1

Cybersecurity Risk Management Jobs in Washington

About the Team We are seeking a highly skilled Principal cybersecurity engineer to architect the development of our internal suite of Cybersecurity Risk Management and Automation tools. This role ...

About the Team We are seeking a highly skilled Principal cybersecurity engineer to architect the development of our internal suite of Cybersecurity Risk Management and Automation tools. This role ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Washington salary details

$64.6K

$150.6K

$210.7K

How much do cybersecurity risk management jobs pay per year?

As of Jun 1, 2026, the average yearly pay for cybersecurity risk management in Washington is $150,592.00, according to ZipRecruiter salary data. Most workers in this role earn between $125,700.00 and $169,900.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are popular job titles related to Cybersecurity Risk Management jobs in Washington? For Cybersecurity Risk Management jobs in Washington, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Washington look for? The top searched job categories for Cybersecurity Risk Management jobs in Washington are:
What cities in Washington are hiring for Cybersecurity Risk Management jobs? Cities in Washington with the most Cybersecurity Risk Management job openings:
Sr. Manager, Information Technology and Information Security Risk

Sr. Manager, Information Technology and Information Security Risk

Tier4 Group

Reston, VA โ€ข On-site

Full-time

Posted 4 days ago


Job description

Sr. Manager, Information Technology and Information Security Risk
Hybrid Work Schedule- 3 days onsite in Reston, VA

SUMMARY OF POSITION:

The Information Technology and Information Security Risk (IT/IS) Sr. Manager plays a critical enterprise-wide role in overseeing cybersecurity, technology, data, AI and information security risk governance. This role partners with the Chief Risk Officer (CRO) and the Enterprise Risk Management team in identifying, assessing, and monitoring the organizationโ€™s technology and cybersecurity risk profile to ensure alignment with the our clientโ€™s strategic objectives, risk appetite, and regulatory expectations.
This role has broad ownership and visibility across the enterprise and serves as a key second-line risk partner to senior leadership, business lines, IT, Information Security, Compliance, and third-party vendors. The Senior Manager will help ensure adherence to regulatory expectations from agencies such as FHFA, FFIEC, OCC, FDIC, SEC, and FINRA. This person will partner with business lines, IT, and compliance teams to maintain a strong security posture and reduce exposure across critical financial systems and third-party relationships, strengthening the organizationโ€™s overall cyber resilience and operational risk management framework.

Core Responsibilities

  • Evaluate and provide independent challenge regarding the alignments of the organizationโ€™s IT and IS strategy with enterprise business objectives, risk appetite, and regulatory expectations.
  • Review and assess the adequacy of information technology and security risk assessments across applications, infrastructure, and business processes.
  • Partner with IT project teams to influence decisions related to technology architecture, cybersecurity controls, system implementations, and operational risk mitigation strategies
  • Evaluate new and existing systems, platforms, and SAAS integrations for cybersecurity risks and regulatory compliance impacts.
  • Conduct third party and vendor security risk assessments, including review of SOC 1/SOC 2 reports, SIG questionnaires, penetration testing results, and remediation plans to ensure vendor information security practices align with OF expectations.
  • Provide effective second-line oversight and credible challenge related to cybersecurity incidents, operational disruptions, and emerging technology risks, including analysis of potential impacts to customer data, financial systems, and regulatory obligations.
  • Collaborate with business units and technology teams to identify, document, and monitor risks, ensuring remediation activities meet regulatory timelines and internal risk appetite.
  • Oversee the implementation of information technology and security risk management policies and the Cyber-Security Incident Response Plan
  • Conduct cyber security awareness training and education through periodic email phishing tests, in-person and computer-based training, presentations to employees, and security related tabletop exercises.
  • Monitor the status of remediation for IT and IS related issues and ensure that the remediation documentation is complete and adequate.
  • Monitor cybersecurity and financial sector threat intelligence; communicate emerging risks to leadership.
  • Oversee IT and IS key risk indicators (KRIs) and maintain clear and accurate dashboards and reporting metrics for senior management, risk committees, and regulators
  • Ability to analyze complex technical environments and communicate risk in business-focused terms.
  • Strong knowledge of information security frameworks including NIST CSF, NIST 800โ€‘53, ISO 27001, CIS Controls.
  • Effective communication skills for interacting with auditors, examiners, and senior management.

PREFERRED SKILLS AND EXPERIENCE:

  • Bachelorโ€™s degree in Information Security, Cybersecurity, Risk Management, or related fields (or equivalent work experience) preferred.
  • 8โ€“10 years of relevant experience in information security or risk management roles with experience in financial services, banking, payments, fintech, or related regulatory environments preferred.
  • Experience with data analytics and visualization tools (e.g., Power BI, Tableau, or Python).
  • Experience working in a regulated financial services or technology environment.
  • CRISC, CISSP, CISM, Security+ or CGEIT or similar certifications