1

Information Security Risk Analyst Jobs in Virginia

Information Security Analyst

Richmond, VA ยท On-site

$61 - $66/hr

Provides research and analysis of information security data and responds to inquiries; identifies ... Participates in cross-functional linked teams to address IS policy/risk or compliance issues.

Information Security Analyst

Richmond, VA ยท On-site

$58 - $63/hr

Stefanini is looking for an Information Security Analyst for Richmond, VA. For quick Apply, please ... Participates in cross-functional linked teams to address IS policy/risk or compliance issues.

Participates in cross-functional linked teams to address IS policy/risk or compliance issues ... information security areas.Provides some complex support and collaboration in completing analysis ...

Participates in cross-functional linked teams to address IS policy/risk or compliance issues ... information security areas. Provides some complex support and collaboration in completing analysis ...

Showing results 41-60

Information Security Risk Analyst information

See Virginia salary details

$31

$57

$74

How much do information security risk analyst jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for information security risk analyst in Virginia is $57.95, according to ZipRecruiter salary data. Most workers in this role earn between $45.05 and $65.05 per hour, depending on experience, location, and employer.

What is an information security risk analyst?

Information Security Risk Analysts are professionals responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze potential threats, vulnerabilities, and impacts to ensure that appropriate security measures are in place. These analysts often develop risk management strategies, conduct security assessments, and recommend security enhancements. Their goal is to help organizations protect sensitive information and comply with relevant regulations.

What does an information security risk analyst do?

As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.

What are the key skills and qualifications needed to thrive as an information security risk analyst, and why are they important?

To thrive as an Information Security Risk Analyst, you need a solid understanding of cybersecurity principles, risk management frameworks, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like risk assessment platforms, vulnerability scanners, and security information and event management (SIEM) systems is typically required. Strong analytical thinking, communication, and attention to detail help you translate complex risks into actionable recommendations and collaborate with stakeholders. These skills are crucial for effectively identifying, assessing, and mitigating security risks to protect organizational assets and ensure compliance.

How does an information security risk analyst typically collaborate with other departments to address security risks?

Information Security Risk Analysts work closely with various departments such as IT, compliance, legal, and business units to identify and mitigate security risks. They often facilitate risk assessments, communicate findings, and recommend solutions tailored to each department's needs. Regular meetings and cross-functional projects are common, ensuring security measures align with business objectives while maintaining compliance. This collaborative approach helps foster a culture of security awareness throughout the organization.

What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?

AspectInformation Security Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment teams, compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.

What are the most commonly searched types of Information Security Risk Analyst jobs in Virginia?

The most popular types of Information Security Risk Analyst jobs in Virginia are:

What are popular job titles related to Information Security Risk Analyst jobs in Virginia?

For Information Security Risk Analyst jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Information Security Risk Analyst jobs in Virginia look for?

The top searched job categories for Information Security Risk Analyst jobs in Virginia are:

Infographic showing various Information Security Risk Analyst job openings in Virginia as of August 2026, with employment types broken down into 78% Full Time, and 22% Contract. Highlights an 94% In-person, and 6% Hybrid job distribution, with an average salary of $120,534 per year, or $57.9 per hour.

Information Systems Security Manager - Advanced with Security Clearance

Rividium, Inc

Springfield, VA โ€ข On-site

Other

Re-posted 21 days ago


Job description

Title Information Systems Security Manager - Advanced Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking an individual to be responsible for the cybersecurity of a program, organization, system, or enclave. Responsibilites and abilities for this position shall include, but not limited to: * Acquire and manage the necessary resources, including leadership support, financial resources, and key security personnel, to support information technology (IT) security goals and objectives and reduce overall organizational risk. * Acquire necessary resources, including financial resources, to conduct an effective enterprise continuity of operations program. * Advise senior management (e.g., Chief Information Officer [CIO]) on risk levels and security posture. * Advise senior management (e.g., CIO) on cost/benefit analysis of information security programs, policies, processes, systems, and elements. * Advise appropriate senior leadership or Authorizing Official of changes affecting the organization's cybersecurity posture. * Collect and maintain data needed to meet system cybersecurity reporting. * Communicate the value of information technology (IT) security throughout all levels of the organization stakeholders. * Collaborate with stakeholders to establish the enterprise continuity of operations program, strategy, and mission assurance. * Ensure that security improvement actions are evaluated, validated, and implemented as required. * Ensure that cybersecurity inspections, tests, and reviews are coordinated for the network environment. * Ensure that cybersecurity requirements are integrated into the continuity planning for that system and/or organization(s). * Ensure that protection and detection capabilities are acquired or developed using the IS security engineering approach and are consistent with organization-level cybersecurity architecture. * Establish overall enterprise information security architecture (EISA) with the organization's overall security strategy. * Evaluate and approve development efforts to ensure that baseline security safeguards are appropriately installed. * Evaluate cost/benefit, economic, and risk analysis in decision-making process. * Identify alternative information security strategies to address organizational security objectives. * Identify information technology (IT) security program implications of new technologies or technology upgrades. * Interface with external organizations (e.g., public affairs, law enforcement, Command or Component Inspector General) to ensure appropriate and accurate dissemination of incident and other Computer Network Defense information. * Interpret and/or approve security requirements relative to the capabilities of new information technologies. * Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program. * Lead and align information technology (IT) security priorities with the security strategy. * Lead and oversee information security budget, staffing, and contracting. * Manage the monitoring of information security data sources to maintain organizational situational awareness. * Manage the publishing of Computer Network Defense guidance (e.g., TCNOs, Concept of Operations, Net Analyst Reports, NTSM, MTOs) for the enterprise constituency. * Manage threat or target analysis of cyber defense information and production of threat information within the enterprise. * Monitor and evaluate the effectiveness of the enterprise's cybersecurity safeguards to ensure that they provide the intended level of protection. * Oversee the information security training and awareness program. * Participate in an information security risk assessment during the Security Assessment and Authorization process. * Participate in the development or modification of the computer environment cybersecurity program plans and requirements. * Prepare, distribute, and maintain plans, instructions, guidance, and standard operating procedures concerning the security of network system(s) operations. * Provide enterprise cybersecurity and supply chain risk management guidance for development of the Continuity of Operations Plans. * Provide leadership and direction to information technology (IT) personnel by ensuring that cybersecurity awareness, basics, literacy, and training are provided to operations personnel commensurate with their responsibilities. * Ability to apply techniques for detecting host and network-based intrusions using intrusion detection technologies. * Ability to integrate information security requirements into the acquisition process; using applicable baseline security controls as one of the sources for security requirements; ensuring a robust software quality control process; and establishing multiple sources (e.g., delivery routes, for critical system elements). * Ability to identify critical infrastructure systems with information communication technology that were designed without system security considerations.Requirements for this position shall include: * Bachelor's degree or higher from an accredited college or university (Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree, or a degree in a Mathematics or Engineering field.) * CISSP-ISSMP or GSLC - IAT, IAM, or IASAE Level 3 CertificationAbout the Organization Established in 2008, RiVidium, Inc. (dba TripleCyber) is a VA-Verified SDVOSB and an SBA-Certified 8(a) company. To prepare our clients for the future, RiVidium has balanced all parts of our organization to attract the finest employees in order to 'Strive to be the missing element defining tomorrow's technology'. RiVidium keeps pace and surpasses its competitors by meeting challenges of advancements in Logistics, Human Capital, Cyber, Intelligence & Technology. EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law. If you need a reasonable accommodation for any part of the employment process, please contact Human Resources (HR) at . This position is currently accepting applications.