user avatar

Cyber Risk Management Analyst

Warriors Solutions

Posted today

Job Requirements

Ashburn, VA
Secret Polygraph Unspecified
Mid Level Career (5+ yrs experience)
$100,000 - $150,000

Job Description



Cyber Risk Management Analyst

Summary:

The Cyber Risk Management Analyst Mid conducts cyber risk analyses and supports the identification, documentation, communication, and tracking of tactical and strategic cybersecurity risks across the CBP environment. The role integrates operational, compliance, vulnerability, threat, and system information into practical risk recommendations and decision-support products.

Location:
  • Primary duty location: Government site in the Washington, DC metropolitan area, primarily Ashburn, VA.
  • Telework may be approved, but should not be the expectation.
  • Travel to CBP locations may be required based on assigned work; role-specific travel expectations are identified below

Qualifications:
  • Relevant cybersecurity, information assurance, risk management, compliance, or information systems risk assessment experience
  • Experience with cyber risk assessments, NIST RMF, NIST Cybersecurity Framework, NIST SP 800-53 controls, POA&Ms, vulnerability findings, and security impact analysis
  • Knowledge of cyber risk communication, risk registers, risk profiles, risk acceptance, Zero Trust concepts, and security policy or procedure development
  • Security+ required; CISSP, CISM, CRISC, GCED, CEH, or comparable certification preferred
  • Strong analytical writing, briefing, and stakeholder coordination skills
  • U.S. citizenship and ability to obtain and maintain the required CBP background investigation

Duties and Responsibilities:
  • Gather and analyze security incidents, vulnerabilities, POA&Ms, known exploited vulnerabilities, threat actors, tactics, techniques, procedures, and other risk data
  • Develop or update risk assessments, risk profiles, risk registers, Risk Assessment Reports, Cyber Risk Recommendation Memos, dashboards, reports, and briefings
  • Evaluate proposed technical changes and provide cyber risk and security impact recommendations
  • Support prioritization of vulnerability remediation, POA&Ms, risk responses, and common security gaps across systems
  • Coordinate with vulnerability assessment, SOC, CTI, ISSO, ISSM, SCA, system owner, and other stakeholders to build tactical and strategic views of cyber risk
  • Support cybersecurity supply chain risk management documentation, acquisition risk activities, SOPs, playbooks, metrics, and historical trend reporting
  • Communicate actionable risk and mitigation recommendations to technical stakeholders and leadership

Decision-Making Authority:

The Cyber Risk Management Analyst Mid may select analytical approaches, validate routine risk data, maintain assigned risk records, and recommend prioritization, mitigation, and escalation actions. Formal risk acceptance, funding, policy, and authorization decisions remain with authorized Government officials.

Salary Range
$100,000 - $150,000

Posted: Wednesday, October 7, 2026

Job # 14930
group id: 10364120

Similar Jobs


Job Category
IT - Security
Clearance Level
Secret