Jobs › Maryland › Crownsville › Cybersecurity Risk Management Manager
Cybersecurity Risk Management Manager
State of Maryland (DoIT) is hiring for the role of Cybersecurity Risk Management Manager, Crownsville, MD (On-site). This is an AI Governance role in the governance, risk, and compliance field. Review the full details below and apply directly with State of Maryland (DoIT).
Leads development and implementation of a centralized cybersecurity risk management framework across Maryland's state agencies, architecting and building a statewide framework aligned with NIST standards while establishing third-party risk management programs and ensuring regulatory compliance. Enterprise-wide risk management: designs risk policies and controls, conducts risk assessments and security gap analyses across agencies, establishes Key Risk Indicators and Key Performance Indicators, provides strategic guidance to executive leadership, and leads continuous monitoring. Third-party risk: develops a vendor risk framework, assesses cloud providers and contractors, and coordinates with procurement and legal on contract security requirements. Regulatory compliance: ensures compliance with federal and state cybersecurity, privacy, and AI regulations, leads internal audits and risk reviews, and designs incident response strategies. Minimum qualifications: Bachelor's degree in cybersecurity, IT, or related field and four years' experience creating and maintaining risk management programs aligned with state and federal standards, including one year of supervisory experience; six years' experience may substitute for the degree.
Location and market context
This role is based in Crownsville on-site. Local candidates benefit from being close to State of Maryland (DoIT)'s teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About AI governance roles
AI governance sits at the intersection of policy, risk, and engineering. Teams are standing up model inventories, use-case intake and review, risk classification, and control monitoring as regulation and board scrutiny of AI intensify. Roles like this one are typically evaluated against frameworks such as NIST AI RMF, ISO/IEC 42001, the EU AI Act, and internal model-risk and privacy practices.
How to position yourself for this AI governance role
Strong candidates emphasize experience translating policy into operational controls, working across legal, compliance, security, product, and data teams, documenting AI system risks, and supporting governance processes. In your resume and outreach, tie your experience to how State of Maryland (DoIT) would apply NIST AI RMF, ISO/IEC 42001, the EU AI Act, and internal model-risk and privacy practices, and lead with concrete outcomes rather than duties.
Similar GRC roles
- Intelligence Analyst - Critical Infrastructure Protection · University of Baltimore · Baltimore, MD
- Information Systems Security Manager (ISSM) · University of Maryland · College Park, MD
- Critical & Emerging Technology Research Professional · University of Maryland (ARLIS) · College Park, MD
- Director of Governance, Risk & Compliance (GRC) · State of Maryland (DoIT) · Crownsville, MD
- Compliance Training Technology Specialist · Johns Hopkins University · Baltimore, MD
- Senior Strategist, AI Governance Field Coordination · Future Matters · San Francisco OR Washington DC, California
- Senior Manager - Data & AI Governance · Mercury · San Francisco, CA
- Principal Program Manager, Cyber Security - Frontier AI Models · Comcast · Philadelphia, PA
More GRC jobs in Crownsville
- Lead, Governance, Risk & Compliance (Remote) · Emergent BioSolutions · Gaithersburg, MD
- Senior Compliance Manager · World Relief · Towson, MD
- Chief Compliance Officer · Institutional Shareholder Services · Rockville, MD
Want to be next in a role like this?
Roles like Cybersecurity Risk Management Manager in Crownsville, MD open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.