1

Cybersecurity Risk Management Jobs in Virginia (NOW HIRING)

About the Team We are seeking a highly skilled Principal cybersecurity engineer to architect the development of our internal suite of Cybersecurity Risk Management and Automation tools. This role ...

This support includes, but is not limited to, cybersecurity solutions (including network, operating ... Experience leading risk management efforts to achieve and maintain authorization for systems using ...

Risk Management Lead

Fort Belvoir, VA · On-site

$131K - $237K/yr

This support includes, but is not limited to, cybersecurity solutions (including network, operating ... Experience leading risk management efforts to achieve and maintain authorization for systems using ...

Risk Management Lead

Fort Belvoir, VA · On-site

$131K - $237K/yr

This support includes, but is not limited to, cybersecurity solutions (including network, operating ... Experience leading risk management efforts to achieve and maintain authorization for systems using ...

Manager, Cyber Risk & Analysis

Mclean, VA · On-site

$112K - $151K/yr

Perform technology and cybersecurity risk management requirement applicability and impact ... assessments against business, technology and cyber processes. Basic Qualifications: * High School ...

Manager, Cyber Risk & Analysis

Mclean, VA

$112K - $151K/yr

Perform technology and cybersecurity risk management requirement applicability and impact ... assessments against business, technology and cyber processes. Basic Qualifications: * High School ...

Interest in cybersecurity, risk management, governance, and controls. * Collaborative team player who can work across multiple stakeholders and teams. Information collected and processed through your ...

Active Secret As a Cybersecurity Director, you will serve as a senior leader responsible for ... This role combines deep expertise in cyber governance, risk management, and compliance with ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Virginia salary details

$56.5K

$131.8K

$184.4K

How much do cybersecurity risk management jobs pay per year?

As of Jun 30, 2026, the average yearly pay for cybersecurity risk management in Virginia is $131,822.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,000.00 and $148,700.00 per year, depending on experience, location, and employer.

What is the role of a risk manager in cybersecurity?

A cybersecurity risk manager identifies, assesses, and prioritizes security risks to an organization’s information systems. They develop strategies to mitigate threats, implement security controls, and ensure compliance with industry standards, often using tools like risk assessment frameworks and security audits. Their role is essential in protecting digital assets and supporting overall cybersecurity posture.

Is security risk management a good career?

Security risk management is a valuable career in cybersecurity, focusing on identifying and mitigating threats to organizational assets. It often requires knowledge of security frameworks, risk assessment tools, and certifications like CISSP or CISM. The field offers strong job growth, competitive salaries, and opportunities across various industries.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What is risk management in cyber security?

In cybersecurity risk management, professionals identify, assess, and prioritize potential security threats to an organization’s information systems. They implement strategies and controls to mitigate or accept risks, often using frameworks like NIST or ISO 27001, and may hold certifications such as CISSP or CISM to ensure effective risk handling.

Can you make $500,000 a year in cyber security?

Cybersecurity risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working in large organizations with complex security needs.
What are popular job titles related to Cybersecurity Risk Management jobs in Virginia? For Cybersecurity Risk Management jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Virginia look for? The top searched job categories for Cybersecurity Risk Management jobs in Virginia are:
What cities in Virginia are hiring for Cybersecurity Risk Management jobs? Cities in Virginia with the most Cybersecurity Risk Management job openings:
Infographic showing various Cybersecurity Risk Management job openings in Virginia as of June 2026, with employment types broken down into 1% As Needed, 83% Full Time, 6% Part Time, 2% Temporary, 7% Contract, and 1% Nights. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $131,822 per year, or $63.4 per hour.
Cyber Security Project Engineer - TS/SCI w/Polygraph

Cyber Security Project Engineer - TS/SCI w/Polygraph

GDIT

Mclean, VA • On-site

$152K - $205K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago


Key responsibilities

  • Identify, analyze, and respond to security incidents across enterprise and cloud environments.

  • Lead and support enterprise-wide incident response activities, including coordination within cloud environments.

  • Conduct intrusion analysis, forensic collection, malware investigation, and produce incident reports for technical and nontechnical audiences.


General Dynamics Information Technology rating

7.8

Company rating: 7.8 out of 10

Based on 63 frontline employees who took The Breakroom Quiz

71st of 207 rated it services


Job description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Top Secret SCI + Polygraph

Clearance Level Must Be Able to Obtain:

Top Secret SCI + Polygraph

Public Trust/Other Required:

None

Job Family:

Cyber and IT Risk Management

Job Qualifications:

Skills:

Cybersecurity Risk Management, Documentations, Information Assurance

Certifications:

None

Experience:

8 + years of related experience

US Citizenship Required:

Yes

Job Description:

Seize your opportunity to make a personal impact as a Cyber Security Project Engineer supporting customer activities. GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding career.

