean delivers resilient, secure, and innovative power and technology solutions through engineering expertise and smart systems integration.
Why Join Us?
Our people are passionate about engineering innovation that improves lives and drives impactful change. Guided by our core values-agility, expertise, and trust-we foster a collaborative and forward-thinking work environment. At M.C. Dean, we are committed to building the next generation of technical leaders in electrical, engineering, and cybersecurity industries.
Seeking a Cyber Engineer 4 that is able to work with a dynamic team of system engineers and administrators responsible for design, implementation, operations & maintenance, and cybersecurity for large complex resilient hardware and virtualized infrastructure. This position will perform Cybersecurity / Information Assurance for all customer managed systems, applications, and hardware.
Responsibilities
  • Design, implement, and maintain Department of Defense provided Security and Vulnerability tools including Host Based Security System (HBSS), Splunk, and Microsoft Defender for Endpoints.
  • Support authorization/reauthorization efforts in alignment with the Department of Defense Risk Management Framework (RMF), NIST 800-53 (e.g. develop and apply Active Directory Group Policy Objects, develop deployment packages, etc.).
  • Analyze new security requirements, define courses of action, and design enterprise solutions, coordinating with engineering and operations teams to implement within the environment.
  • Formalize and execute a process for communicating vulnerability results in a manner understood by technical and non-technical stakeholders based on risk tolerance and impact to the environment.
  • Leverage vulnerability database sources to understand each weakness, its probability and remediation options, including vendor-supplied fixes and workarounds.
  • Design, implement, and maintain, scripts used in asset discovery and vulnerability status.
  • Conduct continuous independent discovery and vulnerability scans/security assessments of enterprise-wide assets and proactive control testing.
  • Set up and execute Nessus scans; establish automated reporting.
  • Document, prioritize, and formally report asset and vulnerability state, along with remediation recommendations and validation.
  • Coordinate with system owners and system administrators/technical points of contact to identify system vulnerabilities, conduct vulnerability analysis, and formulate remediation strategies.
  • Develop packages for complex remediation efforts and coordinate with vulnerability remediation specialists for deployment.
  • Support and monitor patch management compliance across the infrastructure to align to audit requirements.
  • Identify and apply DISA Security Technical Implementation Guide (STIG) benchmarks.
  • Conduct manual STIG reviews.
  • Support preparation of Plan of Action & Milestones (POAM) development to support compliance and authorization/reauthorization activities.
  • Prepare and disseminate regular Cyber Compliance/vulnerability reporting; interact with the customer to explain results and address issues.
  • Contribute to the development of Standard Operating Procedures, Work Instructions, User Guides, and checklists.
  • Work as a team to consistently learn and share advanced skills and foster team excellence.
  • Actively collaborate with the ISSO to develop, maintain, and enhance cyber security controls.
  • Collaborate with security groups such as red teams, threat intelligence and risk management to form a holistic team dedicated to thwarting attackers and reducing attack surface.

Qualifications
Clearance/Citizen Type: Applicants selected will be subject to a government security investigation and may meet eligibility requirements, including U.S. Citizenship, for access to classified information; ACTIVE TS/SCI w/ Poly clearance REQUIRED.
Education:
  • 5+ Years of Experience with a Master's Degree in Information Technology, Risk Management, Cybersecurity
  • 7+ Years of Experience with a Bachelor's Degree in Information Technology, Risk Management, Cybersecurity

Required Progressive Experience:
  • Working with industry and government agencies on the design of platforms and integrated systems Working on government and/commercial projects implementing cybersecurity requirements in a variety of industrial control systems (e.g., building management, electronic security, fire alarm/mass notification, electrical distribution, power management, etc.)
  • Proficiency with ACAS and HBSS and mitigation strategies
  • Developing policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data
  • Assessment, mitigation, and closure of network vulnerabilities and vulnerability management eMASS
  • Establishing, managing, and tracking of Plan of Action & Milestones (POA&M) Applying STIGs to servers, databases, applications, and other hardware Security Readiness Review (SRR) Tools (scripts and ACAS)
  • Ability to identify, maintain, and troubleshoot control network components
  • Excellent understanding of the DoD RMF lifecycle and NIST 800-53 controls implementation
  • Awareness of NIST Special Publication 800-82, Guide to Industrial Control Systems (ICS) Security and UFC 4-010-06 Unified Facilities Criteria (UFC) Cybersecurity of Facility
  • Working knowledge of operational control systems and implementing a variety of security assessment tools
  • Working knowledge of other operational control systems
  • Familiarity with DoDIN CCRI/CCORI and CYBERCOM TASKORDS
  • Familiarity with various industry products

One of the Required Certifications:
  • CASP CE CISSP CISSP - ISSAP CISSP - ISSEP CSSLP CISA CISM GCED GCIH

Also:
  • Strong Oral, Written and Presentation Skills with the ability and experience communicating directly with Customers
  • Demonstrated background working with multidisciplinary teams
  • Demonstrated time management and organization skills to meet deadlines and quality objectives
  • Strong MS Excel, Word, PowerPoint, AUTOCAD, Cameo and Visio Skills is a plus.

We offer an excellent benefits package including:
  • A competitive salary
  • Medical, dental, vision, life, and disability insurance
  • Paid time off
  • Tuition reimbursement
  • 401k Retirement Plan
  • Military Reserve pay offset
  • Paid maternity leave

Abilities:
  • Exposure to computer screens for an extended period of time.
  • Sitting for extended periods of time.
  • Reach by extending hands or arms in any direction.
  • Have finger dexterity in order to manipulate objects with fingers rather than whole hands or arms, for example, using a keyboard.
  • Listen to and understand information and ideas presented through spoken words and sentences.
  • Communicate information and ideas in speaking so others will understand.
  • Read and understand information and ideas presented in writing.
  • Apply general rules to specific problems to produce answers that make sense.
  • Identify and understand the speech of another person.

Pay Range
USD $125,120.00 - USD $187,680.00 /Yr.

What M.C. Dean employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


M.C. Dean logo

About M.C. Dean

Sourced by ZipRecruiter

M.C. Dean is Building Intelligence®. We design, build, operate, and maintain cyber-physical solutions for the nation's most recognizable mission-critical facilities, secure environments, complex infrastructure, and global enterprises. The company's capabilities include electrical, electronic security, telecommunications, life-safety, instrumentation and control, and command and control systems. M.C. Dean is headquartered in Tysons, Virginia, and employs more than 5,100 professionals who engineer and deploy automated, secure, and resilient power and technology systems; and deliver the management platforms essential for long-term system sustainability.

Industry

Engineering professional services

Company size

10,000+ Employees

Headquarters location

Tysons, VA, US

Year founded

1949

Social media