1

Cyber Risk Resilience Analyst Jobs (NOW HIRING)

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk ...

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk ...

Cyber Risk Reporting Analyst

Jersey City, NJ ยท On-site

$90K - $125K/yr

We are seeking a talented Cyber Risk Reporting Analyst to join our team and support Cyber / IT Risk Management BAU activities. The ideal candidate will have strong expertise in data analysis, Excel ...

... technology, cyber, data, and resiliency domains. You will collaborate with passionate and ... Foster strong partnerships with line of business risk offices and team members to analyze how ...

Position Overview The Director, Cyber Risk leads Asurion's cyber and technology risk management ... Build, lead, and develop a team of senior managers and analysts; set objectives, manage performance ...

Position Overview The Director, Cyber Risk leads Asurion's cyber and technology risk management ... Build, lead, and develop a team of senior managers and analysts; set objectives, manage performance ...

Showing results 21-40

Cyber Risk Resilience Analyst information

See salary details

$44.5K

$107.5K

$151K

How much do cyber risk resilience analyst jobs pay per year?

As of Sep 11, 2026, the average yearly pay for cyber risk resilience analyst in the United States is $107,522.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $126,500.00 per year, depending on experience, location, and employer.

What is a cyber risk resilience analyst?

A Cyber Risk Resilience Analyst is a professional who assesses an organization's cybersecurity posture, identifies vulnerabilities, and develops strategies to reduce risks and ensure continuity in the face of cyber threats. They analyze threats, evaluate current security measures, and recommend improvements to enhance the organization's ability to withstand and recover from cyber incidents. These analysts often collaborate with IT, security teams, and business leaders to implement best practices and compliance standards, helping organizations remain resilient against evolving cyber risks.

What are the key skills and qualifications needed to thrive as a cyber risk resilience analyst?

To thrive as a Cyber Risk Resilience Analyst, you need a solid understanding of cybersecurity principles, risk assessment methodologies, and business continuity planning, often supported by a degree in information security or related fields. Familiarity with tools like SIEM systems, vulnerability scanners, and certifications such as CISSP or CISM are typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for evaluating threats and advising stakeholders. These competencies are vital to proactively manage cyber risks, ensure organizational resilience, and safeguard critical assets.

How does a cyber risk resilience analyst typically collaborate with other departments to strengthen organizational security?

A Cyber Risk Resilience Analyst works closely with IT, legal, compliance, and business units to identify vulnerabilities and develop strategies for risk mitigation. Regularly, they facilitate cross-departmental workshops, conduct risk assessments, and communicate findings to both technical and non-technical stakeholders. This collaboration ensures that security policies are aligned with business goals and regulatory requirements, fostering a culture of shared responsibility for cyber resilience across the organization.

What is the difference between Cyber Risk Resilience Analyst vs Cybersecurity Analyst?

AspectCyber Risk Resilience AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentFocus on risk management, resilience planning, and incident responseFocus on threat detection, system monitoring, and security measures
Employer & Industry UsageFinancial, healthcare, government sectors emphasizing risk mitigationIT and tech companies, security firms, and organizations with technical security needs

The main difference is that Cyber Risk Resilience Analysts concentrate on assessing and improving an organization's ability to withstand cyber threats and recover from incidents, while Cybersecurity Analysts primarily focus on identifying and mitigating security threats through technical measures. Both roles require similar certifications but serve different aspects of cybersecurity strategy.

What are popular job titles related to Cyber Risk Resilience Analyst jobs?

For Cyber Risk Resilience Analyst jobs, the most frequently searched job titles are:

Infographic showing various Cyber Risk Resilience Analyst job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 90% Full Time, 7% Part Time, and 2% Contract. Highlights an 82% Physical, 5% Hybrid, and 13% Remote job distribution, with an average salary of $107,522 per year, or $51.7 per hour.

Cyber Risk Analyst SME

Arlington, VA โ€ข On-site

Technomics, Inc.
Guided Missile and Space Vehicle Manufacturingย โ€ขย 201 - 500 employees

