Job Requirements
Ashburn, VA
Public Trust Polygraph Unspecified
Career Level not specified
$170,000 - $189,500
Job Description
Cyber Risk Management Lead
On site in Ashburn, VA - Monday through Friday, 8:30am to 5:00pm
The Cyber Risk Management Lead leads the identification, communication and distribution of cybersecurity risks and actionable mitigations at both the tactical and strategic levels across a large federal IT environment. The Lead works closely with vulnerability assessment, security operations and cyber threat intelligence teams, Security Control Assessors, ISSMs, ISSOs and system owners to build a complete picture of cyber risk and to brief senior management on the organization's cyber risk posture.
Responsibilities:
Requirements:
Compensation: $170,000 - $189,500 per year
#cjpost
On site in Ashburn, VA - Monday through Friday, 8:30am to 5:00pm
The Cyber Risk Management Lead leads the identification, communication and distribution of cybersecurity risks and actionable mitigations at both the tactical and strategic levels across a large federal IT environment. The Lead works closely with vulnerability assessment, security operations and cyber threat intelligence teams, Security Control Assessors, ISSMs, ISSOs and system owners to build a complete picture of cyber risk and to brief senior management on the organization's cyber risk posture.
Responsibilities:
- Identify tactical risks by working with vulnerability assessment, security operations and cyber threat intelligence teams; review and recommend approval or denial of tactical change requests.
- Support prioritization of vulnerability remediation and identify common security-gap patterns using frameworks such as MITRE ATT&CK.
- Identify strategic risks by working with Security Control Assessors, ISSMs, ISSOs and system owners; support cyber acquisition risk management through templates and guidance tied to acquisition decision events.
- Develop and review Risk Assessment Reports (RARs) and Cyber Risk Recommendation Memos.
- Conduct risk assessments, gathering data on incidents, vulnerabilities, POA&Ms, Known Exploited Vulnerabilities, loss-magnitude metrics, threat actors and TTPs.
- Support development of an organizational risk tolerance level and information system risk profiles aligned to the NIST Cybersecurity Framework.
- Maintain a near-real-time risk management dashboard and cybersecurity risk register for senior management visibility.
- Brief senior management on cyber risk posture and support Cybersecurity Supply Chain Risk Management (C-SCRM) documentation.
Requirements:
- Bachelor's degree in Information Assurance, Computer Science or a related field.
- At least 7 years of professional experience in information assurance, cybersecurity, risk management or compliance; or, with a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity or a related field, at least 5 years of such experience.
- One of the following certifications: CompTIA Security+, ISC2 CISSP, ISACA CISM, ISACA CRISC, GIAC GCED or CEH.
- Demonstrated experience with risk assessments, NIST SP 800-37 RMF, the NIST Cybersecurity Framework and NIST SP 800-53 security controls.
- Experience managing POA&Ms, reviewing vulnerability scan results, reviewing audit logs in an enterprise logging system, and reviewing OS, application and database security baseline configurations.
- Experience performing security impact analysis on change requests and writing security policy.
- Understanding of OMB M-22-09 and the Zero Trust Architecture pillars.
- US Citizenship (no dual citizenship) and the ability to pass a federal background investigation in order to be granted access to sensitive information.
Compensation: $170,000 - $189,500 per year
#cjpost
group id: 10238000