Description The Cybersecurity Analyst supports the security, compliance, and maintenance of information systems throughout the Risk Management Framework (RMF) lifecycle, from system preparation ...
Description The Cybersecurity Analyst supports the security, compliance, and maintenance of information systems throughout the Risk Management Framework (RMF) lifecycle, from system preparation ...
Cybersecurity Analyst Expert
Mclean, VA · On-site
The Cybersecurity Analyst supports the security, compliance, and maintenance of information systems throughout the Risk Management Framework (RMF) lifecycle, from system preparation through ...
Cybersecurity Analyst Expert
Mclean, VA · On-site
The Cybersecurity Analyst supports the security, compliance, and maintenance of information systems throughout the Risk Management Framework (RMF) lifecycle, from system preparation through ...
Third-Party Risk Analyst
Mclean, VA · On-site
$45 - $47/hr
Third-Party Risk Analyst Location: McLean, VA (5 days - Onsite) Job Overview The Third-Party Risk ... Monitor and document third-party risk and cybersecurity trends. Documentation & Communications
Quick apply
Third-Party Risk Analyst
Mclean, VA · On-site
$45 - $47/hr
Third-Party Risk Analyst Location: McLean, VA (5 days - Onsite) Job Overview The Third-Party Risk ... Monitor and document third-party risk and cybersecurity trends. Documentation & Communications
The Cybersecurity Analyst will perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor. The role will ...
The Cybersecurity Analyst will perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor. The role will ...
Senior Manager - Security Risk, Tech and Cyber Risk, Compliance
Washington, DC · On-site
$120 - $160/hr
Advanced cybersecurity risk management skills * Experience utilizing ISO/IEC 27001 and NIST Cybersecurity Framework (CSF) * Analytical thinking for complex regulatory challenges * Experience leading ...
Senior Manager - Security Risk, Tech and Cyber Risk, Compliance
Washington, DC · On-site
$120 - $160/hr
Advanced cybersecurity risk management skills * Experience utilizing ISO/IEC 27001 and NIST Cybersecurity Framework (CSF) * Analytical thinking for complex regulatory challenges * Experience leading ...
Coordinate cybersecurity risk assessment projects across multiple workstreams * Maintain project ... Experience performing data analysis and developing executive-level reports and presentations
Coordinate cybersecurity risk assessment projects across multiple workstreams * Maintain project ... Experience performing data analysis and developing executive-level reports and presentations
Cybersecurity Risk Assessment * Business Resiliency & Continuity Risk * Risk Analysis & Evaluation * Control Assessment & Validation * Risk Mitigation Planning * Risk Documentation & Reporting ...
Cybersecurity Risk Assessment * Business Resiliency & Continuity Risk * Risk Analysis & Evaluation * Control Assessment & Validation * Risk Mitigation Planning * Risk Documentation & Reporting ...
Cybersecurity Compliance Analyst (2 Positions Available)
Arlington, VA · On-site
$94K - $137K/yr
You will conduct compliance assessments, supports audits, perform cybersecurity risk analyses, tracks remediation activities, and maintain documentation demonstrating compliance with established ...
Cybersecurity Compliance Analyst (2 Positions Available)
Arlington, VA · On-site
$94K - $137K/yr
You will conduct compliance assessments, supports audits, perform cybersecurity risk analyses, tracks remediation activities, and maintain documentation demonstrating compliance with established ...
Cyber Risk Analyst SME
Arlington, VA · On-site
We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...
Cyber Risk Analyst SME
Arlington, VA · On-site
We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...
Cyber Risk Analyst SME
Arlington, VA · On-site +1
We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...
Cyber Risk Analyst SME
Arlington, VA · On-site +1
We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...
Risk and Cybersecurity Strategy Consultant
Washington, DC · On-site
$140 - $180/hr
Provide expert‑level technical guidance and analysis to support cybersecurity and risk assessment initiatives, including supply chain risk management. * Develop, enhance, and maintain standard ...
Risk and Cybersecurity Strategy Consultant
Washington, DC · On-site
$140 - $180/hr
Provide expert‑level technical guidance and analysis to support cybersecurity and risk assessment initiatives, including supply chain risk management. * Develop, enhance, and maintain standard ...
