1

Senior Risk Analyst Jobs in Chevy Chase, MD (NOW HIRING)

Be Seen First

The Senior Cybersecurity Risk Analyst is a remote, senior individual contributor position within the Cybersecurity Governance, Risk, and Compliance (GR&C) team. This role owns the enterprise's cyber ...

New

Showing results 21-40

Senior Risk Analyst information

See Chevy Chase, MD salary details

$56.5K

$116K

$150.4K

How much do senior risk analyst jobs pay per year?

As of Aug 18, 2026, the average yearly pay for senior risk analyst in Chevy Chase, MD is $115,951.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,500.00 and $144,600.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a senior risk analyst?

To thrive as a Senior Risk Analyst, you need strong analytical skills, a solid grasp of risk assessment methodologies, and typically a degree in finance, economics, or a related field. Proficiency with risk management software, data analysis tools like Excel, and familiarity with regulatory frameworks such as Basel III or SOX is often required. Attention to detail, critical thinking, and effective communication are crucial soft skills for identifying, evaluating, and reporting risks. These competencies are vital for ensuring accurate risk identification and mitigation, supporting sound business decisions, and maintaining regulatory compliance.

How does a senior risk analyst typically collaborate with other departments to identify and mitigate risks?

Senior Risk Analysts regularly work with teams across the organization, such as compliance, finance, operations, and IT, to identify emerging risks and implement mitigation strategies. They often participate in cross-functional meetings, provide insights from data analysis, and help develop policies that address both regulatory requirements and business objectives. Building strong working relationships and communicating complex risk scenarios in an accessible way are key to ensuring coordinated risk management efforts. This collaborative approach not only helps in early detection of potential issues but also fosters a proactive risk culture within the company.

What is the difference between Senior Risk Analyst vs Risk Analyst?

AspectSenior Risk AnalystRisk Analyst
Required CredentialsBachelor's degree, often certifications like FRM or CRMBachelor's degree, some certifications like FRM or CRM
Work EnvironmentFinancial institutions, insurance companies, consulting firmsFinancial firms, corporations, government agencies
Employer & Industry UsageUsed across finance, insurance, and consulting sectorsCommon in finance, banking, and insurance industries

The main difference is that Senior Risk Analysts typically have more experience, advanced certifications, and handle more complex risk assessments. They often lead projects and mentor junior staff, whereas Risk Analysts focus on data collection, analysis, and supporting risk management processes.

Do risk analysts make good money?

Risk analysts typically earn a competitive salary that varies by industry, experience, and location. According to industry data, the median annual wage for risk analysts is around $80,000, with experienced professionals earning over $100,000. Certifications like FRM or CRM can enhance earning potential, and strong analytical skills are essential in this role.

How much does a senior risk analyst make in the US?

A senior risk analyst in the US typically earns between $80,000 and $120,000 annually, depending on experience, industry, and location. They often require strong analytical skills, knowledge of risk management tools, and relevant certifications such as FRM or CRM.

What does a senior risk analyst do?

A senior risk analyst evaluates potential risks that could impact an organization’s financial health, operations, or reputation. They analyze data, develop risk mitigation strategies, and use tools like risk assessment software to inform decision-making. This role often requires strong analytical skills, industry knowledge, and relevant certifications such as FRM or CRM.

What is the salary of a senior risk analyst?

The salary of a senior risk analyst typically ranges from $80,000 to $130,000 annually, depending on experience, industry, and location. They often require strong analytical skills and proficiency with risk management tools and software.

What cities near Chevy Chase, MD are hiring for Senior Risk Analyst jobs?

Cities near Chevy Chase, MD with the most Senior Risk Analyst job openings:

Infographic showing various Senior Risk Analyst job openings in Chevy Chase, MD as of August 2026, with employment types broken down into 1% As Needed, 91% Full Time, 6% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $115,951 per year, or $55.7 per hour.

Senior Cybersecurity Risk Analyst (Remote)

Johnson Service Group

Mclean, VA • On-site

$74.51 - $76.92/hr

Contractor

Medical, Dental, Vision, Retirement

This job post has expired today. Applications are no longer accepted.


Job description

Johnson Service Group is seeking for Cybersecurity Risk Analyst to work in VA.  This can be a remote position.


Purpose and Scope:

The Senior Cybersecurity Risk Analyst is a remote, senior individual contributor position within the Cybersecurity Governance, Risk, and Compliance (GR&C) team. This role owns the enterprise's cyber risk assessment work: evaluating activities and operational decisions across the enterprise and articulating the resulting cyber risk to business leadership against the enterprise's risk appetite.


The work is assessment heavy. The Senior Cybersecurity Risk Analyst examines technology and operational decisions for cyber risk that compliance-driven review alone does not surface, then frames that risk in business terms so GR&C and leaders can make informed accept, mitigate, or remediate decisions. The role is a twin to the Compliance function: where Compliance concentrates on the administrative work of demonstrating conformance to mandatory controls, this role works alongside it to drive cohesive cyber risk management across the enterprise regardless of which framework imposes a given requirement.
Consistent with the GR&C charter, the role helps protect Amentum against internal and external cyber threats and helps set, improve, and make recommendations on the enterprise security program based on industry best practices, regulations, policies, standards, and guidelines. GR&C surfaces and advises on risk so that business and operational owners can make informed decisions. This person must be technical enough to recognize risk in networking, cloud, endpoint, and identity decisions made by engineering and IT, and credible enough that their risk judgments carry weight with those teams and with leadership. The role acts on behalf of the entire enterprise rather than any single team, contract, or project, and brings attention to risk without hindering the business.


