Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Risk Analyst

Eclaro

Cybersecurity Risk Analyst

ECLARO is looking for a Cybersecurity Risk Analyst for our client in Manassas, VA. ECLARO's client is a leading technology solutions provider, collaborating with customers to manage their needs and achieve success in their business goals. If you're up to the challenge, then take a chance at this rewarding opportunity!

Position Overview:

  • Seeking a results-driven and analytically minded Cybersecurity Risk Analyst to serve a dual mission within the Cybersecurity team: owning Third-Party Risk Management (TPRM) operations and supporting the organization's broader Cyber Governance & Risk.
  • The successful consultant will be the Subject Matter Expert (SME) for TPRM program, currently administered through the SAFe platform, and will be equally responsible for insider threat monitoring, custom cybersecurity awareness training development, awareness metrics reporting, Disaster Recovery (DR) coordination, and executive-level risk reporting.
  • This role demands a practitioner who can translate technical risk data into clear business intelligence, build compelling Power BI dashboards and reports for leadership, and collaborate effectively across IT, Operations, and Procurement.
  • The ideal consultant brings hands-on TPRM experience, strong data visualization skills, and a passion for building programs that protect members, infrastructure, and operational continuity.

Responsibilities:

  • Third-Party Risk Management (TPRM) Operations:
    • Evaluate new and prospective vendors through structured cybersecurity risk assessments to determine cyber clearance eligibility before contract execution or system access.
    • Serve as the primary SME and platform administrator for TPRM solution (SAFe), maintaining data integrity, configuring risk workflows, and driving continuous platform optimization.
    • Maintain and continuously update the enterprise vendor inventory, tracking risk tier classification, assessment status, contract dates, and lifecycle position for all third parties.
    • Execute structured vendor onboarding workflows, including security due diligence, contractual security requirements review, and formal risk acceptance documentation.
    • Monitor and triage automated vendor security alerts generated through SAFe; analyze alert severity and communicate actionable risk intelligence to appropriate business and security stakeholders on time.
    • Manage vendor offboarding procedures, ensuring complete termination of data and system access, contractual closure, and record retention compliance.
    • Conduct periodic reassessments and ongoing monitoring of in-scope vendors according to risk tiering methodology and assessment calendar.
    • Develop and maintain Power BI dashboards and reports presenting vendor risk metrics, assessment completion rates, open risks, and trend analysis for leadership and risk committees.
  • Cyber Governance, Risk & Insider Threat:
    • Support Insider Threat program by monitoring behavioral risk indicators, documenting escalation procedures, and maintaining governance records.
    • Assist in the preparation of cybersecurity governance artifacts, including risk registers, policy documents, control metrics, and compliance reports aligned to NIST CSF and applicable regulatory frameworks.
    • Generate periodic cyber risk reports for IT leadership, audit, and regulatory audiences, summarizing risk posture, open findings, control gaps, and remediation status.
    • Build and maintain Power BI dashboards to visualize governance and risk metrics, control effectiveness trends, and risk KPIs across the organization.
    • Participate in risk assessment activities and support internal control evaluations relevant to IT environments.
  • Cybersecurity Awareness Training & Metrics Reporting:
    • Design and develop custom cybersecurity awareness training content tailored to the specific business operations and risk profiles of individual departments (e.g., Operations, Finance, Customer Engagement, Engineering).
    • Assisting in collaborating with department leads to schedule, deploy, and track training completion across the organization.
    • Assist in administering phishing simulation campaigns; analyze results and produce actionable reports identifying at-risk user populations and trending behaviors.
    • Build and maintain Power BI dashboards tracking cybersecurity awareness KPIs, including training completion rates, phishing click-through rates, repeat offender trends, and department-level performance over time.
    • Assist in preparing and presenting monthly and quarterly Cyber Awareness Reports for leadership, translating program metrics into clear risk narratives and recommended actions.
    • Stay current with evolving social engineering tactics, threat actor techniques, and regulatory guidance (e.g., CISA advisories) to keep training content timely and impactful.
