1

Cyber Risk Jobs in Washington (NOW HIRING)

Director, Cyber Risk

Sterling, VA ยท On-site

$180 - $280/hr

Own and continuously improve the cyber and technology risk management framework, methodology, taxonomy, and lifecycle aligned to NIST CSF 2.0, ISO 27001/27005, and applicable regulatory obligations.

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk ...

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk ...

Manager, Cyber Risk & Analysis

Mclean, VA ยท On-site

$165 - $188/hr

## Manager, Cyber Risk & AnalysisApplylocations: McLean, VA: Richmond, VAtime type: Full timeposted on: Posted Todayjob requisition id: R248661Manager, Cyber Risk & AnalysisAs a Manager, you will apply ...

New

Manager, Cyber Risk & Analysis As a Manager, you will apply your technical expertise, risk management acumen, and project management skills to drive Risk Management Strategy for a major technology ...

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk ...

Manager, Cyber Risk & Analysis As a Manager, you will apply your technical expertise, risk management acumen, and project management skills to drive Risk Management Strategy for a major technology ...

Manager - Cyber Risk & Analysis As a Technology Risk Manager, you will drive strategy and execute on high priority projects for the company in the Card Technology Risk area. The successful candidate ...

Data Analyst/Cyber Risk

Fort George G Meade, MD ยท On-site

$135K - $216K/yr

Responsibilities Peraton seeks a Data Analyst/Cyber Risk to provide Mission Assurance and Operations Research Analysis (MA/ORSA) support. Location : Fort Meade, Maryland. In this role, you will be ...

Manager, Cyber Risk & Analysis

Mclean, VA ยท On-site

$112K - $151K/yr

Manager, Cyber Risk & Analysis Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and ...

Cyber Risk Analyst (TS/SCI) Reston, VA, USA Full-time Clearance: Top Secret/SCI Summary: Warnings about cyber threats are everywhere and the constantly evolving nature of these threats can make ...

Cyber Risk Analyst (TS/SCI)

Reston, VA ยท On-site

$95 - $140/hr

Cyber Risk Analyst (TS/SCI) Reston, VA, USA / Full-time / Clearance: Top Secret/SCI Summary: Warnings about cyber threats are everywhere and the constantly evolving nature of these threats can make ...

next page

Showing results 1-20

Cyber Risk information

See Washington salary details

$77.6K

$146K

$183.5K

How much do cyber risk jobs pay per year?

As of Aug 19, 2026, the average yearly pay for cyber risk in Washington is $145,971.00, according to ZipRecruiter salary data. Most workers in this role earn between $128,000.00 and $165,900.00 per year, depending on experience, location, and employer.

What is cyber risk?

Cyber risk refers to the potential for financial loss, disruption, or damage to an organization due to the failure of its information technology systems. This includes threats such as data breaches, hacking, malware, ransomware, and unauthorized access to sensitive information. Managing cyber risk involves identifying vulnerabilities, implementing security measures, and creating response plans to minimize the impact of cyber incidents. Organizations often employ specialists to assess and mitigate these risks, ensuring the safety of their digital assets.

What are the key skills and qualifications needed to thrive as a Cyber Risk professional?

To thrive as a Cyber Risk professional, you need a solid understanding of information security principles, risk assessment methodologies, and regulatory compliance frameworks, often supported by a degree in cybersecurity, IT, or related fields. Familiarity with tools such as SIEM platforms, vulnerability scanners, and relevant certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey complex security issues to diverse stakeholders. These competencies are crucial for protecting organizational assets, ensuring compliance, and proactively managing evolving cyber threats.

What are some typical challenges faced by professionals in a Cyber Risk role, and how can they be addressed?

Professionals in Cyber Risk roles often encounter challenges such as rapidly evolving cyber threats, balancing business needs with security requirements, and managing cross-departmental communication. Staying current with emerging risks and regulatory changes requires continuous learning and adaptability. Effective collaboration with IT, legal, and business units is crucial to implement practical risk mitigation strategies. Building strong relationships and clear communication channels within the organization can help address these challenges and ensure cyber risk is managed proactively.

What is the difference between Cyber Risk vs Cyber Security Analyst?

