1

Cyber Risk Resilience Analyst Jobs (NOW HIRING)

$140K - $190K/yr

... cyber resilience, data protection, and regulatory compliance across the Firm's technology ... Analyze new and emerging risks, including related regulatory requirements and supervisory guidance ...

Cyber Risk Analyst (TS/SCI) Reston, VA, USA Full-time Clearance: Top Secret/SCI Summary: Warnings about cyber threats are everywhere and the constantly evolving nature of these threats can make ...

Cyber Risk Analyst (TS/SCI) Reston, VA, USA / Full-time / Clearance: Top Secret/SCI Summary: Warnings about cyber threats are everywhere and the constantly evolving nature of these threats can make ...

$108K - $185K/yr

Contribute to the development of risk metrics, KRIs, KCIs, maturity indicators, and predictive cyber risk analytics* Collaborate across Lines of Defense to strengthen enterprise cyber resilience and ...

$108K - $185K/yr

Contribute to the development of risk metrics, KRIs, KCIs, maturity indicators, and predictive cyber risk analytics * Collaborate across Lines of Defense to strengthen enterprise cyber resilience and ...

Showing results 41-60

Cyber Risk Resilience Analyst information

See salary details

$44.5K

$107.5K

$151K

How much do cyber risk resilience analyst jobs pay per year?

As of Sep 10, 2026, the average yearly pay for cyber risk resilience analyst in the United States is $107,522.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $126,500.00 per year, depending on experience, location, and employer.

What is a cyber risk resilience analyst?

A Cyber Risk Resilience Analyst is a professional who assesses an organization's cybersecurity posture, identifies vulnerabilities, and develops strategies to reduce risks and ensure continuity in the face of cyber threats. They analyze threats, evaluate current security measures, and recommend improvements to enhance the organization's ability to withstand and recover from cyber incidents. These analysts often collaborate with IT, security teams, and business leaders to implement best practices and compliance standards, helping organizations remain resilient against evolving cyber risks.

What are the key skills and qualifications needed to thrive as a cyber risk resilience analyst?

To thrive as a Cyber Risk Resilience Analyst, you need a solid understanding of cybersecurity principles, risk assessment methodologies, and business continuity planning, often supported by a degree in information security or related fields. Familiarity with tools like SIEM systems, vulnerability scanners, and certifications such as CISSP or CISM are typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for evaluating threats and advising stakeholders. These competencies are vital to proactively manage cyber risks, ensure organizational resilience, and safeguard critical assets.

How does a cyber risk resilience analyst typically collaborate with other departments to strengthen organizational security?

A Cyber Risk Resilience Analyst works closely with IT, legal, compliance, and business units to identify vulnerabilities and develop strategies for risk mitigation. Regularly, they facilitate cross-departmental workshops, conduct risk assessments, and communicate findings to both technical and non-technical stakeholders. This collaboration ensures that security policies are aligned with business goals and regulatory requirements, fostering a culture of shared responsibility for cyber resilience across the organization.

What is the difference between Cyber Risk Resilience Analyst vs Cybersecurity Analyst?

AspectCyber Risk Resilience AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentFocus on risk management, resilience planning, and incident responseFocus on threat detection, system monitoring, and security measures
Employer & Industry UsageFinancial, healthcare, government sectors emphasizing risk mitigationIT and tech companies, security firms, and organizations with technical security needs

The main difference is that Cyber Risk Resilience Analysts concentrate on assessing and improving an organization's ability to withstand cyber threats and recover from incidents, while Cybersecurity Analysts primarily focus on identifying and mitigating security threats through technical measures. Both roles require similar certifications but serve different aspects of cybersecurity strategy.

What are popular job titles related to Cyber Risk Resilience Analyst jobs?

For Cyber Risk Resilience Analyst jobs, the most frequently searched job titles are:

Infographic showing various Cyber Risk Resilience Analyst job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 82% Physical, 4% Hybrid, and 14% Remote job distribution, with an average salary of $107,522 per year, or $51.7 per hour.

