Jobs and Careers
ST

Principal IT Risk Management Analyst

Strayer University
Remote, United States, United StatesRemotefull_timeVerifiedPosted 9 Jul 2026
💰 $178,900/yr($119,300/yr$178,900/yr)

About the role

At Strategic Education Inc., our mission is to enable economic mobility through education. Through our portfolio of institutions and learning solutions, we serve working adult learners by improving affordability, engagement, and workforce readiness. This mission guides our approach to technology, cybersecurity, and risk management.

The Principal IT Risk Management Analyst is a senior leader responsible for advancing the organization's IT risk management program. This is not a compliance or audit role. The successful candidate will have deep experience identifying, assessing, quantifying, and managing technology risk, along with the technical understanding needed to evaluate security controls, identify technology risks, and engage effectively with cybersecurity, engineering, and architecture teams. While the role does not require designing technical solutions or interpreting detailed system configurations, it does require the ability to understand how technology decisions, vulnerabilities, and control weaknesses translate into organizational risk and business impact.

This role drives strategy, leads complex technology risk assessments, and partners across the enterprise to ensure technology risks are effectively identified, measured, managed, and communicated in alignment with organizational risk appetite and tolerance. Success in this role requires the ability to translate technical risk into meaningful business context for executive leadership.

Essential Duties & Responsibilities 

Strategic Leadership 

  • Lead and evolve the IT security risk management program in alignment with organizational goals, risk appetite, and risk tolerance 

  • Partner with executive leadership to shape risk strategy and drive enterprise-wide adoption 

  • Serve as a key advisor on risk posture, translating technical findings into strategic business decisions 

Risk Assessment & Analysis 

  • Identify, assess, and quantify technology risks by evaluating cybersecurity threats, operational vulnerabilities, and emerging technology risks using qualitative and quantitative methodologies 

  • Conduct risk assessments using established frameworks, including NIST CSF and CIS Controls v8 

  • Translate technical findings into clear, actionable business risk and support risk-based decision making 

  • Manage and maintain the enterprise IT risk register, including risk ownership, scoring, and lifecycle tracking 

Risk Mitigation & Governance 

  • Design and implement IT security risk mitigation strategies and controls aligned with industry standards 

  • Lead the risk exception management process, including evaluation, documentation, and risk acceptance decisions 

  • Provide risk-informed guidance for complex technology initiatives, including emerging areas such as artificial intelligence and machine learning 

  • Integrate IT security risk management practices into business and technology processes 

  • Support the development and lifecycle management of information security policies and standards 

Risk Reporting & Insights 

  • Define and evolve risk metrics, key risk indicators (KRIs), and risk appetite thresholds 

  • Develop dashboards and reporting that translate risk data into actionable insights for executive and board-level audiences 

  • Communicate complex risk concepts clearly to both technical and non-technica

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Strayer University

View company profile →