About the Team We are seeking a highly skilled Principal cybersecurity engineer to architect the development of our internal suite of Cybersecurity Risk Management and Automation tools. This role ...
About the Team We are seeking a highly skilled Principal cybersecurity engineer to architect the development of our internal suite of Cybersecurity Risk Management and Automation tools. This role ...
... Management (TPRM) capabilities, policies, governance, and operating practices ... You will work across business, technology, cybersecurity, operational resilience, legal ...
... Management (TPRM) capabilities, policies, governance, and operating practices ... You will work across business, technology, cybersecurity, operational resilience, legal ...
Technology Risk - Risk Management - Principal
Reston, VA · On-site
Medical
Life
... Management (TPRM) capabilities, policies, governance, and operating practices ... You will work across business, technology, cybersecurity, operational resilience, legal ...
Technology Risk - Risk Management - Principal
Reston, VA · On-site
Medical
Life
... Management (TPRM) capabilities, policies, governance, and operating practices ... You will work across business, technology, cybersecurity, operational resilience, legal ...
... Management (TPRM) capabilities, policies, governance, and operating practices ... You will work across business, technology, cybersecurity, operational resilience, legal ...
... Management (TPRM) capabilities, policies, governance, and operating practices ... You will work across business, technology, cybersecurity, operational resilience, legal ...
... Management (TPRM) capabilities, policies, governance, and operating practices ... You will work across business, technology, cybersecurity, operational resilience, legal ...
... Management (TPRM) capabilities, policies, governance, and operating practices ... You will work across business, technology, cybersecurity, operational resilience, legal ...
Cloud & Cyber Security Program Protection Specialist
Gainesville, VA · Hybrid
$100K - $180K/yr
Cloud & Cyber Security Program Protection Specialist - TECH#735 JOB CATEGORY: Cloud ... Security Risk Management * Security Classification Management * Critical Program Information (CPI)
Quick apply
Cloud & Cyber Security Program Protection Specialist
Gainesville, VA · Hybrid
$100K - $180K/yr
Cloud & Cyber Security Program Protection Specialist - TECH#735 JOB CATEGORY: Cloud ... Security Risk Management * Security Classification Management * Critical Program Information (CPI)
Lead Cybersecurity Risk Management by demonstrating expert knowledge of cybersecurity risk management frameworks (RMF) and methodologies * Conduct Security Controls Assessments (SCA), workshops, and ...
Lead Cybersecurity Risk Management by demonstrating expert knowledge of cybersecurity risk management frameworks (RMF) and methodologies * Conduct Security Controls Assessments (SCA), workshops, and ...
Cybersecurity Assessment and Authorization Subject Matter Expert (SME) (59788)
Fort Myer, VA · On-site +1
Medical
Dental
Vision
Retirement
Assists ISSMs and AOs with implementation of the DoD Risk Management Framework throughout the ... Cybersecurity Risk Analysis and Vulnerability Management: Analyzes security findings and ...
Cybersecurity Assessment and Authorization Subject Matter Expert (SME) (59788)
Fort Myer, VA · On-site +1
Medical
Dental
Vision
Retirement
Assists ISSMs and AOs with implementation of the DoD Risk Management Framework throughout the ... Cybersecurity Risk Analysis and Vulnerability Management: Analyzes security findings and ...
Manager, Cyber Risk & Analysis
Mclean, VA · On-site
$112K - $151K/yr
Perform technology and cybersecurity risk management requirement applicability and impact ... assessments against business, technology and cyber processes. Basic Qualifications: * High School ...
Manager, Cyber Risk & Analysis
Mclean, VA · On-site
$112K - $151K/yr
Perform technology and cybersecurity risk management requirement applicability and impact ... assessments against business, technology and cyber processes. Basic Qualifications: * High School ...
Cybersecurity Compliance Analyst (2 Positions Available)
Arlington, VA · On-site
$94K - $137K/yr
Medical
Dental
Vision
Retirement
Knowledge of cybersecurity risk management principles, security controls, and regulatory compliance practices. Experience preparing reports, maintaining compliance documentation, and tracking ...
Cybersecurity Compliance Analyst (2 Positions Available)
Arlington, VA · On-site
$94K - $137K/yr
Medical
Dental
Vision
Retirement
Knowledge of cybersecurity risk management principles, security controls, and regulatory compliance practices. Experience preparing reports, maintaining compliance documentation, and tracking ...