At GDIT, people are our differentiator. As a Cyber Security Project Engineer , you will help ensure today is safe and tomorrow is smarter. Our work depends on an Cyber Security Project Engineer joining our highly skilled team to be a premier provider of cyber security services to the customer. We provide consummate cyber security risk management "as a service" platform across multiple fabrics and centers. We have responsibility to ensure operational IT capabilities provide the client with necessary timeliness, accuracy and security of information demanded from all our highly professional roles. Be the change, lead our change - join us!

HOW A CYBER SECURITY PROJECT ENGINEER WILL MAKE AN IMPACT:

The Cyber Security Project Engineeris responsible for identifying, analyzing, and responding to security incidents across enterprise and cloud environments. This role involves intrusion analysis, forensic collection, malware investigation, and coordination with cyber defense teams to mitigate threats and strengthen the organization's security posture.

  • Incident Response & Coordination
    • Lead and support enterprise-wide incident response activities.
    • Coordinate incident response functions within cloud environments.
    • Produce afteraction reviews and incident reports for technical and nontechnical audiences.
  • Threat Detection & Analysis
    • Collect and analyze intrusion artifacts to support mitigation efforts.
    • Receive, triage, and investigate network alerts from multiple sources.
    • Monitor external threat intelligence to assess potential enterprise impact.
    • Perform cyber defense trend analysis and reporting.
  • Forensics & Evidence Handling
    • Conduct initial, forensically sound image collection and analysis.
    • Preserve evidence integrity in accordance with standards and procedures.
  • Documentation & Knowledge Sharing
    • Develop and publish cyber defense techniques, guidance, and incident findings.
    • Contribute to enterprise knowledge bases and security best practices.

WHAT YOU'LL NEED TO SUCCEED:

  • Education: Bachelors (Computer engineering, Computer Science, Electrical Engineering, Information systems, Information Technology, Cybersecurity, or a closely related discipline)
  • Required Experience: 8+ yrs
  • Required Technical Skills:
  • Incident Response & Cyber Defense
    • Incident response methodologies, categories, and timelines.
    • Cyber defense policies and procedures.
    • Ability to perform damage assessments and determine remediation paths.
  • Threat Detection & Intrusion Analysis
    • Intrusion detection methodologies for host and network environments.
    • Experience using security event correlation tools.
    • Understanding of attack classes, attack stages, and adversary behaviors.
  • Malware & Vulnerability Analysis
    • Malware analysis concepts and containment techniques.
    • Ability to identify, capture, contain, and report malware.
    • Skill in recognizing and categorizing vulnerabilities and associated attacks.
  • Network & System Security
    • Knowledge of network security architecture, topology, and communication principles.
    • Understanding of network protocols (TCP/IP, DHCP, DNS, directory services).
    • Familiarity with network services, interactions, and secure communications.
    • Knowledge of system administration, OS hardening, and application security threats.
  • Cloud Security
    • Understanding of cloud service models and how they affect incident response capabilities.
  • Security Clearance Level: TS/SCI with active polygraph
  • Required Certifications: One of - CEH(P, ECIH, GRID, RCCE Level 1, CBROPS, CCSP, CEH, Cloud+, FITSP-O, GCED, GCIH, GSEC, PenTest+, Security+
  • Preferred Certifications: Board certified in relevant security programs (e.g., CISSP, CISM, CISA, CEH, NCSF, CAP); Professional certifications in cloud technologies - Amazon and Microsoft Azure; Understanding of FISMA
  • Location: McLean, VA - On Customer Site

GDIT IS YOUR PLACE:

  • 401K with company match
  • Comprehensive health and wellness packages
  • Internal mobility team dedicated to helping you own your career
  • Professional growth opportunities including paid education and certifications
  • Cutting-edge technology you can learn from
  • Rest and recharge with paid vacation and holidays

#WeAreGDIT
#JET
#GDITEnhanced2026
#VA_2026Alumni

The likely salary range for this position is $152,113 - $205,799. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Onsite

Work Location:

USA VA McLean

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:

We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

What General Dynamics Information Technology employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


General Dynamics Information Technology logo

About General Dynamics Information Technology

Sourced by ZipRecruiter

GDIT is a global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense, and intelligence community. Its 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. The company operates across 50+ countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber, and application development.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Falls Church, VA, US