1

Security Risk Manager Jobs in Washington, DC (NOW HIRING)

Risk Manager, Endpoint Security Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big ...

CGI Federal has an exciting opportunity for a Risk Manager within our Intel sector advancing the national security mission through cutting edge technology. You must have a passion for keeping pace ...

Traditional security and integrated risk programs have often been unsuccessful in unifying the need ... Work you'll do As an Insider Risk Manager on the Cyber team, you will be responsible for:

next page

Showing results 1-20

Security Risk Manager information

See Washington, DC salary details

$15

$29

$59

How much do security risk manager jobs pay per hour?

As of Jul 22, 2026, the average hourly pay for security risk manager in Washington, DC is $29.42, according to ZipRecruiter salary data. Most workers in this role earn between $20.67 and $33.22 per hour, depending on experience, location, and employer.

How much does a risk manager get paid?

A Security Risk Manager's average salary in the United States ranges from $80,000 to $130,000 annually, depending on experience, certifications, and industry. Senior roles or those with specialized skills can earn higher salaries, often exceeding $150,000. Compensation may also include bonuses and benefits related to security and risk management tools.

What is the difference between Security Risk Manager vs Security Analyst?

AspectSecurity Risk ManagerSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP (optional)
Work EnvironmentStrategic, managerial, policy-focusedOperational, monitoring, incident response
Employer & Industry UsageOrganizations with risk management frameworksIT departments, cybersecurity teams

The Security Risk Manager focuses on identifying, assessing, and mitigating security risks at a strategic level, often managing policies and frameworks. In contrast, the Security Analyst handles day-to-day security monitoring, incident response, and vulnerability assessments. Both roles require cybersecurity certifications, but the Risk Manager's role is more strategic, while the Analyst's role is more technical and operational.

What are some common challenges Security Risk Managers face when implementing new security policies within an organization?

Security Risk Managers often encounter challenges such as resistance to change from employees, balancing security needs with business operations, and ensuring compliance with industry regulations. Gaining buy-in from various stakeholders requires strong communication and education efforts, as some team members may perceive new protocols as disruptive. Additionally, Security Risk Managers must continuously assess evolving threats while adapting policies to keep the organization protected without hindering productivity.

What are the key skills and qualifications needed to thrive as a Security Risk Manager, and why are they important?

To thrive as a Security Risk Manager, you need a solid understanding of risk assessment, security protocols, and regulatory compliance, typically supported by a degree in cybersecurity, information security, or a related field. Familiarity with risk management frameworks (like ISO 27001 or NIST), security information and event management (SIEM) systems, and certifications such as CISSP or CISM are commonly required. Strong analytical thinking, communication, and leadership skills help you effectively identify vulnerabilities and collaborate with stakeholders. These competencies are crucial for proactively managing threats, ensuring organizational resilience, and maintaining regulatory compliance.

What is the highest salary for a risk manager?

The highest salary for a Security Risk Manager can exceed $150,000 annually, especially for those with extensive experience, advanced certifications like CISSP or CISM, and leadership roles in large organizations. Salaries vary based on industry, location, and the complexity of security environments managed.

What does a security risk manager do?

A security risk manager assesses and identifies potential security threats to an organization’s information systems and physical assets. They develop strategies, implement policies, and oversee security measures to mitigate risks, often using tools like risk assessment frameworks and security audits. Strong analytical skills and relevant certifications such as CISSP or CISM are typically required.

Can I make $200,000 a year in cyber security?

Security Risk Managers with extensive experience, advanced certifications, and specialized skills can potentially earn $200,000 or more annually, especially in high-demand industries or senior roles. Salary levels depend on factors such as location, company size, and individual expertise, with senior positions often offering higher compensation.
Infographic showing various Security Risk Manager job openings in Washington, DC as of July 2026, with employment types broken down into 89% Full Time, 10% Part Time, and 1% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $61,202 per year, or $29.4 per hour.
SAP Security Risk & Compliance Analyst (TS/SCI #26-126) with Security Clearance

