1

Cyber Security Risk Assessment Jobs in Virginia (NOW HIRING)

Sr. Cyber Analyst

Hampton, VA

$97K - $125K/yr

Provides recommendations to activity leadership on processes and methodologies to assess cybersecurity risk on information systems. Works with other Cyber Analysts, SMEs, and SCA-Rs to ensure that ...

Required Qualifications: * 10+ years of experience in cybersecurity risk assessment, vulnerability ... analysis, or cyber mission assurance. * Deep knowledge of NIST SP 800-30, NIST Risk Management ...

Sr. Analyst, Cybersecurity

Richmond, VA

$99K - $127K/yr

You will assist the Cybersecurity, technology, compliance, and information risk teams in ... Perform information security risk assessments, understand threats, vulnerabilities and exposures ...

Sr. Analyst, Cybersecurity

Richmond, VA · On-site

$99K - $128K/yr

You will assist the Cybersecurity, technology, compliance, and information risk teams in ... Perform information security risk assessments, understand threats, vulnerabilities and exposures ...

Sr. Analyst, Cybersecurity

Richmond, VA · On-site

$99K - $128K/yr

You will assist the Cybersecurity, technology, compliance, and information risk teams in ... Perform information security risk assessments, understand threats, vulnerabilities and exposures ...

Program Risk Manager

Herndon, VA · On-site

$86K - $138K/yr

Conduct structured risk assessments for proposals, program changes, acquisitions, policy updates, and major milestones to quantify impacts to cost, schedule, performance, cybersecurity, and ...

Program Risk Manager

Herndon, VA · On-site

$86K - $138K/yr

Conduct structured risk assessments for proposals, program changes, acquisitions, policy updates, and major milestones to quantify impacts to cost, schedule, performance, cybersecurity, and ...

Conduct structured risk assessments for proposals, program changes, acquisitions, policy updates, and major milestones to quantify impacts to cost, schedule, performance, cybersecurity, and ...

Risk Assessment: Conduct cybersecurity risk assessments of industrial control systems (ICS) networks, systems, and components to identify vulnerabilities and recommend mitigation strategies.

next page

Showing results 1-20

People also search for

Cyber Security Risk Assessment information

See Virginia salary details

$56.5K

$131.8K

$184.4K

How much do cyber security risk assessment jobs pay per year?

As of Jun 10, 2026, the average yearly pay for cyber security risk assessment in Virginia is $131,822.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,000.00 and $148,700.00 per year, depending on experience, location, and employer.

Can you make $500,000 a year in cyber security?

Cyber security professionals, especially those in senior roles such as security architects or chief information security officers, can earn $500,000 or more annually, often through a combination of base salary, bonuses, and stock options. Achieving this level typically requires extensive experience, advanced certifications like CISSP or CISM, and working in high-demand industries or organizations with complex security needs.

What are the key skills and qualifications needed to thrive in Cyber Security Risk Assessment, and why are they important?

To excel in Cyber Security Risk Assessment, you need a solid understanding of information security principles, risk management frameworks, and often a degree in cybersecurity, IT, or related fields. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM are commonly required. Analytical thinking, attention to detail, and strong communication skills help professionals effectively assess risks and convey findings to stakeholders. These skills are crucial for identifying vulnerabilities, prioritizing threats, and ensuring the organization’s data and systems are adequately protected.

What is the role of risk assessment in cyber security?

In cyber security, a risk assessment is a process that identifies, evaluates, and prioritizes potential threats and vulnerabilities to an organization's information systems. It helps security professionals, such as cyber security risk assessors, determine where to allocate resources and implement controls to reduce the likelihood and impact of cyber threats. Conducting regular risk assessments is essential for maintaining an effective security posture and complying with industry standards and regulations.

What is the difference between Cyber Security Risk Assessment vs Cyber Security Analyst?

AspectCyber Security Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating security risks and vulnerabilitiesMonitoring, analyzing, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams

While both roles require similar certifications and work within cybersecurity, a Cyber Security Risk Assessment focuses on evaluating potential vulnerabilities and risks to an organization’s assets. In contrast, a Cyber Security Analyst actively monitors and responds to security threats, ensuring ongoing protection. Understanding these differences helps organizations assign the right responsibilities to each role.

Is SOC analyst a high paying job?

SOC analysts typically earn competitive salaries that increase with experience, certifications, and the size of the organization. Entry-level positions may start at average wages, while experienced analysts with certifications like CISSP or CEH can earn higher salaries, making it a financially rewarding cybersecurity role.

What are some common challenges faced by professionals conducting cyber security risk assessments?

Professionals in cyber security risk assessment often face challenges such as keeping up with rapidly evolving threats, effectively communicating technical risks to non-technical stakeholders, and ensuring comprehensive coverage across complex IT environments. Balancing thoroughness with tight deadlines can also be demanding, as assessments must be both detailed and timely. Collaborating with various departments to gather accurate information and maintain up-to-date asset inventories is crucial for effective risk analysis and mitigation.

What is a cyber security risk assessment?

A cyber security risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities that could negatively impact an organization's information systems. By analyzing assets, threats, vulnerabilities, and impacts, organizations can determine the likelihood and consequences of cyber incidents. The goal is to implement appropriate measures to reduce risks to acceptable levels, ensuring data protection and regulatory compliance. Regular risk assessments help organizations stay ahead of evolving cyber threats and make informed security decisions.

What is the 80 20 rule in cyber security?