Cyber Security Risk Engineer
Washington, DC · On-site
Our company provides application analysis, design, development and programming, software ... Responsible for developing and executing risk mitigation concepts, plans and services used to ...
Cyber Security Risk Engineer
Washington, DC · On-site
Our company provides application analysis, design, development and programming, software ... Responsible for developing and executing risk mitigation concepts, plans and services used to ...
Cybersecurity Engineer
Washington, DC · On-site
$73.01 - $121.23/hr
Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...
Cybersecurity Engineer
Washington, DC · On-site
$73.01 - $121.23/hr
Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...
Cyber Security Analyst - Remote / Telecommute
Baltimore, MD · Remote
$57 - $62/hr
Knowledge of cybersecurity risk management techniques, frameworks, best practices, and industry ... Certified Threat Intelligence Analyst (CTIA)-ECCOUNCIL. * Certification and Accreditation ...
Quick apply
Cyber Security Analyst - Remote / Telecommute
Baltimore, MD · Remote
$57 - $62/hr
Knowledge of cybersecurity risk management techniques, frameworks, best practices, and industry ... Certified Threat Intelligence Analyst (CTIA)-ECCOUNCIL. * Certification and Accreditation ...
Cybersecurity Engineer
Washington, DC · On-site
$53.33 - $88/hr
Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...
Cybersecurity Engineer
Washington, DC · On-site
$53.33 - $88/hr
Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...
Cybersecurity Engineer
$53.33 - $88/hr
Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...
Cybersecurity Engineer
$53.33 - $88/hr
Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...
Cybersecurity Engineer
Washington, DC · On-site
$53.33 - $88/hr
Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...
Quick apply
Cybersecurity Engineer
Washington, DC · On-site
$53.33 - $88/hr
Conduct security assessments, vulnerability scans, and risk analyses * Identify cybersecurity vulnerabilities and recommend corrective actions * Support Risk Management Framework (RMF) and Assessment ...
Senior Security Risk Management Engineer
Washington, DC · On-site
$160K - $195K/yr
Conduct cybersecurity risk assessments. Analyze technical, operational, and architectural risks. Identify system vulnerabilities and control deficiencies. Evaluate likelihood and impact of identified ...
Quick apply
Senior Security Risk Management Engineer
Washington, DC · On-site
$160K - $195K/yr
Conduct cybersecurity risk assessments. Analyze technical, operational, and architectural risks. Identify system vulnerabilities and control deficiencies. Evaluate likelihood and impact of identified ...
Description Tharros is seeking a Senior Security Risk Management SME to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region. This role will support enterprise ...
Description Tharros is seeking a Senior Security Risk Management SME to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region. This role will support enterprise ...
Conduct cybersecurity risk assessments related to cryptographic technologies, key management ... Experience developing technical analyses, cybersecurity documentation, policy recommendations, or ...
Conduct cybersecurity risk assessments related to cryptographic technologies, key management ... Experience developing technical analyses, cybersecurity documentation, policy recommendations, or ...
Cybersecurity Risk Analyst information
See Silver Spring, MD salary details
$15.90 - $20.65
3% of jobs
$20.65 - $25.39
7% of jobs
$25.39 - $30.14
12% of jobs
$31.07 is the 25th percentile. Wages below this are outliers.
$30.14 - $34.88
15% of jobs
$34.88 - $39.63
13% of jobs
The median wage is $39.78 / hr.
$39.63 - $44.37
16% of jobs
$44.37 - $49.11
8% of jobs
$49.71 is the 75th percentile. Wages above this are outliers.
$49.11 - $53.86
11% of jobs
$53.86 - $58.60
6% of jobs
$58.60 - $63.35
6% of jobs
$63.35 - $68.09
3% of jobs
$15
$41
$68
How much do cybersecurity risk analyst jobs pay per hour?
What does a cybersecurity risk analyst do?
What are the key skills and qualifications needed to thrive as a cybersecurity risk analyst, and why are they important?
What are some common challenges faced by cybersecurity risk analysts when working with cross-functional teams?
What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?
| Aspect | Cybersecurity Risk Analyst | Cybersecurity Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CISSP, CISA | CompTIA Security+, CEH, CISSP |
| Primary Focus | Assessing and managing security risks | Monitoring, detecting, and responding to security threats |
| Work Environment | Risk management teams, security departments | Security operations centers, IT teams |
| Industry Usage | Finance, healthcare, government | All industries with cybersecurity needs |
While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.
