1

Cyber Risk Jobs in Washington, DC (NOW HIRING)

Cyber GRC Specialist

Washington, DC ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance. Duties and ...

You'll be part of a highly functional team responsible for developing strategy, assessing risk and coordinating reporting to Capital One's Board of Directors, executive leadership, Cyber and ...

Cyber GRC Specialist

Washington, DC ยท On-site

$90 - $130/hr

Maintain the cyber risk register and document risk decisions, remediation plans, due dates, dependencies, and residual risk * Administer and contribute process support to ISO and security-risk ...

New

Showing results 41-60

Cyber Risk information

See Washington, DC salary details

$77.6K

$146K

$183.5K

How much do cyber risk jobs pay per year?

As of Aug 19, 2026, the average yearly pay for cyber risk in Washington, DC is $145,971.00, according to ZipRecruiter salary data. Most workers in this role earn between $128,000.00 and $165,900.00 per year, depending on experience, location, and employer.

What is cyber risk?

Cyber risk refers to the potential for financial loss, disruption, or damage to an organization due to the failure of its information technology systems. This includes threats such as data breaches, hacking, malware, ransomware, and unauthorized access to sensitive information. Managing cyber risk involves identifying vulnerabilities, implementing security measures, and creating response plans to minimize the impact of cyber incidents. Organizations often employ specialists to assess and mitigate these risks, ensuring the safety of their digital assets.

What are the key skills and qualifications needed to thrive as a Cyber Risk professional?

To thrive as a Cyber Risk professional, you need a solid understanding of information security principles, risk assessment methodologies, and regulatory compliance frameworks, often supported by a degree in cybersecurity, IT, or related fields. Familiarity with tools such as SIEM platforms, vulnerability scanners, and relevant certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey complex security issues to diverse stakeholders. These competencies are crucial for protecting organizational assets, ensuring compliance, and proactively managing evolving cyber threats.

What are some typical challenges faced by professionals in a Cyber Risk role, and how can they be addressed?

Professionals in Cyber Risk roles often encounter challenges such as rapidly evolving cyber threats, balancing business needs with security requirements, and managing cross-departmental communication. Staying current with emerging risks and regulatory changes requires continuous learning and adaptability. Effective collaboration with IT, legal, and business units is crucial to implement practical risk mitigation strategies. Building strong relationships and clear communication channels within the organization can help address these challenges and ensure cyber risk is managed proactively.

What is the difference between Cyber Risk vs Cyber Security Analyst?

AspectCyber RiskCyber Security Analyst
Primary FocusIdentifying, assessing, and managing cybersecurity risks and vulnerabilitiesMonitoring, analyzing, and responding to security threats and incidents
Required CredentialsCertifications like CISSP, CISM, CRISC; risk management experienceCertifications like CompTIA Security+, CISSP; technical security skills
Work EnvironmentRisk management teams, compliance departments, strategic planningSecurity operations centers, IT teams, incident response teams
Industry UsageUsed across finance, healthcare, government for risk mitigationUsed in IT and cybersecurity departments for threat defense

While both roles focus on cybersecurity, Cyber Risk professionals primarily assess and manage potential threats at a strategic level, whereas Cyber Security Analysts focus on technical threat detection and response. Understanding these differences helps organizations allocate resources effectively and align roles with their security objectives.

What are the most commonly searched types of Cyber Risk jobs in Washington, DC?

The most popular types of Cyber Risk jobs in Washington, DC are:

Infographic showing various Cyber Risk job openings in Washington, DC as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 9% Part Time, and 4% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $145,971 per year, or $70.2 per hour.

NC3 Cyber Subject Matter Expert

Arenatechnologies

Alexandria, VA โ€ข On-site

$180 - $200/hr

Other

Medical, Life, Retirement

Posted 14 days ago


Job description

Overview

Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter. Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.

The SLA Analysis Groupโ€™s mission is to deliver objective analyses, plans and strategies to US Navy, US Marine Corps, USAF, other DoD, and Australian Defence Force clients to support technology development, acquisition, delivery and sustainment decisions. The group provides the core of SPA thought leadership on Undersea Strategy, Software Development and Cost Estimating, with additional benchmark capabilities in AI/ML & Decision Analytics, Modeling and Simulation, and Future Force Assessments. #MC

SPA has a need for a senior NC3 Cyber Analyst to lead analysis, integration, and advocacy for cyber hardening across the Department of the Air Forceโ€™s Nuclear Command, Control, and Communications (NC3) enterprise. This role helps ensure that NC3 systems remain resilient, survivable, and secure so national leaders can exercise Nuclear Command and Control (NC2) under all conditions

Responsibilities

The NC3 Cyber Analyst evaluates NC3 systems, architectures, and modernization efforts to assess cyber risk, survivability, and resilience across cyber, physical, and electromagnetic threats, delivering decision-quality findings to AF/A10 and NC3 governance bodies. They integrate AF/A10 objectives into NC3 cyberโ€‘hardening PPBE activities to ensure cyber requirements and mitigations inform Service and Joint requirements, acquisitions, and resourcing. They support AF/A10X in NC3 governance forumsโ€”such as NEORAG and NC3 cyber working groupsโ€”by developing seniorโ€‘leader packages, technical inputs, and talking points, and by tracking actions and decisions. The analyst collaborates with DAF CIO/CISO, MAJCOMs, AFNWC/AFLCMC, USSTRATCOM, and other stakeholders to increase transparency, align cyberโ€‘hardening efforts with strategic guidance, and help provide an enterpriseโ€‘level view of NC3 cyber risk and mitigation priorities.

Qualifications

Required:

  • Bachelorโ€™s degree in cybersecurity, computer science, information systems, engineering, or a related technical field.
  • 8+ years of experience in cybersecurity operations, engineering, or cyber risk management, with a substantial portion focused on missionโ€‘critical or command-and-control systems in DoD or the Intelligence Community.
  • Demonstrated experience assessing the resiliency and survivability of complex systems against cyber, physical, and electromagnetic threats, and translating those assessments into clear recommendations for policy, requirements, and investment.
  • Familiarity with NC3 or other nuclear/strategic C2 environments, including how cyber vulnerabilities and mitigations intersect with mission assurance, survivability, and surety requirements.
  • Strong understanding of DoD cybersecurity frameworks, including RMF, eMASS, IAVM, and application of NIST SP 800โ€‘53 and related guidance to enterprise systems.
  • Proven ability to support PPBE-related analysis and documentation, connecting cyber risk findings to program/budget positions and decision forums.
  • Active TS/SCI clearance and the ability to maintain it throughout employment

Desired:

  • Direct experience supporting AF/A10X or NC3 governance forums (e.g., NEORAG, NC3 cyber working groups, NLCC/CONLC3Sโ€‘related bodies), including preparation of readโ€‘aheads, talking points, and postโ€‘forum products.
  • Experience using modelโ€‘based or dataโ€‘driven approaches (e.g., architecture models, dashboards, risk registers) to link cyber vulnerabilities and mitigations to NC3 mission threads and operational impacts.
  • Background coordinating across Service, Joint, and interagency stakeholders (e.g., USSTRATCOM, DoD CIO, OSD, AFNWC/AFLCMC, MAJCOMs) on NC3 or other highโ€‘consequence cyber issues.
  • Relevant advanced degree (e.g., in cybersecurity, systems engineering, or operations research) or advanced cybersecurity certification (e.g., CISSP, CISM, CASP+).

Pay Range Information

At SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Virginia, Pay Transparency Salary range: USD $180,000.00/Yr. - USD $200,000.00/Yr.

#J-18808-Ljbffr