2

Remote Cyber Security Risk Analyst Jobs in Washington, DC

This role involves conducting on-site and remote cyber risk assessments, developing mitigation ... You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans ...

Hybrid - onsite and remote Hours: 40 hrs a week Security Clearance: Full background check, criminal - credit - fingerprinting Responsibilities * Support the operation of the risk function by ...

Hybrid - onsite and remote Hours: 40 hrs a week Security Clearance: Full background check, criminal - credit - fingerprinting Responsibilities * Support the operation of the risk function by ...

Hybrid - onsite and remote Hours: 40 hrs a week Security Clearance: Full background check, criminal - credit - fingerprinting Responsibilities * Support the operation of the risk function by ...

Hybrid - onsite and remote Hours: 40 hrs a week Security Clearance: Full background check, criminal - credit - fingerprinting Responsibilities * Support the operation of the risk function by ...

Perform risk assessments based on Federal guidelines and industry best practices * Assist teams in ... Support remediation of control-based POA&Ms by analyzing control weaknesses, recommending ...

next page

Showing results 1-20

Remote Cyber Security Risk Analyst information

See Washington, DC salary details

$48.7K

$112.6K

$169.9K

How much do remote cyber security risk analyst jobs pay per year?

As of Sep 15, 2026, the average yearly pay for remote cyber security risk analyst in Washington, DC is $112,580.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,000.00 and $130,800.00 per year, depending on experience, location, and employer.

What does a remote cyber security risk analyst do?

A Remote Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating potential security threats to an organization's information systems while working from a remote location. They evaluate existing security measures, analyze vulnerabilities, and recommend improvements to reduce risks. Additionally, they monitor for security breaches, conduct risk assessments, and ensure compliance with relevant regulations and policies. Their work helps protect sensitive data and maintain the integrity of technology systems.

What are the key skills and qualifications needed to thrive as a remote cyber security risk analyst, and why are they important?

To thrive as a Remote Cyber Security Risk Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and typically a degree in cybersecurity or a related field. Familiarity with tools like risk management frameworks (e.g., NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP or CISA is highly beneficial. Strong analytical thinking, attention to detail, and effective written and verbal communication skills are essential for collaborating remotely and conveying risk findings to stakeholders. These skills and qualities are crucial for identifying, evaluating, and mitigating cyber risks to protect organizational assets in a distributed work environment.

How does a remote cyber security risk analyst typically collaborate with other departments in a fully remote environment?

Remote Cyber Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks across the organization. Collaboration is usually facilitated through virtual meetings, secure communication platforms, and shared documentation tools. Analysts provide guidance on security best practices, participate in incident response efforts, and help ensure compliance with regulatory standards. Effective communication and proactive engagement with stakeholders are essential for success in this remote role.

What is the difference between Remote Cyber Security Risk Analyst vs Remote Cyber Security Analyst?

AspectRemote Cyber Security Risk AnalystRemote Cyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, complianceMonitoring, threat detection, incident response
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, consulting firms, enterprises

The Remote Cyber Security Risk Analyst focuses on identifying and managing security risks, ensuring compliance, and developing policies. In contrast, the Remote Cyber Security Analyst primarily monitors systems for threats, investigates incidents, and implements security measures. Both roles require similar certifications and often work in overlapping environments, but their core responsibilities differ in scope and focus.

What are popular job titles related to Remote Cyber Security Risk Analyst jobs in Washington, DC?

For Remote Cyber Security Risk Analyst jobs in Washington, DC, the most frequently searched job titles are:

What job categories do people searching Remote Cyber Security Risk Analyst jobs in Washington, DC look for?

The top searched job categories for Remote Cyber Security Risk Analyst jobs in Washington, DC are:

Infographic showing various Remote Cyber Security Risk Analyst job openings in Washington, DC as of September 2026, with employment types broken down into 50% Full Time, and 50% Part Time. Highlights an 100% Remote job distribution, with an average salary of $112,580 per year, or $54.1 per hour.

Senior Cybersecurity Analyst

Falls Church, VA • On-site, Remote

Tlingit Haida Tribal Business Corporation
Guided Missile and Space Vehicle Manufacturing • 1 - 5K employees

$91K - $124K/yr

Full-time

This job post has expired today. Applications are no longer accepted.


Job description


Job Title: Senior Cybersecurity Analyst

Work Location: Remote or hybrid remote if near CO/VA offices

Labor Category: Exempt

Clearance Level: Secret

Travel: Up to 20%

Pay Rate: $91,000 - $124,000


About the Role 

This role works collaboratively with IT leadership, systems administrators, business units, compliance personnel, vendors, auditors, and other stakeholders, the Senior Cybersecurity Analyst will help establish and maintain a risk-based, defense-in-depth cybersecurity program that supports organizational operations, contractual obligations, regulatory requirements, and the protection of critical information assets. The position requires a combination of strong technical cybersecurity expertise, analytical and investigative capabilities, regulatory and compliance knowledge, documentation skills, and the ability to communicate cybersecurity risk effectively to both technical and non-technical audiences.