How much do cybersecurity risk analysts make?

Job description
Description
The Cybersecurity Analyst supports the security, compliance, and maintenance of information systems throughout the Risk Management Framework (RMF) lifecycle, from system preparation through decommissioning. This role ensures alignment with Intelligence Community Directive (ICD), Defense Intelligence Agency (DIA), and Department of Defense (DoD) cybersecurity policies and standards.
The analyst works closely with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), Security Control Assessors (SCAs), Program Managers (PMs), and other stakeholders to execute RMF activities, reduce cybersecurity risk, and improve the overall security posture of supported systems. This position focuses on driving meaningful security outcomes through vulnerability management, continuous monitoring, compliance support, and risk-informed decision-making.
Roles and Responsibilities
- Support information systems throughout the RMF lifecycle, ensuring compliance with applicable cybersecurity policies, standards, and regulations.
- Collaborate with ISSMs, ISSOs, SCAs, PMs, and other stakeholders to support security initiatives and compliance efforts.
- Assist stakeholders in understanding cybersecurity risks, vulnerability impacts, and remediation priorities to improve system security posture.
- Provide technical support for continuous monitoring activities, compliance reporting, and audit readiness initiatives.
- Evaluate cybersecurity implications of system modifications, upgrades, and configuration changes.
- Support implementation, assessment, and documentation of security controls.
- Maintain and update cybersecurity documentation, authorization packages, and RMF artifacts.
- Document vulnerabilities, misconfigurations, and security findings clearly to support remediation planning and stakeholder awareness.
- Utilize Xacta or similar Cyber Risk Management platforms to manage risk assessments, security control evidence, compliance status, and POA&M activities.
- Track and manage POA&M items to ensure vulnerabilities identified through scans, assessments, or audits are properly documented, mitigated, and resolved.
- Analyze vulnerability and compliance data to identify trends, recurring issues, and opportunities for security improvements.
- Promote cybersecurity best practices and ensure alignment with organizational and mission objectives.
Knowledge
- Knowledge of the Risk Management Framework (RMF), NIST 800-series publications, Federal Information Processing Standards (FIPS), Security Authorization and Assessment (SA&A) processes, continuous monitoring, POA&M management, and vulnerability management.
- Understanding of cybersecurity compliance requirements within DoD, DIA, and Intelligence Community environments.
- Familiarity with cybersecurity risk management platforms such as Xacta and related compliance management tools.
Skills
- Strong verbal and written communication skills with the ability to explain technical concepts to both technical and non-technical audiences.
- Experience interpreting vulnerability and compliance reports generated from tools such as Xacta, STIG Viewer, ACAS, Prisma, Splunk, Trellix (HBSS), or similar security platforms.
- Strong analytical, troubleshooting, and problem-solving abilities.
- Ability to identify root causes of security issues and recommend practical remediation strategies.
- Experience working across multiple teams and stakeholders to achieve security and compliance objectives.
- Ability to manage competing priorities while maintaining attention to detail and accuracy.
- Strong organizational skills and ability to maintain comprehensive security documentation.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field. Â
- Obtain and maintain an IAT Level III certification, or maintain an IAT Level II certification, in accordance with DoD 8570.01-M and DoD Directive 8140 Cyberspace Workforce Management requirements.
- Acceptable certifications include: CompTIA Cybersecurity Analyst (CySA+), CompTIA Security+, EC-Council Certified Network Defender (CND v3), CCNA Security, Global Industrial Cyber Security Professional (GICSP), GIAC Security Essentials (GSEC), Systems Security Certified Practitioner (SSCP)
Clearence
- Active Top Secret clearance is required with SCI eligibility and the ability to Pass CI Poly
Pueo is an equal employment opportunity employer and affirmative action employer. All interested individuals will receive consideration and will not be discriminated against on the basis of race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity, genetic information, or protected veteran status. Pueo takes affirmative action in support of its policy to advance diversity and inclusion of individuals who are minorities, women, protected veterans, and individuals with disabilities.   Â
About Pueo Business Solutions
Sourced by ZipRecruiter
Industry
Business management consulting
Company size
51 - 200 Employees
Headquarters location
Fredericksburg, VA, US
Year founded
2016