1

Digital Risk Jobs in Reston, VA (NOW HIRING)

Risk Analyst

Reston, VA ยท On-site

We also empower the business with agile digital at scale to deliver unprecedented levels of ... This individual will help drive governance and risk initiatives by coordinating activities ...

Risk Analyst

Reston, VA ยท On-site

We also empower the business with agile digital at scale to deliver unprecedented levels of ... This individual will help drive governance and risk initiatives by coordinating activities ...

Build & Maintain Digital Ecosystems: Design, evolve, and maintain digital ecosystems, tools, templates, and job aides that streamline well-managed governance, reporting, and proactive risk analytics.

Support the development and delivery of AI risk and governance advisory services, including AI use ... Generate and deliver annual sales across Digital Risks and broader Control Risks' offerings on a ...

Help manage the Digital Risks Advisory business and contribute to performance, financial success ... Support the development and delivery of AI risk and governance advisory services, including AI use ...

Risk Mitigation Subject Matter Expert (SME) - Mid-Level One position anticipated. About Q2IMPACT ... Drawing on deep expertise in advanced analytics, digital platforms, and AI, we help clients solve ...

Experience in banking, digital assets, or capital markets is desirable * Strong relationship ... Credit Risk: Underwriting and portfolio credit risk across products (e.g., PD/LGD/EAD modeling ...

Risk Manager Location: Washington, DC Metropolitan Area (Onsite) Employment Type: Full-Time ... and digital solutions. We are distinguished by our reputation for managing mission-critical ...

Risk Manager Location: Washington, DC Metropolitan Area (Onsite) Employment Type: Full-Time ... and digital solutions. We are distinguished by our reputation for managing mission-critical ...

About The Media Trust The Media Trust (TMT) is a leading provider of digital risk protection and compliance solutions, serving some of the world's largest publishers, ad tech platforms, and ...

next page

Showing results 1-20

Digital Risk information

See Reston, VA salary details

$17

$49

$91

How much do digital risk jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for digital risk in Reston, VA is $49.15, according to ZipRecruiter salary data. Most workers in this role earn between $26.49 and $63.75 per hour, depending on experience, location, and employer.

What is digital risk?

Digital risk refers to the potential threats and vulnerabilities that organizations face as they adopt digital technologies, such as cyber attacks, data breaches, privacy issues, and technology failures. A digital risk professional identifies, assesses, and manages these risks to protect an organization's digital assets and ensure compliance with regulations. Their responsibilities may include implementing cybersecurity measures, monitoring for emerging threats, conducting risk assessments, and developing response strategies. They work closely with IT, compliance, and business teams to create a secure digital environment. The goal is to balance innovation and technology adoption with effective risk management.

What are the key skills and qualifications needed to thrive as a digital risk professional?

To thrive as a Digital Risk professional, you need a solid understanding of risk management frameworks, information security, and regulatory compliance, often supported by a degree in IT, cybersecurity, or a related field. Familiarity with risk assessment tools, cybersecurity platforms, and certifications like CISSP, CISM, or CRISC is typically expected. Strong analytical thinking, attention to detail, and effective communication skills help you identify threats and convey risks to stakeholders. These skills are crucial for proactively protecting organizations from digital threats and ensuring business continuity in a rapidly evolving technological environment.

What are the main challenges faced by professionals working in digital risk roles, and how can they effectively address them?

Professionals in Digital Risk often face challenges such as rapidly evolving cyber threats, regulatory compliance demands, and ensuring robust risk management across digital assets. Staying updated with the latest threat intelligence and regulatory changes is essential. Collaboration with IT, legal, and business teams is crucial to develop comprehensive risk mitigation strategies. Adopting a proactive approach, continuous learning, and leveraging advanced risk assessment tools can help digital risk professionals effectively manage these challenges.

What is the difference between Digital Risk vs Cybersecurity Analyst?

AspectDigital RiskCybersecurity Analyst
Required CredentialsCertifications like CISSP, CISA, CISM, and relevant degreesCertifications like CompTIA Security+, CISSP, CEH, and related degrees
Work EnvironmentFocuses on risk management, compliance, and strategic planning across digital assetsFocuses on protecting IT infrastructure, monitoring threats, and incident response
Employer & Industry UsageUsed by financial institutions, tech firms, and corporations managing digital risksCommon in IT departments, security firms, and organizations with cybersecurity teams

Digital Risk professionals primarily focus on identifying and managing risks related to digital assets and compliance, while Cybersecurity Analysts concentrate on protecting systems from cyber threats. Both roles require similar certifications and often work within the same industry environments, but their core responsibilities differ in scope and focus.

What are popular job titles related to Digital Risk jobs in Reston, VA?

