1

Cybersecurity Risk Analyst Jobs in Virginia (NOW HIRING)

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

... Risk Analyst, Cyber Defense Analyst, Network Security Analyst, IT Security Specialist, Security Consultant, Cybersecurity Specialist, Malware Analyst, Security Architect, ect. DEGREE (Level Desired ...

... Risk Analyst, Cyber Defense Analyst, Network Security Analyst, IT Security Specialist, Security Consultant, Cybersecurity Specialist, Malware Analyst, Security Architect, ect. DEGREE (Level Desired ...

... Risk Analyst, Cyber Defense Analyst, Network Security Analyst, IT Security Specialist, Security Consultant, Cybersecurity Specialist, Malware Analyst, Security Architect, ect. DEGREE (Level Desired ...

Cybersecurity Engineer

Arlington, VA · On-site

$150K - $185K/yr

The role requires deep expertise in cybersecurity engineering, security compliance automation, cloud security, vulnerability analysis, risk assessment, and governance, risk, and compliance (GRC ...

Showing results 21-40

Cybersecurity Risk Analyst information

See Virginia salary details

$15

$40

$65

How much do cybersecurity risk analyst jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for cybersecurity risk analyst in Virginia is $40.14, according to ZipRecruiter salary data. Most workers in this role earn between $29.57 and $48.85 per hour, depending on experience, location, and employer.

What does a cybersecurity risk analyst do?

A Cybersecurity Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organization’s information systems and data. They evaluate potential threats and vulnerabilities, develop strategies to minimize risks, and ensure compliance with security policies and regulations. Their work helps protect sensitive data and maintain the integrity and confidentiality of digital assets. Analysts often collaborate with IT and business teams to implement security controls and respond to security incidents.

What are the key skills and qualifications needed to thrive as a cybersecurity risk analyst, and why are they important?

To thrive as a Cybersecurity Risk Analyst, you need a deep understanding of information security principles, risk management frameworks, and typically hold a degree in computer science or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, effective communication, and attention to detail help you identify risks and convey complex information to stakeholders. These skills and qualifications are vital to proactively safeguard organizational assets and ensure compliance in an evolving threat landscape.

What are some common challenges faced by cybersecurity risk analysts when working with cross-functional teams?

Cybersecurity Risk Analysts often collaborate with IT, compliance, and business units to assess and mitigate risks. A common challenge is translating complex technical risks into language that non-technical stakeholders can understand and act upon. Additionally, balancing security requirements with business objectives may require negotiation and creative problem-solving. Effective communication and relationship-building skills are key to ensuring that security recommendations are adopted across the organization.

What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Primary FocusAssessing and managing security risksMonitoring, detecting, and responding to security threats
Work EnvironmentRisk management teams, security departmentsSecurity operations centers, IT teams
Industry UsageFinance, healthcare, governmentAll industries with cybersecurity needs

While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

How much do cybersecurity risk analysts make?

Cybersecurity risk analysts typically earn a median annual salary of around $85,000 to $110,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in high-demand industries.
Infographic showing various Cybersecurity Risk Analyst job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 16% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $83,487 per year, or $40.1 per hour.

