Risk Management & Assurance: Serves as the primary cybersecurity risk advisor to assigned GBU's, ensuring cyber risks are proactively assessed and managed in alignment with Bechtel's risk appetite.
Risk Management & Assurance: Serves as the primary cybersecurity risk advisor to assigned GBU's, ensuring cyber risks are proactively assessed and managed in alignment with Bechtel's risk appetite.
About the Team The Cybersecurity Risk team is responsible for cybersecurity risk assessments, security exception management, TPRM, and partner eco-system security. This broader team is responsible ...
About the Team The Cybersecurity Risk team is responsible for cybersecurity risk assessments, security exception management, TPRM, and partner eco-system security. This broader team is responsible ...
About the Team The Cybersecurity Risk team is responsible for cybersecurity risk assessments, security exception management, TPRM, and partner eco-system security. This broader team is responsible ...
About the Team The Cybersecurity Risk team is responsible for cybersecurity risk assessments, security exception management, TPRM, and partner eco-system security. This broader team is responsible ...
Senior Cybersecurity Analyst
Falls Church, VA · On-site +1
$91K - $124K/yr
Support third-party/vendor risk management, technology security reviews, change management, and cybersecurity assessments for new systems and services. * Develop cybersecurity metrics, dashboards ...
New
Senior Cybersecurity Analyst
Falls Church, VA · On-site +1
$91K - $124K/yr
Support third-party/vendor risk management, technology security reviews, change management, and cybersecurity assessments for new systems and services. * Develop cybersecurity metrics, dashboards ...
New
Senior Cybersecurity Analyst
Falls Church, VA · On-site
$91K - $124K/yr
Support third-party/vendor risk management, technology security reviews, change management, and cybersecurity assessments for new systems and services. * Develop cybersecurity metrics, dashboards ...
New
Senior Cybersecurity Analyst
Falls Church, VA · On-site
$91K - $124K/yr
Support third-party/vendor risk management, technology security reviews, change management, and cybersecurity assessments for new systems and services. * Develop cybersecurity metrics, dashboards ...
New
As a Cybersecurity Analyst you will play a crucial role in ensuring the cyber security and ... You will be responsible for managing the Risk Management Framework (RMF) support for multiple ...
As a Cybersecurity Analyst you will play a crucial role in ensuring the cyber security and ... You will be responsible for managing the Risk Management Framework (RMF) support for multiple ...
Cybersecurity Risk Analyst (McLean, VA)
Mclean, VA · On-site
$100K - $150K/yr
Cybersecurity Risk Analyst Salary Range: $100,000 - $150,000 Clearance: TS/SCI + CI Poly Location ... Experience with RMF, ATO, NIST SP 800-53, continuous monitoring, vulnerability management, or SOC ...
Cybersecurity Risk Analyst (McLean, VA)
Mclean, VA · On-site
$100K - $150K/yr
Cybersecurity Risk Analyst Salary Range: $100,000 - $150,000 Clearance: TS/SCI + CI Poly Location ... Experience with RMF, ATO, NIST SP 800-53, continuous monitoring, vulnerability management, or SOC ...
As a Cybersecurity Analyst you will play a crucial role in ensuring the cyber security and ... You will be responsible for managing the Risk Management Framework (RMF) support for multiple ...
As a Cybersecurity Analyst you will play a crucial role in ensuring the cyber security and ... You will be responsible for managing the Risk Management Framework (RMF) support for multiple ...
Cybersecurity Engineer
Washington, DC · On-site
$53.33 - $88/hr
Ability to obtain and maintain a government security clearance if required Are you passionate about cybersecurity, risk management, and protecting critical systems from evolving threats? PEMCCO is ...
Quick apply
Cybersecurity Engineer
Washington, DC · On-site
$53.33 - $88/hr
Ability to obtain and maintain a government security clearance if required Are you passionate about cybersecurity, risk management, and protecting critical systems from evolving threats? PEMCCO is ...
Cybersecurity Engineer
Washington, DC · On-site
$53.33 - $88/hr
Ability to obtain and maintain a government security clearance if required Are you passionate about cybersecurity, risk management, and protecting critical systems from evolving threats? PEMCCO is ...
