Lead all phases of the DoD Risk Management Framework (RMF), including system categorization ... Conduct cybersecurity risk assessments and provide recommendations supporting Authorizing Official ...
Lead all phases of the DoD Risk Management Framework (RMF), including system categorization ... Conduct cybersecurity risk assessments and provide recommendations supporting Authorizing Official ...
Senior Cybersecurity Engineer
Washington, DC ยท On-site
$63.96 - $105.54/hr
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
Quick apply
Senior Cybersecurity Engineer
Washington, DC ยท On-site
$63.96 - $105.54/hr
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
At least 10 years of experience with Technology or Cyber Security Risk Management * At least 10 years of experience building control environments * At least 10 years of experience in People ...
At least 10 years of experience with Technology or Cyber Security Risk Management * At least 10 years of experience building control environments * At least 10 years of experience in People ...
Cybersecurity Risk Analyst (McLean, VA)
Mclean, VA ยท On-site
$100K - $150K/yr
Cybersecurity Risk Analyst Salary Range: $100,000 - $150,000 Clearance: TS/SCI + CI Poly Location ... Experience with RMF, ATO, NIST SP 800-53, continuous monitoring, vulnerability management, or SOC ...
Cybersecurity Risk Analyst (McLean, VA)
Mclean, VA ยท On-site
$100K - $150K/yr
Cybersecurity Risk Analyst Salary Range: $100,000 - $150,000 Clearance: TS/SCI + CI Poly Location ... Experience with RMF, ATO, NIST SP 800-53, continuous monitoring, vulnerability management, or SOC ...
Cybersecurity Engineer
Washington, DC ยท On-site
Ability to obtain and maintain a government security clearance if required Are you passionate about cybersecurity, risk management, and protecting critical systems from evolving threats? PEMCCO is ...
Quick apply
Cybersecurity Engineer
Washington, DC ยท On-site
Ability to obtain and maintain a government security clearance if required Are you passionate about cybersecurity, risk management, and protecting critical systems from evolving threats? PEMCCO is ...
You'll partner with vulnerability management, cyber architecture and engineering, hosting, network ... Certifications in cybersecurity, risk, cloud, vulnerability management, or ServiceNow, including ...
You'll partner with vulnerability management, cyber architecture and engineering, hosting, network ... Certifications in cybersecurity, risk, cloud, vulnerability management, or ServiceNow, including ...
At least 10 years of experience with Technology or Cyber Security Risk Management * At least 10 years of experience building control environments * At least 10 years of experience in People ...
At least 10 years of experience with Technology or Cyber Security Risk Management * At least 10 years of experience building control environments * At least 10 years of experience in People ...
Senior Cybersecurity Engineer
Washington, DC ยท On-site
$88.11 - $145.39/hr
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
Senior Cybersecurity Engineer
Washington, DC ยท On-site
$88.11 - $145.39/hr
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
Digital Risk Advisory & Cybersecurity Associate Attorney
Washington, DC ยท On-site
$245K - $345K/yr
Counsel clients on privacy, cybersecurity, regulatory compliance, and enterprise risk management matters. * Conduct cybersecurity risk assessments and assist clients in strengthening cybersecurity ...
Quick apply
Digital Risk Advisory & Cybersecurity Associate Attorney
Washington, DC ยท On-site
$245K - $345K/yr
Counsel clients on privacy, cybersecurity, regulatory compliance, and enterprise risk management matters. * Conduct cybersecurity risk assessments and assist clients in strengthening cybersecurity ...
Cyber Security Assessment & Authorization SME
Vienna, VA ยท On-site
$105K - $125K/yr
Expert knowledge of the Department of Defense (DoD) Risk Management Framework (RMF), Assessment and Authorization (A&A) processes, and applicable DoD, DLA, and NIST cybersecurity policies and ...
Cyber Security Assessment & Authorization SME
Vienna, VA ยท On-site
$105K - $125K/yr
Expert knowledge of the Department of Defense (DoD) Risk Management Framework (RMF), Assessment and Authorization (A&A) processes, and applicable DoD, DLA, and NIST cybersecurity policies and ...
Framework Knowledge: Strong working knowledge of federal cybersecurity and risk management ... frameworks, specifically NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) and ...
Framework Knowledge: Strong working knowledge of federal cybersecurity and risk management ... frameworks, specifically NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) and ...
