1

Cyber Security Risk Management Jobs in Washington, DC

ASSYST is seeking a Cybersecurity Risk Advisor to support federal Cybersecurity program. The ... They will act as the subject matter expert in all areas of the Risk Management Framework (RMF) and ...

Cybersecurity Risk Analyst

Mclean, VA

$100K - $150K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • PTO

Cybersecurity Risk Analyst Salary Range: $100,000 - $150,000 Clearance: TS/SCI + CI Poly Location ... Experience with RMF, ATO, NIST SP 800-53, continuous monitoring, vulnerability management, or SOC ...

... cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security ...

... cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security ...

... cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security ...

... cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security ...

Cybersecurity Engineer

Arlington, VA

$150K - $185K/yr

  • Medical

  • Dental

  • Vision

  • PTO

Lead RMF and Cybersecurity Risk Management Construct (CSRMC) activities, including system authorization, continuous monitoring, and maintenance of ATO/cATO packages. * Manage and maintain eMASS ...

Cybersecurity Engineer

Arlington, VA · On-site

$150K - $185K/yr

  • Medical

  • Dental

  • Vision

  • PTO

Lead RMF and Cybersecurity Risk Management Construct (CSRMC) activities, including system authorization, continuous monitoring, and maintenance of ATO/cATO packages. * Manage and maintain eMASS ...

Cybersecurity Engineer

Arlington, VA · On-site

$150K - $185K/yr

  • Medical

  • Dental

  • Vision

  • PTO

Lead RMF and Cybersecurity Risk Management Construct (CSRMC) activities, including system authorization, continuous monitoring, and maintenance of ATO/cATO packages. * Manage and maintain eMASS ...

Cybersecurity Engineer

Arlington, VA · On-site

$150 - $185/hr

  • Medical

  • Dental

  • Vision

  • PTO

Lead RMF and Cybersecurity Risk Management Construct (CSRMC) activities, including system authorization, continuous monitoring, and maintenance of ATO/cATO packages. * Manage and maintain eMASS ...

New

Showing results 21-40

Cyber Security Risk Management information

See Washington, DC salary details

$64.6K

$150.6K

$210.7K

How much do cyber security risk management jobs pay per year?

As of Aug 20, 2026, the average yearly pay for cyber security risk management in Washington, DC is $150,592.00, according to ZipRecruiter salary data. Most workers in this role earn between $125,700.00 and $169,900.00 per year, depending on experience, location, and employer.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

What are the key skills and qualifications needed to thrive in cyber security risk management?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What are some typical challenges faced in cyber security risk management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

What does a cyber security risk management do?

A cyber security risk management professional identifies, assesses, and prioritizes potential security threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, often using frameworks like NIST or ISO, and may conduct regular audits to ensure security measures are effective.

What are popular job titles related to Cyber Security Risk Management jobs in Washington, DC?

For Cyber Security Risk Management jobs in Washington, DC, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Management jobs in Washington, DC look for?

The top searched job categories for Cyber Security Risk Management jobs in Washington, DC are:

Infographic showing various Cyber Security Risk Management job openings in Washington, DC as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $150,592 per year, or $72.4 per hour.

Senior Security Risk Management SME

Analygence

Washington, DC • On-site

Full-time

Re-posted 15 days ago


Job description

Description
Tharros is seeking a Senior Security Risk Management SME to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region.
This role will support enterprise cybersecurity risk management, Assessment and Authorization, continuous monitoring, FISMA compliance, secure cloud and hybrid engineering, and risk-based decision support across a complex mission environment. The ideal candidate can help translate security data, authorization evidence, vulnerabilities, POA&M status, and compliance requirements into clear risk insights and actionable remediation priorities.
Responsibilities:
  • Support enterprise cybersecurity risk management across classified and unclassified mission environments.
  • Lead or support Assessment and Authorization activities for Federal information systems.
  • Support security control assessments aligned to NIST, CNSSI, Intelligence Community, and Federal cybersecurity requirements.
  • Review and validate security artifacts, including System Security Plans, Security Assessment Plans, Security Assessment Reports, POA&Ms, and authorization evidence.
  • Support POA&M development, validation, remediation tracking, closure, and reporting.
  • Collaborate with system owners, ISSOs, developers, engineers, assessors, and other stakeholders to address findings and strengthen security posture.
  • Provide risk mitigation recommendations for assigned systems, networks, applications, and environments.
  • Support continuous monitoring activities that maintain system security posture over time.
  • Help improve and automate A&A, continuous monitoring, evidence management, and risk reporting processes.
  • Support quality reviews and process improvements for authorization documentation and security control implementation.
  • Translate complex security, compliance, and technical data into leadership-ready risk insights, dashboards, briefings, and remediation recommendations.
  • Support risk management activities across cloud, hybrid, cross-domain, and secure mission environments.

Requirements
  • Active TS/SCI
  • 10+ years of related cybersecurity risk management experience.
  • At least 2 years of recent experience in each of the following areas: A&A, FISMA compliance, IC cybersecurity policy and standards, continuous monitoring, CDS, and secure cloud and hybrid engineering.
  • Experience with emerging and evolving security risk management practices, including automation of A&A and continuous monitoring activities.
  • Experience applying NIST 800 series, CNSSI 1253, security controls, and RMF principles.
  • CISM, CAP, or GRC certification, or comparable demonstrable experience.
  • Experience developing, reviewing, or supporting authorization artifacts such as SSPs, SAPs, SARs, POA&Ms, risk assessments, control implementation evidence, and continuous monitoring reports.
  • Strong written and verbal communication skills, including the ability to explain risk, compliance status, and remediation needs clearly.
  • Ability to work onsite at a Government-approved location as required.

Preferred Qualifications:
  • Prior DHS, Intelligence Community, DoD, CISO office, ISSM, AO, SCA, or national security cybersecurity risk management experience.
  • Experience with enterprise RMF/A&A portfolios, ConMon automation, ATO/ATC readiness, POA&M quality, risk dashboards, GRC workflows, and evidence automation.
  • Experience with AWS, Microsoft Azure, Microsoft 365, or other cloud platforms.
  • Experience supporting classified, hybrid cloud, cross-domain, TS/SCI, or secure mission environments.
  • Experience turning vulnerability, threat, audit, compliance, system criticality, and continuous monitoring data into decision-ready risk insights.