For Digital Risk jobs in Reston, VA, the most frequently searched job titles are:

What job categories do people searching Digital Risk jobs in Reston, VA look for?

The top searched job categories for Digital Risk jobs in Reston, VA are:

What cities near Reston, VA are hiring for Digital Risk jobs?

Cities near Reston, VA with the most Digital Risk job openings:

Infographic showing various Digital Risk job openings in Reston, VA as of August 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 81% Physical, 4% Hybrid, and 15% Remote job distribution, with an average salary of $102,237 per year, or $49.2 per hour.

Manager, Threat Detection Engineer

Washington, DC โ€ข On-site

Carlyle
Furniture Manufacturingย โ€ขย 11 - 50 employees

Full-time

Medical, Life, Retirement, PTO

Re-posted 8 days ago


Key responsibilities

  • Own the detection content lifecycle, including tuning, improving, or retiring detection rules based on analyst feedback, coverage, alert quality, data quality, and operational factors.

  • Develop high-fidelity detections across various telemetry sources, translating threat intelligence and adversary behaviors into testable detection hypotheses and production analytics.

  • Coordinate and support threat hunts, review technical work, establish detection standards, and coach contributors on detection design, testing, and usability.


Job description

Position Summary

The Threat Detection Engineer is a hands-on technical leader who strengthens how Carlyle identifies, understands and detects cyber threats. Reporting to the AVP, Threat Detection and Intelligence Lead, the Threat Detection Engineer leads assigned detection engineering and threat intelligence processes, turns intelligence into production detections and works with security partners to improve operational outcomes.

This role oversees detection content from requirements and design through testing, deployment, tuning and retirement. It also develops intelligence that supports security operations and risk decisions and partners on threat hunting, external-risk response, digital-risk support for executive protection, automation, SOC interaction and platform reliability. The Threat Detection Engineer chooses among AI-assisted methods, deterministic automation and process changes based on the problem, risk and expected value.

This is a hands-on technical leadership role that prioritizes assigned services, reviews technical work, coaches contributors and works across teams to carry out Carlyle's Threat Detection and Intelligence strategy.

In-Office Requirement: 4 days per week

Primary Responsibilities

Detection Engineering and Coverage - 30%

  • Own the detection content lifecycle and use analyst feedback, detection coverage, alert quality, data quality, delivery time and cost to decide what should be tuned, improved or retired.
  • Develop high-fidelity detections across endpoint, identity, email, network, cloud and business-critical application telemetry, identifying visibility and data gaps and ensuring alerts contain the context analysts need to investigate and act.
  • Translate adversary behaviors, threat intelligence, incident learnings and control gaps into testable detection hypotheses and production-ready analytics.
  • Implement approved quality gates for detection content, including data validation, expected-behavior testing, false-positive tolerance, investigation guidance and rollback plans. Use detection-as-code for internally managed content and supported tuning, compensating analytics or provider escalation for vendor-managed content.
  • Coordinate and support targeted threat hunts with incident response and other security partners to validate hypotheses, uncover gaps and convert repeatable findings into durable detections or response logic.
  • Review technical work, establish reusable standards and coach contributors on detection design, testing and investigative usability.

Threat Intelligence and External Risk - 30%

  • Manage intelligence requirements based on Carlyle's threat profile, critical assets, executives and business priorities, including portfolio-related risks relevant to Carlyle.
  • Collect, assess and synthesize strategic, operational and tactical intelligence concerning relevant threat actors, campaigns, vulnerabilities, techniques and emerging risks.
  • Produce timely assessments and briefings tailored to security operations, incident response, technology leaders, executives and other stakeholders.
  • Turn intelligence into prioritized detection, hunting, hardening and response requirements. Measure whether the intelligence was timely, useful and acted on, including how quickly it led to a detection or decision.
  • Govern indicator and intelligence-data lifecycles, including sourcing, validation, normalization, enrichment, confidence, aging, pruning and benign-pattern review; maintain trusted information-sharing relationships and evaluate source relevance and reliability.
  • Coordinate monitoring for dark-web activity, lookalike domains, social-media threats, impersonation, exposed information and other digital risks. Provide cyber and digital-risk support to executive protection. Work with Legal, Communications, service providers and relevant business stakeholders on assessments, escalations and takedowns.

Automation, Quality and Platform Enablement - 30%

  • Use AI-assisted and analytical tools to accelerate detection-rule development, translation, testing and documentation. Ensure generated content is reviewed, traceable and handled in accordance with data requirements.
  • Partner with analysts and platform owners to build, pilot and maintain automation playbooks that enrich alerts, correlate evidence, summarize investigations, prioritize and route work, and recommend next steps. Combine model-assisted and deterministic steps, with human approval for consequential actions.
  • Develop reusable scripts, integrations and data transformations that connect detection, intelligence, case-management and response workflows through supported APIs and structured data contracts.
  • Validate generated rules and automated workflows through analyst review, regression testing, failure-mode assessment and rollback criteria. Pilot material workflow changes with affected analysts, provide training and measure adoption, investigation time, quality and rework.
  • Partner with platform owners and architects to improve telemetry coverage, data quality, integration reliability, scalability and cost effectiveness, and provide ongoing production support for assigned detection, intelligence and automation capabilities.

Program Leadership and Partnerships - 10%

  • Translate the Threat Detection and Intelligence strategy into an actionable roadmap and prioritized backlog. Make day-to-day decisions for assigned work and escalate significant risks.
  • Build effective partnerships with incident response, vulnerability management, engineering, infrastructure, cloud, identity and Communications stakeholders. Define operating handoffs, ownership boundaries and escalation paths that support effective response.
  • Present concise metrics, risks, recommendations and progress updates to technical and non-technical audiences, connecting detailed findings to Carlyle's broader objectives.
  • Monitor day-to-day service-provider performance and resolve delivery, handoff and escalation issues with the appropriate owners.

Requirements

Education & Certificates

  • Bachelor's degree, required.
  • Concentration in cybersecurity, computer science, information systems, engineering or a related discipline strongly preferred, or equivalent relevant professional experience.
  • Advanced degree in a related discipline is preferred.
  • Relevant certifications in security operations, incident response, threat intelligence, cloud security or information security are preferred.

Professional Experience

  • 5-7 years of relevant information-security or cybersecurity experience.
  • 4+ years of hands-on experience spanning threat detection engineering and cyber threat intelligence. Candidates must have developed production detections and used intelligence to improve detection, hunting or response.
  • Demonstrated ownership of complex security processes or services and experience leading cross-functional technical initiatives from definition through measurable operational adoption.
  • Hands-on experience creating, testing, deploying and tuning production detection logic via structured query, rule or analytic language, required.
  • Experience working with security telemetry from multiple domains and diagnosing data-quality or schema issues that affect detection outcomes; experience with cloud security telemetry and controls is preferred.
  • Experience developing automation with a general-purpose language and integrating systems through APIs, structured data formats and version-controlled workflows.
  • Demonstrated use of AI-assisted or analytical techniques in a production security workflow, including testing generated content, measuring results and recognizing when traditional automation or process changes are the better approach.
  • Experience with dark-web analysis, domain impersonation, cyber or digital-risk support for executive protection, or takedown coordination is preferred.
  • Experience creating detection logic in multiple languages or translating analytics across platforms is strongly preferred. Examples may include Sigma, KQL, SPL, XQL, YARA-L, EQL, SQL, YARA or comparable languages.

Competencies & Attributes

  • Deep knowledge of adversary behavior, detection engineering methods and the practical use of MITRE ATT&CK to organize requirements and assess coverage.
  • Working knowledge of SIEM, EDR/XDR, SOAR, threat intelligence, case-management and digital-risk capabilities, with the ability to work across platforms rather than depend on one vendor.
  • Strong understanding of detection testing, data validation, alert fidelity, false-positive reduction, lifecycle governance, intelligence standards, indicator confidence and aging, and structured analytical techniques.
  • Ability to write clear technical requirements, detection documentation, intelligence assessments, executive summaries, operating procedures and decision-ready recommendations, and to adapt technical depth to the audience.
  • Strong prioritization, problem-solving and collaboration skills, with the ability to make progress through ambiguity and adjust as threat conditions and business needs evolve.
  • Demonstrated ability to review technical work, coach others and improve team practices without formal reporting authority. Acts with integrity, discretion, accountability and respect for others.

Benefits/Compensation

The compensation range for this role is specific to Washington, DC, and New York, NY and takes into account a wide range of factors including but not limited to the skill sets required/preferred; prior experience and training; licenses and/or certifications.

The anticipated base salary range for this role is $160,000 to $180,000.

In addition to the base salary, the hired professional will enjoy a comprehensive benefits package spanning retirement benefits, health insurance, life insurance and disability, paid time off, paid holidays, family planning benefits and various wellness programs. Additionally, the hired professional may also be eligible to participate in an annual discretionary incentive program, the award of which will be dependent on various factors, including, without limitation, individual and organizational performance.

Due to the high volume of candidates, please be advised that only candidates selected to interview will be contacted by Carlyle.


Who We Are


When people, ideas, and capital come together, opportunity expands across private markets. At Carlyle, this belief has shaped how we invest for decades, fueling growth for companies and delivering performance for investors.

Visit our website to learn more about our firm and the ways our platform is shaping private markets.