1

Cyber Risk Management Jobs in Washington (NOW HIRING)

In this role, you will leverage your expertise in cyber strategy, technology risk, and solution management to guide client teams in defining and executing their Cyber Tech Risk programs-shaping ...

Senior Cyber Vulnerability Analyst

Falls Church, VA

$106.70K - $137.60K/yr

Use knowledge of Risk Management Framework (RMF) to map cyber vulnerabilities and mitigations to NIST SP 800-53 controls and ensure compliance with regulatory requirements, best practices, and ...

Senior Cyber Vulnerability Analyst

Falls Church, VA · On-site

$106.70K - $137.60K/yr

Use knowledge of Risk Management Framework (RMF) to map cyber vulnerabilities and mitigations to NIST SP 800-53 controls and ensure compliance with regulatory requirements, best practices, and ...

next page

Showing results 1-20

Cyber Risk Management information

See Washington salary details

$16

$34

$83

How much do cyber risk management jobs pay per hour?

As of May 30, 2026, the average hourly pay for cyber risk management in Washington is $34.36, according to ZipRecruiter salary data. Most workers in this role earn between $22.07 and $43.85 per hour, depending on experience, location, and employer.

What is a Cyber Risk Management job?

A Cyber Risk Management job involves identifying, assessing, and mitigating cybersecurity risks that could impact an organization. Professionals in this field develop risk management frameworks, implement security controls, and ensure compliance with industry regulations. They work closely with IT and business teams to minimize cyber threats, such as data breaches and ransomware attacks. Their goal is to protect sensitive information and maintain business continuity.

What are the key skills and qualifications needed to thrive in the Cyber Risk Management position, and why are they important?

To thrive in Cyber Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance, often supported by a degree in cybersecurity, information technology, or a related field. Familiarity with tools such as risk management software, vulnerability assessment platforms, and certifications like CISSP, CISM, or CRISC is highly valued. Excellent analytical thinking, communication, and problem-solving skills help professionals effectively advise stakeholders and coordinate incident response efforts. These skills are crucial for identifying, evaluating, and mitigating cyber risks to safeguard organizational assets and ensure business continuity.

What are some common challenges faced in a Cyber Risk Management role, and how are they typically addressed?

Professionals in Cyber Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, ensuring compliance with complex regulations, and balancing security needs with business objectives. Addressing these issues requires continuous learning, leveraging up-to-date threat intelligence, and collaborating closely with IT, legal, and management teams to develop effective risk mitigation strategies. Many organizations encourage ongoing training and participation in industry events to stay current, while fostering a culture of open communication to quickly identify and address vulnerabilities. Embracing a proactive and adaptable approach ensures that cyber risks are managed effectively while supporting the organization’s goals.
What are popular job titles related to Cyber Risk Management jobs in Washington? For Cyber Risk Management jobs in Washington, the most frequently searched job titles are:
What job categories do people searching Cyber Risk Management jobs in Washington look for? The top searched job categories for Cyber Risk Management jobs in Washington are:
What cities in Washington are hiring for Cyber Risk Management jobs? Cities in Washington with the most Cyber Risk Management job openings:
Infographic showing various Cyber Risk Management job openings in Washington as of May 2026, with employment types broken down into 1% As Needed, 48% Full Time, 47% Part Time, 2% Temporary, 1% Contract, and 1% Nights. Highlights an 75% Physical, and 25% Hybrid job distribution, with an average salary of $71,466 per year, or $34.4 per hour.
Head of Enterprise Risk Management - Mobility

Head of Enterprise Risk Management - Mobility

S&P Global

Centreville, VA • On-site

Full-time

Posted 5 days ago


S&P Global rating

8.0

Company rating: 8.0 out of 10

Based on 5 frontline employees who took The Breakroom Quiz


Job description

The Role: Head of Enterprise Risk Management - Mobility
The Team: Join a best-in-class global legal team committed to delivering timely, practical and actionable risk leadership that enables informed decision-making and safeguards our reputation, people, and assets. This position reports directly to the Chief Risk, Compliance and Privacy Officer who reports to the Chief Legal Officer of Mobility.
Responsibilities and Impact: The Head of Enterprise Risk Management is a senior leader responsible for designing, implementing and sustaining and integrating Enterprise Risk Management (ERM) framework supporting a business of approximately $1.8 billion in revenue and approximately 3,500 employees world-wide. This role leads risk strategy, governance, identification, assessment, mitigation, monitoring and reporting across all material risk domains -including operational, technology/cyber, third-party and resilience risk- while fostering strong risk culture.
The Head of Risk Management partners closely with business leaders, technology teams, internal audit, legal, and compliance to ensure effective risk-aware decision-making and long-term organizational resilience.
The ideal candidate will bring deep knowledge of enterprise risk management, strong business judgment, and the ability to partner with leadership to proactively identify, assess, and mitigate risks across the organization. They will combine strategic vision with operational rigor to embed a risk-aware culture, drive informed decision-making, and strengthen the organization's resilience and long-term sustainability.
What's in it for you:
  • work in a dynamic, fast-paced environment
  • partner closely with colleagues across the enterprise, to integrate risk into business strategy
  • design and translate risk frameworks into scalable, practical solutions that support innovation while effectively managing risk
  • lead a team of risk professionals
  • serve as a business-oriented, senior leader and core member of the team, providing strategic direction and oversight on issues of significant importance to the company

Responsibilities:
Risk Strategy & Governance
  • Lead development and deployment of the enterprise risk strategy, ensuring alignment with the company's strategic objectives and risk appetite.
  • Establish and maintain risk governance structures, frameworks, policies and standards.
  • Support risk committees, coordinate agendas and track action items.
  • Advise on risk priorities, trends and emerging threats.

