1

Cybersecurity Risk Analyst Jobs in Silver Spring, MD

Third-Party Risk Analyst

Mclean, VA · On-site

$45 - $47/hr

Third-Party Risk Analyst Location: McLean, VA (5 days - Onsite) Job Overview The Third-Party Risk ... Monitor and document third-party risk and cybersecurity trends. Documentation & Communications

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

Cybersecurity Engineer

Washington, DC · On-site

$73.01 - $121.23/hr

Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...

Cybersecurity Engineer

Washington, DC · On-site

$53.33 - $88/hr

Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...

Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...

Cybersecurity Engineer

Washington, DC · On-site

$53.33 - $88/hr

Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...

Showing results 21-40

Cybersecurity Risk Analyst information

See Silver Spring, MD salary details

$15

$41

$68

How much do cybersecurity risk analyst jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for cybersecurity risk analyst in Silver Spring, MD is $41.85, according to ZipRecruiter salary data. Most workers in this role earn between $30.82 and $50.96 per hour, depending on experience, location, and employer.

What does a cybersecurity risk analyst do?

A Cybersecurity Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organization’s information systems and data. They evaluate potential threats and vulnerabilities, develop strategies to minimize risks, and ensure compliance with security policies and regulations. Their work helps protect sensitive data and maintain the integrity and confidentiality of digital assets. Analysts often collaborate with IT and business teams to implement security controls and respond to security incidents.

What are the key skills and qualifications needed to thrive as a cybersecurity risk analyst, and why are they important?

To thrive as a Cybersecurity Risk Analyst, you need a deep understanding of information security principles, risk management frameworks, and typically hold a degree in computer science or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, effective communication, and attention to detail help you identify risks and convey complex information to stakeholders. These skills and qualifications are vital to proactively safeguard organizational assets and ensure compliance in an evolving threat landscape.

What are some common challenges faced by cybersecurity risk analysts when working with cross-functional teams?

Cybersecurity Risk Analysts often collaborate with IT, compliance, and business units to assess and mitigate risks. A common challenge is translating complex technical risks into language that non-technical stakeholders can understand and act upon. Additionally, balancing security requirements with business objectives may require negotiation and creative problem-solving. Effective communication and relationship-building skills are key to ensuring that security recommendations are adopted across the organization.

What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Primary FocusAssessing and managing security risksMonitoring, detecting, and responding to security threats
Work EnvironmentRisk management teams, security departmentsSecurity operations centers, IT teams
Industry UsageFinance, healthcare, governmentAll industries with cybersecurity needs

While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

How much do cybersecurity risk analysts make?

Cybersecurity risk analysts typically earn a median annual salary of around $85,000 to $110,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in high-demand industries.
Infographic showing various Cybersecurity Risk Analyst job openings in Silver Spring, MD as of August 2026, with employment types broken down into 1% As Needed, 91% Full Time, 6% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $87,054 per year, or $41.9 per hour.

Full-time

Re-posted 5 days ago


Job description

Description


The Cybersecurity Analyst supports the security, compliance, and maintenance of information systems throughout the Risk Management Framework (RMF) lifecycle, from system preparation through decommissioning. This role ensures alignment with Intelligence Community Directive (ICD), Defense Intelligence Agency (DIA), and Department of Defense (DoD) cybersecurity policies and standards.


The analyst works closely with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), Security Control Assessors (SCAs), Program Managers (PMs), and other stakeholders to execute RMF activities, reduce cybersecurity risk, and improve the overall security posture of supported systems. This position focuses on driving meaningful security outcomes through vulnerability management, continuous monitoring, compliance support, and risk-informed decision-making.


Roles and Responsibilities

  • Support information systems throughout the RMF lifecycle, ensuring compliance with applicable cybersecurity policies, standards, and regulations.
  • Collaborate with ISSMs, ISSOs, SCAs, PMs, and other stakeholders to support security initiatives and compliance efforts.
  • Assist stakeholders in understanding cybersecurity risks, vulnerability impacts, and remediation priorities to improve system security posture.
  • Provide technical support for continuous monitoring activities, compliance reporting, and audit readiness initiatives.
  • Evaluate cybersecurity implications of system modifications, upgrades, and configuration changes.
  • Support implementation, assessment, and documentation of security controls.
  • Maintain and update cybersecurity documentation, authorization packages, and RMF artifacts.
  • Document vulnerabilities, misconfigurations, and security findings clearly to support remediation planning and stakeholder awareness.
  • Utilize Xacta or similar Cyber Risk Management platforms to manage risk assessments, security control evidence, compliance status, and POA&M activities.
  • Track and manage POA&M items to ensure vulnerabilities identified through scans, assessments, or audits are properly documented, mitigated, and resolved.
  • Analyze vulnerability and compliance data to identify trends, recurring issues, and opportunities for security improvements.
  • Promote cybersecurity best practices and ensure alignment with organizational and mission objectives.

Knowledge

  • Knowledge of the Risk Management Framework (RMF), NIST 800-series publications, Federal Information Processing Standards (FIPS), Security Authorization and Assessment (SA&A) processes, continuous monitoring, POA&M management, and vulnerability management.
  • Understanding of cybersecurity compliance requirements within DoD, DIA, and Intelligence Community environments.
  • Familiarity with cybersecurity risk management platforms such as Xacta and related compliance management tools.

Skills

  • Strong verbal and written communication skills with the ability to explain technical concepts to both technical and non-technical audiences.
  • Experience interpreting vulnerability and compliance reports generated from tools such as Xacta, STIG Viewer, ACAS, Prisma, Splunk, Trellix (HBSS), or similar security platforms.
  • Strong analytical, troubleshooting, and problem-solving abilities.
  • Ability to identify root causes of security issues and recommend practical remediation strategies.
  • Experience working across multiple teams and stakeholders to achieve security and compliance objectives.
  • Ability to manage competing priorities while maintaining attention to detail and accuracy.
  • Strong organizational skills and ability to maintain comprehensive security documentation.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.  
  • Obtain and maintain an IAT Level III certification, or maintain an IAT Level II certification, in accordance with DoD 8570.01-M and DoD Directive 8140 Cyberspace Workforce Management requirements.
  • Acceptable certifications include: CompTIA Cybersecurity Analyst (CySA+), CompTIA Security+, EC-Council Certified Network Defender (CND v3), CCNA Security, Global Industrial Cyber Security Professional (GICSP), GIAC Security Essentials (GSEC), Systems Security Certified Practitioner (SSCP)

Clearence

  • Active Top Secret clearance is required with SCI eligibility and the ability to Pass CI Poly


Pueo is an equal employment opportunity employer and affirmative action employer. All interested individuals will receive consideration and will not be discriminated against on the basis of race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity, genetic information, or protected veteran status. Pueo takes affirmative action in support of its policy to advance diversity and inclusion of individuals who are minorities, women, protected veterans, and individuals with disabilities.   Â