1

Cybersecurity Risk Management Jobs in Virginia (NOW HIRING)

About the Team The Cybersecurity Risk team is responsible for cybersecurity risk assessments ... Issue and Remediation Management: Identify, document, track, and drive remediation of control gaps ...

Cybersecurity Risk Analyst Salary Range: $100,000 - $150,000 Clearance: TS/SCI + CI Poly Location ... Experience with RMF, ATO, NIST SP 800-53, continuous monitoring, vulnerability management, or SOC ...

If you are an experienced researcher with an interest in risk management and cybersecurity, we want to hear from you! As a Senior Cyber Risk Engineer, you will work directly with government, industry ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Virginia salary details

$56.5K

$131.8K

$184.4K

How much do cybersecurity risk management jobs pay per year?

As of Jul 28, 2026, the average yearly pay for cybersecurity risk management in Virginia is $131,822.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,000.00 and $148,700.00 per year, depending on experience, location, and employer.

Can I make $200,000 a year in cyber security?

Cybersecurity risk management professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and roles in senior management or specialized fields. Salary levels vary based on industry, location, and the complexity of the organization's security needs.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

How much does a cybersecurity risk analyst make?

A cybersecurity risk analyst typically earns between $70,000 and $120,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in high-demand industries.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What does a cyber risk manager do?

A cyber risk manager assesses and prioritizes cybersecurity threats to an organization, develops strategies to mitigate risks, and implements security policies. They often use tools like risk assessment frameworks and require certifications such as CISSP or CISM to effectively manage security risks and ensure compliance.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

Can you make $500,000 a year in cyber security?

Cybersecurity risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working for large organizations with complex security needs.
What are popular job titles related to Cybersecurity Risk Management jobs in Virginia? For Cybersecurity Risk Management jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Virginia look for? The top searched job categories for Cybersecurity Risk Management jobs in Virginia are:
What cities in Virginia are hiring for Cybersecurity Risk Management jobs? Cities in Virginia with the most Cybersecurity Risk Management job openings:
Infographic showing various Cybersecurity Risk Management job openings in Virginia as of July 2026, with employment types broken down into 3% Locum Tenens, 86% Full Time, 8% Part Time, and 3% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $131,822 per year, or $63.4 per hour.
Enterprise Manager, Technology & Cybersecurity Risk

Enterprise Manager, Technology & Cybersecurity Risk

Genworth Financial

Richmond, VA • Hybrid

$109K - $148K/yr

Full-time

Medical, Life, Retirement, PTO

Posted 5 days ago


Genworth Financial rating

8.5

Company rating: 8.5 out of 10

Based on 7 frontline employees who took The Breakroom Quiz

104th of 299 rated insurance


Job description

At Genworth, we empower families to navigate the aging journey with confidence. We are compassionate, experienced allies for those navigating care withguidance, products, and services that meet families where they are. Further, we are the spouses, children, siblings, friends, and neighbors of those that need care-and we bring those experiences with us to work in serving our millions of policyholders each day.

We apply that same compassion and empathy as we work with each other and our local communities. Genworth values all perspectives, characteristics, and experiences so that employees can bring their full, authentic selves to work to help each other and our company succeed. We celebrate our diversity and understand that being intentional about inclusion is the only way to create a sense of belonging for all associates. We also invest in the vitality of our local communities through grants from the Genworth Foundation, event sponsorships, and employee volunteerism.

Our four values guide our strategy, our decisions, and our interactions:

  • Make it human. We care about the people that make up our customers, colleagues, and communities.
  • Make it about others. We do what's best for our customers and collaborate to drive progress.
  • Make it happen. We work with intention toward a common purpose and forge ways forward together.
  • Make it better.We create fulfilling purpose-driven careers by learning from the world and each other.

POSITION TITLE

Enterprise Manager, Technology & Cybersecurity Risk

POSITION LOCATION

Richmond, Virginia

This position is available to Virginia residents as Richmond, Virginia in-office applicants

*A Hybrid schedule of both Remote and In-Office days is required. In office days are Tuesday, Wednesday and Thursday with working hours targeting our core business hours of 9am-5pm EST.

YOUR ROLE

The Enterprise Manager, Technology Risk & Cybersecurity Risk is a senior individual contributor responsible for leading risk identification, assessment, and mitigation activities across the organization's technology environment, with a strong emphasis on technology and cybersecurity risk management and supporting oversight of third-party risk.

This role serves as a subject matter expert in technology risk, partnering closely with Technology, Cybersecurity, and Business teams to ensure risks are effectively managed, controls are appropriately designed, and regulatory and industry expectations are met.

This role operates with minimal supervision, significant independent judgment, and cross-functional influence, contributing to enterprise risk objectives and strengthening the organization's overall risk posture.