The ISSE will drive efforts that support software and hardware cybersecurity Risk Management Framework (RMF) Authority to Operate (ATO). LMI is a new breed of digital solutions provider dedicated to ...
The ISSE will drive efforts that support software and hardware cybersecurity Risk Management Framework (RMF) Authority to Operate (ATO). LMI is a new breed of digital solutions provider dedicated to ...
Cybersecurity Analyst
Mclean, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
The Cybersecurity Analyst will perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor. The role will ...
Cybersecurity Analyst
Mclean, VA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
The Cybersecurity Analyst will perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor. The role will ...
Cybersecurity Analyst
Medical
Dental
Vision
Life
Retirement
PTO
The Cybersecurity Analyst will perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor. The role will ...
Cybersecurity Analyst
Medical
Dental
Vision
Life
Retirement
PTO
The Cybersecurity Analyst will perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian agency as a contractor. The role will ...
Cybersecurity Engineer
Virginia Beach, VA · On-site
$100 - $115/hr
Medical
Dental
Vision
Life
Retirement
PTO
Apply the cybersecurity risk management framework (RMF) to program information systems in accordance with NIST SP 800-37 (RMF for Information Systems and Organizations) and DoDI 8510.01 (RMF for DoD ...
Cybersecurity Engineer
Virginia Beach, VA · On-site
$100 - $115/hr
Medical
Dental
Vision
Life
Retirement
PTO
Apply the cybersecurity risk management framework (RMF) to program information systems in accordance with NIST SP 800-37 (RMF for Information Systems and Organizations) and DoDI 8510.01 (RMF for DoD ...
Cybersecurity Information System Security Engineer - Clearance Required
Fort Belvoir, VA · On-site
$64.75 - $79.50/hr
The ISSE will drive efforts that support software and hardware cybersecurity Risk Management Framework (RMF) Authority to Operate (ATO). LMI is a new breed of digital solutions provider dedicated to ...
Cybersecurity Information System Security Engineer - Clearance Required
Fort Belvoir, VA · On-site
$64.75 - $79.50/hr
The ISSE will drive efforts that support software and hardware cybersecurity Risk Management Framework (RMF) Authority to Operate (ATO). LMI is a new breed of digital solutions provider dedicated to ...
The Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and Authorization (A ...
The Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and Authorization (A ...
Overview The Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and ...
Overview The Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and ...
Overview The Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and ...
Overview The Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and ...
Overview The Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and ...
Overview The Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and ...
The Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and Authorization (A ...
The Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and Authorization (A ...
Cybersecurity Risk Management information
See Virginia salary details
$56.5K - $68.1K
1% of jobs
$68.1K - $79.8K
4% of jobs
$79.8K - $91.4K
5% of jobs
$91.4K - $103K
9% of jobs
$109.4K is the 25th percentile. Wages below this are outliers.
$103K - $114.6K
11% of jobs
$114.6K - $126.3K
10% of jobs
The median wage is $130.7K / yr.
$126.3K - $137.9K
28% of jobs
$144.6K is the 75th percentile. Wages above this are outliers.
$137.9K - $149.5K
14% of jobs
$149.5K - $161.2K
11% of jobs
$161.2K - $172.8K
4% of jobs
$172.8K - $184.4K
4% of jobs
$56.5K
$131.8K
$184.4K
How much do cybersecurity risk management jobs pay per year?
What is cybersecurity risk management?
What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?
What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?
What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?
| Aspect | Cybersecurity Risk Management | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government, large enterprises | IT departments, cybersecurity firms, corporate security teams |
Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.
What are popular job titles related to Cybersecurity Risk Management jobs in Virginia?
For Cybersecurity Risk Management jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Virginia look for?
The top searched job categories for Cybersecurity Risk Management jobs in Virginia are:
What cities in Virginia are hiring for Cybersecurity Risk Management jobs?
Cities in Virginia with the most Cybersecurity Risk Management job openings:

Workday rating
7.6
Based on 12 frontline employees who took The Breakroom Quiz
155th of 245 rated software companies
Job description
Your work days are brighter here.
We're obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we're shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you'll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We're in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you'll do meaningful work with Workmates who've got your back. In return, we'll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you've found a match in Workday, and we hope to be a match for you too.
