1

Cyber Risk Manager Jobs in Alexandria, VA (NOW HIRING)

Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone ...

Cyber GRC Specialist

Washington, DC · On-site

$90 - $130/hr

* Support and mature cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and leadership reporting * Maintain the cyber ...

Showing results 41-60

Cyber Risk Manager information

See Alexandria, VA salary details

$55.1K

$119.4K

$182K

How much do cyber risk manager jobs pay per year?

As of Aug 22, 2026, the average yearly pay for cyber risk manager in Alexandria, VA is $119,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,300.00 and $138,100.00 per year, depending on experience, location, and employer.

How does a cyber risk manager collaborate with other departments to strengthen an organization's cybersecurity posture?

A Cyber Risk Manager frequently works with IT, legal, compliance, and business units to identify, assess, and mitigate cyber risks across the organization. This collaboration involves leading risk assessments, facilitating security awareness training, and ensuring that cybersecurity policies align with business objectives. Regular cross-department meetings and incident response simulations are common, fostering a shared responsibility for cyber resilience. Effective communication and relationship-building skills are essential in this role to bridge technical and non-technical teams.

What are the key skills and qualifications needed to thrive as a cyber risk manager, and why are they important?

To thrive as a Cyber Risk Manager, you need a solid background in information security, risk assessment, and compliance, often supported by a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC tools, and relevant certifications like CISSP or CISM is typically required. Excellent analytical thinking, communication, and leadership skills set top performers apart in this role. These skills are crucial for identifying risks, implementing effective controls, and ensuring the organization’s digital assets remain secure and compliant.

What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?

AspectCyber Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, security firms, corporate environments

The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.

How much does a cyber risk manager make?

A cyber risk manager's salary typically ranges from $90,000 to $150,000 annually, depending on experience, certifications, and industry. Senior roles or those in high-demand sectors can earn higher compensation, often supplemented with bonuses and benefits.

What does a cyber risk manager do?

A cyber risk manager assesses and mitigates cybersecurity threats to an organization’s information systems. They identify vulnerabilities, develop risk management strategies, and implement security controls, often using tools like risk assessment frameworks and security software. Certification such as CISSP or CISM can enhance their effectiveness in managing cyber risks.

What are popular job titles related to Cyber Risk Manager jobs in Alexandria, VA?

For Cyber Risk Manager jobs in Alexandria, VA, the most frequently searched job titles are:

What job categories do people searching Cyber Risk Manager jobs in Alexandria, VA look for?

The top searched job categories for Cyber Risk Manager jobs in Alexandria, VA are:

What cities near Alexandria, VA are hiring for Cyber Risk Manager jobs?

Cities near Alexandria, VA with the most Cyber Risk Manager job openings:

Infographic showing various Cyber Risk Manager job openings in Alexandria, VA as of August 2026, with employment types broken down into 84% Full Time, 15% Part Time, and 1% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $119,400 per year, or $57.4 per hour.

$81K - $110K/yr

Full-time

Retirement, PTO

Re-posted 18 days ago


General Dynamics Information Technology rating

7.8

Company rating: 7.8 out of 10

Based on 63 frontline employees who took The Breakroom Quiz

88th of 225 rated it services


Job description

Share
REQ#: RQ220793Public Trust: None Requisition Type: Regular Your Impact

Own your opportunity to be at the center of GDITs business operations. Make an impact by collaborating across functions to make mission success achievable.

Job Description

Help safeguard critical government systems by applying your hands-on ISSM/ISSO experience to security governance, risk evaluation, and compliance oversight. As an IT and Cyber Risk Auditor at GDIT, you will leverage your background managing RMF controls, system documentation, and continuous monitoring activities to deliver thorough, accurate, and missionfocused security assessments.

This role is ideal for cybersecurity professionals who have previously served as an ISSM or ISSO and are seeking to transition into a dedicated risk, audit, and compliance position where they can influence security posture across multiple systems and programs.


MEANINGFUL WORK AND PERSONAL IMPACT

As an IT and Cyber Risk Auditor, the work you do at GDIT will have a direct and measurable impact on our customers mission. Youll help ensure the integrity, security, and compliance of their IT systems by identifying potential risks, validating critical controls, and supporting continuous improvement efforts. Your work will enhance operational resilience and enable the customer to execute their mission with confidence.


Conduct comprehensive security audits and RMF control assessments in accordance with DCSA, JSIG, and SAP security requirements, leveraging prior ISSO/ISSM experience.

Review, validate, and improve security documentation and artifacts such as SSPs, POA&Ms, Continuous Monitoring outputs, and other evidence required by RMF and DCSA assessment standards.

Develop, implement, and oversee operational information system security policies and guidelines aligned with the Risk Management Framework (RMF), JSIG, and applicable DCSA directives.

Evaluate system security controls for effectiveness, completeness, and compliance with NIST SP 80053, DCSA/DoW requirements, JSIG standards, and internal organizational policies.

Collaborate with ISSOs, ISSMs, SAP security personnel, and technical teams to analyze findings, recommend remediation actions, and ensure timely correction of identified vulnerabilities.

Analyze system changes, configuration updates, and vulnerability data to determine authorization impacts, risklevel changes, and required updates under RMF and JSIG/SAP processes.

Support ongoing ATO and SAP authorization maintenance by tracking assessments, evidence submissions, and documentation required throughout the RMF and JSIG lifecycles.

Prepare and deliver clear, riskfocused briefings to system owners, DCSA assessors, SAP authorities, and other stakeholders regarding compliance status, audit results, and securityrelated decisions.


WHAT YOULL NEED TO SUCCEED
Bring your cyber expertise and drive for innovation to GDIT. The IT and Cyber Risk Auditor must have:
Education: Bachelors degree
Experience: 2+ years of related experience as a prior ISSO/ISSM. In lieu of degree, additional 4+ years of work experience/training/education will be required

Certifications: IAT II (Security +, SSCP, CCNA Security)

Technical skills: Strong understanding of NIST SP 800-53, DoW cybersecurity requirements, and control implementation/assessment practices. Familiarity with Windows/Linux environments, vulnerability tools, and security baselines.

Prior SAP experience desired
Security clearance: Must have an active Top Secret clearance in order to be considered, and the ability to obtain and maintain TS/SCI clearance.

US citizenship required
Role requirements: Onsite, 5 days/week in Falls Church, VA office location


GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.
Growth: AI-powered career tool that identifies career steps and learning opportunities.
Support: An internal mobility team focused on helping you achieve your career goals.
Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off.
Community: Award-winning culture of innovation and a military-friendly workplace.
OWN YOUR OPPORTUNITY
Explore a career in cyber at GDIT and youll find endless opportunities to grow alongside colleagues who share your focus on defending and protecting what matters.

#GDITPriority

Work Requirements
Years of Experience

2 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification

CompTIA Security+ CE | CompTIA - CompTIA

Travel Required

Less than 10%

Citizenship

U.S. Citizenship Required

Salary and Benefit Information

The likely salary range for this position is $81,349 - $110,055. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
View information about benefits and our total rewards program.

Our Identity Verification Process

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans


What General Dynamics Information Technology employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


General Dynamics Information Technology logo

About General Dynamics Information Technology

Sourced by ZipRecruiter

GDIT is a global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense, and intelligence community. Its 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. The company operates across 50+ countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber, and application development.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Falls Church, VA, US