1

Cybersecurity Risk Analyst Jobs in Virginia (NOW HIRING)

Cybersecurity Engineer

Arlington, VA · On-site

$150K - $185K/yr

The role requires deep expertise in cybersecurity engineering, security compliance automation, cloud security, vulnerability analysis, risk assessment, and governance, risk, and compliance (GRC ...

Cybersecurity Engineer

Arlington, VA · On-site

$150 - $185/hr

The role requires deep expertise in cybersecurity engineering, security compliance automation, cloud security, vulnerability analysis, risk assessment, and governance, risk, and compliance (GRC ...

Cybersecurity Engineer

Arlington, VA · On-site

$150K - $185K/yr

The role requires deep expertise in cybersecurity engineering, security compliance automation, cloud security, vulnerability analysis, risk assessment, and governance, risk, and compliance (GRC ...

Sr. Cyber Analyst

Hampton, VA

$97K - $125K/yr

Provides recommendations to activity leadership on processes and methodologies to assess cybersecurity risk on information systems. Works with other Cyber Analysts, SMEs, and SCA-Rs to ensure that ...

The RMF Cyber Security Analyst Senior will provide support for a program, an organization, system ... Provide risk mitigation strategies. * Perform quality checks on POA&Ms, risk assessments, and ...

New

Cybersecurity Analyst / ISSO

Stafford, VA · On-site

$100K - $120K/yr

Leading cybersecurity risk management efforts across enterprise systems by assessing AI and machine ... Proven capability to interpret, analyze, and direct programmatic responses to MFCC (Marine Forces ...

Cybersecurity Analyst / ISSO

Stafford, VA · On-site

$100K - $120K/yr

Leading cybersecurity risk management efforts across enterprise systems by assessing AI and machine ... Proven capability to interpret, analyze, and direct programmatic responses to MFCC (Marine Forces ...

Cyber Risk Analyst (TS/SCI)

Reston, VA · On-site

$95 - $140/hr

Cyber Risk Analyst (TS/SCI) Reston, VA, USA / Full-time / Clearance: Top Secret/SCI Summary ... Experience with DoD or IC cybersecurity projects or programs * Experience with DevSecOps, Path-to ...

Cyber Risk Analyst (TS/SCI) Reston, VA, USA Full-time Clearance: Top Secret/SCI Summary: Warnings ... Experience with DoD or IC cybersecurity projects or programs * Experience with DevSecOps, Path-to ...

About the Team We are seeking a highly skilled Principal cybersecurity engineer to architect the ... Advanced Risk Modeling: Expertise in quantitative risk analysis (e.g., Monte Carlo simulations or ...

Showing results 41-60

Cybersecurity Risk Analyst information

See Virginia salary details

$15

$40

$65

How much do cybersecurity risk analyst jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for cybersecurity risk analyst in Virginia is $40.14, according to ZipRecruiter salary data. Most workers in this role earn between $29.57 and $48.85 per hour, depending on experience, location, and employer.

What does a cybersecurity risk analyst do?

A Cybersecurity Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organization’s information systems and data. They evaluate potential threats and vulnerabilities, develop strategies to minimize risks, and ensure compliance with security policies and regulations. Their work helps protect sensitive data and maintain the integrity and confidentiality of digital assets. Analysts often collaborate with IT and business teams to implement security controls and respond to security incidents.

What are the key skills and qualifications needed to thrive as a cybersecurity risk analyst, and why are they important?

To thrive as a Cybersecurity Risk Analyst, you need a deep understanding of information security principles, risk management frameworks, and typically hold a degree in computer science or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, effective communication, and attention to detail help you identify risks and convey complex information to stakeholders. These skills and qualifications are vital to proactively safeguard organizational assets and ensure compliance in an evolving threat landscape.

What are some common challenges faced by cybersecurity risk analysts when working with cross-functional teams?

Cybersecurity Risk Analysts often collaborate with IT, compliance, and business units to assess and mitigate risks. A common challenge is translating complex technical risks into language that non-technical stakeholders can understand and act upon. Additionally, balancing security requirements with business objectives may require negotiation and creative problem-solving. Effective communication and relationship-building skills are key to ensuring that security recommendations are adopted across the organization.

What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Primary FocusAssessing and managing security risksMonitoring, detecting, and responding to security threats
Work EnvironmentRisk management teams, security departmentsSecurity operations centers, IT teams
Industry UsageFinance, healthcare, governmentAll industries with cybersecurity needs

While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

How much do cybersecurity risk analysts make?

Cybersecurity risk analysts typically earn a median annual salary of around $85,000 to $110,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in high-demand industries.
Infographic showing various Cybersecurity Risk Analyst job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 16% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $83,487 per year, or $40.1 per hour.