Cybersecurity Analyst with Security Clearance

Amentum

Mclean, VA • On-site

Other

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted yesterday


Job description

Amentum is seeking a Cybersecurity Analyst to join our team and support our McLean, VA customer. We are looking for team members who are passionate about making a difference by working on critical efforts we manage as a premier government contractor. Here at Amentum, we are purpose-driven with a fierce commitment to deliver on our promises. We create trailblazing solutions, have unwavering integrity, and embrace inclusion and collaboration. Our team is excited to help customers solve todays and tomorrow's problems, giving confidence and reassurance that together we'll accomplish mission success. Purpose / Scope: The Cybersecurity Analyst will perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor. The role will conduct cybersecurity analysis in preparation for A&A reviewing and validation of all associated cybersecurity documentation and technical controls. The role will work within a team that conducts A&A activities. This individual will develop System Security Plans (SSP), Contingency Plans, Business Impact Analyses (BIA), Plan of Action and Milestones (POA&Ms), Security Assessment Report (SARs), Security Assessment Plan (SAPs), and other RMF documentation. This position covers all cybersecurity aspects including, but not limited to, identifying risks, validating the mitigation of plans of action, analyzing system designs, and assisting with A&A issues that may prevent a system from receiving authorization. It supports the implementation of RMF by developing documentation and updating policies, procedures, and processes as assigned. The Cybersecurity Analyst will assess and mitigates system security threats/risks throughout the program life cycle. Contribute to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations. Create and review A&A Body of Evidence documentation, providing feedback on completeness and compliance of its content. Develop and execute Security Test Plan (STP) in close cooperation with team members. Manage and ensure Continuous Monitoring (CONMON) to maintain system authorization. Essential Responsibilities: * Identify key stakeholders in A&A efforts and ensure system documentation reflects current system security configurations to include hardware and software components, data flow, interconnections, and ports, protocols, and services, etc. * Identify potential risks associated with system configurations and advise on mitigation strategies * Participate in A&A status meetings and facilitate moving systems toward a successful A&A effort * Assist to estimate Level of Effort (LOE) involved in performing A&A activities * Assist customer program offices in interpreting and applying mitigation strategies * Conduct thorough reviews of all vulnerabilities, architecture, and defense in depth strategies and report findings in POA&Ms document * Document residual risks and provide the cybersecurity risk analysis and mitigation determination results * Maintain cybersecurity policy and processes as assigned * Able to analyze, interpret, and apply Federal cybersecurity guidance to customer needs * Communicate the security posture of systems through designated reporting mechanism * Collaborate with other team members in cybersecurity Minimum Requirements: * 5+ years of experience in the following areas: Cybersecurity policy, procedures, and processes, including RMF and NIST 800-53 and A&A's * Experience developing A&A documentation from scratch and performing assessments; RMF step 1 through 4 * Familiar with NIST publications, specifically RMF and NIST controls * One or more of the following certifications preferred (Security+, CAP, CISSP, CISM, GSEC, GCIH, or GSLC) * Minimum DoD 8570 Information Assurance Management Technology (IAM) level II * Familiar with dealing with defense-in-depth, and other information security and assurance principles and associated supporting technologies * Hands on experience and detailed familiarity with the A&A processes * Experience working in Xacta, Greenlight/Roadrunner * Excellent customer service and organization skills * Must demonstrate proficiency in the following areas: multi-tasking, critical thinking; and the ability to work quickly, efficiently and accurately in a dynamic and fluid environment * Must have a Top-Secret Clearance with polygraph * Must be able to read, speak, write, and understand the English language Preferred Qualifications: * BA/BS Degree * Excellent oral and written communication skills * Ability to interact and relay security technical requirements at all levels of leadership and work force * Ability to work both independently and as a member of a team Work Environment, Physical Demands, and Mental Demands: Typical office environment with no unusual hazards, occasional lifting to 20 pounds, constant sitting while using the computer terminal, constant use of sight abilities while reviewing documents, constant use of speech/hearing abilities for communication, constant mental alertness, must possess planning/organizing skills, and must be able to work under deadlines. Other Responsibilities: Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment. As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams. Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction. It is our policy to consistently provide services that meet customer expectations. Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts. Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities Procedure Compliance - Each employee must read, understand and implement the general and specific operational, safety, quality and environmental requirements of all plans, procedures and policies pertaining to his/her job. Compensation Details:
$130,000 - $160,000 The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws. Benefits Overview: Our health and welfare benefits are designed to support you and your priorities. Offerings include: * Health, dental, and vision insurance * Paid time off and holidays * Retirement benefits (including 401(k) matching) * Educational reimbursement * Parental leave * Employee stock purchase plan * Tax-saving options * Disability and life insurance * Pet insurance Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits. Original Posting:
07/21/2026 - Until Filled
Amentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs. Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed, marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language at Labor Laws Posters .