2

Remote Cism Jobs in Virginia (NOW HIRING)

Zero Trust Architect

Mclean, VA · On-site +1

$77K - $176K/yr

Remote Work: Hybrid Job Number: R0234025 Location: McLean,VA,US Share job via: Share Zero Trust ... Information Security Certification such as CEH, CISM, CCSP, CCSK, CISSP, or CompTIA Security ...

Showing results 41-59

Remote Cism information

See Virginia salary details

$17

$21

$23

How much do remote cism jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for remote cism in Virginia is $21.32, according to ZipRecruiter salary data. Most workers in this role earn between $17.88 and $22.64 per hour, depending on experience, location, and employer.

What are the main challenges faced by professionals in a Remote CISM role?

As a Remote CISM, one of the main challenges is maintaining effective oversight and coordination of security policies across diverse, distributed teams and systems. Communicating complex security requirements to non-technical stakeholders, handling real-time incident responses remotely, and staying up-to-date with rapidly evolving cyber threats can also be demanding. However, strong collaboration tools, clear processes, and proactive engagement with IT and business teams make these challenges manageable. Remote CISMs often need to adapt quickly and foster a strong security culture despite not being physically present, which can build valuable leadership and influence skills for career advancement.

What are the key skills and qualifications needed to thrive in the Remote CISM position, and why are they important?

To thrive as a Remote CISM (Certified Information Security Manager), you need a solid background in information security governance, risk management, and incident response, supported by a relevant degree and the CISM certification. Familiarity with security frameworks such as ISO 27001, NIST, and proficiency in tools for risk assessment, SIEM, and compliance tracking are critical. Strong communication, leadership, and analytical thinking skills help in coordinating with remote teams and managing security projects effectively. These competencies are essential for ensuring robust information security controls and for successfully mitigating cyber risks in a distributed work environment.

What is a Remote CISM?

A Remote CISM (Certified Information Security Manager) job involves overseeing and managing an organization's information security program from a remote location. Responsibilities typically include developing security policies, assessing risks, ensuring compliance, and leading incident response efforts. Remote CISM professionals collaborate with teams to protect sensitive data and mitigate cybersecurity threats while working outside of a traditional office setting. Strong communication skills, strategic planning, and knowledge of industry standards like ISO 27001 and NIST frameworks are essential.

What are the most commonly searched types of Cism jobs in Virginia? The most popular types of Cism jobs in Virginia are:
What cities in Virginia are hiring for Remote Cism jobs? Cities in Virginia with the most Remote Cism job openings:
Infographic showing various Remote Cism job openings in Virginia as of August 2026, with employment types broken down into 90% Full Time, 4% Part Time, and 6% Contract. Highlights an 77% Physical, 10% Hybrid, and 13% Remote job distribution, with an average salary of $44,340 per year, or $21.3 per hour.

Cybersecurity Assessment And Authorization Subject Matter Expert (SME) (61123)

Beshenich & Muir Associates

Fort Myer, VA • On-site, Remote

Full-time

Medical, Dental, Vision, Retirement

Re-posted 12 days ago


Job description

BMA is seeking a Cybersecurity Assessment And Authorization Subject Matter Expert (SME) to join our team. This is a fully remote role.
Job Summary
Serves as a Cybersecurity Subject Matter Expert (SME) responsible for supporting the Assessment and Authorization (A&A) of information systems in accordance with Department of Defense (DoD) cybersecurity policies, the Risk Management Framework (RMF), and applicable cybersecurity standards. Provides technical expertise in the implementation, assessment, and authorization of information systems, evaluates cybersecurity risks and vulnerabilities, and advises senior leadership on authorization status and compliance efforts.
  • Key Responsibilities
    • Serves as a Cybersecurity Subject Matter Expert (SME) for Assessment and Authorization (A&A) activities supporting DoD information systems.
    • Performs cybersecurity activities required to authorize information systems in accordance with the Risk Management Framework (RMF).
    • Provides technical expertise for information systems undergoing the authorization process.
    • Applies National Institute of Standards and Technology (NIST) Special Publication 800-53 security controls during the assessment and authorization process.
    • Evaluates cybersecurity requirements across complex enterprise IT environments, including enclaves, applications, and outsourced IT services.
    • Identifies security control deficiencies and determines the appropriate severity of vulnerabilities.
    • Assesses the impact of identified vulnerabilities on an information system's current or future authorization.
    • Develops recommendations to address cybersecurity risks and improve system compliance.
    • Briefs senior management on the status, progress, and results of RMF and authorization activities.
    • Ensures compliance with applicable DoD cybersecurity policies, procedures, and security standards.

Clearance Requirements
Must possess an IT-II Non-Critical Sensitive designation with a current Tier 3 (T3) background investigation at the time of proposal submission.
Required Skills & Certifications
  • Five (5) years of relevant Risk Management Framework (RMF) and NIST Assessment and Authorization (A&A) experience.
  • Department of Defense (DoD) cybersecurity experience.
  • Experience assessing security controls and conducting authorization reviews for large, complex organizations.
  • Experience supporting the Department of Defense (DoD) authorization process, including cybersecurity policies, procedures, and processes.
  • Knowledge of cybersecurity principles related to emerging technologies, including cloud computing, Industrial Control Systems (ICS), warehouse execution systems, and Operational Technology (OT) infrastructures.
  • Must possess an IT-II Non-Critical Sensitive designation or Tier 3 (T3) background investigation at the time of proposal submission.

Desired Certifications
  • Certified Authorization Professional (CAP)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified Cloud Security Professional (CCSP)

Overview
BMA is an employee-owned small business headquartered in Huntsville, AL that provides superior customer service by empowering all levels of our staff to make timely decisions to produce high-quality results. BMA fosters an environment of passion, precision, and dedication in order to fulfill our commitments to our partners, government, and country.
Benefits
We believe that our employees well-being is paramount to our success so our benefits package has been crafted with that in mind. We offer multiple healthcare coverage options to include low deductible, high deductible, and plans eligible for our Health Savings Account (HSA) option. Along with medical coverage, employees have dental, vision, accident & illness, short- and long-term disability all available to them. BMA proudly maintains a 401(k) plan with an industry leading 6% match that can include profit sharing based on company performance. Lastly, being an employee-owned company means that BMA offers a 100% Employee Stock Ownership Plan (ESOP), providing eligible employees the opportunity to earn stock in BMA, subject to plan eligibility and vesting requirements.
AAP & EEO Statement
Beshenich Muir & Associates, LLC (BMA) is an Equal opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, religious creed, gender, sexual orientation, gender identity, gender expression, transgender, pregnancy, marital status, national origin, ancestry, citizenship status, age, disability, protected Veteran Status, genetics or any other characteristics protected by applicable Federal, State, or Local Law.