1

Security Risk Analyst Jobs in Washington, DC (NOW HIRING)

... security consulting, personal protection solutions and global medical concierge capabilities ... The ideal candidate is a seasoned analyst with deep expertise in both corporate risk and financial ...

Their work depends on a Technical Security Risk Analyst joining the team to support Government activities in McLean, VA. \n \n \n As a Technical Security Risk Analyst supporting the customer, you ...

Cybersecurity and Risk Analyst

Arlington, VA · On-site

$120K - $135K/yr

The Cybersecurity and Risk Analyst defines system security requirements for IT systems and applications and conducts comprehensive risk assessments of management, operational, and technical security ...

Showing results 41-60

Security Risk Analyst information

See Washington, DC salary details

$11

$57

$79

How much do security risk analyst jobs pay per hour?

As of Aug 6, 2026, the average hourly pay for security risk analyst in Washington, DC is $57.10, according to ZipRecruiter salary data. Most workers in this role earn between $46.30 and $68.08 per hour, depending on experience, location, and employer.

What does a security risk analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a security risk analyst?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges security risk analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.
What job categories do people searching Security Risk Analyst jobs in Washington, DC look for? The top searched job categories for Security Risk Analyst jobs in Washington, DC are:
Infographic showing various Security Risk Analyst job openings in Washington, DC as of August 2026, with employment types broken down into 79% Full Time, and 21% Contract. Highlights an 79% In-person, 5% Hybrid, and 16% Remote job distribution, with an average salary of $118,762 per year, or $57.1 per hour.

Security Governance Risk & Compliance (GRC) Analyst with Security Clearance

Virtru Corporation

Washington, DC • On-site

$130K - $170K/yr

Other

Medical, Dental, Vision, Retirement, PTO

Posted 14 days ago


Job description

About Virtru: While the rest of the security industry obsesses over locking data down to prevent it from being lost or stolen, we're doing something fundamentally different at Virtru. We're setting data free so that you can intentionally share it with others, but without sacrificing security, privacy, or control. We've created both a suite of powerful data protection applications and an open platform that's sparking an ecosystem of innovation. Through the Trusted Data Format (TDF) open standard, we're not just protecting data; we're creating a new paradigm where security enables sharing rather than preventing it. Think of us as the Android of data protection: a robust platform with an open core that developers and partners can build upon, coupled with our own best-in-class applications that showcase what's possible when you reimagine security from the ground up. Backed by Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global, we're helping Fortune 500 companies and government agencies discover that true data security means having the freedom to share, collaborate, and innovate - without compromise. Compensation: $130,000-$170,000/year Team & Position Details: Here at Virtru you'll help build a cutting edge security compliance program aligned with FedRAMP, SOC 2, PCI, HIPAA, GDPR, and just about any other security/privacy framework you can think of, whilst getting your hands on some of today's most important tools and tech like Kubernetes, GCP, AWS, Terraform. We put a high value on input from everyone on our team. Your voice will have a significant impact. With a constantly growing customer base, there is no shortage of challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service. As a GRC Analyst at Virtru, you will be the primary point of contact for compliance-related inquiries. You will lead and manage the organization's efforts to achieve and maintain CMMC compliance, by conducting gap analyses and developing a roadmap to address compliance requirements. You will also play a vital role in supporting our existing FedRAMP, SOC2, and PCI DSS compliance. Get in touch if you are excited to help us grow into a world-class security compliance program. As a Security Governance Risk & Compliance (GRC) Analyst, your responsibilities will include: * Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure and Software as a Service (SaaS) services (GCP, AWS, GitHub, Okta, etc). * Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services. * Conduct risk assessments across business units and processes. Identify risk findings and recommend remediation and risk mitigation strategies. * Participate in incident response (IR) activities, providing risk analysis and remediation support as needed. * Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders. * Incorporate CMMC certification into Virtru's slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI). * Facilitate the third-party vendor on-boarding and annual review process by evaluating the security of current and prospective partners. * Enhance the team with your individualism, spirit, and love of learning.
Skills that will help you thrive in this role: * Minimum of 5+ years of information security, IT audit and/or IT Risk Management, or GRC Analyst/Engineer experience * Deep understanding of at least few of the following: CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks * Technical acumen. Strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc) and SIEM tools (Datadog, Splunk) * You're a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization * Have experience training and coaching teams to become better security and privacy practitioners * Like working on an autonomous agile team. At Virtru, you will have ownership of security, but you'll collaborate with everyone to make sure we produce and implement the right solutions * Ability to resolve conflicts and drive issues to completion. * Work independently with little or no supervision while maintaining a high level of efficiency.
Virtruvian qualities that will set you up for success: * Thinking outside of the box to respectfully challenge your teammates and managers in the pursuit of excellence * Strong sense of urgency with an action-oriented mindset * Able to collaborate and adapt to shifting priorities as business needs evolve * Comfortable with asynchronous communication including slack, email, zoom, etc.
Perks & Benefits: At Virtru, we believe people do their best work when their wellbeing is put first. This is why we make your wellbeing our priority with a thoughtful and holistic program that encompasses Occupational, Mental, Social, Physical, and Environmental Wellness by offering benefits such as... * A Flexible PTO policy - we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge. * A $1,500 annual Learning & Development Stipend focused on providing you the resources to continually learn and professionally grow. * Frequent company-sponsored team celebrations that provide ample opportunities to connect with teammates and be social! * Access to an Employee Assistance Program * Access to Headspace, a mental health app tailored to your specific needs. * A flat 3% contribution to your retirement account * A high degree of flexibility - Have an appointment, errand, or family emergency to take care of? Hop to it! We give you the time and space to take care of you and your own first.
In addition to wellbeing, Virtru places a strong emphasis on diversity, equity, inclusion, and belonging. Our DB&I Council is dedicated to fostering an inclusive workplace and making the psychological safety of each and every one of our teammates a top priority. Additional perks include: * Competitive compensation * Generous parental, medical, and bereavement policies * Uncapped commissions for Sales roles * 401K contribution and stock options * Full medical, dental, and vision benefits * New Hire Swag and IT Welcome boxes * Structured semi-annual 360° performance reviews
Virtru is committed to building an inclusive environment for people of all backgrounds and everyone is encouraged to apply. Virtru is an Equal Opportunity Employer and does not discriminate on the basis of race, color, gender, religion, disability, national origin, protected veteran status, age, or any other status protected by applicable national, federal, state, or local law.