2

Remote Aviation Risk Management Jobs in Ashburn, VA

Integrates multiple stakeholder interests to address complex technical and programmatic aviation ... risk management, business optimization, and managed services enables us to partner with our clients ...

Integrates multiple stakeholder interests to address complex technical and programmatic aviation ... risk management, business optimization, and managed services enables us to partner with our clients ...

Be Seen First

This position is primarily remote , with occasional travel. The ideal candidate is self-driven ... risk management solutions on complex infrastructure and energy projects. We are a hands-on ...

Be Seen First

This position is primarily remote , with occasional travel. The ideal candidate is self-driven ... risk management solutions on complex infrastructure and energy projects. We are a hands-on ...

Maintain the Risk Management Register and track remediation activities. * Support cybersecurity ... Work Environment This position is primarily remote with occasional on-site meetings or support ...

Maintain the Risk Management Register and track remediation activities. * Support cybersecurity ... Work Environment This position is primarily remote with occasional on-site meetings or support ...

Maintain the Risk Management Register and track remediation activities. * Support cybersecurity ... Work Environment This position is primarily remote with occasional on-site meetings or support ...

Maintain the Risk Management Register and track remediation activities. * Support cybersecurity ... Work Environment This position is primarily remote with occasional on-site meetings or support ...

Remote Department: Employment and Litigation Services (ELS) Experience Level: Mid-level (minimum 3 ... DCI Consulting Group is a leading Human Resources (HR) risk management and workforce analytics firm ...

Manager, Cyber Security

Reston, VA ยท Remote

$115K - $156K/yr

... risk management judgment, and the ability to coordinate across technical, program, operations, assessor, and client stakeholder groups. Job Location: This position is remote within the United States.

Showing results 21-40

Remote Aviation Risk Management information

See Ashburn, VA salary details

$14

$31

$75

How much do remote aviation risk management jobs pay per hour?

As of Aug 11, 2026, the average hourly pay for remote aviation risk management in Ashburn, VA is $31.02, according to ZipRecruiter salary data. Most workers in this role earn between $19.90 and $39.57 per hour, depending on experience, location, and employer.

What is the difference between Remote Aviation Risk Management vs Remote Aviation Safety Coordinator?

AspectRemote Aviation Risk ManagementRemote Aviation Safety Coordinator
CertificationsFAA certifications, risk management credentialsFAA safety certifications, safety management system training
Work EnvironmentAnalyzing risks, developing mitigation strategies remotelyMonitoring safety protocols, coordinating safety efforts remotely
Employer & Industry UsageAirlines, aviation companies, risk consulting firmsAirlines, corporate flight departments, safety agencies

Remote Aviation Risk Management focuses on identifying and mitigating risks in aviation operations, often involving risk assessments and strategy development. Remote Aviation Safety Coordinators primarily oversee safety protocols and ensure compliance with safety standards. While both roles require aviation safety knowledge and certifications, Risk Management emphasizes risk analysis, whereas Safety Coordinators focus on safety program implementation and monitoring.

What are the key skills and qualifications needed to thrive in remote aviation risk management?

To thrive in Remote Aviation Risk Management, you need a solid understanding of aviation safety regulations, risk assessment methodologies, and incident investigation, typically supported by a relevant degree and industry certifications such as SMS (Safety Management Systems). Familiarity with risk management software, aviation data analytics tools, and regulatory compliance platforms is essential. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying risks and conveying safety recommendations remotely. These skills and qualifications are vital to ensure the proactive identification and mitigation of aviation hazards, maintaining safety and compliance in a remote working environment.

What are some common challenges faced in remote aviation risk management, and how can they be addressed?

Remote aviation risk management professionals often face challenges related to communication and coordination with geographically dispersed teams and stakeholders. Ensuring timely access to accurate data and maintaining situational awareness can be more complex without on-site presence. To address these challenges, professionals rely heavily on robust digital communication tools, real-time data sharing platforms, and clear protocols for reporting and escalation. Building strong relationships with team members and staying proactive in seeking updates are also key strategies for success in this remote role.

What is remote aviation risk management?

Remote aviation risk management refers to the process of identifying, assessing, and mitigating risks related to aviation operations, often from an off-site location using digital tools and technologies. Professionals in this field analyze flight data, weather reports, maintenance records, and other relevant information to ensure safety and regulatory compliance. They collaborate with pilots, airlines, and regulatory bodies to develop safety protocols and respond to incidents remotely. This approach enables continuous risk monitoring and decision-making without being physically present at airports or operational sites.
What are popular job titles related to Remote Aviation Risk Management jobs in Ashburn, VA? For Remote Aviation Risk Management jobs in Ashburn, VA, the most frequently searched job titles are:
What job categories do people searching Remote Aviation Risk Management jobs in Ashburn, VA look for? The top searched job categories for Remote Aviation Risk Management jobs in Ashburn, VA are:
What cities near Ashburn, VA are hiring for Remote Aviation Risk Management jobs? Cities near Ashburn, VA with the most Remote Aviation Risk Management job openings:
Infographic showing various Remote Aviation Risk Management job openings in Ashburn, VA as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, and 3% Contract. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $64,526 per year, or $31 per hour.

