1

Cyber Risk Manager Jobs in Gainesville, VA (NOW HIRING)

Cyber Defense IAM

Chantilly, VA · On-site

$165K - $190K/yr

The IAM LII will contribute to developing methods to monitor and measure risk, compliance, and assurance efforts. At least 5 years of IT or cyber management operations experience is required. Do you ...

Perform principal-level risk assessment activities beyond third parties - including security exception management, internal control reviews, and cyber risk assessments - applying qualitative and ...

Perform principal-level risk assessment activities beyond third parties - including security exception management, internal control reviews, and cyber risk assessments - applying qualitative and ...

... management. * Deep understanding of threat actors, cybercrime ecosystems, nation-state operations, malware, ransomware, vulnerabilities, and threat hunting concepts. * Experience assessing cyber risk ...

Showing results 41-60

Cyber Risk Manager information

See Gainesville, VA salary details

$50.9K

$110.1K

$167.9K

How much do cyber risk manager jobs pay per year?

As of Aug 19, 2026, the average yearly pay for cyber risk manager in Gainesville, VA is $110,149.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,900.00 and $127,400.00 per year, depending on experience, location, and employer.

How does a cyber risk manager collaborate with other departments to strengthen an organization's cybersecurity posture?

A Cyber Risk Manager frequently works with IT, legal, compliance, and business units to identify, assess, and mitigate cyber risks across the organization. This collaboration involves leading risk assessments, facilitating security awareness training, and ensuring that cybersecurity policies align with business objectives. Regular cross-department meetings and incident response simulations are common, fostering a shared responsibility for cyber resilience. Effective communication and relationship-building skills are essential in this role to bridge technical and non-technical teams.

What are the key skills and qualifications needed to thrive as a cyber risk manager, and why are they important?

To thrive as a Cyber Risk Manager, you need a solid background in information security, risk assessment, and compliance, often supported by a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC tools, and relevant certifications like CISSP or CISM is typically required. Excellent analytical thinking, communication, and leadership skills set top performers apart in this role. These skills are crucial for identifying risks, implementing effective controls, and ensuring the organization’s digital assets remain secure and compliant.

What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?

AspectCyber Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, security firms, corporate environments

The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.

How much does a cyber risk manager make?

A cyber risk manager's salary typically ranges from $90,000 to $150,000 annually, depending on experience, certifications, and industry. Senior roles or those in high-demand sectors can earn higher compensation, often supplemented with bonuses and benefits.

What does a cyber risk manager do?

A cyber risk manager assesses and mitigates cybersecurity threats to an organization’s information systems. They identify vulnerabilities, develop risk management strategies, and implement security controls, often using tools like risk assessment frameworks and security software. Certification such as CISSP or CISM can enhance their effectiveness in managing cyber risks.

What are popular job titles related to Cyber Risk Manager jobs in Gainesville, VA?

For Cyber Risk Manager jobs in Gainesville, VA, the most frequently searched job titles are:

What job categories do people searching Cyber Risk Manager jobs in Gainesville, VA look for?

The top searched job categories for Cyber Risk Manager jobs in Gainesville, VA are:

What cities near Gainesville, VA are hiring for Cyber Risk Manager jobs?

Cities near Gainesville, VA with the most Cyber Risk Manager job openings:

Infographic showing various Cyber Risk Manager job openings in Gainesville, VA as of August 2026, with employment types broken down into 85% Full Time, 14% Part Time, and 1% Contract. Highlights an 80% Physical, 2% Hybrid, and 18% Remote job distribution, with an average salary of $110,149 per year, or $53 per hour.