    • Evaluate training platform effectiveness and recommend enhancements or alternative tools to improve learner engagement and retention.
  • Disaster Recovery (DR) Coordination & Reporting:
    • Coordinate and facilitate Disaster Recovery testing exercises for core business applications in collaboration with technical SMEs across IT Operations.
    • Develop DR test plans, scoping documents, timelines, and stakeholder communication plans in coordination with system owners and application custodians.
    • Document test execution results, capture gaps or failures, and produce comprehensive post-exercise reports for IT leadership and executive stakeholders.
    • Track remediation of identified DR gaps to closure; maintain updated DR runbooks, test records, and lessons-learned logs.
    • Assist in the broader Business Continuity Planning (BCP) process as it pertains to cybersecurity resilience and recovery readiness.
  • SharePoint Intranet & Stakeholder Dashboard Publishing:
    • Design, build, and maintain dedicated SharePoint sites and pages serving as the centralized hub for cybersecurity communications, dashboards, and reporting artifacts.
    • Embed and publish Power BI reports directly into SharePoint pages, ensuring stakeholders can access live, role-appropriate dashboards without requiring Power BI licensing or direct platform access.
    • Develop audience-specific SharePoint pages tailored to the information needs of distinct stakeholder groups, including IT leadership, department managers, executive sponsors, audit / compliance teams, and general staff, applying role-based access controls and page permissions accordingly.
    • Maintain separate SharePoint views for TPRM metrics, cyber awareness training completion and phishing stats, governance and risk posture indicators, and DR testing results, ensuring content remains current and accurate.
    • Collaborating with department heads and business units leads to understanding their reporting consumption preferences and translating those needs into intuitive, self-service SharePoint dashboard pages.
    • Establish and enforce a publishing cadence (monthly, quarterly) for dashboard refreshes and narrative updates aligned to governance reporting calendar.
    • Apply SharePoint governance best practices, including naming conventions, version control, content lifecycle management, and access review procedures.
    • Coordinate with IT infrastructure and Microsoft 365 administrators as needed for site provisioning, permissions architecture, and integration with Power BI Service workspaces.
  • Internal:
    • Communicate within the assigned department and with other departments to ensure understanding and achievement of department and organization goals and standards; provide the highest level of service to internal customers; exchange information and ideas for improvements in the department and organization; coordinate customer service activities, plans, and requirements; and improve the knowledge base of company policies, procedures, and programs.
    • Participate in staff meetings to develop and implement present and plans; monitor and revise strategies and programs; confer on mutual issues; exchange information; and share in the determination and formulation of policies and procedures.
  • External:
    • Provide the highest level of quality customer service to external customers through various forms of communication as well as proactive and professional relationships with customers, the business community, and the general public.

Required Qualifications:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or a closely related field.
  • Equivalent combination of education and demonstrated professional experience will be considered.
  • Minimum 3-5 years of progressive experience in cybersecurity, IT risk management, or a related GRC discipline.
  • Demonstrated experience operating or administering a formal TPRM program or third-party risk platform.
  • Proven ability to build Power BI reports and dashboards that translate security data into executive-ready metrics.
  • Experience developing and delivering cybersecurity awareness training and reporting program metrics.
  • Familiarity with Disaster Recovery planning, tabletop exercises, or DR test coordination.
  • Power BI Report & Dashboard Development
  • Vendor Risk Assessment & Lifecycle Management
  • TPRM Platform Administration (SAFe or Equivalent)
  • GRC Documentation & Control Mapping
  • Security Questionnaire Evaluation (SIG, Custom)
  • Phishing Simulation Analysis & Reporting
  • Cyber Awareness Metrics Tracking & Presentation
  • DR Test Planning, Facilitation & Post-Exercise Reporting
  • Insider Threat Monitoring Support
  • Advanced Microsoft Excel (Pivot Tables, Data Models)
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity Risk Analyst in Manassas Park, VA vacancy
  • $99k - $225k