About the Team
We are seeking a highly skilled Principal cybersecurity engineer to architect the development of our internal suite of Cybersecurity Risk Management and Automation tools. This role requires a rare blend of deep domain expertise in security risk and the technical ability to bridge the gap between high-level strategy and robust software execution.As a Principle engineer, you will serve as the primary visionary for how our risk data is structured, analyzed, and automated, acting as the bridge between the Cybersecurity Risk organization and our Engineering teams.
About the Role
As a Principle engineer, you will serve as the primary visionary for how our risk data is structured, analyzed, and automated, acting as the bridge between the Cybersecurity Risk organization and our Engineering teams.
About You
Basic Qualifications
9+ Years of Experience building custom GRC (Governance, Risk, and Compliance) platforms.
Software Engineering & Development: Demonstrable proficiency in Python, Go, or Java with a strong background in version control (Git), API design, and the ability to build complex PoCs for risk models.
Full-Lifecycle Engineering Governance: Proven mastery of the end-to-end SDLC, including the creation and oversight of comprehensive SRS documentation, Project Plans, and Product Backlogs to ensure architectural alignment from initial planning through to deployment and maintenance.
Architectural & Quality Standards: Ability to define System Architectures, Data Models (ERDs), and API specifications while enforcing rigorous QA standards through formalized Test Plans, automated Build Scripts, and Production Operations manuals.
Experience leading the technical roadmap for software engineering teams or data scientists without direct reporting authority (e.g., Lead, Principal, or Staff level experience).
Technical Influence: Data & Automation Engineering: Validated proficiency in data pipeline logic, ELT/ETL processes, and data quality assurance, specifically as they apply to automating security telemetry.
Other Qualifications
Strategic Technical Translation: Architect high-level business and security "end-states" into sophisticated process designs and technical specifications. You will own the translation of risk philosophy into the logic used by our engineering squads.
Risk Domain Authority: Serve as the definitive Subject Matter Expert (SME) for defining risk metrics and calculation methodologies, specifically within:
Enterprise Risk (ERM): Designing and implementing data-driven risk frameworks (e.g., NIST, FAIR) through sophisticated automation.
Third-Party Risk (TPRM): Architecting systems for automated due diligence, continuous monitoring, and assessment scoring for our vendor ecosystem.
Cross-Functional Influence: Champion security risk automation across the organization, mentoring junior engineers and influencing stakeholders on best practices for data-driven risk modeling.
Essential Domain Knowledge
Mastery of Cybersecurity Risk: A proven track record of designing and implementing Enterprise and Third-Party Risk Management (TPRM) programs at scale.
Architectural Design: Demonstrated ability to take a blank slate and define complex security processes, translating them into technical user stories, functional specifications, and logic diagrams.
Advanced Risk Modeling: Expertise in quantitative risk analysis (e.g., Monte Carlo simulations or FAIR methodology) and how to programmatically apply these models to software.
Workday Pay Transparency Statement
The annualized base salary ranges for the primary location and any additional locations are listed below. Workday pay ranges vary based on work location. As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role-specific commission/bonus, as well as annual refresh stock grants. Recruiters can share more detail during the hiring process. Each candidate's compensation offer will be based on multiple factors including, but not limited to, geography, experience, skills, job duties, and business need, among other things. For more information regarding Workday's comprehensive benefits, please click here.
Primary Location: USA.VA.Reston
Our Approach to Flexible Work
With Flex Work, we're combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records.
Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans.
At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email accommodations@workday.com.
Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
At Workday, we value our candidates' privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.
About Workday
Sourced by ZipRecruiter
Workday's journey began with a transformative idea generated during a breakfast conversation between its founders in sunny California. What set us apart from the start was our people-centric culture, driven by the core value of prioritizing our employees. At Workday, the happiness, growth, and contributions of every team member are at the heart of who we are. Our collaborative and employee-focused culture is the key ingredient for our business success. We not only care for our people but also for the communities and the environment, all while maintaining profitability. Embrace your uniqueness, as we encourage our Workmates to shine brightly in their authentic selves. Our passion and energy make us distinct, and we are inspired to create a brighter workday for everyone.
Industry
Software development
Company size
10,000+ Employees
Headquarters location
Pleasanton, CA, US
Year founded
2005