Critical Infrastructure Risk Management Lead with Security Clearance

MITRE Corporation

Fairfax, VA • On-site

Other

Re-posted 11 days ago


MITRE Corporation rating

8.2

Company rating: 8.2 out of 10

Based on 8 frontline employees who took The Breakroom Quiz

162nd of 449 rated engineering


Job description

Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges-and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We're making a difference every day-working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities for career growth, and a culture of innovation that embraces adaptability, collaboration, technical excellence, and people in partnership. If this sounds like the choice you want to make, then choose MITRE - and make a difference with us. Our nation's ability to defend the homeland, deter aggression, and build a resilient Joint force rests on our capacity to identify, prioritize, and successfully field the optimal set of effective, suitable, and survivable systems. We must re-envision national security to keep pace with advanced adversaries, leveraging the entire spectrum of the Nation's Innovation Base, while creating and leveraging a growing set of new options and authorities for accelerating Joint and whole-of-nation capabilities. That's where MITRE's Acquisition Studies & Analysis (ASA) Department comes in. We are a diverse group of defense acquisition experts, operations research / system analysts, cybersecurity professionals, and communication systems engineers- all with a united passion to solve problems for a safer world. We're experienced professionals who advise senior leaders and decision-makers across the national security enterprise. Our evidence-based work garners visibility and provokes thought and action. We're team players who build partnerships across government, industry, academia, and research centers. And above all - we bring objectivity, innovation, courage, and technical excellence to help our sponsors make the right decision Roles & Responsibilities: MITRE's ASA Department seeks a well-connected and recognized expert on risk management for critical infrastructure systems and associated technology. The ideal candidate will be a credible authority on critical infrastructure risk management, understanding how critical infrastructure supports weapons systems and other associated platforms, understanding of established cyber capabilities (e.g., D3FEND, D3FEND for OT, ATT&CK, ATT&CK for ICS, Crown Jewels Analysis for Control Systems), foundational understanding of operational technologies and control systems, knowledge of established industry standards and guidance (i.e., ISA/IEC 62443, NIST 800-82, NIST 800-30), ability to write reports focused on operational technology security in risk terms, lead complex operational technology related projects across numerous efforts, and develop frameworks, policies, processes, and procedures. You will belong to a high-performing team that regularly initiates and implements projects in support of sponsors' strategic initiatives, often before a sponsor can fully recognize or articulate that they are needed. The team may publish, speak at high visibility events, and advise senior government officials along with their performers from various organizations. Responsibilities include: * Effectively engage and lead sponsors, stakeholders, performers regarding planning, execution, and documentation of workshops, outcomes, and follow on activities.
* Develop and propose innovative strategies, policies, and processes that improve risk management to critical infrastructure, ranging from programs, portfolios, and enterprise-wide initiatives.
* Contribute with impact as part of one or more integrated product teams to enable DoW to transition emerging technologies and prototypes into fielded operational capabilities for risk management.
* Strategically communicate internally and externally on key issues related to critical infrastructure cybersecurity and resilience.
* Regularly report status updates to government employees along with their performers from various organizations
* Build and manage relationships between senior sponsors, MITRE, and other stakeholders (Federally Funded Research & Development Centers (FFRDCs), University Affiliated Research Centers (UARCs), Industry, academia).
* Increase collaboration and coordination on critical infrastructure cybersecurity and cyber resilience across federal, state, and industry to improve identified issues within policy, standards, risk management, etc.
* Provide subject matter expertise and drive consistent risk management capabilities across organizational, country, and bureaucracy boundaries. Basic Qualifications: * Typically requires a minimum of 10 years of related experience with a Bachelor's degree; or 8 years and a Master's degree; or a PhD with 5 years' experience; or equivalent combination of related education and work experience.
* Experience with broad exposure across the DoW's critical infrastructure cybersecurity and cyber resilience programs . * Track record of providing successful thought leadership in planning, executing, and leading workshops.
* Experience building coalitions and communities that span multiple organizations across government and the private sector.
* Strong critical thinking, analytic, and problem-solving skills - comfortable working in dynamic settings where task objectives may evolve, need to be shaped, or creative solutions to task impediments must be identified.
* Demonstrated ability to work in team settings, to include the ability to mentor and lead small to medium multidisciplinary teams toward significant mission outcomes.
* Strong interpersonal skills as well as effective verbal and written communication skills.
* Working familiarity with industry and DoW policies and standards across the critical infrastructure and cyber domains.
* Knowledge and experience developing and executing frameworks for risk management. * Willingness to visit Sponsor sites often for direct engagement and/or meetings.
* Ability to lead and conduct highly political and dynamic meetings across DoW, defense contractors, industry, and others.
* Active DoD Secret clearance
* U.S. Citizenship required.
* This position requires a minimum of 50% hybrid on-site presence. Preferred Qualifications: * Ability to maintain a DoD Top Secret clearance with access to Secure Compartmented Information (TS/SCI).
* Bachelor's degree or higher in an Applied Science or Engineering.
* Private sector experience defense, technology, or consulting industries.
* Demonstrated ability to maintain and leverage a strong professional network to provide thought leadership across the enterprise.
* Demonstrated ability leading critical acquisition modernization or reform efforts with visibility and trust at high levels of government and/or industry. This requisition requires the candidate to have a minimum of the following clearance(s):
Secret This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s):
Secret Salary compensation range and midpoint:
$172,800 - $216,000 - $259,200 Annual Work Location Type:
Hybrid It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local or international law. MITRE intends to maintain a website that is fully accessible to all individuals. If you are unable to search or apply for jobs and would like to request a reasonable accommodation for any part of MITRE's employment process, please email for general support and for intern positions. This service is for individuals requiring reasonable accommodation requests. Please note that vendor solicitations will not receive a reply. Benefits information may be found here . Copyright © 1997-2026, The MITRE Corporation. All rights reserved. MITRE is a registered trademark of The MITRE Corporation. Material on this site may be copied and distributed with permission only.

What MITRE Corporation employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom


MITRE logo

About MITRE

Sourced by ZipRecruiter

Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges-and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We're making a difference every day-working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities, and a culture of innovation that embraces diversity, inclusion, flexibility, collaboration, and career growth. If this sounds like the choice you want to make, then choose MITRE-and make a difference with us. MITRE is a trusted operator of federally funded research and development centers and we're on a mission to make the world a safer place-for all of humanity, today and in the future. To deliver on our mission, we need the world's best talent and leaders-groundbreakers and partnership-builders on a global scale in areas like healthcare, artificial intelligence, critical infrastructure resiliency, pandemic management, and cybersecurity. In return, we have the privilege of backing you with thousands of technical experts in diverse fields, a culture of innovation and knowledge sharing, access to data and resources uniquely available to MITRE through our wide-ranging partnerships across government, industry and academia.

Industry

It services

Company size

5,001 - 10,000 Employees

Headquarters location

McLean, VA, US

Year founded

1958

Social media