1

Cybersecurity Risk Analyst Jobs in Virginia (NOW HIRING)

Program Risk Manager

Herndon, VA · On-site

$86K - $138K/yr

... analysis, mitigation planning, stakeholder facilitation, and senior-level briefings. * Technical familiarity: RMF/ATO impacts, supply chain risk, cybersecurity risk integration, and program financial ...

Program Risk Manager

Herndon, VA · On-site

$86K - $138K/yr

... analysis, mitigation planning, stakeholder facilitation, and seniorlevel briefings. * Technical familiarity: RMF/ATO impacts, supply chain risk, cybersecurity risk integration, and program financial ...

Program Risk Manager

Herndon, VA · On-site

$86K - $138K/yr

... analysis, mitigation planning, stakeholder facilitation, and seniorlevel briefings. * Technical familiarity: RMF/ATO impacts, supply chain risk, cybersecurity risk integration, and program financial ...

Cyber and IT Risk Management Job Qualifications: Skills: Continuous Monitoring, Security ... cybersecurity event monitoring, focused on incident detection, triage, and analysis with the ...

About the Team We are seeking a highly skilled Principal cybersecurity engineer to architect the ... Advanced Risk Modeling: Expertise in quantitative risk analysis (e.g., Monte Carlo simulations or ...

Leads governance, risk, and compliance activities supporting MODES III cybersecurity operations ... Provides senior-level risk analysis and compliance reporting to Government stakeholders, ensuring ...

Responsibilities: • Leads governance, risk, and compliance activities supporting MODES III cybersecurity operations, ensuring alignment with DoD, DISA, and MC&FP cybersecurity requirements. • ...

Cyber Risk Analyst (TS/SCI) Reston, VA, USA Full-time Clearance: Top Secret/SCI Summary: Warnings ... Experience with DoD or IC cybersecurity projects or programs * Experience with DevSecOps, Path-to ...

Cyber Risk Analyst (TS/SCI) Reston, VA, USA Full-time Clearance: Top Secret/SCI Summary: Warnings ... Experience with DoD or IC cybersecurity projects or programs * Experience with DevSecOps, Path-to ...

next page

Showing results 1-20

Cybersecurity Risk Analyst information

See Virginia salary details

$15

$40

$65

How much do cybersecurity risk analyst jobs pay per hour?

As of May 31, 2026, the average hourly pay for cybersecurity risk analyst in Virginia is $40.14, according to ZipRecruiter salary data. Most workers in this role earn between $29.57 and $48.85 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cybersecurity Risk Analyst, and why are they important?

To thrive as a Cybersecurity Risk Analyst, you need a deep understanding of information security principles, risk management frameworks, and typically hold a degree in computer science or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, effective communication, and attention to detail help you identify risks and convey complex information to stakeholders. These skills and qualifications are vital to proactively safeguard organizational assets and ensure compliance in an evolving threat landscape.

What are some common challenges faced by Cybersecurity Risk Analysts when working with cross-functional teams?

Cybersecurity Risk Analysts often collaborate with IT, compliance, and business units to assess and mitigate risks. A common challenge is translating complex technical risks into language that non-technical stakeholders can understand and act upon. Additionally, balancing security requirements with business objectives may require negotiation and creative problem-solving. Effective communication and relationship-building skills are key to ensuring that security recommendations are adopted across the organization.

What does a Cybersecurity Risk Analyst do?

A Cybersecurity Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organization’s information systems and data. They evaluate potential threats and vulnerabilities, develop strategies to minimize risks, and ensure compliance with security policies and regulations. Their work helps protect sensitive data and maintain the integrity and confidentiality of digital assets. Analysts often collaborate with IT and business teams to implement security controls and respond to security incidents.

What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Primary FocusAssessing and managing security risksMonitoring, detecting, and responding to security threats
Work EnvironmentRisk management teams, security departmentsSecurity operations centers, IT teams
Industry UsageFinance, healthcare, governmentAll industries with cybersecurity needs

While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

What job categories do people searching Cybersecurity Risk Analyst jobs in Virginia look for? The top searched job categories for Cybersecurity Risk Analyst jobs in Virginia are:
Infographic showing various Cybersecurity Risk Analyst job openings in Virginia as of May 2026, with employment types broken down into 67% Full Time, and 33% Contract. Highlights an 100% In-person job distribution, with an average salary of $83,487 per year, or $40.1 per hour.
Cybersecurity Lead

$112.20K - $151.60K/yr

Other

Posted 13 days ago


Job description

Company Overview
By Light Professional IT Services LLC readies warfighters and federal agencies with technology and systems engineered to connect, protect, and prepare individuals and teams for whatever comes next. Headquartered in McLean, VA, By Light supports defense, civilian, and commercial IT customers worldwide.
Position Overview
Our By Light team, the premier providers of innovative Information Technology (IT) services and communications support to the Department of Defense and Federal Agencies, is growing. We're increasing our team to support the US Army Comprehensive Modernization (COMPMOD) program. The program delivers end-to-end EFIS&T services-including survey and design through installation, security, and testing. This work spans NIPR and SIPR networks, Wi-Fi, VoIP, ISP/OSP infrastructure, and voice modernization across all CONUS Army installations.
We're looking for a Cybersecurity Lead to guide cybersecurity compliance and risk management efforts for Army network modernization initiatives. You'll ensure systems are designed, configured, and documented to meet DoD and Army cybersecurity requirements, and you'll lead teams through RMF and A&A activities.
You'll work closely with engineers, program leadership, and government stakeholders to support inspections, resolve cybersecurity issues, and deliver operationally ready systems.
#compmod
Responsibilities
  • Support preparation for and execution of Command Cyber Readiness Inspections (CCRIs)
  • Provide cybersecurity input and artifacts for Engineering Installation Plans (EIPs)
  • Ensure systems and networks are designed and configured to meet RMF requirements
  • Support Assess and Authorize (A&A) activities in compliance with DoD RMF
  • Develop and deliver required RMF artifacts, including:
    • Network device configurations
    • STIG checklists
    • Network diagrams and topologies
    • System and security documentation
    • POA&Ms
  • Support program milestone decisions through cybersecurity risk analysis and issue resolution recommendations
  • Prepare, review, and deliver required reports, plans, and briefings
  • Provide cybersecurity support for program reviews, conferences, and stakeholder meetings

Required Experience/Qualifications
  • Bachelor's degree in Cybersecurity, Information Assurance, or a related IT field
  • Four (4) additional years of relevant experience may be substituted in lieu of a degree
  • DoD 8570 IAT Level III certification
  • 10+ years of cybersecurity or information assurance experience, including 2+ years leading cyber or IA teams
  • Experience leading teams of up to 10 personnel
  • Strong working knowledge of RMF and DoD/Army cybersecurity policies and guidance

Preferred Experience/Qualifications
  • Prior experience supporting the U.S. Army or other federal agencies
  • Strong communication skills with the ability to engage senior military leadership, program managers, and technical teams

Special Requirements/Security Clearance
  • Active TS/SCI at the time of application
  • Travel up to 25%, as required

Physical Demands
  • Ability to lift up to 30 lbs