In cyber security risk assessment, the 80/20 rule suggests that approximately 80% of security issues are caused by 20% of vulnerabilities or threats. Security professionals focus on identifying and mitigating the most critical risks to efficiently improve overall security posture.
What are popular job titles related to Cyber Security Risk Assessment jobs in Virginia? For Cyber Security Risk Assessment jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Cyber Security Risk Assessment jobs in Virginia look for? The top searched job categories for Cyber Security Risk Assessment jobs in Virginia are:
What cities in Virginia are hiring for Cyber Security Risk Assessment jobs? Cities in Virginia with the most Cyber Security Risk Assessment job openings:
Infographic showing various Cyber Security Risk Assessment job openings in Virginia as of June 2026, with employment types broken down into 1% As Needed, 82% Full Time, 13% Part Time, and 4% Contract. Highlights an 91% Physical, 4% Hybrid, and 5% Remote job distribution, with an average salary of $131,822 per year, or $63.4 per hour.

Senior Cyber Risk and Vulnerability Assessor

Guidehouse

Mclean, VA • Hybrid

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 20 days ago


Guidehouse rating

7.5

Company rating: 7.5 out of 10

Based on 26 frontline employees who took The Breakroom Quiz

37th of 57 rated business consultants


Job description

Job Family:

Cyber Consulting


Travel Required:

Up to 10%


Clearance Required:

Active Public Trust

What You Will Do:

Guidehouse's Cybersecurity practice helps federal and regulated clients assess, manage, and reduce cybersecurity risk across highimpact systems and missioncritical environments. Our teams combine deep technical assessment expertise with strong knowledge of federal risk management and authorization processes to support informed risk decisions and system authorization outcomes.

As a Senior Cyber Risk and Vulnerability Assessor , you will lead comprehensive security control assessments for complex, highimpact, and enterprise systems across onpremises, cloud, and hybrid environments. You will oversee assessment strategy and execution, validate remediation effectiveness, and provide authoritative risk determinations in support of Authorizing Officials (AOs) and senior agency leadership.

This role is ideal for a senior assessment professional with strong technical depth, proven leadership experience, and the ability to translate assessment results into clear, defensible risk recommendations aligned to federal cybersecurity requirements.

This role positions you as a senior assessment authority within Guidehouse's Cybersecurity practice, accountable for delivering highquality security assessments that enable informed authorization decisions and strengthen enterprise risk posture.

Key Responsibilities

  • Lead and oversee security control assessments for moderate and highimpact information systems, including complex enterprise and missioncritical environments.
  • Direct assessment planning and control testing strategies, ensuring appropriate coverage, rigor, and consistency with system architectures and risk profiles.
  • Conduct and supervise cloud, onpremises, and hybrid system assessments, including IaaS, PaaS, and SaaS environments.
  • Validate the effectiveness of remediation actions, including retesting controls and verifying closure of findings.
  • Analyze assessment results and develop risk determinations, observations, and recommendations suitable for senior decisionmakers and AOs.
  • Ensure assessments are executed in alignment with applicable federal frameworks and mandates, including: FISMA, NIST SP 80037, NIST SP 80053, OMB guidance and memoranda, Agencyspecific cybersecurity policies and procedures.
  • Oversee development and quality of assessment deliverables, including security assessment plans (SAPs), security assessment reports (SARs), POA&Ms, and authorization support documentation.
  • Provide guidance on risk acceptance, remediation prioritization, and continuous monitoring strategies.
  • Serve as a trusted advisor to system owners, ISSOs, and security engineers on assessment findings and control implementation improvements.
  • Coordinate assessment activities across multiple systems or programs, ensuring schedule adherence and stakeholder alignment.
  • Mentor and develop assessors and consultants; provide technical review and quality assurance for assessment work products.
  • Support practice growth through proposal development, technical contributions, and assessment methodology development.

What You Will Need:

  • Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred.
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related field (additional relevant experience may substitute for formal education).
  • Minimum of NINE (9) or more years of progressively responsible experience performing or leading security control assessments, audits, or cybersecurity risk assessments.
  • Required certifications:
    • Certified in Governance, Risk and Compliance (CGRC) (active)
    • Certified Information Systems Security Professional (CISSP) (active)
  • Demonstrated experience conducting assessments under the NIST RMF.
  • Experience assessing highimpact or highvalue asset (HVA) systems.
  • Strong understanding of security control implementation and assessment across enterprise, cloud, and hybrid architectures.
  • Proven ability to communicate risk clearly and effectively to technical and executive stakeholders, including Authorizing Officials.
  • Excellent written and verbal communication skills, including formal assessment reporting and executive briefings.

What Would Be Nice to Have:

  • Experience with continuous monitoring programs and control inheritance models.
  • Familiarity with major cloud service providers and their shared responsibility models.
  • Additional certifications such as CISM, CISA, CCSP, HVA Assessment Lead/Technical Lead/Operator, or cloud security credentials.
  • Prior consulting experience with responsibility for delivery quality, stakeholder management, and team leadership.


What We Offer:

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits include:

  • Medical, Rx, Dental & Vision Insurance

  • Personal and Family Sick Time & Company Paid Holidays

  • Position may be eligible for a discretionary variable incentive bonus

  • Parental Leave and Adoption Assistance

  • 401(k) Retirement Plan

  • Basic Life & Supplemental Life

  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts

  • Short-Term & Long-Term Disability

  • Student Loan PayDown

  • Tuition Reimbursement, Personal Development & Learning Opportunities

  • Skills Development & Certifications

  • Employee Referral Program

  • Corporate Sponsored Events & Community Outreach

  • Emergency Back-Up Childcare Program

  • Mobility Stipend

About Guidehouse

Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse's Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant's dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.


What Guidehouse employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom