1

Cyber Security Risk Analyst Jobs in Silver Spring, MD

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

Third-Party Risk Analyst

Mclean, VA · On-site

$45 - $47/hr

Third-Party Risk Analyst Location: McLean, VA (5 days - Onsite) Job Overview The Third-Party Risk ... Monitor and document third-party risk and cybersecurity trends. Documentation & Communications

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

next page

Showing results 1-20

Cyber Security Risk Analyst information

See Silver Spring, MD salary details

$44.5K

$102.8K

$155.1K

How much do cyber security risk analyst jobs pay per year?

As of Jun 24, 2026, the average yearly pay for cyber security risk analyst in Silver Spring, MD is $102,757.00, according to ZipRecruiter salary data. Most workers in this role earn between $82,200.00 and $119,400.00 per year, depending on experience, location, and employer.

Is 40 too old for cyber security?

Cyber Security Risk Analysts can be successful at any age, as the field values skills, experience, and continuous learning. Many professionals transition into cybersecurity later in their careers, often obtaining certifications like CISSP or CompTIA Security+ to enhance their qualifications. Age is generally not a barrier if you have relevant skills and stay current with industry developments.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is typically considered an entry-level or early-career position in cybersecurity, often requiring foundational knowledge of security tools, monitoring, and incident response. However, some SOC roles may require prior experience or certifications like CompTIA Security+ or Cisco CCNA, depending on the organization's complexity. Advancement usually involves gaining experience and additional certifications in cybersecurity.

What are the key skills and qualifications needed to thrive in the Cyber Security Risk Analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

What is a Cyber Security Risk Analyst job?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by Cyber Security Risk Analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

What does a cybersecurity risk analyst do?

A cybersecurity risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and recommending measures to mitigate risks. They often use tools like risk assessment frameworks and require knowledge of security protocols, compliance standards, and threat intelligence. Their work helps organizations protect sensitive data and maintain secure systems.

Can you make $500,000 a year in cyber security?

Cyber Security Risk Analysts typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary generally requires senior roles such as Chief Information Security Officer (CISO) or executive positions, which involve broader responsibilities and leadership skills. High salaries in cybersecurity are often associated with extensive experience, advanced certifications, and strategic management roles.
What are popular job titles related to Cyber Security Risk Analyst jobs in Silver Spring, MD? For Cyber Security Risk Analyst jobs in Silver Spring, MD, the most frequently searched job titles are:
What job categories do people searching Cyber Security Risk Analyst jobs in Silver Spring, MD look for? The top searched job categories for Cyber Security Risk Analyst jobs in Silver Spring, MD are:
What cities near Silver Spring, MD are hiring for Cyber Security Risk Analyst jobs? Cities near Silver Spring, MD with the most Cyber Security Risk Analyst job openings:
Foreign Investment Risk Analyst

