1

Government Risk Management Jobs in Virginia (NOW HIRING)

Risk Mitigation Specialist - MID

Quantico, VA · On-site

$104K/yr

... to other government stakeholders and DCSA field assets. Work Schedule: Standard 8-4, may flex an ... Actively manage and oversee a portfolio of companies operating under mitigation. * Provide ...

Risk Mitigation Specialist - MID

Quantico, VA · On-site

$104K/yr

... to other government stakeholders and DCSA field assets. Work Schedule: Standard 8-4, may flex an ... Actively manage and oversee a portfolio of companies operating under mitigation. * Provide ...

Program Risk Manager

Herndon, VA · On-site

$86K - $138K/yr

Develop, maintain, and execute the Program Risk Management Plan and procedures aligned with PMO ... The company serves as a valued partner to essential government agencies and supports every branch ...

Program Risk Manager

Herndon, VA · On-site

$86K - $138K/yr

Develop, maintain, and execute the Program Risk Management Plan and procedures aligned with PMO ... The company serves as a valued partner to essential government agencies and supports every branch ...

Program Risk Manager

Herndon, VA · On-site

$86K - $138K/yr

Develop, maintain, and execute the Program Risk Management Plan and procedures aligned with PMO ... The company serves as a valued partner to essential government agencies and supports every branch ...

next page

Showing results 1-20

Government Risk Management information

See Virginia salary details

$51.1K

$110.6K

$168.5K

How much do government risk management jobs pay per year?

As of Jun 12, 2026, the average yearly pay for government risk management in Virginia is $110,599.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,200.00 and $127,900.00 per year, depending on experience, location, and employer.

What is a government risk specialist?

A government risk specialist is a professional responsible for identifying, assessing, and managing risks related to government operations, policies, and compliance. They often analyze data, develop risk mitigation strategies, and ensure adherence to regulations, typically requiring knowledge of public sector procedures and risk management tools. Certification in risk management or related fields can enhance job prospects in this role.

What is a Government Risk Management job?

A Government Risk Management job involves identifying, assessing, and mitigating risks that could impact government operations, policies, or compliance. Professionals in this role analyze financial, operational, and security risks to ensure agencies or departments meet regulatory requirements and safeguard public resources. They develop risk management strategies, implement controls, and monitor emerging threats. This role requires strong analytical skills, regulatory knowledge, and the ability to collaborate with various stakeholders to minimize risks and enhance government efficiency.

What are the key skills and qualifications needed to thrive in the Government Risk Management position, and why are they important?

To thrive in Government Risk Management, you need a background in risk assessment, regulatory compliance, and public administration, often supported by a relevant degree such as public policy, law, or business. Familiarity with risk management frameworks (such as COSO or ISO 31000), statistical analysis tools, and government-specific compliance systems is commonly required, along with certifications like Certified Government Auditing Professional (CGAP) or Certified Risk Manager (CRM). Exceptional analytical thinking, stakeholder communication, and problem-solving abilities set candidates apart in this field. These qualifications are crucial for effectively identifying, mitigating, and reporting risks within government entities, ensuring regulatory adherence and organizational integrity.

What is risk management in government?

Risk management in government involves identifying, assessing, and prioritizing potential threats to public safety, resources, and operations. Government risk managers develop strategies to mitigate or prevent risks, often using tools like risk assessments and compliance standards to ensure effective decision-making and policy implementation.

Is risk management a good career?

Risk management is a valuable career that involves identifying, assessing, and mitigating risks for organizations, often requiring skills in analysis, communication, and decision-making. Professionals in this field can work in various industries such as finance, healthcare, and government, with opportunities for advancement and certification like the Certified Risk Manager (CRM). It offers stable employment and the chance to contribute to organizational safety and success.

What is the highest paying risk management job?

In risk management, executive roles such as Chief Risk Officer (CRO) typically have the highest salaries, often exceeding six figures annually. These positions require extensive experience, advanced certifications like FRM or CRM, and strong leadership skills, especially in large organizations or financial institutions.

What are the typical day-to-day responsibilities in a Government Risk Management position?

In a Government Risk Management role, your daily tasks often include identifying potential risks to the agency, conducting risk assessments, and developing mitigation strategies tailored to public sector operations. You’ll work closely with various departments to ensure compliance with policies and regulations, draft risk reports, and facilitate training or awareness sessions for staff. Collaboration is common, as you might participate in cross-functional teams to review new initiatives or respond to emerging threats. Expect a mix of analytical work, documentation, and interactive meetings, providing a dynamic and impactful work environment.

Infographic showing various Government Risk Management job openings in Virginia as of June 2026, with employment types broken down into 82% Full Time, and 18% Part Time. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $110,599 per year, or $53.2 per hour.

Risk Management Support Lead

Empower AI Inc.

Quantico, VA

Full-time

Posted 10 days ago


Job description

Overview

Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai.

Empower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company's commitment to hiring and supporting active-duty and veteran employees.

Responsibilities

As a Risk Management Support Lead, you will be accountable for safeguarding the enterprise mission of the Defense Counterintelligence and Security Agency (DCSA) Customer Support Services (CSS) contract by ensuring all systems meet cybersecurity, Risk Management Framework (RMF), and Authorization to Operate (ATO) requirements.

You will lead end-to-end RMF execution from system categorization through continuous monitoring, manage System Security Plans (SSP), Security Assessment Reports (SAR), and Plans of Action and Milestones (POA&M), operate the Enterprise Mission Assurance Support Service (eMASS) platform, and serve as primary liaison with the Government Authorizing Official (AO) for ATO approvals. You will apply expert knowledge of NIST SP 800-37, NIST SP 800-53, DoDI 8510.01, and DoD Security Technical Implementation Guides (STIGs) across the DCSA CSS system portfolio.

Highlights of Responsibilities:

  • Lead end-to-end RMF process for multiple information systems, from system categorization (Step 1) through continuous monitoring (Step 6).
  • Manage RMF artifacts including System Security Plans (SSP), Security Assessment Reports (SAR), and Plans of Action and Milestones (POA&M).
  • Operate the Enterprise Mission Assurance Support Service (eMASS) platform to manage and document RMF processes.
  • Apply NIST SP 800-37 (RMF), NIST SP 800-53 (Security Controls), and DoDI 8510.01 (RMF for DoD IT) across all assigned systems.
  • Apply DoD Security Technical Implementation Guides (STIGs) and use Security Content Automation Protocol (SCAP) tools to assess and document compliance.
  • Manage vulnerability lifecycle using ACAS/Nessus, interpret scan results, and manage remediation through POA&Ms.
  • Work with technical teams to select, implement, and document NIST SP 800-53 security controls; provide guidance on control implementation and evidence collection.
  • Prepare systems for security control assessments, act as primary liaison with security assessors, and compile final authorization packages for AO submission.
  • Serve as the subject matter expert for DoD cybersecurity policy interpretation including STIGs; provide guidance to technical teams on achieving and maintaining compliance.
  • Maintain DoD 8570/8140 IAM Level III certification currency.
Qualifications

Requirements:

  • Shall possess a TOP SECRET security clearance with SCI eligibility (favorably adjudicated T5 or T5R; within investigation scope or currently enrolled in Continuous Evaluation/Continuous Vetting).
  • Active CISSP (Certified Information Systems Security Professional) or CAP (Certified Authorization Professional) certification.
  • Active PMP (Project Management Professional) certification.
  • DoD 8570/8140 IAM Level III certification.
  • Expert-level knowledge of NIST SP 800-37 (RMF), NIST SP 800-53 (Security Controls), and DoDI 8510.01.
  • Demonstrated experience with eMASS for RMF process management and documentation.
  • Experience with STIGs, SCAP tools, ACAS/Nessus, and vulnerability lifecycle management.
  • Experience with enterprise technologies including VMware, Linux (RHEL), Windows Server, Active Directory, and enterprise storage.
  • Strong customer service orientation and experience serving as the primary liaison with Government Authorizing Officials.
  • Excellent written, oral, and interpersonal communication skills.

Education and Experience:

Required Education/Experience: Bachelor's degree in Computer Science, Information Technology, or a related field. Minimum ten (10) years of recent experience managing complex projects, preferably in a risk or security context. Minimum seven (7) years of direct, hands-on experience leading RMF efforts for DoD systems and successfully achieving Authorization to Operate (ATO). Experience supporting a DoD or IC customer is a plus.

Physical Requirements:

This position requires the ability to perform the below essential functions:

  • Sitting for long periods
  • Standing for long periods
  • Ambulate throughout an office
About Empower AI

All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm's overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.

Employment Type: FULL_TIME