1

Senior Information Security Risk Analyst Jobs in Virginia

Senior IT Security Engineer

Chesapeake, VA · On-site

$92K - $126K/yr

The Senior IT Security Engineer works closely with the IT Security Administrator, IT Operations ... GRC (Governance, Risk, and Compliance) • Direct the organization's risk management program ...

Senior IT Security Engineer

Chesapeake, VA · On-site

$92K - $126K/yr

The Senior IT Security Engineer works closely with the IT Security Administrator, IT Operations ... GRC (Governance, Risk, and Compliance) • Direct the organization's risk management program ...

next page

Showing results 1-20

Senior Information Security Risk Analyst information

See Virginia salary details

$31

$57

$74

How much do senior information security risk analyst jobs pay per hour?

As of Aug 11, 2026, the average hourly pay for senior information security risk analyst in Virginia is $57.95, according to ZipRecruiter salary data. Most workers in this role earn between $45.05 and $65.05 per hour, depending on experience, location, and employer.

What is the difference between Senior Information Security Risk Analyst vs Information Security Analyst?

AspectSenior Information Security Risk AnalystInformation Security Analyst
CertificationsCISSP, CISA, CRISCCISSP, Security+, CEH
Work EnvironmentFocus on risk assessment, policy development, and strategic planningImplementing security measures, monitoring, and incident response
Employer & Industry UsageFinancial, healthcare, and large enterprises with complex security needsVariety of industries, including tech, retail, and government

Senior Information Security Risk Analysts typically handle advanced risk assessments and strategic security planning, often requiring certifications like CISSP or CISA. Information Security Analysts focus on implementing security controls and monitoring systems. Both roles are vital in maintaining organizational security but differ in scope and seniority.

How does a senior information security risk analyst typically collaborate with other departments to manage organizational risk?

A Senior Information Security Risk Analyst regularly works with various departments such as IT, legal, compliance, and business units to identify and address security risks. This collaboration often includes conducting risk assessments, reviewing new projects for potential vulnerabilities, and providing guidance on security best practices. Effective communication skills are essential, as the analyst must translate technical risks into business impacts and help teams implement appropriate controls. Close teamwork ensures that security is integrated into all business processes and that the organization remains compliant with relevant regulations.

What are the key skills and qualifications needed to thrive as a senior information security risk analyst?

A Senior Information Security Risk Analyst requires a deep understanding of cybersecurity frameworks, risk assessment methodologies, and regulatory compliance, usually backed by a degree in information security or a related field. Familiarity with tools like risk management software (e.g., Archer, RSA), SIEM systems, and certifications such as CISSP, CISM, or CRISC are typically expected. Exceptional analytical thinking, attention to detail, and strong communication skills set top performers apart in this role. These competencies are crucial to effectively identify, evaluate, and mitigate security risks, ensuring the organization's information assets remain protected against evolving threats.

What does a senior information security risk analyst do?

A Senior Information Security Risk Analyst is responsible for identifying, evaluating, and mitigating risks to an organization's information systems and data. They conduct risk assessments, develop security policies, and recommend measures to protect against cyber threats and vulnerabilities. Additionally, they work closely with IT and business teams to ensure compliance with regulations and industry standards, and they often play a key role in incident response and security awareness training.
What are popular job titles related to Senior Information Security Risk Analyst jobs in Virginia? For Senior Information Security Risk Analyst jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Senior Information Security Risk Analyst jobs in Virginia look for? The top searched job categories for Senior Information Security Risk Analyst jobs in Virginia are:
What cities in Virginia are hiring for Senior Information Security Risk Analyst jobs? Cities in Virginia with the most Senior Information Security Risk Analyst job openings:
Infographic showing various Senior Information Security Risk Analyst job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 20% Part Time, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $120,534 per year, or $57.9 per hour.

Senior Information Security Analyst

Data Systems Analysts, Inc.

Fairfax, VA • On-site

Full-time

Posted 27 days ago


Job description

DSA is hiring a Senior Information Security Analyst. This is a full-time position supporting a customer in the DC Metro area with a HYBRID Schedule. This position supports the Environmental Protection Agency (EPA). DSA is the Prime and has been working with this customer on this contract for more than 13 years. It is a dynamic team with a passion for supporting Federal programs that serve U.S. citizens.
Location is Hybrid: Allows the candidate the ability to work onsite at DSA or customer site with potential for telework. DSA work locations include Fairfax, VA. 
Work Location is flexible with telework as approved. The ability to work onsite each week is required. Core work hours dedicated to DSA and our direct customers are 8 am est to 5 pm est.
The Environmental Protection Agency (EPA) Office of Information Security and Privacy (OISP) is responsible for developing and maintaining agency-wide information security and privacy programs; developing and maintaining information security and privacy policies, procedures, and control techniques; training personnel with significant information security responsibilities and assisting senior agency officials with information security and privacy responsibilities.
The Senior Information Security Analyst will be an integral part of a team responsible for supporting the development and maturation of an Agency-wide information security (InfoSec) program for a large civilian Federal agency. The candidate will serve as a subject matter expert with regards to the Risk Management Framework (RMF) and all associated information security policies and procedures and should possess in-depth knowledge of applying, selecting and testing the NIST family of security controls.

Primary Responsibilities: 

  • Advising senior-level stakeholders on InfoSec initiatives including compliance, awareness and training, and security operations.
  • Leading Independent Validation and Verification (IV&V) efforts on security authorization/ATO packages to ensure compliance with agency requirements.
  • Leveraging the existing Governance, Risk, and Compliance (GRC) tool, Telos Xacta (or an alternate like CSAM or RSA Archer), to track and reconcile findings from assessments, audits, and vulnerability scans.
  • Coordinating government data calls (FISMA, FMFIA, BDR, etc.) and monthly reports.
  • Assessing the effectiveness of the InfoSec and privacy training program and leading the collection, analyzing, and presentation of enterprise-level InfoSec performance metrics.
  • Managing InfoSec Program POA&Ms, including advising on remediation efforts.
  • Working closely with senior agency security officials, system owners, information system security officers (ISSOs) and other stakeholders to advise and implement security solutions.
  • Identify opportunities for efficiencies in work process and innovative approaches.
  • Participating in team problem solving efforts and offer ideas to solve client issues.
  • Conducting relevant research, data analysis, and developing reports.
  • Preparing and assisting in the development of policy and procedures.
  • Implementing processes and procedures to monitor risk across programs / projects.
  • Preparing briefings to the executive team to debrief the results of studies, analyses, and plans.
  • Assisting the client leadership in reviewing monthly project progress, documenting issues, and monitoring resolution.


Required Qualifications:

  • Ability to obtain a Public Trust. 
  • Bachelor's degree in information technology or related field and 8 years of relevant IA experience. May substitute security certification (e.g. CISSP) for 2 years of experience.
  • 3+ years in a leadership role
  • Strong data analysis skills.
  • Excellent written and verbal communication skills.
  • Possess in-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 4 security controls.
  • Possess in-depth knowledge of NIST 800-37 Risk Management Framework.
  • Experience with a Governance, Risk and Compliance tool (e.g., Xacta, RSA Archer, CSAM or eMASS).
  • Excellent attention to detail.
  • Ability to handle and prioritize multiple tasks and deadlines.


Desired Qualifications:

  • Advanced level cybersecurity certification (e.g., CompTIA CISM, ISC2 CISSP)
  • In-depth knowledge of applying, selecting and testing the NIST 800-53 Rev 5 security controls

#DSA209

#LI-CW1