Cyber Security Assessment & Authorization SME
Vienna, VA ยท Remote
$105K - $125K/yr
... and the Risk Management Framework (RMF). They execute cybersecurity authorization processes to ... obtain and maintain system authorizations while providing expert guidance to stakeholders ...
Quick apply
Cyber Security Assessment & Authorization SME
Vienna, VA ยท Remote
$105K - $125K/yr
... and the Risk Management Framework (RMF). They execute cybersecurity authorization processes to ... obtain and maintain system authorizations while providing expert guidance to stakeholders ...
... chain management, e-commerce solutions, and B2B public exchanges and B2B process integration ... Responsible for developing and executing risk mitigation concepts, plans and services used to ...
... chain management, e-commerce solutions, and B2B public exchanges and B2B process integration ... Responsible for developing and executing risk mitigation concepts, plans and services used to ...
Senior Cybersecurity & Compliance Advisor
Washington, DC ยท On-site
$113K - $146K/yr
Apogee is seeking an experienced Senior Cybersecurity & Compliance Advisor to provide cybersecurity governance, risk management, and compliance guidance supporting a federal simulation and analytics ...
Quick apply
Senior Cybersecurity & Compliance Advisor
Washington, DC ยท On-site
$113K - $146K/yr
Apogee is seeking an experienced Senior Cybersecurity & Compliance Advisor to provide cybersecurity governance, risk management, and compliance guidance supporting a federal simulation and analytics ...
Senior Cybersecurity & Compliance Advisor
Washington, DC ยท On-site
$113K - $146K/yr
Apogee is seeking an experienced Senior Cybersecurity & Compliance Advisor to provide cybersecurity governance, risk management, and compliance guidance supporting a federal simulation and analytics ...
Senior Cybersecurity & Compliance Advisor
Washington, DC ยท On-site
$113K - $146K/yr
Apogee is seeking an experienced Senior Cybersecurity & Compliance Advisor to provide cybersecurity governance, risk management, and compliance guidance supporting a federal simulation and analytics ...
Senior Cybersecurity & Compliance Advisor
Washington, DC ยท On-site
$113K - $146K/yr
Apogee is seeking an experienced Senior Cybersecurity & Compliance Advisor to provide cybersecurity governance, risk management, and compliance guidance supporting a federal simulation and analytics ...
Senior Cybersecurity & Compliance Advisor
Washington, DC ยท On-site
$113K - $146K/yr
Apogee is seeking an experienced Senior Cybersecurity & Compliance Advisor to provide cybersecurity governance, risk management, and compliance guidance supporting a federal simulation and analytics ...
Senior Cybersecurity Engineer
Washington, DC ยท On-site
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
Quick apply
Senior Cybersecurity Engineer
Washington, DC ยท On-site
Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities * Review system architectures, designs, and configurations to ensure compliance with cybersecurity requirements
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC ยท On-site +1
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC ยท On-site +1
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC ยท Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC ยท Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC ยท Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC ยท Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Cybersecurity Risk Management information
See Columbia, MD salary details
$56.1K - $67.7K
1% of jobs
$67.7K - $79.2K
4% of jobs
$79.2K - $90.7K
5% of jobs
$90.7K - $102.3K
9% of jobs
$108.6K is the 25th percentile. Wages below this are outliers.
$102.3K - $113.8K
11% of jobs
$113.8K - $125.4K
10% of jobs
The median wage is $129.8K / yr.
$125.4K - $136.9K
28% of jobs
$143.6K is the 75th percentile. Wages above this are outliers.
$136.9K - $148.5K
14% of jobs
$148.5K - $160K
11% of jobs
$160K - $171.5K
4% of jobs
$171.5K - $183.1K
4% of jobs
$56.1K
$130.9K
$183.1K
How much do cybersecurity risk management jobs pay per year?
What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?
What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?
| Aspect | Cybersecurity Risk Management | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government, large enterprises | IT departments, cybersecurity firms, corporate security teams |
Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.
What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?
What is cybersecurity risk management?

