1

Cyber Security Risk Analyst Jobs in Virginia (NOW HIRING)

Responsibilities: • Leads governance, risk, and compliance activities supporting MODES III cybersecurity operations, ensuring alignment with DoD, DISA, and MC&FP cybersecurity requirements. • ...

Leads governance, risk, and compliance activities supporting MODES III cybersecurity operations ... Provides senior-level risk analysis and compliance reporting to Government stakeholders, ensuring ...

About the Team We are seeking a highly skilled Principal cybersecurity engineer to architect the ... Advanced Risk Modeling: Expertise in quantitative risk analysis (e.g., Monte Carlo simulations or ...

The Cybersecurity Compliance analyst will serve the Joint Staff (JS) by consolidating JS cybersecurity risk metrics, tracking compliance, and reporting to completion (i.e. Scorecard, FISMA ...

Cyber Risk Analyst (TS/SCI) Reston, VA, USA Full-time Clearance: Top Secret/SCI Summary: Warnings ... Experience with DoD or IC cybersecurity projects or programs * Experience with DevSecOps, Path-to ...

Our specialties include cybersecurity, cloud modernization, software development, data analytics ... Advise leadership on cyber risk, threat trends, security gaps, mitigation strategies, and ...

Manager, Cyber Risk & Analysis

Mclean, VA · On-site

$112K - $151K/yr

Manager, Cyber Risk & Analysis Capital One is one of the fastest growing organizations in the world ... This role sits at the intersection of cybersecurity and privacy in support of the Governance Risk ...

Responsibilities : • Conduct cybersecurity risk assessments of industrial control systems (ICS ... activities, analyzing and mitigating threats to quickly restore secure and stable operations.

Manager, Cyber Risk & Analysis

Mclean, VA

$112K - $151K/yr

Manager, Cyber Risk & Analysis Capital One is one of the fastest growing organizations in the world ... This role sits at the intersection of cybersecurity and privacy in support of the Governance Risk ...

Their work depends on a Technical Security Risk Analyst joining the team to support Government activities in McLean, VA. \n \n \n As a Technical Security Risk Analyst supporting the customer, you ...

next page

Showing results 1-20

Cyber Security Risk Analyst information

See Virginia salary details

$42.6K

$98.5K

$148.7K

How much do cyber security risk analyst jobs pay per year?

As of Jul 24, 2026, the average yearly pay for cyber security risk analyst in Virginia is $98,547.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,800.00 and $114,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Cyber Security Risk Analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

Can you make $200,000 in cyber security?

Cyber Security Risk Analysts with extensive experience, advanced certifications, and specialized skills can potentially earn $200,000 or more annually, especially in high-demand industries or senior roles. Achieving this salary often requires a combination of technical expertise, certifications like CISSP or CISA, and a strong understanding of risk management and security frameworks.

What does a cyber security risk analyst do?

A cyber security risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and recommending measures to mitigate risks. They analyze security data, develop risk management strategies, and often use tools like vulnerability scanners and risk assessment frameworks to protect information systems.

What is a Cyber Security Risk Analyst job?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by Cyber Security Risk Analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

How much does a cybersecurity risk analyst make?

A cybersecurity risk analyst's average salary in the United States ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions typically start around $60,000, while experienced analysts with certifications like CISSP or CISA can earn over $130,000. The role often requires knowledge of risk assessment tools and security frameworks.

Can you make $500,000 a year in cyber security?

Cyber Security Risk Analysts typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary usually requires senior roles such as Chief Information Security Officer (CISO) or executive positions, which involve strategic leadership and extensive industry experience. High salaries in cybersecurity are often associated with leadership, specialized skills, and working in high-demand sectors or organizations.
What are the most commonly searched types of Cyber Security Risk Analyst jobs in Virginia? The most popular types of Cyber Security Risk Analyst jobs in Virginia are:
What job categories do people searching Cyber Security Risk Analyst jobs in Virginia look for? The top searched job categories for Cyber Security Risk Analyst jobs in Virginia are:
What cities in Virginia are hiring for Cyber Security Risk Analyst jobs? Cities in Virginia with the most Cyber Security Risk Analyst job openings:
Infographic showing various Cyber Security Risk Analyst job openings in Virginia as of July 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $98,547 per year, or $47.4 per hour.
DHS Foreign Investment Risk Analyst

DHS Foreign Investment Risk Analyst

Systems Planning and Analysis

Alexandria, VA

$110K - $140K/yr

Full-time

Medical, Life, Retirement

Posted 10 days ago


Job description

Overview

Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter. Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.  

The Joint, Office of the Secretary of Defense, Interagency Division provides expert support services to a range of customers spanning across the Department of Defense, Federal Civilian, and international markets. JOID provides a diverse portfolio of analytical and programmatic capabilities to help our customers make informed decisions on their most challenging issues.

The Industry and Security Analysis Group (ISAG) within JOID provides analytical, technical, and program support to promote, grow, and protect the U.S. industrial base. ISAG's support spans the Department of Defense (DOD), Department of Commerce, and other agencies to deliver critical decision support to national security leaders. Our team informs policy decisions, enables execution of comprehensive strategies and monitors and reports on the effectiveness of implementation. This enables senior leaders to execute strategies for developing and sustaining a robust industrial base that meets our nation's strategic resource objectives. From policy to practice, we are a team of economic and national security professionals providing innovative solutions for our Nation's most pressing security challenges.

We have an upcoming need for a Foreign Investment Risk Analyst to provide onsite support the DHS in the NCR.

Responsibilities

The Foreign Investment Risk Analyst will support Department of Homeland Security in the execution of their Committee on Foreign Investment in the United States (CFIUS) risk reduction efforts. CFIUS is an interagency committee authorized to review certain transactions involving foreign investment in the United States and certain real estate transactions by foreign persons, in order to determine the effect of such transactions on the national security. The candidate will review CFIUS filings, to include documentation relating to mergers and stock purchase agreements, corporate ownership structures, and USG contracting information. Conduct due diligence and fact-finding research with DHS stakeholders to assess risk arising from foreign direct investment and the implications relative to DHS's security interests, industrial base supply chain, dual-use technology transfer, personal data, and cybersecurity. Perform analysis on available CFIUS documentation, DHS SME assessments, and classified finished intelligence. Author risk-based assessments regarding certain foreign investments, and produce case summaries, talking points, and action memorandum for senior DHS leaders.

Qualifications

Required:

  • Bachelor's Degree with 8+ years of relevant experience.
  • Experience developing clear and concise risk summaries suitable for senior leadership.
  • Experience conducting coordination and engagement with internal and external stakeholders.
  • Proficient with Microsoft Office tools.
  • Top Secret clearance with SCI eligiblity and DHS suitability.
  • Able to work fully onsite based on client needs.
Pay Range InformationAt SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Virginia, Pay Transparency Salary range: USD $110,000.00/Yr. - USD $140,000.00/Yr.Employment Type: FULL_TIME