1

Cybersecurity Risk Analyst Jobs in Virginia (NOW HIRING)

This is an ideal role for a cybersecurity professional who thrives at the intersection of risk analysis, compliance, and mission impact. Work Location: * This position is 100% on-site, primarily ...

This is an ideal role for a cybersecurity professional who thrives at the intersection of risk analysis, compliance, and mission impact. Work Location: * This position is 100% on-site, primarily ...

This is an ideal role for a cybersecurity professional who thrives at the intersection of risk analysis, compliance, and mission impact. Work Location: * This position is 100% on-site, primarily ...

Partner with technology, cybersecurity, compliance, and risk teams to strengthen control ... Strong analytical, organizational, and documentation skills. * Experience reviewing documentation ...

Partner with technology, cybersecurity, compliance, and risk teams to strengthen control ... Strong analytical, organizational, and documentation skills. * Experience reviewing documentation ...

Analyze testing results and provide cybersecurity risk assessments to the Government SCA and Authorizing Official. * RMF Package Development and Reporting * Oversee preparation and delivery of RMF ...

Cybersecurity Assessment Lead

Virginia Beach, VA · On-site

$98K - $133K/yr

This position leads independent security control validation activities, ensures RMF packages are complete and compliant, and provides cybersecurity risk analysis to the Government Security Control ...

Sr. Analyst, Cybersecurity

Richmond, VA

$99K - $127K/yr

A Senior Technology/Information Risk Analyst with experience in the areas highlighted below. This ... You will assist the Cybersecurity, technology, compliance, and information risk teams in ...

Sr. Analyst, Cybersecurity

Richmond, VA · On-site

$92K - $119K/yr

A Senior Technology/Information Risk Analyst with experience in the areas highlighted below. This ... You will assist the Cybersecurity, technology, compliance, and information risk teams in ...

Sr. Analyst, Cybersecurity

Richmond, VA · On-site

$99K - $127K/yr

A Senior Technology/Information Risk Analyst with experience in the areas highlighted below. This ... You will assist the Cybersecurity, technology, compliance, and information risk teams in ...

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

Third-Party Risk Analyst

Mclean, VA · On-site

$45 - $47/hr

Third-Party Risk Analyst Location: McLean, VA (5 days - Onsite) Job Overview The Third-Party Risk ... Monitor and document third-party risk and cybersecurity trends. Documentation & Communications

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

next page

Showing results 1-20

Cybersecurity Risk Analyst information

See Virginia salary details

$15

$40

$65

How much do cybersecurity risk analyst jobs pay per hour?

As of Jun 23, 2026, the average hourly pay for cybersecurity risk analyst in Virginia is $40.14, according to ZipRecruiter salary data. Most workers in this role earn between $29.57 and $48.85 per hour, depending on experience, location, and employer.

What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Primary FocusAssessing and managing security risksMonitoring, detecting, and responding to security threats
Work EnvironmentRisk management teams, security departmentsSecurity operations centers, IT teams
Industry UsageFinance, healthcare, governmentAll industries with cybersecurity needs

While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

What are the key skills and qualifications needed to thrive as a Cybersecurity Risk Analyst, and why are they important?

To thrive as a Cybersecurity Risk Analyst, you need a deep understanding of information security principles, risk management frameworks, and typically hold a degree in computer science or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, effective communication, and attention to detail help you identify risks and convey complex information to stakeholders. These skills and qualifications are vital to proactively safeguard organizational assets and ensure compliance in an evolving threat landscape.

Can I make $200,000 a year in cyber security?

Cybersecurity Risk Analysts can potentially earn $200,000 or more annually, especially with advanced certifications like CISSP, extensive experience, and specialized skills in areas such as threat management or security architecture. High salaries are often found in senior roles, management positions, or in organizations with complex security needs. Factors like location, industry, and company size also influence earning potential.

What does a cyber risk analyst do?

A cybersecurity risk analyst evaluates an organization’s information systems to identify vulnerabilities and assess potential threats. They analyze security data, develop risk mitigation strategies, and recommend security improvements, often using tools like risk assessment frameworks and security software. The role requires strong analytical skills and knowledge of cybersecurity principles and standards.

What are some common challenges faced by Cybersecurity Risk Analysts when working with cross-functional teams?

Cybersecurity Risk Analysts often collaborate with IT, compliance, and business units to assess and mitigate risks. A common challenge is translating complex technical risks into language that non-technical stakeholders can understand and act upon. Additionally, balancing security requirements with business objectives may require negotiation and creative problem-solving. Effective communication and relationship-building skills are key to ensuring that security recommendations are adopted across the organization.

Is SOC 1 entry level?

SOC 1 (Service Organization Control 1) reports are audit reports used by organizations to demonstrate controls over financial reporting. The term SOC 1 itself does not specify an entry-level position; however, roles involved in preparing or auditing SOC 1 reports, such as cybersecurity risk analysts or auditors, typically require some experience in controls, compliance, or auditing, but entry-level positions may assist with documentation and testing under supervision.

What does a Cybersecurity Risk Analyst do?

A Cybersecurity Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organization’s information systems and data. They evaluate potential threats and vulnerabilities, develop strategies to minimize risks, and ensure compliance with security policies and regulations. Their work helps protect sensitive data and maintain the integrity and confidentiality of digital assets. Analysts often collaborate with IT and business teams to implement security controls and respond to security incidents.