(703) Cybersecurity Information System Security Officer (ISSO)
Arlington, VA โข Hybrid
Full-time
Posted 27 days ago
Job description
Position Description:
Arlo Solutions is seeking an experienced Information System Security Officer (ISSO) to support the Office of the Under Secretary of War for Acquisition & Sustainment (OUSW(A&S)). This hybrid position supports cybersecurity operations at the Pentagon and Alexandria, Virginia, providing leadership across the full DoD Risk Management Framework (RMF) lifecycle for multiple information systems supporting Controlled Unclassified Information (CUI) through classified environments. The ISSO serves as the primary cybersecurity advisor responsible for ensuring systems remain secure, compliant, and mission-ready by leading Assessment & Authorization (A&A), Continuous Monitoring (ConMon), cybersecurity governance, and risk management activities. The position requires close collaboration with Program Managers, Information System Owners, Engineers, Security Control Assessors (SCAs), Authorizing Officials (AOs), and senior Government leadership to integrate cybersecurity throughout the system lifecycle.
Location:ย Arlington, VA (Hybrid
Clearance: ย Active Top Secret Security Clearance (SCI eligibility preferred)
Responsibilities and/or Success Factors:ย
- Serve as the ISSM for multiple DoD information systems supporting OUSW(A&S) mission requirements.
- Lead all phases of the DoD Risk Management Framework (RMF), including system categorization, control implementation, assessment, authorization, and continuous monitoring.
- Develop and maintain RMF authorization packages, including System Security Plans (SSPs), Security Assessment documentation, Plans of Action & Milestones (POA&Ms), Continuous Monitoring artifacts, and supporting Body of Evidence (BoE).
- Coordinate Assessment & Authorization (A&A) activities supporting Authorization to Operate (ATO), Interim Authorization to Test (IATT), Authorization to Operate with Conditions (ATO-C), and system reauthorization.
- Manage Continuous Monitoring (ConMon), vulnerability management, STIG compliance, security control implementation, and cybersecurity reporting.
- Conduct cybersecurity risk assessments and provide recommendations supporting Authorizing Official (AO) risk decisions.ย
- Coordinate Security Control Assessments (SCAs), validate remediation activities, and ensure timely closure of assessment findings.
- Review system architectures, authorization boundaries, data flows, and proposed changes to maintain cybersecurity compliance.ย
- Provide cybersecurity guidance to Government leadership, Program Managers, engineers, ISSOs, ISSEs, and system administrators.
- Prepare executive briefings, authorization recommendations, and cybersecurity status reports for senior Government leadership.
- Support implementation of Zero Trust Architecture (ZTA), cloud security, DevSecOps, reciprocity, inherited controls, and enterprise cybersecurity governance initiatives.
Minimum Qualifications Including Certificates:
- Active Top Secret Security Clearance (SCI eligibility preferred)
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field (or equivalent experience)ย
- Minimum 8 years supporting DoD cybersecurity programs
- Minimum 5 years supporting DoD RMF and Assessment & Authorization activities
- Experience managing multiple RMF authorization packages and briefing senior Government leadership Excellent analytical, written, verbal, and presentation skillsย
- Candidates should meet applicable DoD 8140 Cyber Workforce Qualification Program requirements.
Preferred certifications include:ย
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- CompTIA CASP+
- Certified Cloud Security Professional (CCSP)
Desired Qualifications:
Candidates should demonstrate experience with:
DoD Risk Management Framework (RMF) and Assessment & Authorization (A&A) Continuous Monitoring (ConMon) and cybersecurity governance System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and POA&M management Security control implementation, validation, inheritance, and reciprocity Vulnerability management, STIG compliance, ACAS, and cybersecurity reporting eMASS, Xacta, or comparable Governance, Risk, and Compliance (GRC) platforms Microsoft Windows, Linux, virtualization, enterprise networking, and cloud environments supporting FedRAMP High and the DoD Cloud Computing Security Requirements Guide (SRG) Zero Trust Architecture (ZTA) and secure system engineering principles
The ideal candidate is a proactive cybersecurity leader capable of managing multiple complex DoD information systems while balancing mission requirements, cybersecurity risk, and regulatory compliance.
Success in this role requires strong leadership, technical expertise, and the ability to communicate cybersecurity risk effectively to senior Government decision-makers while enabling secure modernization and mission success through disciplined application of the DoD Risk Management Framework.
About Arlo Solutions
Sourced by ZipRecruiter
Industry
It services
Company size
1 - 10 Employees
Headquarters location
Washington, DC, US
Year founded
2014