1

Cybersecurity Risk Management Jobs in Columbia, MD

Senior Cybersecurity Engineer

Washington, DC ยท On-site

$63.96 - $105.54/hr

Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements

Ability to obtain and maintain a government security clearance if required Are you passionate about cybersecurity, risk management, and protecting critical systems from evolving threats? PEMCCO is ...

Senior Cybersecurity Engineer

Washington, DC ยท On-site

$88.11 - $145.39/hr

Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements

Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements

Showing results 41-60

Cybersecurity Risk Management information

See Columbia, MD salary details

$56.1K

$130.9K

$183.1K

How much do cybersecurity risk management jobs pay per year?

As of Aug 10, 2026, the average yearly pay for cybersecurity risk management in Columbia, MD is $130,879.00, according to ZipRecruiter salary data. Most workers in this role earn between $109,300.00 and $147,600.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.
What are popular job titles related to Cybersecurity Risk Management jobs in Columbia, MD? For Cybersecurity Risk Management jobs in Columbia, MD, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Columbia, MD look for? The top searched job categories for Cybersecurity Risk Management jobs in Columbia, MD are:
What cities near Columbia, MD are hiring for Cybersecurity Risk Management jobs? Cities near Columbia, MD with the most Cybersecurity Risk Management job openings:
Infographic showing various Cybersecurity Risk Management job openings in Columbia, MD as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, and 3% Contract. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $130,879 per year, or $62.9 per hour.

(703) Cybersecurity Information System Security Officer (ISSO)

Arlo Solutions LLC

Arlington, VA โ€ข Hybrid

Full-time

Posted 27 days ago


Job description

Position Description:

Arlo Solutions is seeking an experienced Information System Security Officer (ISSO) to support the Office of the Under Secretary of War for Acquisition & Sustainment (OUSW(A&S)). This hybrid position supports cybersecurity operations at the Pentagon and Alexandria, Virginia, providing leadership across the full DoD Risk Management Framework (RMF) lifecycle for multiple information systems supporting Controlled Unclassified Information (CUI) through classified environments. The ISSO serves as the primary cybersecurity advisor responsible for ensuring systems remain secure, compliant, and mission-ready by leading Assessment & Authorization (A&A), Continuous Monitoring (ConMon), cybersecurity governance, and risk management activities. The position requires close collaboration with Program Managers, Information System Owners, Engineers, Security Control Assessors (SCAs), Authorizing Officials (AOs), and senior Government leadership to integrate cybersecurity throughout the system lifecycle.


Location:ย 
Arlington, VA (Hybrid
Clearance:
ย Active Top Secret Security Clearance (SCI eligibility preferred)

Responsibilities and/or Success Factors:ย 

  • Serve as the ISSM for multiple DoD information systems supporting OUSW(A&S) mission requirements.
  • Lead all phases of the DoD Risk Management Framework (RMF), including system categorization, control implementation, assessment, authorization, and continuous monitoring.
  • Develop and maintain RMF authorization packages, including System Security Plans (SSPs), Security Assessment documentation, Plans of Action & Milestones (POA&Ms), Continuous Monitoring artifacts, and supporting Body of Evidence (BoE).
  • Coordinate Assessment & Authorization (A&A) activities supporting Authorization to Operate (ATO), Interim Authorization to Test (IATT), Authorization to Operate with Conditions (ATO-C), and system reauthorization.
  • Manage Continuous Monitoring (ConMon), vulnerability management, STIG compliance, security control implementation, and cybersecurity reporting.
  • Conduct cybersecurity risk assessments and provide recommendations supporting Authorizing Official (AO) risk decisions.ย 
  • Coordinate Security Control Assessments (SCAs), validate remediation activities, and ensure timely closure of assessment findings.
  • Review system architectures, authorization boundaries, data flows, and proposed changes to maintain cybersecurity compliance.ย 
  • Provide cybersecurity guidance to Government leadership, Program Managers, engineers, ISSOs, ISSEs, and system administrators.
  • Prepare executive briefings, authorization recommendations, and cybersecurity status reports for senior Government leadership.
  • Support implementation of Zero Trust Architecture (ZTA), cloud security, DevSecOps, reciprocity, inherited controls, and enterprise cybersecurity governance initiatives.

Minimum Qualifications Including Certificates:

  • Active Top Secret Security Clearance (SCI eligibility preferred)
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field (or equivalent experience)ย 
  • Minimum 8 years supporting DoD cybersecurity programs
  • Minimum 5 years supporting DoD RMF and Assessment & Authorization activities
  • Experience managing multiple RMF authorization packages and briefing senior Government leadership Excellent analytical, written, verbal, and presentation skillsย 
  • Candidates should meet applicable DoD 8140 Cyber Workforce Qualification Program requirements.

Preferred certifications include:ย 

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • CompTIA CASP+
  • Certified Cloud Security Professional (CCSP)

Desired Qualifications:

Candidates should demonstrate experience with:

DoD Risk Management Framework (RMF) and Assessment & Authorization (A&A) Continuous Monitoring (ConMon) and cybersecurity governance System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and POA&M management Security control implementation, validation, inheritance, and reciprocity Vulnerability management, STIG compliance, ACAS, and cybersecurity reporting eMASS, Xacta, or comparable Governance, Risk, and Compliance (GRC) platforms Microsoft Windows, Linux, virtualization, enterprise networking, and cloud environments supporting FedRAMP High and the DoD Cloud Computing Security Requirements Guide (SRG) Zero Trust Architecture (ZTA) and secure system engineering principles

The ideal candidate is a proactive cybersecurity leader capable of managing multiple complex DoD information systems while balancing mission requirements, cybersecurity risk, and regulatory compliance.

Success in this role requires strong leadership, technical expertise, and the ability to communicate cybersecurity risk effectively to senior Government decision-makers while enabling secure modernization and mission success through disciplined application of the DoD Risk Management Framework.