1

Technology Risk Jobs in Virginia (NOW HIRING)

Principal Risk Specialist

Richmond, VA · On-site

$97K/yr

Ensure assigned Tech controls are operating effectively and as designed/intended. Own the operational oversight adhering to appropriate policies/standards and provide risk consulting for assigned ...

Ensure assigned Tech controls are operating effectively and as designed/intended. Own the operational oversight adhering to appropriate policies/standards and provide risk consulting for assigned ...

Ensure assigned Tech controls are operating effectively and as designed/intended. Own the operational oversight adhering to appropriate policies/standards and provide risk consulting for assigned ...

Principal Risk Specialist

Mclean, VA · On-site

$101K/yr

Ensure assigned Tech controls are operating effectively and as designed/intended. Own the operational oversight adhering to appropriate policies/standards and provide risk consulting for assigned ...

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...

Showing results 21-40

Technology Risk information

See Virginia salary details

$14

$30

$73

How much do technology risk jobs pay per hour?

As of Sep 10, 2026, the average hourly pay for technology risk in Virginia is $30.08, according to ZipRecruiter salary data. Most workers in this role earn between $19.33 and $38.37 per hour, depending on experience, location, and employer.

What is technology risk?

Technology risk refers to the potential for losses or disruptions in an organization due to failures, vulnerabilities, or misuse of technology systems and infrastructure. Professionals in technology risk assess, manage, and mitigate risks related to cybersecurity, data privacy, IT systems, and compliance with regulations. Their work is crucial for protecting sensitive information, ensuring business continuity, and maintaining trust with clients and stakeholders.

What are the key skills and qualifications needed to thrive in technology risk, and why are they important?

To thrive in Technology Risk, you need a solid understanding of IT systems, cybersecurity principles, risk management frameworks, and often a degree in information technology or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, vulnerability assessment software, and certifications such as CISA, CISSP, or CRISC are commonly required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess threats and convey complex risk issues to diverse stakeholders. These skills ensure organizations can proactively identify, assess, and mitigate technology risks to protect assets and maintain regulatory compliance.

What are some common challenges faced by professionals working in technology risk roles?

Professionals in Technology Risk often encounter challenges such as keeping up with rapidly evolving cyber threats, ensuring regulatory compliance across different jurisdictions, and effectively communicating technical risks to non-technical stakeholders. Balancing proactive risk mitigation with the need to support business innovation can also be demanding. Collaboration with IT, legal, and business units is essential to identify vulnerabilities and implement practical controls without hindering productivity.

What is the difference between Technology Risk vs Cybersecurity Analyst?

AspectTechnology RiskCybersecurity Analyst
Primary FocusIdentifying and managing technology-related risks to business operationsProtecting systems and data from cyber threats and attacks
CertificationsCRISC, CISSP, CISACISSP, CEH, Security+
Work EnvironmentRisk management teams, compliance departmentsSecurity operations centers, IT security teams
Industry UsageFinance, healthcare, technology firmsAny industry with digital assets, especially finance and government

Technology Risk professionals focus on assessing and mitigating risks associated with technology systems and processes, ensuring compliance and reducing potential disruptions. Cybersecurity Analysts primarily work to defend systems from cyber threats, focusing on security measures and incident response. While both roles involve technology and security, their core objectives and daily tasks differ significantly.

What are the most commonly searched types of Technology Risk jobs in Virginia?

The most popular types of Technology Risk jobs in Virginia are:

Infographic showing various Technology Risk job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 80% Full Time, 16% Part Time, and 3% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $62,558 per year, or $30.1 per hour.

Principal Risk Specialist, Tech & Cyber Risk | Retail Bank

Mclean, VA • On-site

$101K/yr

Other

Posted 23 days ago


Key responsibilities

  • Drive end-to-end technology and cyber risk assessments, managing the lifecycle from implementation to remediation tracking.

  • Utilize project management and communication skills to prioritize risk initiatives, build stakeholder relationships, and guide risk and engineering partners.

  • Monitor risk metrics, oversee remediation efforts, and support compliance documentation and risk reporting activities.


Job description

Principal Risk Specialist, Tech & Cyber Risk

As a Principal Associate of Tech & Cyber Risk within Capital One’s Business Risk Office, you will enable and drive end-to-end risk management of the portfolio by partnering directly with risk partners, technology stakeholders, operations and engineering teams to identify, assess, and mitigate technology and cyber risks.

