1

Cyber Risk Manager Jobs in Gainesville, VA (NOW HIRING)

Cyber Risk Analyst (TS/SCI) Reston, VA, USA / Full-time / Clearance: Top Secret/SCI Summary ... Knowledge of Risk Management Framework (RMF) and the A&A activities needed to obtain and maintain ...

Cyber Risk Analyst (TS/SCI) Reston, VA, USA Full-time Clearance: Top Secret/SCI Summary: Warnings ... Knowledge of Risk Management Framework (RMF) and the A&A activities needed to obtain and maintain ...

... air, and cyberspace - for U.S. government agencies and all branches of the armed forces. We are ... Peraton is seeking an experienced Schedule & Risk Manager to serve as the authoritative source of ...

Schedule & Risk Manager

Herndon, VA · On-site

$112K - $179K/yr

... air, and cyberspace - for U.S. government agencies and all branches of the armed forces. We are ... Peraton is seeking an experienced Schedule & Risk Manager to serve as the authoritative source of ...

... air, and cyberspace -- for U.S. government agencies and all branches of the armed forces. We are ... Peraton is seeking an experienced Schedule & Risk Manager to serve as the authoritative source of ...

... air, and cyberspace - for U.S. government agencies and all branches of the armed forces. We are ... Peraton is seeking an experienced Schedule & Risk Manager to serve as the authoritative source of ...

Strong understanding of cyber operations, threat intelligence, and vulnerability management ... Familiarity with MITRE ATT&CK, CVSS scoring, and cyber-risk frameworks. * Experience with machine ...

Strong understanding of cyber operations, threat intelligence, and vulnerability management ... Familiarity with MITRE ATT&CK, CVSS scoring, and cyber-risk frameworks. * Experience with machine ...

Significant experience with malware analysis and cyber risk automation tools. Clearance ... Frequently communicates with co-workers, management, and customers, which may involve delivering ...

Significant experience with malware analysis and cyber risk automation tools. Clearance ... Frequently communicates with co-workers, management, and customers, which may involve delivering ...

Significant experience with malware analysis and cyber risk automation tools. Clearance ... Frequently communicates with co-workers, management, and customers, which may involve delivering ...

Significant experience with malware analysis and cyber risk automation tools. Clearance ... Frequently communicates with co-workers, management, and customers, which may involve delivering ...

Significant experience with malware analysis and cyber risk automation tools. Clearance ... Frequently communicates with co-workers, management, and customers, which may involve delivering ...

next page

Showing results 1-20

Cyber Risk Manager information

See Gainesville, VA salary details

$50.9K

$110.1K

$167.9K

How much do cyber risk manager jobs pay per year?

As of Sep 14, 2026, the average yearly pay for cyber risk manager in Gainesville, VA is $110,149.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,900.00 and $127,400.00 per year, depending on experience, location, and employer.

How does a cyber risk manager collaborate with other departments to strengthen an organization's cybersecurity posture?

A Cyber Risk Manager frequently works with IT, legal, compliance, and business units to identify, assess, and mitigate cyber risks across the organization. This collaboration involves leading risk assessments, facilitating security awareness training, and ensuring that cybersecurity policies align with business objectives. Regular cross-department meetings and incident response simulations are common, fostering a shared responsibility for cyber resilience. Effective communication and relationship-building skills are essential in this role to bridge technical and non-technical teams.

What are the key skills and qualifications needed to thrive as a cyber risk manager, and why are they important?

To thrive as a Cyber Risk Manager, you need a solid background in information security, risk assessment, and compliance, often supported by a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC tools, and relevant certifications like CISSP or CISM is typically required. Excellent analytical thinking, communication, and leadership skills set top performers apart in this role. These skills are crucial for identifying risks, implementing effective controls, and ensuring the organization’s digital assets remain secure and compliant.

What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?

AspectCyber Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, security firms, corporate environments

The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.

How much does a cyber risk manager make?

A cyber risk manager's salary typically ranges from $90,000 to $150,000 annually, depending on experience, certifications, and industry. Senior roles or those in high-demand sectors can earn higher compensation, often supplemented with bonuses and benefits.

