2

Remote Cyber Security Risk Analyst Jobs in Virginia

This role involves conducting on-site and remote cyber risk assessments, developing mitigation ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

Sr. Analyst - SCRM

VA ยท On-site +1

$88K - $116K/yr

General information Job Posting Title Sr. Analyst - SCRM Date Thursday, May 28, 2026 City Remote ... risk suppliers (e.g., performance, financial, cybersecurity, and geopolitical indicators ...

Cybersecurity Analyst, Mid

Stafford, VA ยท On-site +1

$105K - $115K/yr

We have an opening for a Cyber Security Analyst, Mid to provide cyber security support and develop and maintain DoDI 8510.01-compliant Risk Management Framework (RMF) authorization packages for all ...

Cyber Security Engineer Job number: 850 This is a remote position. Ad Hoc is a technology company ... Conduct security assessments, vulnerability analysis, and risk evaluations of applications ...

FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... Experience with FedRAMP and/or other authorization processes and NIST risk management framework

FTE + Benefits Remote: 80% (4 days a week) Supports the FedRAMP and FISMA authorization(s) of new ... Experience with FedRAMP and/or other authorization processes and NIST risk management framework

FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... Experience with FedRAMP and/or other authorization processes and NIST risk management framework

FTE + Benefits Remote: 80% (4 days a week) Client supports the FedRAMP and FISMA authorization(s ... Experience with FedRAMP and/or other authorization processes and NIST risk management framework

Manager, Cyber Security

Reston, VA ยท Remote

$115K - $156K/yr

... analyses, E-Authentication Risk Assessments, security control implementation statements, and ... Remote Office (US99)

Cyber Security Engineer

Arlington, VA ยท On-site +1

$107K - $195K/yr

... Risk Management Framework. This exciting and challenging work will help you expand your ... Percentage of remote work will vary based on client requirements/deliverables. In this role, you ...

next page

Showing results 1-20

Remote Cyber Security Risk Analyst information

How does a Remote Cyber Security Risk Analyst typically collaborate with other departments in a fully remote environment?

Remote Cyber Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks across the organization. Collaboration is usually facilitated through virtual meetings, secure communication platforms, and shared documentation tools. Analysts provide guidance on security best practices, participate in incident response efforts, and help ensure compliance with regulatory standards. Effective communication and proactive engagement with stakeholders are essential for success in this remote role.

What does a Remote Cyber Security Risk Analyst do?

A Remote Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating potential security threats to an organization's information systems while working from a remote location. They evaluate existing security measures, analyze vulnerabilities, and recommend improvements to reduce risks. Additionally, they monitor for security breaches, conduct risk assessments, and ensure compliance with relevant regulations and policies. Their work helps protect sensitive data and maintain the integrity of technology systems.

What are the key skills and qualifications needed to thrive as a Remote Cyber Security Risk Analyst, and why are they important?

To thrive as a Remote Cyber Security Risk Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and typically a degree in cybersecurity or a related field. Familiarity with tools like risk management frameworks (e.g., NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP or CISA is highly beneficial. Strong analytical thinking, attention to detail, and effective written and verbal communication skills are essential for collaborating remotely and conveying risk findings to stakeholders. These skills and qualities are crucial for identifying, evaluating, and mitigating cyber risks to protect organizational assets in a distributed work environment.

What is the difference between Remote Cyber Security Risk Analyst vs Remote Cyber Security Analyst?

AspectRemote Cyber Security Risk AnalystRemote Cyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, complianceMonitoring, threat detection, incident response
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, consulting firms, enterprises

The Remote Cyber Security Risk Analyst focuses on identifying and managing security risks, ensuring compliance, and developing policies. In contrast, the Remote Cyber Security Analyst primarily monitors systems for threats, investigates incidents, and implements security measures. Both roles require similar certifications and often work in overlapping environments, but their core responsibilities differ in scope and focus.

What are the most commonly searched types of Cyber Security Risk Analyst jobs in Virginia? The most popular types of Cyber Security Risk Analyst jobs in Virginia are:
What job categories do people searching Remote Cyber Security Risk Analyst jobs in Virginia look for? The top searched job categories for Remote Cyber Security Risk Analyst jobs in Virginia are:
What cities in Virginia are hiring for Remote Cyber Security Risk Analyst jobs? Cities in Virginia with the most Remote Cyber Security Risk Analyst job openings:
Cyber Risk Analyst SME

Cyber Risk Analyst SME

Technomics

Arlington, VA โ€ข On-site, Remote

Full-time

Posted 24 days ago


Job description

Technomics is a growing employee-owned, decision analytics company that specializes in cost and economic analysis to facilitate better decisions faster. We enable a wide range of clients across the Federal government, from senior level policy makers to program managers, to choose smartly, buy effectively and operate efficiently. We deliver practical, credible and defensible results offering actionable insights by applying data-driven and analytics-based approaches in combination with multidisciplinary talent, subject matter experts, and tangible and repeatable assets in the form of databases, models, approaches and techniques.

