... Risk Management Framework (RMF) Subject Matter Expert (SME) to support our clients. The RMF SME ... Requirements: * Bachelor's degree in Cybersecurity, Information Systems, or related field (or ...
... Risk Management Framework (RMF) Subject Matter Expert (SME) to support our clients. The RMF SME ... Requirements: * Bachelor's degree in Cybersecurity, Information Systems, or related field (or ...
Manage enterprise cybersecurity risk program, including risk assessments, mitigation strategies, and reporting. * Ensure compliance with relevant regulations, frameworks, and standards (e.g., NIST ...
Manage enterprise cybersecurity risk program, including risk assessments, mitigation strategies, and reporting. * Ensure compliance with relevant regulations, frameworks, and standards (e.g., NIST ...
Cybersecurity Product Manager
Nashville, TN · On-site
$107K - $144K/yr
... Management (IAM, ILM) and data protection programs include maintaining alignment to the IT General Controls (ITGC) program. This role will work hand in hand with Cybersecurity, Risk leadership and ...
Cybersecurity Product Manager
Nashville, TN · On-site
$107K - $144K/yr
... Management (IAM, ILM) and data protection programs include maintaining alignment to the IT General Controls (ITGC) program. This role will work hand in hand with Cybersecurity, Risk leadership and ...
Manage enterprise cybersecurity risk program, including risk assessments, mitigation strategies, and reporting. * Ensure compliance with relevant regulations, frameworks, and standards (e.g., NIST ...
Manage enterprise cybersecurity risk program, including risk assessments, mitigation strategies, and reporting. * Ensure compliance with relevant regulations, frameworks, and standards (e.g., NIST ...
Cybersecurity Lead
Oak Ridge, TN · On-site
$96K - $130K/yr
NIST 800-53 Rev 5, Risk Management Framework, NIST Cybersecurity Framework (CSF), FedRAMP ... Authorization, Tenable Nessus (ACAS), and DISA STIGs. Desired Skills * Strategic thinker with ...
Cybersecurity Lead
Oak Ridge, TN · On-site
$96K - $130K/yr
NIST 800-53 Rev 5, Risk Management Framework, NIST Cybersecurity Framework (CSF), FedRAMP ... Authorization, Tenable Nessus (ACAS), and DISA STIGs. Desired Skills * Strategic thinker with ...
... cybersecurity activities under the Risk Management Framework, including system authorization processes, security control implementation, continuous monitoring, and vulnerability management.
... cybersecurity activities under the Risk Management Framework, including system authorization processes, security control implementation, continuous monitoring, and vulnerability management.
Bachelor's degree with 3-5 years of relevant experience (ex. cybersecurity assessments, risk management, cybersecurity policy, and compliance, etc.). An equivalent combination of education and ...
Bachelor's degree with 3-5 years of relevant experience (ex. cybersecurity assessments, risk management, cybersecurity policy, and compliance, etc.). An equivalent combination of education and ...
Bachelor's degree with 5-8 years of relevant experience (ex. cybersecurity assessments, risk management, cybersecurity policy, and compliance, etc.). An equivalent combination of education and ...
Bachelor's degree with 5-8 years of relevant experience (ex. cybersecurity assessments, risk management, cybersecurity policy, and compliance, etc.). An equivalent combination of education and ...
Cyber Security Manager (Customer Identity and Access Management)
Nashville, TN · Hybrid
$107K - $144K/yr
At Regions, the Cyber Security Manager is responsible for leading a diverse team of engineers and ... Ensures disciplined change management by evaluating risk and control impacts when designing or ...
Cyber Security Manager (Customer Identity and Access Management)
Nashville, TN · Hybrid
$107K - $144K/yr
At Regions, the Cyber Security Manager is responsible for leading a diverse team of engineers and ... Ensures disciplined change management by evaluating risk and control impacts when designing or ...
Cyber Manager - ServiceNow
Nashville, TN · On-site
$16 - $18.50/hr
... Risk Management workstreams in partnership with architects and product owners • Managing ... Required : • Bachelor's degree in Computer Science, Cyber Security, Information Security ...
Cyber Manager - ServiceNow
Nashville, TN · On-site
$16 - $18.50/hr
... Risk Management workstreams in partnership with architects and product owners • Managing ... Required : • Bachelor's degree in Computer Science, Cyber Security, Information Security ...