SAP Security Risk & Compliance Analyst (TS/SCI #26-126) with Security Clearance

Strategic Analysis, Inc

Arlington, VA • On-site

Other

Posted 7 days ago


Job description

Strategic Analysis, Inc. is an Equal Opportunity Employer. SAP Security Risk & Compliance Analyst (TS/SCI #26-126) Job Code:26-126
Location:Arlington, VA
FT/PT Status:Full Time
Required Clearance:Top Secret w/ CI Poly
Salary Range:$170k-$185k The SAP Security Risk & Compliance Analyst serves as a trusted advisor responsible for assessing, evaluating, and improving the security posture of Special Access Programs (SAP), Sensitive Compartmented Information (SCI), and other classified programs. This position provides comprehensive security compliance, risk management, and assessment support by evaluating security programs against applicable government regulations, customer requirements, and industry best practices.
Working collaboratively with government representatives, program leadership, contractors, and multidisciplinary security teams, the analyst identifies security vulnerabilities, recommends corrective actions, and helps organizations maintain compliance while supporting mission success. This role requires strong analytical skills, sound risk-based decision making, exceptional communication abilities, and experience interpreting complex security requirements across multiple security disciplines. Responsibilities: ·    Conduct comprehensive security compliance reviews, inspections, assessments, and self-inspections for Special Access Programs (SAP), Sensitive Compartmented Information (SCI), and classified environments. ·    Evaluate security programs against applicable government directives, contractual requirements, security standards, and organizational policies. ·    Analyze security findings to identify vulnerabilities, trends, and systemic risks while developing practical risk mitigation recommendations. ·    Prepare detailed compliance reports, executive summaries, risk assessments, corrective action plans, and briefing materials for leadership. ·    Advise program managers, security professionals, and organizational leadership regarding security compliance requirements, inspection readiness, and risk management strategies. ·    Assess the effectiveness of security controls across personnel, physical, information, industrial, operational, and cybersecurity disciplines. ·    Support incident response activities by evaluating security incidents, conducting root cause analysis, documenting findings, and recommending corrective actions. ·    Monitor corrective actions through completion and verify resolution of identified compliance deficiencies. ·    Interpret and apply government security regulations, contractual requirements, and customer guidance to support consistent program execution. ·    Develop, maintain, and improve security policies, standard operating procedures, compliance guidance, and risk management processes. ·    Provide consultation to internal and external stakeholders regarding security requirements, inspection preparation, and continuous compliance initiatives. ·    Develop and present executive briefings, customer presentations, and security training supporting compliance awareness and organizational readiness. ·    Identify opportunities to improve inspection processes, reporting methodologies, security metrics, and operational efficiencies. ·    Support multidisciplinary security initiatives involving personnel security, physical security, information security, industrial security, facility security, and cybersecurity. Required Qualifications:  ·    Active TS/SCI with current CI Poly
·    7+ years' experience in the following areas:
o    Supporting Special Access Programs (SAP), SCI, or other classified security programs. o    Conducting compliance inspections, security assessments, audits, or program reviews. o    Performing security risk analysis and developing risk-based recommendations. o    Preparing formal reports, executive briefings, and corrective action documentation. o    Interpreting and applying government security policies, regulations, and contractual security requirements. ·    Demonstrated ability to communicate effectively with executive leadership, government representatives, and technical personnel. ·    Strong analytical, organizational, investigative, and problem-solving skills. ·    Ability to independently manage multiple assessments and competing priorities. Education & Experience:  One of the following is required:
·    Bachelor's degree in Criminal Justice, Intelligence Studies, Cybersecurity, Information Assurance, Homeland Security, Business Administration, or a related field; OR ·    Associate degree with additional directly related experience; OR ·    Completion of military, government, or industry security training programs with progressively responsible experience supporting classified security programs; OR ·    An equivalent combination of education, specialized training, professional certifications, and directly related experience. Relevant security certifications, government training, military education, and demonstrated expertise may be substituted for a formal degree.
  Strategic Analysis, Inc. is an Equal Opportunity employer and is committed to non-discrimination in employment. All qualified applicants will receive consideration for employment without regard to race, color, religions, sex (including pregnancy, sexual orientation, or gender identity), national origin, disability (physical or mental), age (40 or older), protected veteran status, genetic information (including family medical history) or any other characteristic protected by law. This policy includes but is not limited to the following employment actions: recruitment, hiring, firing, promotion, demotion, compensation, fringe benefits, training, mentoring and sponsorship programs.