Can you make $500,000 a year in cyber security?

Cybersecurity Risk Analysts typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary usually requires advanced roles such as cybersecurity executives, consultants, or specialists with extensive expertise and leadership responsibilities.
Infographic showing various Cybersecurity Risk Analyst job openings in Virginia as of June 2026, with employment types broken down into 67% Full Time, and 33% Contract. Highlights an 100% In-person job distribution, with an average salary of $83,487 per year, or $40.1 per hour.
Cyber Risk Analyst with Security Clearance

Cyber Risk Analyst with Security Clearance

Peraton

Chantilly, VA • On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 7 days ago


Peraton rating

8.2

Company rating: 8.2 out of 10

Based on 53 frontline employees who took The Breakroom Quiz

45th of 204 rated it services


Job description

About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we're keeping people around the world safe and secure. About The Role oin Peraton in advancing the safety, efficiency, and modernization of the National Airspace System (NAS) through the FAA's Brand New Air Traffic Control System (BNATCS) contract. As a trusted partner to the Federal Aviation Administration, Peraton helps deliver the systems and services that keep our nation's skies safe and connected. We're looking for innovative professionals who thrive in mission-critical environments and are passionate about shaping the future of air traffic management. This is your chance to make an impact on one of the world's most vital transportation infrastructures, working alongside leaders in aviation, engineering, data science, and systems integration. At Peraton, you won't just support the mission - you'll define it. Help protect the systems that keep U.S. airspace safe, resilient, and trusted. We are seeking a Cyber Risk Analyst to support cybersecurity risk identification, assessment, and mitigation across modernization initiatives aligned with the Federal Aviation Administration (FAA). This is an ideal role for a cybersecurity professional who thrives at the intersection of risk analysis, compliance, and mission impact. Work Location: * This position is 100% on-site, primarily located in Chantilly, VA, with an alternate work location available in Bowie, MD. Candidates must be able to work on-site at one of these locations based on program requirements.Your Impact: In this role, you will be at the center of cybersecurity decision-making-analyzing risk, advising leadership, and ensuring emerging technologies are deployed securely and responsibly. You'll work across engineering, operations, and compliance teams to translate technical vulnerabilities into clear, actionable risk insights that shape how aviation systems are protected. * Identify, analyze, and document cybersecurity risks across FAA systems and modernization initiatives.
* Support Risk Management Framework (RMF) activities, including risk assessments, control validation, and mitigation planning.
* Evaluate system compliance with NIST standards, FISMA, FedRAMP, and FAA cybersecurity requirements.
* Conduct risk assessments, gap analyses, and threat evaluations for new and existing systems.
* Translate technical findings into clear risk statements and executive-level recommendations.
* Support system authorization (ATO), continuous monitoring, and audit readiness activities.
* Collaborate with system owners, ISSOs, architects, and engineers to track and reduce cybersecurity risk.
* Monitor remediation efforts and validate closure of cybersecurity findings.
* Support development and maintenance of risk registers, POA&Ms, and compliance artifacts.
* Prepare reports, dashboards, and briefings for FAA leadership and program stakeholders.
* Ability to clearly communicate cyber risk to both technical and non-technical audiences.Why This Role Matters Cyber risk management is essential to maintaining trust in the National Airspace System. As a Cyber Risk Analyst, you help ensure that new technologies are introduced responsibly, vulnerabilities are addressed proactively, and leadership has the insight needed to make informed decisions. Your work directly supports the FAA's mission to protect national infrastructure, reduce cyber risk, and maintain the safest and most reliable aviation system in the world. This role is not just about compliance-it's about enabling secure innovation at a national scale. Qualifications Basic Qualifications: * U.S. Citizenship Required.
* Must have the ability to obtain / maintain a Public Trust clearance.
* Bachelor's degree and 5 years experience or Masters degree and 3 years experience or Associate's degree and 7 years experience or HS diploma/equivalent and 9 years experience. * Demonstrated experience supporting cyber risk management or compliance in federal or regulated environments
* Strong knowledge of NIST 800-53, NIST RMF, FISMA, and cybersecurity risk methodologies
* Experience supporting system authorization, POA&M management, and continuous monitoring
* Demonstrated experience supporting security control assessments, risk scoring, and mitigation tracking for enterprise systems.
* Familiarity with incident response coordination.Preferred Qualifications * Experience supporting FAA, DOT, or other federal aviation systems.
* Familiarity with aviation systems, critical infrastructure, or safety-critical environments.
* Experience with FedRAMP cloud environments and shared responsibility models.
* Knowledge of Zero Trust principles and risk-based security architectures.
* Industry certifications such as CISSP, CISM, CRISC, or Security+.
* Experience using GRC tools or risk tracking platforms.
* Familiarity with NextGen FAA modernization efforts.#BNATC Details Target Salary Range: $86,000 - $138,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at https://www.careers.peraton.com/benefits. Application Statements: The application period for the job is estimated to be 30 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates. By applying to this job, you are expressing interest in the role and the Company. During the review of your application, you may be required to participate in an on-camera interview, as well as participate in a process to verify your identity. EEO:Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

What Peraton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Peraton logo

About Peraton

Sourced by ZipRecruiter

At Peraton, we re at the forefront of delivering the next big thing every day. We re the partner of choice to help solve some of the world s most daunting challenges, delivering bold, new solutions to keep people around the world safer and more secure.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Herndon, VA, US

Year founded

2017