Cyber Manager - ServiceNow
Memphis, TN · On-site
$16 - $18.75/hr
... Risk Management workstreams in partnership with architects and product owners • Managing ... Required : • Bachelor's degree in Computer Science, Cyber Security, Information Security ...
Cyber Manager - ServiceNow
Memphis, TN · On-site
$16 - $18.75/hr
... Risk Management workstreams in partnership with architects and product owners • Managing ... Required : • Bachelor's degree in Computer Science, Cyber Security, Information Security ...
Management or participation in Cybersecurity, Information Security, Risk, Compliance and/or Data Privacy Programs or Projects * Sample projects/programs could include but are not limited to:
Management or participation in Cybersecurity, Information Security, Risk, Compliance and/or Data Privacy Programs or Projects * Sample projects/programs could include but are not limited to:
Cyber Risk Consultant
Nashville, TN · On-site
Our Cyber Risk Management team is seeking a resource to support the execution and maturation of the ... Experience with qualitative risk analysis methodologies in cybersecurity or IT environments.
Cyber Risk Consultant
Nashville, TN · On-site
Our Cyber Risk Management team is seeking a resource to support the execution and maturation of the ... Experience with qualitative risk analysis methodologies in cybersecurity or IT environments.
We are looking for candidates who are self-driven and proficient in cybersecurity, third-party risk/security management, data security and general IT risk management processes. The candidate will ...
We are looking for candidates who are self-driven and proficient in cybersecurity, third-party risk/security management, data security and general IT risk management processes. The candidate will ...
Risk Management Framework (RMF), Cyber Security Framework (CSF), NIST 800-53, Cybersecurity ... Maturity Model Certification (CMMC), NIST 800-171. Duration: Direct Hire Federal Government ...
Risk Management Framework (RMF), Cyber Security Framework (CSF), NIST 800-53, Cybersecurity ... Maturity Model Certification (CMMC), NIST 800-171. Duration: Direct Hire Federal Government ...
VP, Information Security & Risk Management
Brentwood, TN · On-site
$148K - $185K/yr
The Vice President of Information Security & Risk Management is responsible for developing ... Bachelor's degree in Cybersecurity, Information Technology, or related discipline * Certifications ...
VP, Information Security & Risk Management
Brentwood, TN · On-site
$148K - $185K/yr
The Vice President of Information Security & Risk Management is responsible for developing ... Bachelor's degree in Cybersecurity, Information Technology, or related discipline * Certifications ...
Director - Product Security
Nashville, TN · On-site +1
$225K - $235K/yr
Ensure all required cybersecurity documentation, including risk assessments and SBOMs, is prepared and submitted for premarket applications (510(k), PMA). * Manage the generation and maintenance of ...
Director - Product Security
Nashville, TN · On-site +1
$225K - $235K/yr
Ensure all required cybersecurity documentation, including risk assessments and SBOMs, is prepared and submitted for premarket applications (510(k), PMA). * Manage the generation and maintenance of ...
Risk Management: Oversee the assessment and management of cybersecurity risks associated with third-party vendors, partners, and bio-medical devices. Policy Development and Enforcement * Policy ...
Quick apply
Risk Management: Oversee the assessment and management of cybersecurity risks associated with third-party vendors, partners, and bio-medical devices. Policy Development and Enforcement * Policy ...
Cyber Security Tutor
Chattanooga, TN · Remote
$40/hr
Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk management, compliance requirements, and ethical computing practices. * Curriculum Awareness ...
Cyber Security Tutor
Chattanooga, TN · Remote
$40/hr
Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk management, compliance requirements, and ethical computing practices. * Curriculum Awareness ...
Cyber Security Tutor
Murfreesboro, TN · Remote
$40/hr
Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk management, compliance requirements, and ethical computing practices. * Curriculum Awareness ...
Cyber Security Tutor
Murfreesboro, TN · Remote
$40/hr
Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk management, compliance requirements, and ethical computing practices. * Curriculum Awareness ...
Cybersecurity Risk Management information
See Tennessee salary details
$51.7K - $62.4K
1% of jobs
$62.4K - $73K
4% of jobs
$73K - $83.7K
5% of jobs
$83.7K - $94.3K
9% of jobs
$100.2K is the 25th percentile. Wages below this are outliers.
$94.3K - $105K
11% of jobs
$105K - $115.6K
10% of jobs
The median wage is $119.7K / yr.