Full-time

Re-posted 18 days ago


Job description

Technomics is a growing employee-owned, decision analytics company that specializes in cost and economic analysis to facilitate better decisions faster . We enable a wide range of clients across the Federal government, from senior level policy makers to program managers, to choose smartly, buy effectively and operate efficiently. We deliver practical, credible and defensible results offering actionable insights by applying data-driven and analytics-based approaches in combination with multidisciplinary talent, subject matter experts, and tangible and repeatable assets in the form of databases, models, approaches and techniques.
Analystshave the knowledge, skills, abilities and initiative to deliver timely, practical and innovative solutions to our clients as part of high-performing project teams typically composed of a mix of junior and mid-level analysts who will look to you for technical acumen and mentoring.
Our employee-owners pride themselves on their ability to apply deep analytical rigor and innovative thought that assist clients in understanding and solving a myriad of challenging resource planning and management problems.
This position may be located in Arlington, VA (Headquarters), Washington D.C., Pentagon, Springfield, VA., Chantilly, VA., Tysons Corner, VA.
Description:
We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk identification.
The ideal candidate has deep experience with NIST SP 800-30, MITRE ATT&CK, and threat modeling approaches, and can translate technical risks into mission/business impacts. You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans, presenting findings, and traveling to client sites for mission assessments.
We are looking for someone who is agile, creative, and collaborative ๏ฟฝ able to apply lessons learned, enable data tagging and structured knowledge capture, and help shift the organization from reactive responses toward proactive risk management.
Clearance Required: Active DOE Q or higher (or ability to obtain)
Key Responsibilities:
  • Serve as a Subject Matter Expert (SME) in cyber risk assessment, analysis, and mitigation strategies for critical missions.
  • Conduct on-site and remote cyber risk assessments of enterprise systems, applications, and mission-critical infrastructures.
  • Apply NIST SP 800-30 risk assessment methodology, threat modeling techniques, and frameworks such as MITRE ATT&CK to evaluate vulnerabilities, threats, and risks.
  • Develop and present risk characterization reports, mitigation considerations, and recommendations to client leadership and system owners.
  • Create and manage task plans, assessment schedules, and execution strategies to ensure effective delivery of assessment activities.
  • Collaborate with multi-disciplinary teams of SMEs (cybersecurity, systems engineering, OT, supply chain, and mission assurance) to address enterprise risks.
  • Support the identification, analysis, and validation of complex security risks and associated vulnerabilities, including both technical and operational impacts.
  • Assist in the development of threat-informed mitigation strategies aligned with client enterprise assurance goals.
  • Implement data tagging and structured knowledge capture to enable proactive risk identification, trend analysis, and lessons-learned reuse.
  • Build analytic processes that leverage historical assessment data, external threat databases, and adversary TTPs to anticipate potential risks rather than solely reacting to identified vulnerabilities.
  • Provide expert consultation on risk acceptance, mitigation prioritization, and remediation planning to stakeholders.
  • Maintain awareness of emerging threats, vulnerabilities, adversary tactics, and best practices for defense in depth across the nuclear enterprise.

Required Qualifications:
  • 10+ years of experience in cybersecurity risk assessment, vulnerability analysis, or cyber mission assurance.
  • Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal standards.
  • Hands-on experience with threat modeling approaches and application of MITRE ATT&CK for risk evaluation.
  • Demonstrated ability to conduct complex cyber risk assessments and present findings to executive and technical audiences.
  • Proven ability to develop task plans, manage assessment milestones, and work independently or as part of a team.
  • Strong writing and briefing skills to produce risk reports, mitigation strategies, and decision support artifacts.

Preferred Qualifications:
  • Experience supporting national security organizations.
  • Familiarity with supply chain risk management (SCRM), insider threat analysis, or mission-critical system assurance.
  • Operational Technology (OT) and Systems Engineering (SE) experience in complex enterprise environments.
  • Knowledge of nuclear enterprise operations and mission dependencies.
  • Technical certifications such as Security+, CISSP, CISM, C-RMA, CAP, CEH, or OSCP.
  • Prior experience briefing and advising SES-level leadership or program executives.
  • Familiarity with tools supporting risk assessments and vulnerability analysis (e.g., Threat Modeling tools).

Work Environment:
  • Hybrid environment with headquarters-based work in D.C. and regular travel to client sites for on-site risk assessments.
  • Fast-paced, collaborative environment with cross-disciplinary SMEs (cybersecurity, engineering, OT, program management, and intelligence).
  • Requires agility, creativity, and strong interpersonal skills to interact effectively with diverse stakeholders across government, contractors, and mission partners.
  • Role demands adaptability to dynamic mission needs, shifting priorities, and classified environments.
  • Emphasis on teamwork, analytical rigor, and the ability to translate technical risks into mission/business impacts.

Salary range: $105,000- 200,000 USD
The salary range listed is one part of our total compensation package, which may also include bonuses, incentives and benefits. Individual compensation is determined based on qualifications such as relevant years of experience, education, certifications and geographic location
Technomics is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to protected status under applicable law, including disability and protected veteran status.