DFC - Vulnerability Management Analyst

cFocus Software Incorporated

Washington, DC โ€ข On-site, Remote

Full-time

Posted 16 days ago


Job description

cFocus Software seeks a Vulnerability Management Analyst to join our program supporting the United States International Defense Finance Agency (DFC). This position is remote. This position requires an Active Public Trust clearance.
Qualifications:
  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 5+ years of cybersecurity experience, including three or more years in vulnerability management, security compliance, POA&M management, or a closely related function.
  • Hands-on experience analyzing authenticated scan results and validating vulnerabilities using Tenable Nessus, Qualys, Microsoft Defender, or comparable enterprise platforms.
  • Demonstrated ability to assess vulnerability risk using CVSS, exploitability, CISA KEV status, asset criticality, exposure, mission impact, threat intelligence, and compensating controls.
  • Experience creating and maintaining POA&M records, tracking remediation milestones, reconciling GRC and ticketing systems, validating closure evidence, and documenting false-positive determinations.
  • Working knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53 controls, NIST SP 800-40 vulnerability and patch-management principles, CISA KEV/BOD 22-01 requirements, and federal continuous-monitoring expectations.
  • Ability to communicate technical risk clearly to federal cybersecurity leaders, System Owners, engineers, administrators, auditors, and nontechnical stakeholders.
  • Strong analytical writing, data-quality, documentation, prioritization, and time-management skills in a deadline-driven environment.
  • Active Security+, CySA+, CEH, GCVA, CISSP or other relevant security certifications preferred.

Duties:
  • Coordinate authenticated vulnerability scans with DFC stakeholders at frequencies aligned with policy, system criticality, exposure, threat conditions, and Government direction.
  • Analyze output from Tenable, Qualys, Microsoft Defender, and other Government-approved vulnerability, endpoint, configuration, and posture-management platforms.
  • Validate scanner findings against the operational environment and distinguish valid findings from false positives using documented rationale and supporting evidence.
  • Assess and assign severity using CVSS, DFC policy, exploitability, known-exploitation status, asset criticality, external exposure, mission impact, and relevant threat intelligence.
  • Recommend risk-informed remediation priorities, actions, timelines, evidence requirements, and closure criteria.
  • Coordinate with engineering, operations, application, cloud, endpoint, and system administration teams to establish remediation ownership, dependencies, and target completion dates
  • Provide rapid analysis and coordination for CISA Known Exploited Vulnerabilities (KEV), Binding Operational Directive 22-01 requirements, CISA Emergency Directives, vendor-declared zero-days, and vulnerabilities with active exploitation.
  • Notify the ISSM within four hours of applicable CISA notification, vendor disclosure, Government notification, or Contractor identification.
  • Verify exposure across applicable CSAM authorization boundaries and deliver a written impact assessment within one business day.
  • Document affected systems, boundaries and assets; severity; exposure; exploitability; known exploitation; mission impact; remediation ownership; required timelines; recommended action; and residual-risk considerations.
  • Track emergency remediation against CISA-, DFC-, or Government-directed deadlines and provide written confirmation of remediation status, compliance status, residual risk, and closure evidence.
  • Use CSAM as the authoritative POA&M and compliance ledger and ServiceNow as the operational remediation ticketing record.
  • Create complete POA&M items in CSAM within three business days after finding identification or Government direction, unless the Government establishes another deadline.
  • Populate and maintain required fields, including identifier, weakness description, affected system and control, severity, source, responsible owner, required resources, scheduled completion date, milestones, status, residual risk, and closure evidence.
  • Maintain bidirectional traceability so each applicable ServiceNow remediation ticket links to its CSAM POA&M item and each CSAM POA&M record references the appropriate ServiceNow ticket.
  • Track remediation through closure, monitor milestone integrity and aging, and coordinate scheduled-completion-date changes only after federal authorization.
  • Conduct monthly ServiceNow-to-CSAM reconciliation; identify stale or duplicate records, missing links or evidence, inconsistent status, inaccurate dates, and other data-quality issues; issue a written discrepancy log and track gaps to resolution.
  • Prepare risk-acceptance or exception recommendation packages when remediation cannot be completed within applicable timelines or scheduled-completion-date constraints.
  • Document the affected system and weakness, operational and mission impacts, exploitability, exposure, residual risk, compensating controls, remediation constraints, proposed duration and expiration, review interval, and conditions for continued acceptance.
  • Route recommendation packages to the AODR through the COR and ISSM for federal decision and accurately record approved decisions in CSAM.
  • Clearly preserve federal authority: do not accept risk for DFC, approve exceptions, extend POA&M dates without authorization, or make final closure decisions.