Cybersecurity Engineer

ThinkTek

Arlington, VA • On-site

$150K - $185K/yr

Full-time

Medical, Dental, Vision, PTO

Posted 7 days ago


Job description

Cybersecurity Engineer (Secret Clearance)

Who We Are:
ThinkTek LLC is a fast-growing Certified SBA 8(a) and Service-Disabled Veteran-Owned Small Business (SDVOSB) company. We specialize in providing management and technology consulting services to support the business and technology modernization efforts of the Federal Government. ThinkTek was formed with the specific purpose of providing its clients a tailored solution around Program & Project Management, Strategic Planning, and IT Operations.

Position Overview

We are seeking an experienced Cybersecurity Engineer to support a Federal Government customer by providing advanced cybersecurity engineering, assessment, and compliance support. This position serves as a senior cybersecurity practitioner responsible for implementing and assessing security controls, maintaining system authorization packages, conducting security assessments, and supporting risk-based authorization decisions across a portfolio of mission-critical systems.

The Cybersecurity Engineer will work across traditional, cloud-native, and SaaS environments, supporting the Risk Management Framework (RMF), Cybersecurity Risk Management Construct (CSRMC), Continuous Authorization to Operate (cATO), and Zero Trust initiatives. The role requires deep expertise in cybersecurity engineering, security compliance automation, cloud security, vulnerability analysis, risk assessment, and governance, risk, and compliance (GRC) processes.

This position requires a highly skilled cybersecurity professional with strong technical expertise, project management experience, and an active Secret security clearance.

Responsibilities

  • Serve as the lead cybersecurity engineer and Information System Security Officer (ISSO) supporting a portfolio of DSCA mission systems across on-premises, cloud, and SaaS environments.
  • Lead RMF and Cybersecurity Risk Management Construct (CSRMC) activities, including system authorization, continuous monitoring, and maintenance of ATO/cATO packages.
  • Manage and maintain eMASS records, authorization artifacts, control implementation evidence, and Plans of Action & Milestones (POA&Ms).
  • Assess and validate NIST 800-53, DoD RMF, DISA STIG, FedRAMP, and DoD Cloud Computing Security Requirements Guide (CC SRG) security controls.
  • Conduct security control assessments and independent validations to evaluate control effectiveness and support risk-informed authorization decisions.
  • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and authorization recommendation memorandums.
  • Analyze vulnerabilities, security findings, automated scan results, and threat data to assess mission impact and prioritize remediation activities.
  • Review and validate Compliance-as-Code (CaC), Policy-as-Code (PaC), and automated security assessment outputs to ensure accuracy and compliance.
  • Collaborate with system owners, developers, engineers, and program stakeholders to implement security controls, address findings, and reduce enterprise risk.
  • Support DevSecOps and cloud security initiatives by integrating security throughout the system development lifecycle and continuous delivery processes.
  • Monitor security posture across AWS cloud, traditional infrastructure, and SaaS platforms, ensuring compliance with federal and DoD cybersecurity requirements.
  • Brief government leadership and Authorizing Officials on system risk posture, assessment results, remediation strategies, and authorization recommendations.

Required Qualifications

  • Active Secret Security Clearance.
  • Bachelor's degree in Information Technology, Computer Science, Engineering or a related technical field from an accredited college or university.
  • Minimum 5 years of dedicated Information Assurance, Cybersecurity, or Information Security experience.
  • At least 3 consecutive years of recent experience supporting DoD cybersecurity programs.
  • Experience with Risk Management Framework (RMF) authorization processes.
  • Experience administering and maintaining eMASS authorization packages.
  • Experience conducting security control assessments, validations, and risk assessments.
  • Experience supporting ATO, cATO, and continuous monitoring programs.
  • Experience analyzing vulnerabilities, security findings, and organizational risk posture.
  • Experience supporting cloud security initiatives in AWS, Azure, or other FedRAMP-authorized environments.
  • Strong understanding of NIST 800-53 security controls and DISA STIG requirements.

Required Certifications

Candidates must possess:

  • One DoD 8570/8140 IAM Level II or IAT Level ll baseline requirements, such as:
    • CISSP
    • Security+ CE
    • CISM
    • CASP+ CE

Pay Range

The anticipated annual salary range for this position is $150,030 – $185,020. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data, and applicable contract requirements, and may fall outside the posted range.

**THIS POSITION IS CONTINGENT UPON CONTRACT AWARD**

ThinkTek LLC is proud to be an Equal Opportunity Employer (EOE), making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. ThinkTek offers medical, dental, and vision insurance to all full-time employees; PTO and a variety of other paid leave options are also available. You can read more about ThinkTek benefits at https://www.thinktekllc.com/careers/.