AspectCyber RiskCyber Security Analyst
Primary FocusIdentifying, assessing, and managing cybersecurity risks and vulnerabilitiesMonitoring, analyzing, and responding to security threats and incidents
Required CredentialsCertifications like CISSP, CISM, CRISC; risk management experienceCertifications like CompTIA Security+, CISSP; technical security skills
Work EnvironmentRisk management teams, compliance departments, strategic planningSecurity operations centers, IT teams, incident response teams
Industry UsageUsed across finance, healthcare, government for risk mitigationUsed in IT and cybersecurity departments for threat defense

While both roles focus on cybersecurity, Cyber Risk professionals primarily assess and manage potential threats at a strategic level, whereas Cyber Security Analysts focus on technical threat detection and response. Understanding these differences helps organizations allocate resources effectively and align roles with their security objectives.

What are the most commonly searched types of Cyber Risk jobs in Washington?

The most popular types of Cyber Risk jobs in Washington are:

Infographic showing various Cyber Risk job openings in Washington as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 6% Part Time, 2% Temporary, and 7% Contract. Highlights an 82% Physical, 5% Hybrid, and 13% Remote job distribution, with an average salary of $145,971 per year, or $70.2 per hour.

Director, Cyber Risk

Jobtailor

Sterling, VA โ€ข On-site

$180 - $280/hr

Other

Posted 14 days ago


Job description

Responsibilities
  • Own and continuously improve the cyber and technology risk management framework, methodology, taxonomy, and lifecycle aligned to NIST CSF 2.0, ISO 27001/27005, and applicable regulatory obligations.
  • Define standards, procedures, and rating scales for consistent enterprise-wide risk identification, assessment, and reporting; partner with the PISO model to ensure common language and practices across portfolios.
  • Lead enterprise cyber risk assessments across technology, business, regulatory, and emerging-risk domains to produce consistent, defensible determinations.
  • Establish and operate a cyber risk quantification capability (e.g., FAIR-based) to express risk in business and financial terms and inform prioritization and investment decisions.
  • Maintain the enterprise cyber risk register; ensure risks are wellโ€‘described, owned, rated, and tracked to acceptable residual levels; develop and manage KRI/KCI programs for forwardโ€‘looking posture.
  • Operationalize the risk appetite and tolerance framework with the CISO and senior leadership; own risk acceptance and exception governance with clear, auditable documentation and timeโ€‘bound approvals.
  • Govern cyber risk policy structure, ownership, review cadence, and exception handling; chair or support cyber risk forums and escape decisions to appropriate authority levels.
  • Lead secondโ€‘line, riskโ€‘based assurance over design and operating effectiveness of key cyber controls in coordination with firstโ€‘line and Internal Audit; identify thematic weaknesses and drive structural remediation.
  • Own issues and remediation managementโ€”intake, prioritization, owner assignment, tracking to closure, and escalation of aging items.
  • Define and report outcomeโ€‘focused metrics (e.g., residual risk trends, outโ€‘ofโ€‘appetite reduction, earlyโ€‘versusโ€‘late finding ratios, incidents tied to accepted risk) in executiveโ€‘ and boardโ€‘ready formats.
  • Serve as primary point of contact for cyber risk in regulatory exams, audits, and carrierโ€‘partner due diligence.
  • Integrate cyber risk into Enterprise Risk Management to ensure consistency in enterprise risk reporting and governance; partner with Legal, Privacy, Procurement, and technology leaders to embed riskโ€‘informed decisions.
  • Oversee vendor/thirdโ€‘party risk within the cyber risk portfolio to ensure supplyโ€‘chain risk is governed in line with enterprise practices.
  • Build, lead, and develop a team of senior managers and analysts; set objectives, manage performance, and scale capacity through process improvement, tooling, and appropriate AIโ€‘assisted workflows.
Requirements
  • Bachelorโ€™s degree in a related field or equivalent professional experience.
  • 10+ years in cybersecurity, IT/technology risk, or GRC, including 5+ years leading managers or multiple teams/domains.
  • Proven experience designing, leading, or substantially maturing an endโ€‘toโ€‘end enterprise cyber/IT risk management program.
  • Deep knowledge of NIST CSF 2.0, ISO 27001/27005, relevant regulatory regimes, and the threeโ€‘linesโ€‘ofโ€‘defense model.
  • Experience operating a risk register, risk appetite/tolerance framework, and risk acceptance/exception governance.
  • Handsโ€‘on experience with GRC/IRM platforms (e.g., ServiceNow IRM, Archer, OneTrust, or comparable).
  • Excellent executive communication skills with a track record of briefing senior leadership and boards.
  • Strong crossโ€‘functional influence partnering across security, technology, legal, privacy, and business teams.
#J-18808-Ljbffr