Foreign Investment Risk Analyst

Cybersecurity and Infrastructure Security Agency

Arlington, VA • On-site, Remote

$90K - $139K/yr

Full-time

Posted 7 days ago


Job description

Summary
The Cybersecurity and Infrastructure Security Agency (CISA) is the Nation's risk advisor, working with partners to defend against today's threats and collaborating with industry to build a more secure and resilient infrastructure for the future.
Salary range listed reflects the GS base rate (not including locality pay), see the "Additional Information" section of the announcement for details.
The official title of this position is Management Analyst, GS-0343-13/14.
Learn more about this agency
Duties
Help
The Foreign Investment Risk Analyst position within the National Risk Management Center requires an individual with a subject matter expertise in the vulnerabilities, consequences, and mitigations related to national security that would result from transactions involving foreign investment in the United States and rooted in CISA and DHS equities, or those transactions involving telecommunications licenses meeting certain thresholds of foreign ownership or control.
Typical work assignments at the full performance level include, but are not limited to:
  • Identifying cybersecurity and technology risk posed to U.S. national security by transactions involving foreign investment or licensing activities and writing clear, actionable assessments of the risk resulting from the completion of those transactions or approval of an application directly associated with CISA and DHS equities.
  • Providing subject matter expertise, skills, and services necessary to conduct research and analysis of evolving cybersecurity and technology risk in areas within CISA equities.
  • Providing detail-focused services necessary to support the efficient analytic workflow, data collection, and knowledge management for FIRB cases, reviews, and various program support projects (e.g., records upkeep and file management).
  • Applying applicable laws, statutes and regulatory documents and integrating into policy development.
  • Maintaining cybersecurity plans, strategy, and policy to support and align with organizational cybersecurity initiatives and regulatory compliance.
  • Applying business and management best practices for application to CISA/NRMC programs and/or operators.
  • Ensuring organizational efficiency and productivity including staffing, work methods, and administrative control systems.
  • Presenting authoritative finding and recommendations to resolve complex management issues, problems, and conflicts.
  • Leveraging project and program management skills to ensure effectiveness and efficiency of work operations.
  • Participating with internal and external stakeholders in developing and organizing policies and programs.
  • Leading the development of new plans, programs, and initiatives in a dynamic and complex environment.
  • Preparing written reports and briefing material based on analysis and research, that is appropriate for program requirements.
  • Performing evaluation assignments of projects and studies that require analysis of interrelated issues.
  • Evaluating analytical results and keeping the organization informed of progress and unusual issues.
  • Providing technical data, guidelines, and technical reports in field of specialty.
  • Conducting periodic and comprehensive evaluations of ongoing functions to ensure the organization meets its stated goals.
  • Preparing short and long-range planning guidance in accordance with broad program policies and objectives.
  • Presenting findings and recommendations on complex issues or problems impacting major programs.
  • Implementing detailed plans, goals, objectives, requirements, and criteria for complex or high-value management processes and systems.

Military Spouses & U.S. Foreign Service Spouses Only: This position is remote work and telework eligible consistent with the Agency's telework and remote work program policy. Applicants who live within the local commuting area (i.e., a 50-mile or less radius from Glebe Road, Arlington VA (not driving distance)) are eligible for 100% telework in accordance with agency policy.
Requirements
Help
Conditions of employment
  • You must be a U.S. citizen.
  • Complete the initial online assessment and USA Hire Assessment, if required.
  • Selective Service - Males born after 12/31/59 must be registered or exempt from Selective Service see http://www.sss.gov/
  • All Federal employees are required to participate in Direct Deposit/ Electronic Funds Transfer for salary payments.
  • DHS uses e-Verify, an Internet-based system, to confirm the eligibility of all newly hired employees to work in the United States. Learn more about E-Verify, including your rights and responsibilities.
  • You must be able to obtain and maintain a security clearance suitable for Federal employment as determined by a background investigation. This may include a credit check, a review of financial issues, as well as certain criminal offenses and illegal use or possession of drugs.
  • Current Federal employees must meet time-in-grade requirements.
  • One-year probationary period may be required.
  • This position may be designated as essential personnel. Essential personnel must be able to serve during continuity of operation events without regard to declarations of liberal leave or government closures due to weather, protests, and acts of terrorism or lack of funding. Failure to report for or remain in this position may result in disciplinary or adverse action in accordance with applicable laws, rules, and regulations (5 U.S.C. 7501-7533 and 5 CFR Part 752, as applicable).
  • This position has been identified as a drug testing designated position (TDP) for purposes of the CISA's Drug-Free Workplace Program. All applicants tentatively selected for this position will be required to submit to a drug test to screen for illicit/illegal drug use prior to receiving a final offer of employment. A final offer of employment is contingent upon a negative drug test result. After appointment, you may be subject to periodic random drug testing.

Qualifications
Do NOT copy and paste the duties, specialized experience, or occupational assessment questionnaire from this announcement into your resume as that will not be considered a demonstration of your qualifications for this position. Your resume must describe your work and experience, in your own words.
To be considered minimally qualified for this position, you must demonstrate that you have the required experience for the respective grade level in which you are applying.
You qualify at the GS-13 grade level, if you have:
EXPERIENCE: At least one (1) year of specialized experience at the GS-12 grade level (or equivalent) performing the following duties:
  1. Conducting projects and studies that encompass the analysis and evaluation of the distribution of work in the development of strategies, plans, and analysis in support of organizational priorities;
  2. Demonstrating experience in assessing risk related to foreign investment; AND
  3. Coordinating multifaced projects that involve thorough analysis and assessment of responsibilities across various roles within the organization.