Risk Identification & Assessment
  • Drive risk identification and assessment processes across all functions and business units.
  • Maintain enterprise risk registers, risk heat maps and risk taxonomy.
  • Facilitate risk workshops and scenario analysis to capture evolving risk exposures.

Risk Mitigation & Control Design
  • Lead the design and implementation of risk mitigation strategies and controls.
  • Work with business and control owners to strengthen control environments and close gaps.
  • Ensure risks are appropriately escalated and managed within risk appetite thresholds.

Operational & Business Risk Management
  • Provide oversight of operational risk within business processes and critical initiatives.
  • Partner with business leaders to embed risk controls into operational workflows.
  • Conduct low event investigations and root cause analysis.
  • Support change-risk assessments for strategic and transformational activities.

Technology & Cyber Risk
  • Oversee risk identification and assessment for technology and cybersecurity exposures.
  • Collaborate with InfoSec, IT and other stakeholders on risk mitigation actions, testing and monitoring.
  • Align risk practices with technology roadmaps, DevOps processes and digital transformation initiatives.

Operational Resilience & Business Continuity
  • Lead enterprise operational resilience strategy and framework.
  • Ensure business continuity planning, crisis management playbooks, and disaster recovery plans are effective and regularly tested.
  • Incorporate resilience considerations into risk assessments and business planning.

Risk Monitoring, Reporting and Metrics
  • Establish and maintain risk dashboards, key risk indicators (KRIs), and risk reporting protocols
  • Provide timely risk insight to senior leadership and risk governance bodies.
  • Monitor trends and make actionable recommendations to mitigate exposures.

Evaluation of Risk Response
  • Assess the effectiveness and timeliness of risk responses and control actions.
  • Recommend corrective actions and track implementation to closure.
  • Ensure continuous improvement of risk processes and tools.

Risk Culture, Awareness & Training
  • Champion a strong risk culture across the enterprise.
  • Promote risk ownership at all levels and enhance risk literacy throughout the organization.

Third-Party Risk Management
  • Lead the Third-Party Risk Management (TPRM) program, establishing a risk-based framework for onboarding, due diligence, monitoring and offboarding of vendors, suppliers and partners.
  • Oversee identification, assessment and prioritization of third-party risks - including operational, financial, technology, regulatory and reputational exposures - and ensure timely escalation to leadership.
  • Partner with procurement, legal, compliance and business owners to integrate risk mitigation, contractual controls, business continuity and compliance obligations into third-party relationships.
  • Drive continuous improvement, reporting and analytics to enhance visibility, monitoring and resilience of critical third-party dependencies.

What We're Looking For:
Basic Required Qualifications:
  • 10+ years of progressive enterprise risk leadership experience in complex, regulated, or technology-enabled organizations.
  • Bachelor's degree in Risk Management, Business, Finance, Engineering, Information Systems or related field preferred.
  • Professional certifications, such as Certified Risk Manager (CRM), Certified in Risk and Information Systems Control (CRISC), Project Management Professional (PMP), FRM, PRM, ISO 31000 training preferred.
  • Experience building or maturing an Enterprise Risk Management framework.
  • Demonstrated experience with operational and technology risk, third-party risk and enterprise resilience planning.
  • Experience advising leadership and cross-functional stakeholders.
  • Prior experience with risk tools, data analytics for risk monitoring or modern risk platforms.
  • Proven capability to manage high-volume, complex environments with sound judgment and adaptability. Fosters inclusivity and manages emotions to achieve optimal business outcomes. Able to effectively pivot direction and collaborate across teams to meet strategic initiatives.
  • Exceptional business judgment and strong problem-solving abilities. Adept at articulating business needs and defining actionable strategies. Actively seeks input from diverse sources to ensure engagement and influence stakeholder buy-in at all levels.
  • Excellent communication and interpersonal skills, with a demonstrated passion for the business.
  • Operates autonomously while also being a collaborative team player who brings a positive, "can do" attitude to the workplace. Works effectively with other members of the Compliance, Risk and Privacy team, internal clients, and cross-functional organizations to influence and develop strategic initiatives.

About S&P Global Mobility: S&P Global has recently announced the intent to separate our Mobility Segment into a standalone public company.
Right to Work Requirements: This role is limited to persons with indefinite right to work in the United States.
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
It is the policy of Mobility to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Mobility will provide reasonable accommodations for qualified individuals with disabilities.