What you will be doing

1. Technology Risk Management

  • Lead and execute enterprise-wide technology risk assessments across applications, infrastructure, cloud platforms, and data environments
  • Identify, evaluate, and prioritize risks related to system availability, security, resilience, and data integrity
  • Maintain and manage the technology risk register, including risk identification, scoring, and remediation tracking
  • Evaluate and challenge the design and effectiveness of IT general controls (ITGCs) and application controls
  • Align risk and control frameworks to industry standards (e.g., NIST, ISO 27001, COBIT, SOC 2, CIS Controls)
  • Partner with Technology and Security teams to drive control improvements and remediation of identified risk
  • Support risk appetite and tolerance definition, including development and monitoring of key risk indicators (KRIs)
  • Provide oversight and challenge to ensure risks are properly identified and managed within technology initiatives, projects, and change efforts
  • Support regulatory, audit, and compliance activities by providing documentation, evidence, and subject matter expertise
  • Monitor emerging technology risks (e.g., cloud, AI, cyber threats) and translate them into actionable mitigation strategies

2. Cybersecurity Risk Oversight

  • Lead cybersecurity risk assessments across enterprise environments (on-prem, cloud, hybrid)
  • Partner with Information Security leadership to identify and prioritize cyber risks
  • Evaluate cybersecurity controls across key domains:
    • Identity & Access Management (IAM)
    • Data protection & encryption
    • Network and endpoint security
    • Incident response capabilities
  • Assess alignment to frameworks (NIST CSF, NIST 800-53, ISO 27001/27002, CIS Controls)
  • Oversee vulnerability management, penetration testing, and remediation tracking
  • Support cyber incident readiness (tabletop exercises, post-incident reviews)
  • Evaluate risks in emerging areas (cloud, AI, ransomware, supply chain threats)
  • Monitor evolving threat landscape and regulatory expectations
  • Develop cybersecurity KRIs and executive reporting
  • Provide independent risk challenge to security initiatives and control designs
  • Contribute to AI / generative AI cybersecurity risk management

3. Risk Reporting & Insights (Supporting)

  • Develop and deliver clear, concise risk reporting for leadership, including risk summaries, key issues, and trends
  • Support development of risk dashboards and reporting artifacts, with less emphasis on building tools and more focus on interpretation and insight
  • Translate complex technology risks into business-relevant narratives for executive stakeholders.
  • Contribute to risk committee materials and presentations

4. AI Enablement

  • Leverage AI and Generative AI tools to enhance reporting, summarization, and analysis
  • Implement continuous improvement initiatives to increase efficiency and reduce cycle time
  • Support responsible use of AI by identifying and mitigating associated risks (e.g., data privacy, bias, accuracy)

What you bring

Education

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business, or a related field
  • 5+ years of experience in:
    • Technology Risk / IT Risk
    • Cybersecurity Risk
    • IT Audit / Controls
    • Risk Management / GRC
  • Strong experience conducting technology risk assessments and control evaluations
  • Familiarity with IT control frameworks and regulatory expectations

Technical & Risk Expertise

  • Deep understanding of:
    • IT General Controls (ITGCs)
    • Application controls
    • Cybersecurity principles and practices
  • Experience with frameworks such as:
  • NIST, ISO 27001, COBIT, SOC 2, CIS Controls
  • Strong understanding of risk identification, assessment, and mitigation methodologies

Communication Skills

  • Ability to clearly communicate technical risks to non-technical stakeholders
  • Strong written and verbal communication skills
  • Experience preparing executive-level risk summaries and presentations

Nice to have

  • Professional certifications such as:
    • CISA, CRISC, CISM, CISSP
  • Experience with GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust)
  • Experience in cloud risk management (AWS, Azure, GCP)
  • Background in internal audit or regulatory compliance
  • Exposure to third-party risk management frameworks and practices

Employee Benefits & Well-Being

Genworth employees make a difference in people's lives every day. We're committed to making a difference in our employees' lives.

  • Competitive Compensation & Total Rewards Incentives
  • Comprehensive Healthcare Coverage
  • Multiple 401(k) Savings Plan Options
  • Auto Enrollment in Employer-Directed Retirement Account Feature (100% employer-funded!)
  • Generous Paid Time Off - Including 12 Paid Holidays, Volunteer Time Off and Paid Family Leave
  • Disability, Life, and Long Term Care Insurance
  • Tuition Reimbursement, Student Loan Repayment and Training & Certification Support
  • Wellness support including gym membership reimbursement and Employee Assistance Program resources (work/life support, financial & legal management)
  • Caregiver and Mental Health Support Services

ADDITIONAL

  • At this time, Genworth will not sponsor a new applicant for employment authorization for this position.

National Range: $109,000 - $169,000

Disclaimer: This role is aligned to a national market-based pay range. Actual compensation will vary based on geographic location, experience, skills, and other job-related factors. In addition to base salary, this role is eligible to participate in a bonus incentive plan. Incentive compensation is based on individual and company performance and is not guaranteed.


What Genworth Financial employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom