Principal IT Risk Management Analyst
Strayer UniversityAbout the role
The Principal IT Risk Management Analyst is a senior leader responsible for advancing the organization's IT risk management program. This is not a compliance or audit role. The successful candidate will have deep experience identifying, assessing, quantifying, and managing technology risk, along with the technical understanding needed to evaluate security controls, identify technology risks, and engage effectively with cybersecurity, engineering, and architecture teams. While the role does not require designing technical solutions or interpreting detailed system configurations, it does require the ability to understand how technology decisions, vulnerabilities, and control weaknesses translate into organizational risk and business impact.
This role drives strategy, leads complex technology risk assessments, and partners across the enterprise to ensure technology risks are effectively identified, measured, managed, and communicated in alignment with organizational risk appetite and tolerance. Success in this role requires the ability to translate technical risk into meaningful business context for executive leadership.
Essential Duties & Responsibilities
Strategic Leadership
Lead and evolve the IT security risk management program in alignment with organizational goals, risk appetite, and risk tolerance
Partner with executive leadership to shape risk strategy and drive enterprise-wide adoption
Serve as a key advisor on risk posture, translating technical findings into strategic business decisions
Risk Assessment & Analysis
Identify, assess, and quantify technology risks by evaluating cybersecurity threats, operational vulnerabilities, and emerging technology risks using qualitative and quantitative methodologies
Conduct risk assessments using established frameworks, including NIST CSF and CIS Controls v8
Translate technical findings into clear, actionable business risk and support risk-based decision making
Manage and maintain the enterprise IT risk register, including risk ownership, scoring, and lifecycle tracking
Risk Mitigation & Governance
Design and implement IT security risk mitigation strategies and controls aligned with industry standards
Lead the risk exception management process, including evaluation, documentation, and risk acceptance decisions
Provide risk-informed guidance for complex technology initiatives, including emerging areas such as artificial intelligence and machine learning
Integrate IT security risk management practices into business and technology processes
Support the development and lifecycle management of information security policies and standards
Risk Reporting & Insights
Define and evolve risk metrics, key risk indicators (KRIs), and risk appetite thresholds
Develop dashboards and reporting that translate risk data into actionable insights for executive and board-level audiences
Communicate complex risk concepts clearly to both technical and non-technica
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s