You qualify at the GS-14 grade level, if you have:
EXPERIENCE: At least one (1) year of specialized experience at the GS-13 grade level (or equivalent) performing the following duties:
  1. Assessing policy needs to collaborate with stakeholders to develop policies to govern cyber activities;
  2. Conducting research to articulate complex policies and program issues related to foreign investment and/or telecommunications services sector to develop constructive recommendations and proposals;
  3. Presenting findings and recommendations on complex issues or problems impacting major programs; AND
  4. Experience in the interpretation of identified technical vulnerabilities, consequences, and potential mitigations of cybersecurity or technology-focused subject matter experts and synthesis of technical information with intelligence research in support of the holistic analysis of risk.

Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience.
Time-in-Grade Requirements: Under competitive merit promotion procedures, any individual who is currently holding, or who has held within the previous 52 weeks, a General Schedule (GS) position under a non-temporary appointment in the competitive or excepted service, must meet "time-in-grade" requirements (have served 52 weeks at the next lower grade of the grade for which you are applying). NOTE: Current or former GS federal civilian employees, within the previous 52 weeks, applying for a position under the Veterans Employment Opportunities Act (VEOA) must meet time-in-grade requirements.
Time After Competitive Appointment: By the closing date specified in this job announcement, current Federal civilian employees must wait at least 90 days after their latest non-temporary appointment from a competitive service referral certificate before promotion, transfer, reinstatement, reassignment, or detail.
All qualification requirements, including Time-in-Grade, must be met by the closing date of this announcement. Qualification AND Time-in-Grade claims will be subject to verification.
Education
No Educational Substitution: There is no substitution of education for experience at this grade level. You must meet the qualifications listed in the "Requirements" section of this announcement.
Additional information
  • Other incentives may be authorized.
  • If you receive a conditional offer of employment for this position, you will be required to complete an Optional Form 306, Declaration for Federal Employment, and to sign and certify the accuracy of all information in your application, prior to entry on duty. False statements on any part of the application may result in withdrawal of offer of employment, dismissal after beginning work, fine, or imprisonment.
  • Additional vacancies may be filled with this announcement.
  • A one-year probationary period may be required during which we will evaluate your fitness and whether your continued employment advances the public interest. We may consider your performance and conduct, the needs and interests of the agency, whether your continued employment would advance organizational goals of the agency or the Government, and whether your continued employment would advance the efficiency of the Federal service. Upon completion of your probationary period your employment will be terminated unless you receive certification, in writing, that your continued employment advances the public interest.
  • Military Spouses & U.S. Foreign Service Spouses Only: The actual salary will be adjusted based on the grade, step, and locality for the selectee's geographic location. The remote worker's locality pay is based on the location of the employee's residence. General Schedule (GS) locality pay tables may be found at Salaries & Wages.
  • If selected below the full performance level, you may be noncompetitively promoted to the next higher grade level after meeting all regulatory requirements, and upon the recommendation of management. Promotion is neither implied nor guaranteed.

Reasonable Accommodation (RA) Requests: If you believe you have a disability (i.e., physical or mental), covered by the Rehabilitation Act of 1973 as amended that would interfere with completing the USA Hire Competency Based Assessments, you will be granted the opportunity to request a RA in your online application. Requests for RA for the USA Hire Competency Based Assessments and appropriate supporting documentation for RA must be received prior to starting the USA Hire Competency Based Assessments. Decisions on requests for RA are made on a case-by-case basis. If you meet the minimum qualifications of the position, after notification of the adjudication of your request, you will receive an email invitation to complete the USA Hire Competency Based Assessments, based on your adjudication decision. You must complete all assessments within 48 hours of receiving the URL to access the USA Hire Competency Based Assessments, if you received the link after the close of the announcement. To determine if you need a RA, please review the Procedures for Requesting a Reasonable Accommodation for Online Assessments.
Current or Former Political Appointees: The Office of Personnel Management (OPM) must authorize employment offers made to current or former political appointees. If you are currently, or have been within the last 5 years, a political Schedule A, Schedule C, Non-career SES or Presidential Appointee employee in the Executive Branch, you must disclose this information to the Human Resources Office.
Expand Hide additional information
Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of our American republic, and committed to upholding the rule of law and the United States Constitution.
Benefits
Help
A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.
Review our benefits
Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.