1

Cybersecurity Risk Management Jobs in Virginia (NOW HIRING)

... risk management process and cybersecurity tools used in DoD environments • Knowledge of governance, risk, and compliance strategies and tools • HBSS or ACAS Certification • AWS Certifications ...

Cybersecurity Director

Arlington, VA

$127K - $172K/yr

Active Secret As a Cybersecurity Director, you will serve as a senior leader responsible for ... This role combines deep expertise in cyber governance, risk management, and compliance with ...

Program Risk Manager

Herndon, VA · On-site

$86K - $138K/yr

Master's degree in relevant field (e.g., Risk Management, Cybersecurity, Systems Engineering, Business Administration); OR * PMI-RMP or ISACA CRISC certification. * Experience: Progressive risk ...

Program Risk Manager

Herndon, VA · On-site

$86K - $138K/yr

Master's degree in relevant field (e.g., Risk Management, Cybersecurity, Systems Engineering, Business Administration); OR * PMIRMP or ISACA CRISC certification. * Experience: Progressive risk ...

Master's degree in relevant field (e.g., Risk Management, Cybersecurity, Systems Engineering, Business Administration); OR * PMIRMP or ISACA CRISC certification. * Experience: Progressive risk ...

Identify, analyze, and document cybersecurity risks across FAA systems and modernization initiatives. * Support Risk Management Framework (RMF) activities, including risk assessments, control ...

Identify, analyze, and document cybersecurity risks across FAA systems and modernization initiatives. * Support Risk Management Framework (RMF) activities, including risk assessments, control ...

Sr. Analyst, Cybersecurity

Richmond, VA · On-site

$99K - $127K/yr

You will work with senior risk management and technology professionals to design and facilitate cybersecurity risk assessments on existing technology, processes to accommodate new business areas as ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Virginia salary details

$56.5K

$131.8K

$184.4K

How much do cybersecurity risk management jobs pay per year?

As of Jun 30, 2026, the average yearly pay for cybersecurity risk management in Virginia is $131,822.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,000.00 and $148,700.00 per year, depending on experience, location, and employer.

What is the role of a risk manager in cybersecurity?

A cybersecurity risk manager identifies, assesses, and prioritizes security risks to an organization’s information systems. They develop strategies to mitigate threats, implement security controls, and ensure compliance with industry standards, often using tools like risk assessment frameworks and security audits. Their role is essential in protecting digital assets and supporting overall cybersecurity posture.

Is security risk management a good career?

Security risk management is a valuable career in cybersecurity, focusing on identifying and mitigating threats to organizational assets. It often requires knowledge of security frameworks, risk assessment tools, and certifications like CISSP or CISM. The field offers strong job growth, competitive salaries, and opportunities across various industries.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What is risk management in cyber security?

In cybersecurity risk management, professionals identify, assess, and prioritize potential security threats to an organization’s information systems. They implement strategies and controls to mitigate or accept risks, often using frameworks like NIST or ISO 27001, and may hold certifications such as CISSP or CISM to ensure effective risk handling.

Can you make $500,000 a year in cyber security?

Cybersecurity risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working in large organizations with complex security needs.
What are popular job titles related to Cybersecurity Risk Management jobs in Virginia? For Cybersecurity Risk Management jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Virginia look for? The top searched job categories for Cybersecurity Risk Management jobs in Virginia are:
What cities in Virginia are hiring for Cybersecurity Risk Management jobs? Cities in Virginia with the most Cybersecurity Risk Management job openings:
Infographic showing various Cybersecurity Risk Management job openings in Virginia as of June 2026, with employment types broken down into 1% As Needed, 83% Full Time, 6% Part Time, 2% Temporary, 7% Contract, and 1% Nights. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $131,822 per year, or $63.4 per hour.
Enterprise Cybersecurity AI Risk Analyst

Enterprise Cybersecurity AI Risk Analyst

Booz Allen Hamilton, Inc.

