1

Information Security Risk Analyst Jobs in Virginia

Third-Party Risk Analyst

Mclean, VA · On-site

$45 - $47/hr

Third-Party Risk Analyst Location: McLean, VA (5 days - Onsite) Job Overview The Third-Party Risk ... Knowledge of cybersecurity or information security incident management. * Familiarity with third ...

Demonstrated experience in Assessment & Authorization (A&A), risk assessment methodologies, information security, internet security, Portable Electronic Device (PED) vulnerabilities, threat analysis ...

Showing results 21-40

Information Security Risk Analyst information

See Virginia salary details

$31

$57

$74

How much do information security risk analyst jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for information security risk analyst in Virginia is $57.95, according to ZipRecruiter salary data. Most workers in this role earn between $45.05 and $65.05 per hour, depending on experience, location, and employer.

What is an information security risk analyst?

Information Security Risk Analysts are professionals responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze potential threats, vulnerabilities, and impacts to ensure that appropriate security measures are in place. These analysts often develop risk management strategies, conduct security assessments, and recommend security enhancements. Their goal is to help organizations protect sensitive information and comply with relevant regulations.

What does an information security risk analyst do?

As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.

What are the key skills and qualifications needed to thrive as an information security risk analyst, and why are they important?

To thrive as an Information Security Risk Analyst, you need a solid understanding of cybersecurity principles, risk management frameworks, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like risk assessment platforms, vulnerability scanners, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, communication, and attention to detail help you translate complex risks into actionable recommendations and collaborate with stakeholders. These skills are crucial for effectively identifying, assessing, and mitigating security risks to protect organizational assets and ensure compliance.

How does an information security risk analyst typically collaborate with other departments to address security risks?

Information Security Risk Analysts work closely with various departments such as IT, compliance, legal, and business units to identify and mitigate security risks. They often facilitate risk assessments, communicate findings, and recommend solutions tailored to each department's needs. Regular meetings and cross-functional projects are common, ensuring security measures align with business objectives while maintaining compliance. This collaborative approach helps foster a culture of security awareness throughout the organization.

What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?

AspectInformation Security Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.

What are the most commonly searched types of Information Security Risk Analyst jobs in Virginia?

The most popular types of Information Security Risk Analyst jobs in Virginia are:

What are popular job titles related to Information Security Risk Analyst jobs in Virginia?

For Information Security Risk Analyst jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Information Security Risk Analyst jobs in Virginia look for?

The top searched job categories for Information Security Risk Analyst jobs in Virginia are:

Infographic showing various Information Security Risk Analyst job openings in Virginia as of August 2026, with employment types broken down into 78% Full Time, and 22% Contract. Highlights an 94% In-person, and 6% Hybrid job distribution, with an average salary of $120,534 per year, or $57.9 per hour.

IT Security & Risk Analyst II

Oceaneering International, Inc.

Chesapeake, VA • On-site

$90K - $120K/yr

Full-time

Medical, Life, Retirement, PTO

Posted 9 days ago


Oceaneering rating

6.8

Company rating: 6.8 out of 10

Based on 22 frontline employees who took The Breakroom Quiz

371st of 493 rated machine equipment manufacturers


Job description

The Information System Security Officer (ISSO) is responsible for the implementation, management, and oversight of cybersecurity controls for classified information systems under Defense Counterintelligence and Security Agency (DCSA) governance. The ISSO ensures systems comply with federal and DoD cybersecurity requirements, supports system accreditation, and maintains the security posture of assigned environments throughout their lifecycle.

Oceaneering is a global provider of engineered services and products, primarily to the offshore energy industry. We develop products and services for use throughout the lifecycle of an offshore oilfield, from drilling to decommissioning. We operate the world's premier fleet of work class ROVs. Additionally, we are a leader in offshore oilfield maintenance services, umbilicals, subsea hardware, and tooling. We also use applied technology expertise to serve the defense, material handling, aerospace, science, and renewable energy industries.
Equal Opportunity Employer: 
All qualified candidates will receive consideration for all positions without regard to race, color, age, religion, sex (including pregnancy), sexual orientation, gender identity, national origin, veteran status, disability, genetic information, or other non-merit factor.
Oceaneering Marine Services Division (MSD) has over 30 years of experience providing full-service submarine and surface ship repairs supporting maintenance and alterations aboard commercial and U.S. military vessels. We are SUBSAFE and DDS-SOC certified and perform high-consequence maintenance on assets that operate in demanding environments. 

Required Qualifications

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience).

3-5+ years of experience in cybersecurity, information assurance, or classified system security operations.

Hands-on experience supporting DoD RMF, NIST SP 80053 security controls, and DCSA (DAAPM) compliance requirements.

Working knowledge of classified information systems, enclave security, and federal cybersecurity regulations (e.g., DoDI 8500.01, DoDI 8510.01).

Experience developing and maintaining accreditation artifacts such as System Security Plans (SSPs), POA&Ms, and Continuous Monitoring documentation.

Ability to perform vulnerability scanning, configuration management, audit log review, and security assessments.

Familiarity with tools such as ACAS, Nessus, SCCM, SIEM platforms, and other cybersecurity monitoring technologies.

Active DoD security clearance (typically Secret; some roles require TS/SCI).

IAM Level II certification required (e.g., CAP, CASP+, CISM, GSLC) in accordance with DoD 8140/8570.

Preferred Qualifications

Experience supporting DCSA inspections, audits, and security reviews.

Knowledge of classified system provisioning, account management, and secure enclave operations.

Background with STIGs, HBSS/ESM, secure configuration baselines, patch management processes, and enclave/system hardening.

Experience with incident response procedures for classified environments.

Strong communication skills with the ability to brief leadership and collaborate with system owners, administrators, and security stakeholders.

Familiarity with eMASS or similar compliance management platforms.

Experience supporting system changes, upgrades, or new system integrations with RMF documentation updates.

Pay Transparency:

 

We offer a comprehensive and competitive benefits package. Employee benefits vary by role, however, may include Health and Wellness, Mental Health, Retirement Savings, Life and Disability, Paid Maternity and Parental Leave, Paid Time Off, Tuition Reimbursement, and an Employee Assistance Program.

Compensation: $90,000.00 - $120,000.00

Essential Functions

Manage and maintain cybersecurity compliance for classified systems in accordance with DoD RMF, NIST SP 80053, DCSA Assessment and Authorization Process Manual (DAAPM) (DAAG), and applicable DoD directives.

Develop, update, and maintain System Security Plans (SSPs), POA&Ms, Continuous Monitoring plans, and other accreditation artifacts required by DCSA.

Conduct periodic security reviews, vulnerability scans, and technical assessments; track and remediate identified findings.

Oversee system configuration management, ensuring baseline controls, approved hardware/software listings, and secure configuration standards are enforced.

Coordinate with System Owners, Administrators, Program Managers, and Security leadership to maintain system security, support audits, and implement required changes.

Monitor, document, and report cybersecurity incidents; coordinate responses with security teams and ensure proper escalation and documentation.

Ensure proper account management practices, including user provisioning, access reviews, and enforcement of least privilege and needtoknow.

Support DCSA inspections, audits, and assessments by preparing documentation, coordinating interviews, and ensuring system readiness.

Provide security guidance for changes, upgrades, new system integrations, and emerging risks affecting system security posture.

Maintain awareness of evolving DoD/DCSA cybersecurity requirements and advise leadership on necessary updates to policies, controls, and procedures.


What Oceaneering employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom