1

Cyber Security Risk Analyst Jobs in Virginia (NOW HIRING)

Third-Party Risk Analyst

Mclean, VA · On-site

$45 - $47/hr

Third-Party Risk Analyst Location: McLean, VA (5 days - Onsite) Job Overview The Third-Party Risk ... Monitor and document third-party risk and cybersecurity trends. Documentation & Communications

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

... Risk Analyst, Cyber Defense Analyst, Network Security Analyst, IT Security Specialist, Security Consultant, Cybersecurity Specialist, Malware Analyst, Security Architect, ect. DEGREE (Level Desired ...

... Risk Analyst, Cyber Defense Analyst, Network Security Analyst, IT Security Specialist, Security Consultant, Cybersecurity Specialist, Malware Analyst, Security Architect, ect. DEGREE (Level Desired ...

... Risk Analyst, Cyber Defense Analyst, Network Security Analyst, IT Security Specialist, Security Consultant, Cybersecurity Specialist, Malware Analyst, Security Architect, ect. DEGREE (Level Desired ...

Risk Business Analyst

Merrifield, VA · On-site

$40 - $54/hr

Operate effectively within a technology, cybersecurity, governance, risk, and compliance ... Strong analytical, organizational, and problem-solving skills. * Experience performing data ...

Showing results 21-40

Cyber Security Risk Analyst information

See Virginia salary details

$42.6K

$98.5K

$148.7K

How much do cyber security risk analyst jobs pay per year?

As of Aug 8, 2026, the average yearly pay for cyber security risk analyst in Virginia is $98,547.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,800.00 and $114,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the cyber security risk analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

What is a cyber security risk analyst?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by cyber security risk analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

What does a cybersecurity risk analyst do?

A cybersecurity risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and analyzing risks to information systems. They develop strategies to mitigate risks, often using tools like risk assessment frameworks and security audits, and may hold certifications such as CISSP or CISA. Their work helps organizations protect sensitive data and ensure compliance with security standards.

How much does a cyber security risk analyst make?

The average salary for a cyber security risk analyst is around $80,000 to $110,000 per year, depending on experience, certifications, and location. Entry-level positions typically start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. The role often requires knowledge of risk assessment tools and security frameworks.
What are the most commonly searched types of Cyber Security Risk Analyst jobs in Virginia? The most popular types of Cyber Security Risk Analyst jobs in Virginia are:
What cities in Virginia are hiring for Cyber Security Risk Analyst jobs? Cities in Virginia with the most Cyber Security Risk Analyst job openings:
Infographic showing various Cyber Security Risk Analyst job openings in Virginia as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $98,547 per year, or $47.4 per hour.

Cybersecurity Analyst Expert

Pueo Business Solutions LLC

Mclean, VA • On-site

Full-time

Posted 22 days ago


Job description

Description:


The Cybersecurity Analyst supports the security, compliance, and maintenance of information systems throughout the Risk Management Framework (RMF) lifecycle, from system preparation through decommissioning. This role ensures alignment with Intelligence Community Directive (ICD), Defense Intelligence Agency (DIA), and Department of Defense (DoD) cybersecurity policies and standards.


The analyst works closely with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), Security Control Assessors (SCAs), Program Managers (PMs), and other stakeholders to execute RMF activities, reduce cybersecurity risk, and improve the overall security posture of supported systems. This position focuses on driving meaningful security outcomes through vulnerability management, continuous monitoring, compliance support, and risk-informed decision-making.


Roles and Responsibilities

  • Support information systems throughout the RMF lifecycle, ensuring compliance with applicable cybersecurity policies, standards, and regulations.
  • Collaborate with ISSMs, ISSOs, SCAs, PMs, and other stakeholders to support security initiatives and compliance efforts.
  • Assist stakeholders in understanding cybersecurity risks, vulnerability impacts, and remediation priorities to improve system security posture.
  • Provide technical support for continuous monitoring activities, compliance reporting, and audit readiness initiatives.
  • Evaluate cybersecurity implications of system modifications, upgrades, and configuration changes.
  • Support implementation, assessment, and documentation of security controls.
  • Maintain and update cybersecurity documentation, authorization packages, and RMF artifacts.
  • Document vulnerabilities, misconfigurations, and security findings clearly to support remediation planning and stakeholder awareness.
  • Utilize Xacta or similar Cyber Risk Management platforms to manage risk assessments, security control evidence, compliance status, and POA&M activities.
  • Track and manage POA&M items to ensure vulnerabilities identified through scans, assessments, or audits are properly documented, mitigated, and resolved.
  • Analyze vulnerability and compliance data to identify trends, recurring issues, and opportunities for security improvements.
  • Promote cybersecurity best practices and ensure alignment with organizational and mission objectives.

Knowledge

  • Knowledge of the Risk Management Framework (RMF), NIST 800-series publications, Federal Information Processing Standards (FIPS), Security Authorization and Assessment (SA&A) processes, continuous monitoring, POA&M management, and vulnerability management.
  • Understanding of cybersecurity compliance requirements within DoD, DIA, and Intelligence Community environments.
  • Familiarity with cybersecurity risk management platforms such as Xacta and related compliance management tools.

Skills

  • Strong verbal and written communication skills with the ability to explain technical concepts to both technical and non-technical audiences.
  • Experience interpreting vulnerability and compliance reports generated from tools such as Xacta, STIG Viewer, ACAS, Prisma, Splunk, Trellix (HBSS), or similar security platforms.
  • Strong analytical, troubleshooting, and problem-solving abilities.
  • Ability to identify root causes of security issues and recommend practical remediation strategies.
  • Experience working across multiple teams and stakeholders to achieve security and compliance objectives.
  • Ability to manage competing priorities while maintaining attention to detail and accuracy.
  • Strong organizational skills and ability to maintain comprehensive security documentation.

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • Obtain and maintain an IAT Level III certification, or maintain an IAT Level II certification, in accordance with DoD 8570.01-M and DoD Directive 8140 Cyberspace Workforce Management requirements.
  • Acceptable certifications include: CompTIA Cybersecurity Analyst (CySA+), CompTIA Security+, EC-Council Certified Network Defender (CND v3), CCNA Security, Global Industrial Cyber Security Professional (GICSP), GIAC Security Essentials (GSEC), Systems Security Certified Practitioner (SSCP)

Clearence

  • Active Top Secret clearance is required with SCI eligibility and the ability to Pass CI Poly


Pueo is an equal employment opportunity employer and affirmative action employer. All interested individuals will receive consideration and will not be discriminated against on the basis of race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity, genetic information, or protected veteran status. Pueo takes affirmative action in support of its policy to advance diversity and inclusion of individuals who are minorities, women, protected veterans, and individuals with disabilities.

Requirements: