1

Information Security Risk Analyst Jobs in Virginia

Third-Party Risk Analyst

Mclean, VA · On-site

$45 - $47/hr

Third-Party Risk Analyst Location: McLean, VA (5 days - Onsite) Job Overview The Third-Party Risk ... Knowledge of cybersecurity or information security incident management. * Familiarity with third ...

Risk Business Analyst Location: Vienna, VA (Hybrid) Pay Rate: Open to Both C2C and W2 options ... IT and Information Security controls. The Analyst will be responsible for all phases of the ...

Risk Business Analyst Location: Vienna, VA (Hybrid) Pay Rate: Open to Both C2C and W2 options ... Experience in audit and information security risk assessments * Knowledge of applicable federal and ...

Risk Business Analyst Location: Vienna, VA (Hybrid) Pay Rate: Open to Both C2C and W2 options ... Experience in audit and information security risk assessments * Knowledge of applicable federal and ...

Risk Business Analyst Location: Vienna, VA (Hybrid) Pay Rate: Open to Both C2C and W2 options ... Experience in audit and information security risk assessments * Knowledge of applicable federal and ...

Business Risk Analyst

Vienna, VA · On-site

$45 - $55/hr

Risk Business Analyst Location: Vienna, VA (Hybrid) Pay Rate: Open to Both C2C and W2 options ... Experience in audit and information security risk assessments * Knowledge of applicable federal and ...

Showing results 21-40

Information Security Risk Analyst information

See Virginia salary details

$31

$57

$74

How much do information security risk analyst jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for information security risk analyst in Virginia is $57.95, according to ZipRecruiter salary data. Most workers in this role earn between $45.05 and $65.05 per hour, depending on experience, location, and employer.

What is an information security risk analyst?

Information Security Risk Analysts are professionals responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze potential threats, vulnerabilities, and impacts to ensure that appropriate security measures are in place. These analysts often develop risk management strategies, conduct security assessments, and recommend security enhancements. Their goal is to help organizations protect sensitive information and comply with relevant regulations.

What does an information security risk analyst do?

As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.

What are the key skills and qualifications needed to thrive as an information security risk analyst, and why are they important?

To thrive as an Information Security Risk Analyst, you need a solid understanding of cybersecurity principles, risk management frameworks, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like risk assessment platforms, vulnerability scanners, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, communication, and attention to detail help you translate complex risks into actionable recommendations and collaborate with stakeholders. These skills are crucial for effectively identifying, assessing, and mitigating security risks to protect organizational assets and ensure compliance.

How does an information security risk analyst typically collaborate with other departments to address security risks?

Information Security Risk Analysts work closely with various departments such as IT, compliance, legal, and business units to identify and mitigate security risks. They often facilitate risk assessments, communicate findings, and recommend solutions tailored to each department's needs. Regular meetings and cross-functional projects are common, ensuring security measures align with business objectives while maintaining compliance. This collaborative approach helps foster a culture of security awareness throughout the organization.

What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?

AspectInformation Security Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.

What are the most commonly searched types of Information Security Risk Analyst jobs in Virginia?

The most popular types of Information Security Risk Analyst jobs in Virginia are:

What are popular job titles related to Information Security Risk Analyst jobs in Virginia?

For Information Security Risk Analyst jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Information Security Risk Analyst jobs in Virginia look for?

The top searched job categories for Information Security Risk Analyst jobs in Virginia are:

Infographic showing various Information Security Risk Analyst job openings in Virginia as of September 2026, with employment types broken down into 1% As Needed, 74% Full Time, 20% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $120,534 per year, or $57.9 per hour.

Information Security Risk Specialist-McLean, Virginia

Manassas, VA • On-site

BOOZ, ALLEN & HAMILTON, INC.
IT Services • 10K+ employees

$99K - $225K/yr

Full-time, Part-time

Medical, Life, Retirement, PTO

This job post has expired 1 day ago. Applications are no longer accepted.


Booz Allen Hamilton rating

8.9

Company rating: 8.9 out of 10

Based on 49 frontline employees who took The Breakroom Quiz


Job description

Information Security Risk Specialist
The Opportunity :
As an Information Security Risk Spe cia list on our team, you will leverage your expertise to collaborate closely with contractor and DoD government system owners, as well as system administrators and developers, to identify cyber risks, analyze applicable policies , and develop comprehensive mitigation strategies. Utilizing insights from subject matter experts ( SMEs ) and engineers, you will evaluate technical infrastructure and personnel dynamics to assess the full threat landscape. From there, you will guide clients through actionable remediation plans, delivering clear and impactful solutions through presentations, detailed white papers, and well-defined milestones to ensure effective risk management and cybersecurity resilience.
You'll work with your client to translate security concepts so they can make the best decisions to secure critical DoD systems. This is your opportunity to act as an information security SME while broadening your skills in DevSecOps and cloud security.
Join us. The world can't wait.
You Have:
  • 5+ years of experience working in a professional IT environment
  • 3+ years of experience in cybersecurity and Assessment and Authorization ( A & A ) supporting DoD environments
  • Experience supporting federal government or DoD ATO packages, performing A & A and RMF, and c ond ucting risk assessments for federal government or DoD systems hosted in AWS, Azure, or hybrid cloud environments
  • Experience performing technical evaluations and security control assessments in cloud-native and containerized environments
  • Experience interfacing with engineering teams to align DevSecOps pipelines with cybersecurity policies
  • Knowledge of compliance testing tools such as ACAS, SCAP, STIGs or SRGs, eMASS, or Xacta
  • Experience with NIST SP 800-53, CNSSI 1253, artifact generation, SSPs, POA & Ms, SAPs, risk assessments, and continuous monitoring
  • TS/SCI clearance
  • HS diploma or GED
  • DoD 8570 Level II Security+ Certification or higher

Nice If You Have:
  • Experience with DevSecOps, Path-to-Production, and CI / CD
  • Experience administering Red Hat Enterprise Linux 8 or Windows Server 2012 or higher
  • Experience with cloud tools and container orchestration security
  • Knowledge of STIG and compliance scans
  • Ability to advise stakeholders on cloud security strategies, container orchestration security such as Kubernetes and Rancher, and platform hardening
  • Possession of excellent verbal and written communication skills
  • Bachelor's degree in IT or Cybersecurity

Clearance:
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information ; TS/SCI clearance is required.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.
Identity Statement
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Candidate AI Usage Policy
AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.
Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.

Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

What Booz Allen Hamilton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Booz Allen Hamilton logo

About Booz Allen Hamilton

Sourced by ZipRecruiter

Booz Allen Hamilton is a leading provider of management and technology consulting services to the US government in defense, intelligence, and civil markets. Headquartered in McLean, Virginia, the firm also serves major corporations, institutions, and not-for-profit organizations. Founded in 1914 by Edwin G. Booz, the company has a long-standing tradition of helping clients achieve success by delivering a wide range of consulting services that include strategic planning, human capital and learning, communication, systems development, and others. The company's mission is to empower people to change the world, and it has a reputation for maintaining the highest standards of integrity and-excellence.

Industry

It services

Company size

10,000+ Employees

Headquarters location

McLean, VA, US

Year founded

1914