Cybersecurity Engineer
Washington, DC · On-site
$53.33 - $88/hr
Ability to obtain and maintain a government security clearance if required Are you passionate about cybersecurity, risk management, and protecting critical systems from evolving threats? PEMCCO is ...
Cybersecurity Engineer
Washington, DC · On-site
$73.01 - $121.23/hr
Ability to obtain and maintain a government security clearance if required Are you passionate about cybersecurity, risk management, and protecting critical systems from evolving threats? PEMCCO is ...
Cybersecurity Engineer
Washington, DC · On-site
$73.01 - $121.23/hr
Ability to obtain and maintain a government security clearance if required Are you passionate about cybersecurity, risk management, and protecting critical systems from evolving threats? PEMCCO is ...
Cybersecurity Engineer
Washington, DC · On-site
$53.33 - $88/hr
Ability to obtain and maintain a government security clearance if required Are you passionate about cybersecurity, risk management, and protecting critical systems from evolving threats? PEMCCO is ...
Cybersecurity Engineer
Washington, DC · On-site
$53.33 - $88/hr
Ability to obtain and maintain a government security clearance if required Are you passionate about cybersecurity, risk management, and protecting critical systems from evolving threats? PEMCCO is ...
Senior Cybersecurity Advisor
Washington, DC · On-site
$120 - $150/hr
Provide guidance on cybersecurity risk management activities, including Risk Management Framework (RMF), Authorization to Operate (ATO), reciprocity initiatives, control selection, and continuous ...
Senior Cybersecurity Advisor
Washington, DC · On-site
$120 - $150/hr
Provide guidance on cybersecurity risk management activities, including Risk Management Framework (RMF), Authorization to Operate (ATO), reciprocity initiatives, control selection, and continuous ...
Senior Cybersecurity Engineer
Washington, DC · On-site
$63.96 - $105.54/hr
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
Senior Cybersecurity Engineer
Washington, DC · On-site
$63.96 - $105.54/hr
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
Senior Cybersecurity Engineer
Washington, DC · On-site
$63.96 - $105.54/hr
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
Senior Cybersecurity Engineer
Washington, DC · On-site
$63.96 - $105.54/hr
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
Senior Cybersecurity Engineer
Washington, DC · On-site
$88 - $146/hr
This role is ideal for a seasoned cybersecurity professional who enjoys security engineering, risk management, compliance, vulnerability management, and strengthening organizational security posture.
Senior Cybersecurity Engineer
Washington, DC · On-site
$88 - $146/hr
This role is ideal for a seasoned cybersecurity professional who enjoys security engineering, risk management, compliance, vulnerability management, and strengthening organizational security posture.
Senior Cybersecurity Engineer
Washington, DC · On-site
$63.96 - $105.54/hr
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
Quick apply
Senior Cybersecurity Engineer
Washington, DC · On-site
$63.96 - $105.54/hr
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
Cyber Security Task Lead
Linthicum, MD · On-site
$109K - $148K/yr
You will facilitate Government and Contractor communications, maintain compliance frameworks, oversee cybersecurity risk management, and drive strategic IT and security initiatives across project ...
Cyber Security Task Lead
Linthicum, MD · On-site
$109K - $148K/yr
You will facilitate Government and Contractor communications, maintain compliance frameworks, oversee cybersecurity risk management, and drive strategic IT and security initiatives across project ...
Lead all phases of the DoD Risk Management Framework (RMF), including system categorization ... Conduct cybersecurity risk assessments and provide recommendations supporting Authorizing Official ...
Lead all phases of the DoD Risk Management Framework (RMF), including system categorization ... Conduct cybersecurity risk assessments and provide recommendations supporting Authorizing Official ...
Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst
Washington, DC · On-site
$114K - $126K/yr
The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) and its information, communications, and operational ...
Quick apply
Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst
Washington, DC · On-site
$114K - $126K/yr
The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) and its information, communications, and operational ...
Cyber Security Risk Management information
See Washington salary details
$64.6K - $77.8K
1% of jobs
$77.8K - $91.1K
4% of jobs
$91.1K - $104.4K
5% of jobs
$104.4K - $117.7K
9% of jobs
$125K is the 25th percentile. Wages below this are outliers.
$117.7K - $131K
11% of jobs
$131K - $144.3K
10% of jobs
The median wage is $149.4K / yr.
$144.3K - $157.5K
28% of jobs
$165.2K is the 75th percentile. Wages above this are outliers.
$157.5K - $170.8K
14% of jobs
$170.8K - $184.1K
11% of jobs
$184.1K - $197.4K
4% of jobs
$197.4K - $210.7K
4% of jobs
$64.6K
$150.6K
$210.7K
How much do cyber security risk management jobs pay per year?
What is cyber security risk management?
What are the key skills and qualifications needed to thrive in cyber security risk management?
What are some typical challenges faced in cyber security risk management, and how can they be addressed?
What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?
| Aspect | Cyber Security Risk Management | Cyber Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CISSP, CISM | CompTIA Security+, CEH, CISSP (preferred) |
| Work Environment | Policy development, risk assessment, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Organizations focusing on risk mitigation and compliance | Organizations implementing and maintaining security measures |
Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.
What does a cyber security risk management do?
What are popular job titles related to Cyber Security Risk Management jobs in Washington?
For Cyber Security Risk Management jobs in Washington, the most frequently searched job titles are:
What job categories do people searching Cyber Security Risk Management jobs in Washington look for?
The top searched job categories for Cyber Security Risk Management jobs in Washington are:
What cities in Washington are hiring for Cyber Security Risk Management jobs?
Cities in Washington with the most Cyber Security Risk Management job openings:

Full-time, Part-time
Medical, Dental, Vision, Retirement, PTO
Re-posted 6 days ago
Bechtel rating
7.6
Based on 65 frontline employees who took The Breakroom Quiz
285th of 453 rated engineering
Job description
Requisition ID: 292702
- Relocation Authorized: None
- Telework Type: Part-Time Telework
- Work Location: Reston, VA, Houston, TX
- For Reston, VA position: Salary Range: $ 168,900 - $ 244,300 annually (salary range is based on market data; final salary offered is determined by education, experience, and qualifications of the applicant.)
Since 1898, we have helped customers complete more than 25,000 projects in 160 countries on all seven continents that have created jobs, grown economies, improved the resiliency of the world's infrastructure, increased access to energy, resources, and vital services, and made the world a safer, cleaner place.
Differentiated by the quality of our people and our relentless drive to deliver the most successful outcomes, we align our capabilities to our customers' objectives to create a lasting positive impact. We serve the Infrastructure; Nuclear, Security & Environmental; Energy; Mining & Metals, and the Manufacturing and Technology markets. Our services span from initial planning and investment, through start-up and operations.
Core to Bechtel is our Vision, Values and Commitments. They are what we believe, what customers can expect, and how we deliver. Learn more about our extraordinary teams building inspiring projects in our Impact Report.
Reporting to the Manager of Business Engagement, the Cybersecurity Business Information Security Officer – BISO, serves as the primary interface between Bechtel’s Global Business Units (GBUs) and the enterprise cybersecurity organization. The role ensures cybersecurity strategy, risk management, and assurance activities are embedded into business operations, engineering delivery, and project execution. The role is accountable for proactively identifying, assessing, and managing cybersecurity risks within the business; providing assurance that controls meet Bechtel policies, standards, and regulatory obligations; and ensuring alignment with evolving business, customer, and regulatory cybersecurity requirements. Enables secure innovation, facilitates technology adoption, and leads cybersecurity risk posture and assurance.
*This position can be based in Reston, VA or Houston, TX.
Risk Management & Assurance:
Serves as the primary cybersecurity risk advisor to assigned GBU’s, ensuring cyber risks are proactively assessed and managed in alignment with Bechtel’s risk appetite.
Owns and oversees the GBU cybersecurity risk posture, ensuring appropriate governance, assurance, audit readiness, and compliance.
Drives and aligns cybersecurity risk assessments for business processes, digital engineering platforms, cloud solutions, AI initiatives and third-party integrations.
Ensures remediation plans for identified risks are clearly defined, tracked, and executed.
Supports internal and external audits, regulatory reviews, and customer-driven cybersecurity assessments.
Partners with Third-Party Risk Management to assess and manage cybersecurity risks associated with suppliers, joint ventures, subcontractors, and strategic partners.
Business Alignment & Secure Enablement:
Acts as the primary bridge between business leadership and cybersecurity, ensuring security priorities align with business objectives, project delivery timelines, and regulatory obligations.
Advises business stakeholders through IT and digital intake processes as it relates to cybersecurity, including review of technical documentation and facilitation of cybersecurity and enterprise architecture reviews for new and changed technologies.
Works directly with GBU leadership to understand customer-driven, contract-driven, and regulatory cybersecurity requirements in the regions and sectors they operate.
Translates business requirements into clear cybersecurity needs and work with central cybersecurity teams to ensure alignment, feasibility, and timely delivery of controls.
Enables the secure adoption of emerging technologies (e.g., cloud platforms, digital engineering solutions, data analytics, AI, and OT systems) while maintaining appropriate risk management and assurance.
Advisory, Communication & Change Leadership:
Advises business leaders, project teams, and functional stakeholders on cybersecurity requirements, risk considerations, and best practices.
Serves as GBU POC and coordinates incident response activities within Cyber Defense Center.
Promotes a culture of shared accountability for cybersecurity risk and operational resilience.
Provides leadership with tailored dashboards, metrics, and reports on cybersecurity risk posture, trends, compliance status, and assurance outcomes.
Acts as a change ambassador, supporting business units through technology and process changes while maintaining resilience and delivery commitments.
Requires bachelor’s degree in a relevant discipline plus 8 years progressive experience in information security, cybersecurity, or risk management roles - including 2 years working directly with business units or in a liaison role aligning technology and business objectives.
Prefer 3-5 years’ experience in governance, risk, compliance, or regulated environments (e.g., FIMSA, GBLA, export controls, or large-scale infrastructure programs).
Demonstrated experience in stakeholder engagement and executive-level communication, with the ability to influence InfoSec/Cyber/Assurance outcomes across complex, matrixed organizations.
Experience with industry-recognized frameworks and standards such as NIST, ISO/IEC 27001/27002, CSA, or equivalent.
Demonstrated experience driving proactive identification and mitigation of cybersecurity risks within business and project delivery environments.
Experience managing or influencing enterprise-level initiatives, including application portfolios, digital platforms, and IT intake and governance processes.
Demonstrated project and program management skills.
Prefer Project Management Professional (PMP) Certification or formal Project Management training.
Prefer Certified Information Systems Security Professional (CISSP).
Prefer Certified Information Security Manager (CISM).
For decades, Bechtel has worked to inspire the next generation of employees and beyond! Because our teams face some of the world's toughest challenges, we offer robust benefits to ensure our people thrive. Whether it is advancing careers, delivering programs to enhance our culture, or providing time to recharge, Bechtel has the benefits to build a legacy of sustainable growth. Learn more at Bechtel Total Rewards
As a global company, Bechtel has long been home to a vibrant multitude of nationalities, cultures, ethnicities, and life experiences. This diversity has made us a more trusted partner, more effective problem solvers and innovators, and a more attractive destination for leading talent.
We are committed to being a company where every colleague feels that they belong-where colleagues feel part of "One Team," respected and rewarded for what they bring, supported in pursuing their goals, invested in our values and purpose, and treated equitably. Click here to learn more about the people who power our legacy.
At Bechtel, our employees enjoy a competitive total rewards package that includes comprehensive medical, dental, and vision plans, along with optional disability and supplemental insurance options, generous paid time off (160 hours annually, accrued 6.16 hours per pay period), nine paid holidays, paid parental leave, discretionary bonuses, and a well-designed 401K plan with matching and profit-sharing components
Bechtel is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity and expression, age, national origin, disability, citizenship status (except as authorized by law), protected veteran status, genetic information, and any other characteristic protected by federal, state or local law. Applicants with a disability, who require a reasonable accommodation for any part of the application or hiring process, may e-mail their request to acesstmt@bechtel.com