> Markdown version of [/jobs/ext/1746241-principal-it-risk-management-analyst](https://www.wearedevelopers.com/jobs/ext/1746241-principal-it-risk-management-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal IT Risk Management Analyst - **Company:** Strategic Education, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $119,300.0 - $178,900.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, JIRA, CompTIA Security+, Cyber Security, Data Integrity, Technical Data Management Systems, RSA Archer Platform, Nexpose, CIS Benchmarks, Servicenow - **Published:** July 10, 2026 - **Apply:** https://strayer.wd1.myworkdayjobs.com/CAREERS/job/Remote/Principal-IT-Risk-Management-Analyst_R30058-3 ## About the Role Skills & Expertise * Strong leadership, analytical, and problem-solving skills with a risk-first mindset * Demonstrated team leadership through mentoring, coaching, or leading analysts * Ability to own workstreams and guide junior staff in a matrixed environment * Strong technical depth to identify risks, evaluate control effectiveness, and translate vulnerability and technical data into business risk * Deep knowledge of NIST CSF, CIS Controls v8, and related frameworks * Proven ability to build and manage an enterprise IT risk register and exception management program * Experience building and evolving risk metrics, KRIs, dashboards, and executive reporting * Hands-on experience with GRC platforms and workflow automation tools (e.g., Archer, ServiceNow GRC, OneTrust, Jira, Rapid7 Nexpose) and the ability to automate processes * Understanding of AI/ML risk domains, including model risk, data integrity, bias, and adversarial threats, with the ability to recommend controls * Experience drafting, reviewing, and improving information security policies and standards * Ability to communicate technical concepts and residual risk clearly to non-technical stakeholders, * 5+ years of IT risk management experience, with a focus on risk assessment, quantification, and risk register ownership (not primarily compliance or audit) * 3+ years mentoring or leading team members * Demonstrated experience mentoring analysts while owning and delivering discrete risk workstreams or program components * Experience conducting risk assessments aligned to NIST CSF, CIS Controls v8, or similar frameworks * Experience managing an IT risk register, risk exception processes, and residual risk documentation * Experience developing risk metrics, dashboards, and executive reporting * Experience with GRC platforms and workflow automation in a risk context * Experience managing risks related to emerging technologies, including artificial intelligence, * Bachelor's degree in a relevant discipline required; Master's degree preferred Preferred certifications: * CRISC (ISACA) * CISSP (ISC²) * CISM (ISACA) * CompTIA Security+ * CompTIA CySA+ * CompTIA CASP+ * CGEIT (ISACA) Other: * Must be able to travel occasionally should a business need arise. For most roles travel would not be common. Travel may involve plane, car or metro. In accordance with ADA policies, reasonable accommodations regarding travel limitations can be provided. Travel will be more common for roles such as Account Executives (25 - 50%), senior leaders (10 - 20%) or Capella Core Faculty (5 - 10%). * Ability to work onsite in Corporate or Campus location (in a typical office environment) may be required based on role. If so, this would include being mobile within the office, including movement from floor-to-floor using elevators or stairs. * If offsite or hybrid role, must have access to work in setting which enables meeting all requirements of the role (including privacy, reliable internet access, phone, ability to video conference, etc.) at a remote location. * This role may require lifting, however reasonable accommodations will be provided in accordance with our ADA policies. * Must be able to meet critical thinking and problem solving aspects aligned to job duties, as well as effectively communicating with co-workers. * Must be able to work more than 40 hours per week when business needs warrant. Accommodations related to schedule may be considered. * Able to access information using a computer. * Other essential functions and marginal job functions are subject to modification. ## Description The Principal IT Risk Management Analyst is a senior leader responsible for advancing the organization's IT risk management program. This is not a compliance or audit role. The successful candidate will have deep experience identifying, assessing, quantifying, and managing technology risk, along with the technical understanding needed to evaluate security controls, identify technology risks, and engage effectively with cybersecurity, engineering, and architecture teams. While the role does not require designing technical solutions or interpreting detailed system configurations, it does require the ability to understand how technology decisions, vulnerabilities, and control weaknesses translate into organizational risk and business impact. This role drives strategy, leads complex technology risk assessments, and partners across the enterprise to ensure technology risks are effectively identified, measured, managed, and communicated in alignment with organizational risk appetite and tolerance. Success in this role requires the ability to translate technical risk into meaningful business context for executive leadership., Strategic Leadership * Lead and evolve the IT security risk management program in alignment with organizational goals, risk appetite, and risk tolerance * Partner with executive leadership to shape risk strategy and drive enterprise-wide adoption * Serve as a key advisor on risk posture, translating technical findings into strategic business decisions Risk Assessment & Analysis * Identify, assess, and quantify technology risks by evaluating cybersecurity threats, operational vulnerabilities, and emerging technology risks using qualitative and quantitative methodologies * Conduct risk assessments using established frameworks, including NIST CSF and CIS Controls v8 * Translate technical findings into clear, actionable business risk and support risk-based decision making * Manage and maintain the enterprise IT risk register, including risk ownership, scoring, and lifecycle tracking Risk Mitigation & Governance * Design and implement IT security risk mitigation strategies and controls aligned with industry standards * Lead the risk exception management process, including evaluation, documentation, and risk acceptance decisions * Provide risk-informed guidance for complex technology initiatives, including emerging areas such as artificial intelligence and machine learning * Integrate IT security risk management practices into business and technology processes * Support the development and lifecycle management of information security policies and standards Risk Reporting & Insights * Define and evolve risk metrics, key risk indicators (KRIs), and risk appetite thresholds * Develop dashboards and reporting that translate risk data into actionable insights for executive and board-level audiences * Communicate complex risk concepts clearly to both technical and non-technical stakeholders Program Enablement & Continuous Improvement * Drive adoption of IT security risk platforms and workflow automation to improve efficiency and scalability * Identify and implement automation opportunities across risk management workflows * Continuously enhance risk methodologies, tools, and processes * Stay current on the evolving threat landscape, emerging technologies, and industry practices Mentorship & Development * Mentor and guide junior team members in direct or matrixed reporting relationships * Lead or own workstreams while providing direction and support to junior analysts ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [What Industries Outside of AI Are Hiring The Most AI Experts?](https://www.wearedevelopers.com/magazine/98-what-industries-outside-of-ai-are-hiring-the-most-ai-experts) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)