1

Cyber Risk Manager Jobs in Gainesville, VA (NOW HIRING)

Director, Cyber Risk

Sterling, VA · On-site

$180 - $280/hr

Own and continuously improve the cyber and technology risk management framework, methodology, taxonomy, and lifecycle aligned to NIST CSF 2.0, ISO 27001/27005, and applicable regulatory obligations.

Cyber Risk Analyst (TS/SCI) Reston, VA, USA Full-time Clearance: Top Secret/SCI Summary: Warnings ... Knowledge of Risk Management Framework (RMF) and the A&A activities needed to obtain and maintain ...

Schedule & Risk Manager

Herndon, VA · On-site

$112K - $179K/yr

... air, and cyberspace - for U.S. government agencies and all branches of the armed forces. We are ... Peraton is seeking an experienced Schedule & Risk Manager to serve as the authoritative source of ...

... air, and cyberspace - for U.S. government agencies and all branches of the armed forces. We are ... Peraton is seeking an experienced Schedule & Risk Manager to serve as the authoritative source of ...

... air, and cyberspace - for U.S. government agencies and all branches of the armed forces. We are ... Peraton is seeking an experienced Schedule & Risk Manager to serve as the authoritative source of ...

Strong understanding of cyber operations, threat intelligence, and vulnerability management ... Familiarity with MITRE ATT&CK, CVSS scoring, and cyber-risk frameworks. * Experience with machine ...

Strong understanding of cyber operations, threat intelligence, and vulnerability management ... Familiarity with MITRE ATT&CK, CVSS scoring, and cyber-risk frameworks. * Experience with machine ...

Strong understanding of cyber operations, threat intelligence, and vulnerability management ... Familiarity with MITRE ATT&CK, CVSS scoring, and cyber-risk frameworks. * Experience with machine ...

next page

Showing results 1-20

Cyber Risk Manager information

See Gainesville, VA salary details

$50.9K

$110.1K

$167.9K

How much do cyber risk manager jobs pay per year?

As of Aug 19, 2026, the average yearly pay for cyber risk manager in Gainesville, VA is $110,149.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,900.00 and $127,400.00 per year, depending on experience, location, and employer.

How does a cyber risk manager collaborate with other departments to strengthen an organization's cybersecurity posture?

A Cyber Risk Manager frequently works with IT, legal, compliance, and business units to identify, assess, and mitigate cyber risks across the organization. This collaboration involves leading risk assessments, facilitating security awareness training, and ensuring that cybersecurity policies align with business objectives. Regular cross-department meetings and incident response simulations are common, fostering a shared responsibility for cyber resilience. Effective communication and relationship-building skills are essential in this role to bridge technical and non-technical teams.

What are the key skills and qualifications needed to thrive as a cyber risk manager, and why are they important?

To thrive as a Cyber Risk Manager, you need a solid background in information security, risk assessment, and compliance, often supported by a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC tools, and relevant certifications like CISSP or CISM is typically required. Excellent analytical thinking, communication, and leadership skills set top performers apart in this role. These skills are crucial for identifying risks, implementing effective controls, and ensuring the organization’s digital assets remain secure and compliant.

What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?

AspectCyber Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, security firms, corporate environments

The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.

How much does a cyber risk manager make?

A cyber risk manager's salary typically ranges from $90,000 to $150,000 annually, depending on experience, certifications, and industry. Senior roles or those in high-demand sectors can earn higher compensation, often supplemented with bonuses and benefits.

What does a cyber risk manager do?

A cyber risk manager assesses and mitigates cybersecurity threats to an organization’s information systems. They identify vulnerabilities, develop risk management strategies, and implement security controls, often using tools like risk assessment frameworks and security software. Certification such as CISSP or CISM can enhance their effectiveness in managing cyber risks.

What are popular job titles related to Cyber Risk Manager jobs in Gainesville, VA?