$115.6K - $126.2K
28% of jobs
$132.4K is the 75th percentile. Wages above this are outliers.
$126.2K - $136.9K
14% of jobs
$136.9K - $147.5K
11% of jobs
$147.5K - $158.2K
4% of jobs
$158.2K - $168.8K
4% of jobs
$51.7K
$120.7K
$168.8K
How much do cybersecurity risk management jobs pay per year?
What is the role of a risk manager in cybersecurity?
Is security risk management a good career?
What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?
What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?
| Aspect | Cybersecurity Risk Management | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government, large enterprises | IT departments, cybersecurity firms, corporate security teams |
Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.
What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?
What is cybersecurity risk management?
What is risk management in cyber security?
Can you make $500,000 a year in cyber security?

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 29 days ago
Job description
Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to NIST Risk Management Framework (RMF) Subject Matter Expert (SME) to support our clients. The RMF SME will provide expert guidance and support for implementing and maintaining compliance with NIST SP 800-53 security controls across federal systems. This role ensures adherence to the RMF lifecycle, including categorization, selection, implementation, assessment, authorization, and continuous monitoring of security controls.
BGS is an engineering, technology, and security firm helping to advance missions of national importance for government programs, national laboratories, national security facilities, nuclear operations, and complex projects. We support clients at every stage, from strategic planning and program management to the execution of engineering and technical activities. We work to attract and retain the best talent because the best talent delivers the best results for our clients. Our capabilities are based on our experience in complex, secure, and highly regulated environments. We leverage our experience and capabilities to provide mission-driven solutions tuned to our client's mission needs and strategic direction.
Work that Matters. People that Matter More. At BGS, we believe meaningful work starts with great people. We foster a culture built on respect, collaboration, and accountability—where employees are empowered to contribute ideas, grow professionally, and make an impact. We care about our employees’ well-being through competitive benefits, clear expectations, and an environment that values both excellence and connection.
If you align with BGS’ company values and culture, we would love for you to explore opportunities to join our growing team by checking out the job description below!
Responsibilities:
- Lead RMF activities for federal systems, ensuring compliance with NIST SP 800-53 and related standards.
- Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms).
- Conduct gap analyses and risk assessments to identify compliance deficiencies and recommend remediation strategies.
- Provide expert guidance on security control implementation and documentation for Authorization to Operate (ATO) packages.
- Support security audits and assessments, including preparation for FISMA and FedRAMP requirements.
- Deliver training and workshops on RMF processes and NIST SP 800-53 controls.
- Collaborate with system owners, ISSOs, and other stakeholders to ensure continuous monitoring and risk mitigation.
Requirements:
- Bachelor’s degree in Cybersecurity, Information Systems, or related field (or equivalent experience).
- Minimum 5 years of experience in cybersecurity compliance, with at least 3 years focused on RMF and NIST SP 800-53.
- Demonstrated experience developing SSPs, POA&Ms, and conducting security assessments.
- Strong understanding of NIST SP 800 series (800-53, 800-37, 800-171) and FISMA requirements.
- Professional certifications such as CISSP, CISM, CISA, or equivalent are required.
- Excellent technical writing and communication skills for compliance documentation.
Preferred Qualifications:
- ISSEP (formerly CISSP-ISSEP) certification.
- Experience with cloud security and FedRAMP controls.
- Ability to lead compliance workshops and mentor junior staff.
Location/Work Arrangement:
- This position is a Remote Work Arrangement with some travel/onsite requirements.
Benefits:
BGS offers a competitive total compensation package to eligible employees. Benefits include Health, Dental, Vision, Life Insurance, Paid Vacation, 401K, Long and Short-Term Disability.
EEO:
BGS is an Equal Opportunity/Affirmative Action employer. All qualified applicants are encouraged to apply and will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.
Exclusive Agreement Disclaimer:
BGS has standing contracts with federal agencies throughout the United States. We require an affirmative exclusive agreement to represent all candidates to our clients. By submitting this application, you are consenting to allow BGS to represent you as a candidate for the role in which you are applying.
Schedule is full-time, Monday – Friday 40-hour week.
About Boston Government Services
Sourced by ZipRecruiter
Industry
Business management consulting
Company size
51 - 200 Employees
Headquarters location
Oak Ridge, TN, US
Year founded
2007