Senior Analysts have the knowledge, skills, abilities and initiative to deliver timely, practical and innovative solutions to our clients as part of high-performing project teams typically composed of a mix of junior and mid-level analysts who will look to you for technical acumen and mentoring.

Our employee-owners pride themselves on their ability to apply deep analytical rigor and innovative thought that assist clients in understanding and solving a myriad of challenging resource planning and management problems.

This position may be located in Arlington, VA (Headquarters), Washington D.C., Pentagon, Springfield, VA., Chantilly, VA., Tysons Corner, VA.

Description:

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk identification.
The ideal candidate has deep experience with NIST SP 800-30, MITRE ATT&CK, and threat modeling approaches, and can translate technical risks into mission/business impacts. You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans, presenting findings, and traveling to client sites for mission assessments.
We are looking for someone who is agile, creative, and collaborative โ€” able to apply lessons learned, enable data tagging and structured knowledge capture, and help shift the organization from reactive responses toward proactive risk management.

Clearance Required: Active DOE Q or higher (or ability to obtain)

Key Responsibilities:

  • Serve as a Subject Matter Expert (SME) in cyber risk assessment, analysis, and mitigation strategies for critical missions.
  • Conduct on-site and remote cyber risk assessments of enterprise systems, applications, and mission-critical infrastructures.
  • Apply NIST SP 800-30 risk assessment methodology, threat modeling techniques, and frameworks such as MITRE ATT&CK to evaluate vulnerabilities, threats, and risks.
  • Develop and present risk characterization reports, mitigation considerations, and recommendations to client leadership and system owners.
  • Create and manage task plans, assessment schedules, and execution strategies to ensure effective delivery of assessment activities.
  • Collaborate with multi-disciplinary teams of SMEs (cybersecurity, systems engineering, OT, supply chain, and mission assurance) to address enterprise risks.
  • Support the identification, analysis, and validation of complex security risks and associated vulnerabilities, including both technical and operational impacts.
  • Assist in the development of threat-informed mitigation strategies aligned with client enterprise assurance goals.
  • Implement data tagging and structured knowledge capture to enable proactive risk identification, trend analysis, and lessons-learned reuse.
  • Build analytic processes that leverage historical assessment data, external threat databases, and adversary TTPs to anticipate potential risks rather than solely reacting to identified vulnerabilities.
  • Provide expert consultation on risk acceptance, mitigation prioritization, and remediation planning to stakeholders.
  • Maintain awareness of emerging threats, vulnerabilities, adversary tactics, and best practices for defense in depth across the nuclear enterprise.

Required Qualifications:

  • 10+ years of experience in cybersecurity risk assessment, vulnerability analysis, or cyber mission assurance.
  • Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal standards.
  • Hands-on experience with threat modeling approaches and application of MITRE ATT&CK for risk evaluation.
  • Demonstrated ability to conduct complex cyber risk assessments and present findings to executive and technical audiences.
  • Proven ability to develop task plans, manage assessment milestones, and work independently or as part of a team.
  • Strong writing and briefing skills to produce risk reports, mitigation strategies, and decision support artifacts.

Preferred Qualifications:

  • Experience supporting national security organizations.
  • Familiarity with supply chain risk management (SCRM), insider threat analysis, or mission-critical system assurance.
  • Operational Technology (OT) and Systems Engineering (SE) experience in complex enterprise environments.
  • Knowledge of nuclear enterprise operations and mission dependencies.
  • Technical certifications such as Security+, CISSP, CISM, C-RMA, CAP, CEH, or OSCP.
  • Prior experience briefing and advising SES-level leadership or program executives.
  • Familiarity with tools supporting risk assessments and vulnerability analysis (e.g., Threat Modeling tools).

Work Environment:

  • Hybrid environment with headquarters-based work in D.C. and regular travel to client sites for on-site risk assessments.
  • Fast-paced, collaborative environment with cross-disciplinary SMEs (cybersecurity, engineering, OT, program management, and intelligence).
  • Requires agility, creativity, and strong interpersonal skills to interact effectively with diverse stakeholders across government, contractors, and mission partners.
  • Role demands adaptability to dynamic mission needs, shifting priorities, and classified environments.
  • Emphasis on teamwork, analytical rigor, and the ability to translate technical risks into mission/business impacts.

Technomics is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to protected status under applicable law, including disability and protected veteran status.