For Cyber Risk Manager jobs in Gainesville, VA, the most frequently searched job titles are:

What job categories do people searching Cyber Risk Manager jobs in Gainesville, VA look for?

The top searched job categories for Cyber Risk Manager jobs in Gainesville, VA are:

What cities near Gainesville, VA are hiring for Cyber Risk Manager jobs?

Cities near Gainesville, VA with the most Cyber Risk Manager job openings:

Infographic showing various Cyber Risk Manager job openings in Gainesville, VA as of August 2026, with employment types broken down into 85% Full Time, 14% Part Time, and 1% Contract. Highlights an 80% Physical, 2% Hybrid, and 18% Remote job distribution, with an average salary of $110,149 per year, or $53 per hour.

Director, Cyber Risk

Jobtailor

Sterling, VA • On-site

$180 - $280/hr

Other

Posted 13 days ago


Job description

Responsibilities
  • Own and continuously improve the cyber and technology risk management framework, methodology, taxonomy, and lifecycle aligned to NIST CSF 2.0, ISO 27001/27005, and applicable regulatory obligations.
  • Define standards, procedures, and rating scales for consistent enterprise-wide risk identification, assessment, and reporting; partner with the PISO model to ensure common language and practices across portfolios.
  • Lead enterprise cyber risk assessments across technology, business, regulatory, and emerging-risk domains to produce consistent, defensible determinations.
  • Establish and operate a cyber risk quantification capability (e.g., FAIR-based) to express risk in business and financial terms and inform prioritization and investment decisions.
  • Maintain the enterprise cyber risk register; ensure risks are well‑described, owned, rated, and tracked to acceptable residual levels; develop and manage KRI/KCI programs for forward‑looking posture.
  • Operationalize the risk appetite and tolerance framework with the CISO and senior leadership; own risk acceptance and exception governance with clear, auditable documentation and time‑bound approvals.
  • Govern cyber risk policy structure, ownership, review cadence, and exception handling; chair or support cyber risk forums and escape decisions to appropriate authority levels.
  • Lead second‑line, risk‑based assurance over design and operating effectiveness of key cyber controls in coordination with first‑line and Internal Audit; identify thematic weaknesses and drive structural remediation.
  • Own issues and remediation management—intake, prioritization, owner assignment, tracking to closure, and escalation of aging items.
  • Define and report outcome‑focused metrics (e.g., residual risk trends, out‑of‑appetite reduction, early‑versus‑late finding ratios, incidents tied to accepted risk) in executive‑ and board‑ready formats.
  • Serve as primary point of contact for cyber risk in regulatory exams, audits, and carrier‑partner due diligence.
  • Integrate cyber risk into Enterprise Risk Management to ensure consistency in enterprise risk reporting and governance; partner with Legal, Privacy, Procurement, and technology leaders to embed risk‑informed decisions.
  • Oversee vendor/third‑party risk within the cyber risk portfolio to ensure supply‑chain risk is governed in line with enterprise practices.
  • Build, lead, and develop a team of senior managers and analysts; set objectives, manage performance, and scale capacity through process improvement, tooling, and appropriate AI‑assisted workflows.
Requirements
  • Bachelor’s degree in a related field or equivalent professional experience.
  • 10+ years in cybersecurity, IT/technology risk, or GRC, including 5+ years leading managers or multiple teams/domains.
  • Proven experience designing, leading, or substantially maturing an end‑to‑end enterprise cyber/IT risk management program.
  • Deep knowledge of NIST CSF 2.0, ISO 27001/27005, relevant regulatory regimes, and the three‑lines‑of‑defense model.
  • Experience operating a risk register, risk appetite/tolerance framework, and risk acceptance/exception governance.
  • Hands‑on experience with GRC/IRM platforms (e.g., ServiceNow IRM, Archer, OneTrust, or comparable).
  • Excellent executive communication skills with a track record of briefing senior leadership and boards.
  • Strong cross‑functional influence partnering across security, technology, legal, privacy, and business teams.
#J-18808-Ljbffr