NC3 Cyber Subject Matter Expert

Alexandria, VA • On-site

Systems Planning and Analysis
Guided Missile and Space Vehicle Manufacturing • 1 - 5K employees

Full-time

Medical, Life, Retirement

Re-posted 13 days ago


Job description

Overview
Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter. Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.
The SLA Analysis Group's mission is to deliver objective analyses, plans and strategies to US Navy, US Marine Corps, USAF, other DoD, and Australian Defence Force clients to support technology development, acquisition, delivery and sustainment decisions. The group provides the core of SPA thought leadership on Undersea Strategy, Software Development and Cost Estimating, with additional benchmark capabilities in AI/ML & Decision Analytics, Modeling and Simulation, and Future Force Assessments. #MC
SPA has a need for a senior NC3 Cyber Analyst to lead analysis, integration, and advocacy for cyber hardening across the Department of the Air Force's Nuclear Command, Control, and Communications (NC3) enterprise. This role helps ensure that NC3 systems remain resilient, survivable, and secure so national leaders can exercise Nuclear Command and Control (NC2) under all conditions
Responsibilities
The NC3 Cyber Analyst evaluates NC3 systems, architectures, and modernization efforts to assess cyber risk, survivability, and resilience across cyber, physical, and electromagnetic threats, delivering decision-quality findings to AF/A10 and NC3 governance bodies. They integrate AF/A10 objectives into NC3 cyber-hardening PPBE activities to ensure cyber requirements and mitigations inform Service and Joint requirements, acquisitions, and resourcing. They support AF/A10X in NC3 governance forums-such as NEORAG and NC3 cyber working groups-by developing senior-leader packages, technical inputs, and talking points, and by tracking actions and decisions. The analyst collaborates with DAF CIO/CISO, MAJCOMs, AFNWC/AFLCMC, USSTRATCOM, and other stakeholders to increase transparency, align cyber-hardening efforts with strategic guidance, and help provide an enterprise-level view of NC3 cyber risk and mitigation priorities.
Qualifications
Required:
  • Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a related technical field.
  • 8+ years of experience in cybersecurity operations, engineering, or cyber risk management, with a substantial portion focused on mission-critical or command-and-control systems in DoD or the Intelligence Community.
  • Demonstrated experience assessing the resiliency and survivability of complex systems against cyber, physical, and electromagnetic threats, and translating those assessments into clear recommendations for policy, requirements, and investment.
  • Familiarity with NC3 or other nuclear/strategic C2 environments, including how cyber vulnerabilities and mitigations intersect with mission assurance, survivability, and surety requirements.
  • Strong understanding of DoD cybersecurity frameworks, including RMF, eMASS, IAVM, and application of NIST SP 800-53 and related guidance to enterprise systems.
  • Proven ability to support PPBE-related analysis and documentation, connecting cyber risk findings to program/budget positions and decision forums.
  • Active TS/SCI clearance and the ability to maintain it throughout employment

Desired:
  • Direct experience supporting AF/A10X or NC3 governance forums (e.g., NEORAG, NC3 cyber working groups, NLCC/CONLC3S-related bodies), including preparation of read-aheads, talking points, and post-forum products.
  • Experience using model-based or data-driven approaches (e.g., architecture models, dashboards, risk registers) to link cyber vulnerabilities and mitigations to NC3 mission threads and operational impacts.
  • Background coordinating across Service, Joint, and interagency stakeholders (e.g., USSTRATCOM, DoD CIO, OSD, AFNWC/AFLCMC, MAJCOMs) on NC3 or other high-consequence cyber issues.
  • Relevant advanced degree (e.g., in cybersecurity, systems engineering, or operations research) or advanced cybersecurity certification (e.g., CISSP, CISM, CASP+).

Pay Range Information
At SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Virginia, Pay Transparency Salary range: USD $180,000.00/Yr. - USD $200,000.00/Yr.