What You'll Be Doing

  • Monitor, investigate, and respond to cybersecurity alerts, incidents, vulnerabilities, and threats across enterprise, endpoint, cloud, network, and application environments.
  • Support compliance with NIST SP 800-171, CMMC, and applicable federal/DoD cybersecurity requirements, including protection of CUI and FCI.
  • Implement, assess, document, and continuously monitor cybersecurity controls and maintain SSPs, POA&Ms, policies, procedures, and compliance evidence.
  • Conduct cybersecurity risk assessments, vulnerability assessments, and security reviews; prioritize findings and coordinate remediation efforts.
  • Support internal and external audits, CMMC assessments, customer reviews, and other cybersecurity compliance activities.
  • Analyze security logs, alerts, and threat intelligence using tools such as SIEM, EDR, Microsoft 365, Azure, Entra ID, firewalls, and endpoint security platforms.
  • Participate in incident response activities, including investigation, containment, remediation, recovery, documentation, and post-incident reviews.
  • Assess and improve security configurations, system hardening, patch management, endpoint protection, network security, cloud security, and data protection controls.
  • Support identity and access management, including MFA, Conditional Access, privileged access, least privilege, RBAC, and periodic access reviews.
  • Evaluate security posture across Microsoft 365, GCC High, Azure, Entra ID, Active Directory, and other enterprise platforms.
  • Support third-party/vendor risk management, technology security reviews, change management, and cybersecurity assessments for new systems and services.
  • Develop cybersecurity metrics, dashboards, risk registers, vulnerability reports, and compliance reporting for leadership.
  • Develop and maintain cybersecurity policies, standards, procedures, incident response plans, and security documentation.
  • Support security awareness programs, phishing simulations, cybersecurity training, and organization-wide security initiatives.
  • Provide cybersecurity guidance to employees, IT teams, leadership, vendors, auditors, and assessors.
  • Stay current on emerging threats, vulnerabilities, regulations, cybersecurity frameworks, and industry best practices.
  • Serve as a senior cybersecurity resource and escalation point for complex security, risk, compliance, and incident response matters; mentor junior team members as appropriate.
  • Participate in after-hours incident response or emergency cybersecurity support as required.
  • Perform other cybersecurity, information assurance, risk management, and compliance duties as assigned.

What We're Looking For

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; equivalent education, certifications, training, and experience may be considered.
  • 7+ years of cybersecurity, information security, information assurance, risk management, or related IT security experience, including 3+ years in a senior-level cybersecurity role within a complex enterprise environment.
  • Strong knowledge of NIST SP 800-171, CMMC, and federal/DoD contractor cybersecurity requirements, including protection of CUI and FCI.
  • Experience with SSPs, POA&Ms, security controls, compliance evidence, risk assessments, audits, and CMMC readiness/assessments.
  • Experience with vulnerability management, including scanning, analysis, prioritization, remediation, and validation.
  • Hands-on experience with SIEM, EDR, endpoint security, firewalls, identity/security monitoring tools, and cybersecurity incident response.
  • Experience securing Microsoft 365/GCC High, Azure, Entra ID, and Active Directory, including MFA, Conditional Access, RBAC, privileged access, and identity security.
  • Working knowledge of Windows Server, endpoint technologies, network infrastructure, TCP/IP, VLANs, firewalls, VPNs, virtualization, cloud services, and network security.
  • Experience with endpoint protection, EDR, encryption, system hardening, secure configurations, access controls, patch management, and configuration management.
  • Experience conducting cybersecurity risk assessments, control gap analyses, security reviews, and risk mitigation activities.
  • Ability to translate technical and regulatory requirements into practical security controls, procedures, technical requirements, and remediation plans.
  • Experience with vendor/third-party risk management, cybersecurity policies and procedures, incident response planning, and security documentation.
  • Strong analytical, investigative, problem-solving, communication, and organizational skills, with the ability to manage multiple cybersecurity priorities.
  • Ability to work independently and collaborate effectively with IT teams, leadership, business units, vendors, auditors, assessors, and other stakeholders.
  • Ability to provide senior-level technical guidance and mentoring to IT and cybersecurity personnel.
  • Ability to support after-hours incident response or emergency cybersecurity activities as required.
  • Must be legally authorized to work in the United States and meet all applicable U.S. Government/DoD background, eligibility, and security requirements.
  • Must possess or be able to obtain and maintain an active U.S. Government security clearance at the level required for assigned contracts.

Physical Demands & Work Environment

  • Ability to work in an office environment with prolonged periods of sitting and computer use.
  • Ability to travel domestically up to 20% as business needs require.
  • Ability to lift up to 25 pounds occasionally.