1

Cyber Security Risk Analyst Jobs in Virginia (NOW HIRING)

The Cybersecurity Analyst will perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor. The role will ...

New

Cybersecurity Risk Engineersat the SEI use advanced skills in statistics, mathematics, risk analysis, systems engineering, economics and other technical fields in an interdisciplinary manner to help ...

Third-Party Risk Analyst

Mclean, VA · On-site

$45 - $47/hr

Third-Party Risk Analyst Location: McLean, VA (5 days - Onsite) Job Overview The Third-Party Risk ... Monitor and document third-party risk and cybersecurity trends. Documentation & Communications

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

... Risk Analyst, Cyber Defense Analyst, Network Security Analyst, IT Security Specialist, Security Consultant, Cybersecurity Specialist, Malware Analyst, Security Architect, ect. DEGREE (Level Desired ...

... Risk Analyst, Cyber Defense Analyst, Network Security Analyst, IT Security Specialist, Security Consultant, Cybersecurity Specialist, Malware Analyst, Security Architect, ect. DEGREE (Level Desired ...

... Risk Analyst, Cyber Defense Analyst, Network Security Analyst, IT Security Specialist, Security Consultant, Cybersecurity Specialist, Malware Analyst, Security Architect, ect. DEGREE (Level Desired ...

The Cybersecurity Compliance analyst will serve the Joint Staff (JS) by consolidating JS cybersecurity risk metrics, tracking compliance, and reporting to completion (i.e. Scorecard, FISMA ...

Sr. Cyber Analyst

Hampton, VA

$97K - $125K/yr

Provides recommendations to activity leadership on processes and methodologies to assess cybersecurity risk on information systems. Works with other Cyber Analysts, SMEs, and SCA-Rs to ensure that ...

... Cybersecurity Analyst responsible for leading governance, risk, and compliance (GRC) activities ... Responsibilities : • Leads governance, risk, and compliance activities supporting MODES III ...

next page

Showing results 1-20

Cyber Security Risk Analyst information

See Virginia salary details

$42.6K

$98.5K

$148.7K

How much do cyber security risk analyst jobs pay per year?

As of Jul 23, 2026, the average yearly pay for cyber security risk analyst in Virginia is $98,547.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,800.00 and $114,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Cyber Security Risk Analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

Can you make $200,000 in cyber security?

Cyber Security Risk Analysts with extensive experience, advanced certifications, and specialized skills can potentially earn $200,000 or more annually, especially in high-demand industries or senior roles. Achieving this salary often requires a combination of technical expertise, certifications like CISSP or CISA, and a strong understanding of risk management and security frameworks.

What does a cyber security risk analyst do?

A cyber security risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and recommending measures to mitigate risks. They analyze security data, develop risk management strategies, and often use tools like vulnerability scanners and risk assessment frameworks to protect information systems.

What is a Cyber Security Risk Analyst job?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by Cyber Security Risk Analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

How much does a cybersecurity risk analyst make?

A cybersecurity risk analyst's average salary in the United States ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions typically start around $60,000, while experienced analysts with certifications like CISSP or CISA can earn over $130,000. The role often requires knowledge of risk assessment tools and security frameworks.

Can you make $500,000 a year in cyber security?

Cyber Security Risk Analysts typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary usually requires senior roles such as Chief Information Security Officer (CISO) or executive positions, which involve strategic leadership and extensive industry experience. High salaries in cybersecurity are often associated with leadership, specialized skills, and working in high-demand sectors or organizations.
What are the most commonly searched types of Cyber Security Risk Analyst jobs in Virginia? The most popular types of Cyber Security Risk Analyst jobs in Virginia are:
What job categories do people searching Cyber Security Risk Analyst jobs in Virginia look for? The top searched job categories for Cyber Security Risk Analyst jobs in Virginia are:
What cities in Virginia are hiring for Cyber Security Risk Analyst jobs? Cities in Virginia with the most Cyber Security Risk Analyst job openings:
Infographic showing various Cyber Security Risk Analyst job openings in Virginia as of July 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $98,547 per year, or $47.4 per hour.
Cybersecurity Analyst

Cybersecurity Analyst

Pae

Mclean, VA

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted yesterday


Job description

Amentum is seeking a Cybersecurity Analyst to join our team and support our McLean, VA customer. We are looking for team members who are passionate about making a difference by working on critical efforts we manage as a premier government contractor.