Essential Responsibilities:

  1. Conduct cyber risk assessments of activities and operational decisions across the enterprise, identifying risk to the confidentiality, integrity, and availability of enterprise systems and data.
  2. Articulate cyber risk to business and technical leadership in clear, decision-ready terms, framed against the enterprise's risk appetite.
  3. Take lead on cyber risk reviews across a range of assessment types, such as third-party cyber risk assessment, temporary risk acceptance review, and software risk review, and track enterprise artificial intelligence development as it relates to cyber risk.
  4. Work with the Compliance function to ensure that mandatory control interpretations do not leave other cyber risk unaddressed, and that risk treatment is coherent across frameworks.
  5. Evaluate the cyber risk implications of technology decisions, recognizing risk in networking, cloud, endpoint, and identity and access architectures that compliance-only review would not surface.
  6. Articulate when residual cyber risk exceeds the enterprise's appetite and specify the risk reduction required.
  7. Contribute a risk-posture perspective to enterprise scoping and architecture decisions, including the residual risk implications of carved-out certification environments and enclave boundaries.
  8. Improve the operational and procedural aspects of the Cyber GR&C function: assessment methodology, intake, risk articulation standards, evidence handling, and the consistency of risk judgments across the team.
  9. Maintain current knowledge of the cyber risk, threat, technology, and regulatory landscape, and bring that currency into assessments and into the team's collective capability.
  10. Travel up to 25 percent. Perform other position-related duties as assigned.


Minimum Requirements:

  • Must be a U.S. Citizen.
  • U.S. Remote-Telework role; must reside within the United States to work remotely.
  • Minimum of 8 years of hands-on cybersecurity experience, with demonstrated depth in evaluating real technology environments, not solely policy or audit administration.
  • Demonstrated ability to recognize cyber risk in networking, cloud, and endpoint technologies, and in identity and access management, well enough to assess the decisions of engineering and IT teams independently.
  • Demonstrated experience in enterprise risk management and in third-party or vendor cyber risk assessment.
  • Ability to articulate cyber risk to business leadership in decision-ready terms.
  • Current Security+ or an equivalent industry certification. (Certification establishes the baseline; demonstrated hands-on capability is weighted more heavily than credentials.)
  • Working knowledge of NIST publications and their relevance to cyber risk and compliance.
  • Strong written and verbal communication, including the ability to explain technical risk to non-technical stakeholders.
  • Self-starter able to operate autonomously on ambiguous problems with limited direction.
  • Ability to travel up to 25 percent.


Preferred and Differentiating Qualifications:

The following raise the ceiling for this role. Hands-on depth in the areas below is valued above the number of certifications or degrees held.

  • Senior certifications such as CISSP or CySA+, and an identity and access credential such as Microsoft SC-300.
  • Hands-on experience in a Microsoft Azure environment, including Microsoft 365; exposure to Azure Government (GCC High) is strongly preferred.
  • Direct experience assessing identity and access architectures, including Entra ID, B2B and external identity, conditional access, and privileged access.
  • Experience in U.S. Federal or Defense Industrial Base (DIB) environments, and familiarity from a risk perspective with CMMC, NIST SP 800-171/172, and DFARS, and with international frameworks such as UK Cyber Essentials, Australian Essential Eight, UK GDPR, and EU NIS2.
  • Familiarity with multi-framework risk management across standards such as ISO/IEC 27001 and with crosswalk approaches that achieve cohesive risk treatment across frameworks.
  • Experience improving GR&C operational processes: assessment methodology, intake, and risk reporting.
  • Bachelor's degree in a related field. A degree is not required and does not substitute for demonstrated hands-on capability; equivalent experience is fully acceptable.


Work Environment, Physical Demands, and Mental Demands:

Typical remote office environment with no unusual hazards. Occasional lifting to 50 pounds, constant sitting while using a computer terminal, constant use of sight while reviewing documents, constant use of speech and hearing for communication, constant mental alertness, planning and organizing skills, and the ability to work under deadlines.

Company Description

Johnson Service Group, Inc. (JSG) is a North American leader in the staffing and consulting services industry, with over 40 years of experience investing in people and companies. We offer medical, dental, vision, life insurance options, 401(k), weekly pay, and more.

Johnson Service Group (JSG) is an Equal Opportunity Employer. JSG provides equal employment opportunities to all applicants and employees without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, marital status, protected veteran status, or any other characteristic protected by law.


Johnson Service Group logo

About Johnson Service Group

Sourced by ZipRecruiter

Johnson Service Group, Inc. (JSG) is a leader in the staffing and consulting services industry, with over 39 years of experience investing in people and companies. We can be found locally in more than 30 offices throughout the United States and Canada and make connections throughout North America. JSG continues to work diligently to offer our clients and candidates world-class service and diversified offerings to fit their evolving needs. Which is why we have recently expanded our consulting services to include information technology consulting in addition to our wide array of staffing services.

Industry

Recruiting and staffing services

Company size

5,001 - 10,000 Employees

Headquarters location

Westmont, IL, US

Year founded

1984

Social media