In this high-impact role, you will leverage strong project management, communication, and analytical skills to support cutting‑edge technology initiatives and promote strategic risk management across the organization. You will be hands‑on in evaluating and mitigating risks related to AI implementations, supporting the technology integration of acquired companies, and monitoring risk posture within large‑scale architecture transformation programs. By overseeing portfolio health, remediation efforts, tracking key metrics and performing assessments you will help teams proactively align with enterprise policies, ensuring the ongoing resilience and security of our technology ecosystem.

Key Responsibilities
  • End‑to‑End Risk Management & Execution
    • Drive end‑to‑end technology and cyber risk assessments, managing the lifecycle from tactical implementation and ongoing evaluation through to remediation tracking and successful risk finding closure.
    • Support the responsible implementation of AI applications and large‑scale architecture transformations by conducting timely risk assessments and ensuring project teams align with well‑managed best practices and enterprise risk frameworks.
  • Project Management & Stakeholder Engagement
    • Utilize strong project management skills to effectively prioritize risk initiatives, ensuring clear project scope and the timely delivery of impactful results.
    • Exhibit outstanding communication skills to build and manage strong stakeholder relationships across engineering, operations, cyber, risk functions, keeping all levels and lines of defense informed and influencing outcomes to drive project success.
    • Display strong advisory skills to guide risk and engineering partners through complex risk landscapes, adapting with agility to changing business demands and evolving technology environments.
  • Process Improvement & Program Execution
    • Drive continuous improvement within the Tech & Cyber Risk Office by identifying, designing, and implementing enhancements to streamline risk identification, assessment, and mitigation workflows.
  • Metrics, Reporting & Compliance
    • Monitor and analyze key risk metrics and dashboards, partnering closely with stakeholders to oversee remediation efforts and drive metrics toward target compliance levels.
    • Assist in preparing accurate compliance documentation and data for audit engagements, ensuring the overall tech risk posture is transparent and well‑documented.
    • Lead and facilitate recurring risk forums (e.g., Metrics reviews) to ensure progress visibility and stakeholder alignment.
    • Proactively own and drive RCSA (risk and control self‑assessment) workflows, acting as a lead or delegate to improve operational efficiency and risk coverage.
    • Develop and manage comprehensive risk measurement frameworks (KRI/metrics), ensuring actionable data‑driven insights are communicated to senior leadership.
Role Expectations & Desired Behaviors
  • Autonomy & Strategic Execution: Proactively identify, own, and resolve risks with limited supervision; exhibit structured problem‑solving to lead sub‑tasks and strategy.
  • Customer Focus & Reliability: Own the end‑to‑end customer process by facilitating project forums and anticipating partner needs to reduce portfolio risk.
  • Communication & Influence: Tailor messaging for diverse audiences (from peers to senior leadership); lead meeting agendas to drive consensus, influence outcomes, and ensure timely action.
  • Fungibility & SME Development: Actively develop deep domain expertise to rotate across core and adjacent risk roles, sharing knowledge to strengthen team capabilities and flexibility.
Basic Qualifications
  • 5+ years of experience in Technology Risk Management, Cybersecurity, IT Audit, or Technology Consulting.
Preferred Qualifications
  • Experience leveraging data analysis and visualization tools (e.g., Sheets, Pivot Tables, SQL, Tableau, Power BI) to derive risk insights and manage metrics.
  • Project management experience, including planning, execution, and delivery of strategic initiatives. Demonstrated success managing complex, cross‑functional risk or technology projects utilizing agile or waterfall methodologies.
  • Awareness of RCSA (Risk and Control Self‑Assessment) risk frameworks and methodologies.
  • Certifications such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), or Certified Information Systems Security Professional (CISSP).
  • Familiarity with AI risk management frameworks, or possession of/interest in obtaining certifications such as the Certified AI Governance Professional (AIGP).
  • Experience working within a Large Financial Services institution, highly regulated environment, or technology consulting organization.

At this time, Capital One will not sponsor a new applicant for employment authorization for this position.

McLean, VA: $131,300 - $149,800 for Principal Associate, Cyber Risk & Analysis
Richmond, VA: $119,400 - $136,200 for Principal Associate, Cyber Risk & Analysis

Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non‑discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug‑free workplace.

Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23‑A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901‑4920; New York City’s Fair Chance Act; Philadelphia’s Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

#J-18808-Ljbffr