Here at Amentum, we are purpose-driven with a fierce commitment to deliver on our promises. We create trailblazing solutions, have unwavering integrity, and embrace inclusion and collaboration. Our team is excited to help customers solve todays and tomorrow's problems, giving confidence and reassurance that together we'll accomplish mission success.

Purpose / Scope:

The Cybersecurity Analyst will perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor. The role will conduct cybersecurity analysis in preparation for A&A reviewing and validation of all associated cybersecurity documentation and technical controls.

The role will work within a team that conducts A&A activities. This individual will develop System Security Plans (SSP), Contingency Plans, Business Impact Analyses (BIA), Plan of Action and Milestones (POA&Ms), Security Assessment Report (SARs), Security Assessment Plan (SAPs), and other RMF documentation.

This position covers all cybersecurity aspects including, but not limited to, identifying risks, validating the mitigation of plans of action, analyzing system designs, and assisting with A&A issues that may prevent a system from receiving authorization. It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned.

The Cybersecurity Analyst will assess and mitigates system security threats/risks throughout the program life cycle. Contribute to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations. Create and review A&A Body of Evidence documentation, providing feedback on completeness and compliance of its content. Develop and execute Security Test Plan (STP) in close cooperation with team members. Manage and ensure Continuous Monitoring (CONMON) to maintain system authorization.

Essential Responsibilities:

  • Identify key stakeholders in A&A efforts and ensure system documentation reflects current system security configurations to include hardware and software components, data flow, interconnections, and ports, protocols, and services, etc.
  • Identify potential risks associated with system configurations and advise on mitigation strategies
  • Participate in A&A status meetings and facilitate moving systems toward a successful A&A effort
  • Assist to estimate Level of Effort (LOE) involved in performing A&A activities
  • Assist customer program offices in interpreting and applying mitigation strategies
  • Conduct thorough reviews of all vulnerabilities, architecture, and defense in depth strategies and report findings in POA&Ms document
  • Document residual risks and provide the cybersecurity risk analysis and mitigation determination results
  • Maintain cybersecurity policy and processes as assigned
  • Able to analyze, interpret, and apply Federal cybersecurity guidance to customer needs
  • Communicate the security posture of systems through designated reporting mechanism
  • Collaborate with other team members in cybersecurity

Minimum Requirements:

  • 5+ years of experience in the following areas: Cybersecurity policy, procedures, and processes, including RMF and NIST 800-53 and A&A's
  • Experience developing A&A documentation from scratch and performing assessments; RMF step 1 through 4
  • Familiar with NIST publications, specifically RMF and NIST controls
  • One or more of the following certifications preferred (Security+, CAP, CISSP, CISM, GSEC, GCIH, or GSLC)
  • Minimum DoD 8570 Information Assurance Management Technology (IAM) level II
  • Familiar with dealing with defense-in-depth, and other information security and assurance principles and associated supporting technologies
  • Hands on experience and detailed familiarity with the A&A processes
  • Experience working in Xacta, Greenlight/Roadrunner
  • Excellent customer service and organization skills
  • Must demonstrate proficiency in the following areas: multi-tasking, critical thinking; and the ability to work quickly, efficiently and accurately in a dynamic and fluid environment
  • Must have a Top-Secret Clearance with polygraph
  • Must be able to read, speak, write, and understand the English language

Preferred Qualifications:

  • BA/BS Degree
  • Excellent oral and written communication skills
  • Ability to interact and relay security technical requirements at all levels of leadership and work force
  • Ability to work both independently and as a member of a team

Work Environment, Physical Demands, and Mental Demands:

Typical office environment with no unusual hazards, occasional lifting to 20 pounds, constant sitting while using the computer terminal, constant use of sight abilities while reviewing documents, constant use of speech/hearing abilities for communication, constant mental alertness, must possess planning/organizing skills, and must be able to work under deadlines.

Other Responsibilities:

Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment. As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams.

Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction. It is our policy to consistently provide services that meet customer expectations. Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts. Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities

Procedure Compliance - Each employee must read, understand and implement the general and specific operational, safety, quality and environmental requirements of all plans, procedures and policies pertaining to his/her job.

Compensation Details:

$130,000 - $160,000

The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.

Benefits Overview:

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance

  • Paid time off and holidays

  • Retirement benefits (including 401(k) matching)

  • Educational reimbursement

  • Parental leave

  • Employee stock purchase plan

  • Tax-saving options

  • Disability and life insurance

  • Pet insurance

Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

Original Posting:

07/21/2026 - Until Filled

Amentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs.

Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed, marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language atLabor Laws Posters.