What does a cyber risk manager do?

A cyber risk manager assesses and mitigates cybersecurity threats to an organization’s information systems. They identify vulnerabilities, develop risk management strategies, and implement security controls, often using tools like risk assessment frameworks and security software. Certification such as CISSP or CISM can enhance their effectiveness in managing cyber risks.

What are popular job titles related to Cyber Risk Manager jobs in Gainesville, VA?

For Cyber Risk Manager jobs in Gainesville, VA, the most frequently searched job titles are:

What job categories do people searching Cyber Risk Manager jobs in Gainesville, VA look for?

The top searched job categories for Cyber Risk Manager jobs in Gainesville, VA are:

What cities near Gainesville, VA are hiring for Cyber Risk Manager jobs?

Cities near Gainesville, VA with the most Cyber Risk Manager job openings:

Infographic showing various Cyber Risk Manager job openings in Gainesville, VA as of August 2026, with employment types broken down into 85% Full Time, 14% Part Time, and 1% Contract. Highlights an 80% Physical, 2% Hybrid, and 18% Remote job distribution, with an average salary of $110,149 per year, or $53 per hour.

Cyber Risk Analyst (TS/SCI)

Reston, VA • On-site

Beyond SOF
Professional, Scientific, and Technical Services • 11 - 50 employees

Other

Re-posted 11 days ago


Job description

Cyber Risk Analyst (TS/SCI)

Reston, VA, USA / Full-time / Clearance: Top Secret/SCI

Job Description Summary: Warnings about cyber threats are everywhere and the constantly evolving nature of these threats can make understanding them seem overwhelming to the DoD and the IC. In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you. Build your knowledge as an information security risk specialist who knows how to break down complex threats into manageable plans of action.

As a Cyber-Risk Analyst on our team, you’ll use your experience to work with DoD programs to discover their cyber risks, understand policies, and develop a mitigation plan. You’ll get technical, environmental, and personnel details from engineers and SMEs to assess the entire threat landscape. Then, you’ll help your team guide your client through a plan of action with presentations, white papers, and milestones. You’ll work on translating security concepts for your client so they can make the best decisions to secure their mission critical networks and systems. This is your opportunity to act as an information security subject matter expert while broadening your skills in cybersecurity, security and network tools, systems engineering, and data science.

Qualifications
  • 5+ years of experience working in a professional IT environment
  • 3+ years of experience with cybersecurity
  • 3+ years of experience with Assessment and Authorization (A&A) in support of DoD and IC programs, including package development, artifact generation, and authority to operate (ATO)
  • Experience with security hardening of Windows and Linux operating systems and security tools, such as ACAS, SCAP, STIG/SRGs, SCC, eMASS/Xacta, ESS, Prisma Cloud, Kubernetes, Rancher, and Docker
  • Experience generating and maintaining System Security Plans (SSP), Implementation Plans, Privacy Impact Assessments, Security Assessment Plans (SAP), Risk Assessments, Plan of Action and Milestones (POA&M), and other A&A documentation
  • Knowledge of Risk Management Framework (RMF) and the A&A activities needed to obtain and maintain an ATO, including National Institute of Standards and Technology (NIST) and Committee on National Security Systems Instruction (CNSSI), including NIST SP 800-60, NIST SP 800-53, and CNSSI 1253
  • IAT Level II Certification, including a Security+ Certification

Desired Qualifications:

  • Experience with DoD or IC cybersecurity projects or programs
  • Experience with DevSecOps, Path-to-Production, and CI/CD
  • Experience with Cloud Authorization and Cloud Migration
  • Experience with administering Red Hat Enterprise Linux or Windows Server 2012 or higher
  • Ability to provide subject matter expertise to system engineering documents, including technical requirements documents, interface control documents, and system specifications
  • Ability to analyze and communicate complex technical challenges to both technical and non-technical clients and stakeholders
  • Ability to communicate and integrate between multiple customer stakeholders
#J-18808-Ljbffr