Mclean, VA • On-site

Full-time

Medical, Life, Retirement, PTO

Posted 6 days ago


Booz Allen Hamilton rating

8.8

Company rating: 8.8 out of 10

Based on 47 frontline employees who took The Breakroom Quiz

9th of 58 rated business consultants


Job description

Enterprise Cybersecurity AI Risk Analyst
The Opportunity:
Cyber threats are everywhere, and the rapid evolution of artificial intelligence is changing how organizations evaluate technology, data, third-party services, and business risk. In all of this cyber and AI noise, how can teams understand the risks clearly enough to make safe, practical decisions? The answer is you, an information security risk specialist who can help break down emerging AI risk into clear, manageable actions.
As an AI Cyber Risk Analyst on our Enterprise IT and Cyber Risk team, you'll support the safe, risk-informed adoption of artificial intelligence across the organization. You'll review AI tools, platforms, AI-enabled products, generative AI use cases, automation, machine learning-enabled capabilities, and third-party AI integrations to identify cyber, technology, compliance, and operational risk. You'll work across technical and non-technical teams to understand how AI is being used, evaluate applicable policies and control expectations, and document risk decisions in a clear and defensible way.
You'll translate complex AI and cybersecurity concepts into concise business impact statements, risk summaries, and leadership-ready reporting. You'll also help mature the enterprise AI cyber risk review process by contributing to scalable templates, consistent criteria, repeatable practices, and trend reporting that highlights recurring control gaps. This is your opportunity to serve as a key operator in a developing, high-visibility AI risk program while broadening your skills in AI governance, emerging technology risk, cybersecurity, and enterprise risk management.
Work with us as we protect the enterprise while enabling responsible AI adoption. Due to the nature of work performed within this facility, U.S. citizenship is required.
Join us. The world can't wait.
You Have:
  • 5+ years of experience supporting cyber, technology, product, or enterprise risk activities, including risk identification, risk assessment, control evaluation, issue documentation, risk reporting, or lifecycle management
  • Experience with GRC practices, including policy alignment, control expectations, exception handling, risk acceptance, issue tracking, audit or compliance support, or risk governance routines
  • Knowledge of artificial intelligence concepts, AI-enabled tools, generative or agentic AI, machine learning-enabled capabilities, or AI product and use case evaluation
  • Knowledge of industry-standard cybersecurity, privacy, AI, or risk frameworks, including NIST CSF, NIST AI RMF, NIST SP 800-53, NIST SP 800-171, ISO 27001, ISO 42001, MITRE ATLAS, or CMMC
  • Ability to write clear, concise, executive-ready risk summaries, and translate complex technical or emerging technology concepts into business impact
  • Ability to work across technical and non-technical teams with a collaborative, customer-service-oriented mindset
  • Ability to independently manage assigned workstreams, prioritize competing demands, follow through on deliverables, and operate effectively in a developing or evolving risk management environment
  • HS diploma or GED

Nice if You Have:
  • Experience reviewing AI tools, generative AI use cases, AI-enabled products, automation, machine learning models, or emerging technology initiatives for cyber, privacy, compliance, operational, or business risk
  • Experience supporting AI governance, responsible AI, model risk, product risk, supplier or third-party risk, security architecture review, privacy review, or technology risk review processes
  • Experience with GRC or workflow platforms, including ServiceNow, Archer, Smartsheet, or Jira
  • Knowledge of common AI risk themes, including sensitive data exposure, prompt or input risk, output reliability, unauthorized use, model or tool access, third-party AI services, intellectual property considerations, monitoring, and human oversight
  • Knowledge of defense industrial base, federal, regulated, or compliance-driven environments
  • Ability to develop process documentation, risk review templates, control checklists, decision trees, dashboards, or reporting materials
  • Ability to mentor junior team members, coordinate across matrixed teams, or improve operational consistency within a developing program
  • Bachelor's degree
  • Cybersecurity, risk, privacy, AI governance, or cloud Certification, including CISSP, CGRC, CRISC, CISA, Security+, AWS, Azure Certification

Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.
Identity Statement
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Candidate AI Usage Policy
AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.
Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.

Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

What Booz Allen Hamilton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Booz Allen Hamilton logo

About Booz Allen Hamilton

Sourced by ZipRecruiter

Booz Allen Hamilton is a leading provider of management and technology consulting services to the US government in defense, intelligence, and civil markets. Headquartered in McLean, Virginia, the firm also serves major corporations, institutions, and not-for-profit organizations. Founded in 1914 by Edwin G. Booz, the company has a long-standing tradition of helping clients achieve success by delivering a wide range of consulting services that include strategic planning, human capital and learning, communication, systems development, and others. The company's mission is to empower people to change the world, and it has a reputation for maintaining the highest standards of integrity and-excellence.

Industry

It services

Company size

10,000+ Employees

Headquarters location

McLean, VA, US

Year founded

1914