    Enterprise Cybersecurity Vulnerability Risk AnalystThe Opportunity:Cyber threats are everywhere, and vulnerabilities can create risk quickly when findings...  ...action.As a Vulnerability Exception and Deferral Analyst on our Enterprise IT and Cyber Risk team, you’ll manage the... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    5 days ago
  • $100k - $150k

     ...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location: 50 miles of McLean, Virginia Position is contingent upon contract award Ops Tech Alliance is seeking a Cybersecurity Risk Analyst to support enterprise cybersecurity... 
    Suggested
    Contract work

    OPS TECH ALLIANCE LLC

    McLean, VA
    4 days ago
  • $99k - $225k

    Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    4 days ago
  • $85k - $110k

     ...innovation and customer success. Responsibilities An Average Day:As the Cybersecurity Analyst I you will enhance the organization’s cybersecurity posture by performing comprehensive risk assessment and improving incidents response protocols. In this role you will... 
    Suggested
    Immediate start

    AMERICAN SYSTEMS

    Manassas, VA
    1 day ago
  •  ...MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x7x365 cybersecurity support to one of the most coveted targets in the world.  The Cyber Incident Response Analyst... 
    Suggested
    Shift work
    Night shift
    Day shift
    Afternoon shift

    MANTECH

    McLean, VA
    6 hours ago
  • $99k - $225k

    Enterprise Cybersecurity AnalystThe Opportunity:Support mission-critical cybersecurity operations for Booz Allen's Impact Level 5 (IL5) environment...  ...supporting vulnerability scanning, remediation workflows, or risk assessments Ability to collaborate with IT, risk, and... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    1 day ago
  • $86.8k - $198k

    Enterprise Cybersecurity Product AnalystThe Opportunity:As an Enterprise Cybersecurity Product Analyst, you will support Booz Allen's Enterprise Cybersecurity (ECS) Product Security...  ...expectations.Track product security risks and mitigation actions, and communicate status... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  • $130k - $160k

     ...Amentum is seeking a Cybersecurity Analyst to join our team and support our McLean, VA customer. We are looking for team members who are...  ...perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian... 
    Hourly pay
    Civilian Contractor
    Contract work
    For contractors
    Work at office
    Local area

    Amentum

    McLean, VA
    4 days ago
  •  ...Cybersecurity Analyst LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship...  ..., and a proactive approach to identifying and mitigating risks. If you're passionate about protecting digital environments... 
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    Cymertek

    Chantilly, Loudoun County, VA
    1 day ago
  •  ...Cybersecurity Analyst We are seeking a dedicated and detail-oriented Cybersecurity Analyst to join our team and help safeguard our systems...  ...skills, and a proactive approach to identifying and mitigating risks. If you're passionate about protecting digital environments... 
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    Cymertek

    McLean, VA
    1 day ago
  • $120k - $179k

     ...Cybersecurity Analyst Bridge Core provides high energy, unified teams; technology integration experience; and innovative approaches, to enable our clients' mission. We enable our clients' mission by integrating innovative technologies and implementing adoption processes... 
    Shift work
    Night shift
    Weekend work
    Afternoon shift

    B/CORE

    McLean, VA
    4 days ago
  •  ...Description: Secure and resilient cybersecurity is critical to national defense and mission success. Valencor LLC (Valencor) is seeking a Cybersecurity Analyst with expertise in Risk Management Framework (RMF), Zero Trust Architecture (ZTA), and Data-Centric Security... 

    VALENCOR, LLC

    Chantilly, Loudoun County, VA
    1 day ago
  • $104.8k - $192.2k

     ...to build a better working world.Government and Public Sector - Cybersecurity - Penetration Tester - Senior ConsultantFrom strategy to...  ...identity attack vectors to identify systemic security weaknesses.Risk Identification and Escalation- Escalate critical and high-risk... 
    For contractors
    Summer holiday
    Work at office
    Local area
    Flexible hours

    EY (Ernst & Young)

    McLean, VA
    1 day ago
  •  ...Senior Risk Analyst Immediate need for a talented Senior Risk Analyst with experience in the Banking & Financial Industry. This is a 06+ Months Contract opportunity with long-term potential and is located in McLean, VA. Please review the job description below. Key... 
    Contract work
    Immediate start

    Pyramid Corporation

    McLean, VA
    4 days ago
  •  ...Risk and Compliance Systems Analyst – Apex Systems Job #: 3015294 Site: Headquarters (HDQ) Business Unit: Fin Tech & Prod Mgmt Description: Hybrid – 3 days per week on site at HDQ (Vienna, VA) preferred; team will consider GPO (Pensacola, FL) for the right candidate. We... 
    For contractors
    3 days per week

    Apex Systems

    Fairfax, VA
    4 days ago
  • Req ID: 40432 Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills...  ...Monitoring (ConMon) activities in accordance with the Risk Management Framework (RMF). This role is responsible for identifying... 

    Njvc LLC

    Oakton, VA
    2 days ago
  • FVCbank in Manassas, VA is seeking a Fraud Analyst to identify, investigate, and mitigate financial crime risks. You will lead complex fraud investigations, guide high‑risk activity, and ensure compliance with regulatory requirements and internal controls. Ideal candidates... 

    FVCbankCorp, Inc.

    Manassas, VA
    4 days ago
  •  ...Guidance.Assist in maintaining and updating HQ's AFOSI Governance, Risk and Compliance (GRC) application for assessing/managing risk,...  ...or ArcSight. Must possess analytical skills to troubleshoot cybersecurity issues and the ability to conceptualize server infrastructures... 
    Full time
    Work at office
    Immediate start

    Abacus Technology Corporation

    Quantico, VA
    5 days ago
  •  ...lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise...  ...partners. We are seeking a motivated analyst to support the development of advanced...  ...dynamics from regulatory, supervisory, and risk management perspectives.The ideal... 
    Internship
    Local area

    Mitre

    McLean, VA
    6 hours ago
  •  ...Compliance And Risk Analyst The Compliance And Risk Analyst assists the IT Program Manager in the registration of all Application and Database Management Systems (DADMS) for inclusion into the investment portfolio. Responsibilities Use the IT portfolio tool... 
    Temporary work
    Work at office
    Immediate start
    Flexible hours

    Integral Federal

    McLean, VA
    3 days ago
  • $88.4k - $154.7k

     ...possible.Job Description:Are you ready to uncover the “needle in the haystack of needles”? Parsons is seeking a skilled Network Targeting Analyst to join our team! In this role, you’ll work with development teams and mission owners to identify and interpret critical data that... 
    Flexible hours

    Parsons

    Centreville, VA
    5 days ago
  • Vacancy: Security Risk Analyst The Security Risk Analyst specializes in audit coordination, fulfillment of auditor document requests, and in ensuring that information reflecting security compliance is in place and is conveyed to auditors. May 15, 2023U.S. citizenship... 
    Work experience placement
    Work at office
    Remote work
    Work from home

    Omni Systems

    McLean, VA
    5 days ago
  •  ...Essential Duties and Responsibilities: - Serve as the Risk, Quality, and Performance Analyst, ensuring compliance with service quality, performance...  ...- Coordinate with program management, operations, and cybersecurity teams to support service reviews, performance... 
    Minimum wage
    Contract work
    Temporary work
    Work experience placement
    Remote work

    MAXIMUS

    McLean, VA
    2 days ago
  •  ...primary client‑facing lead and delivery owner for Technology Cybersecurity engagement. Responsible for managing client relationships and...  ...briefings, and executive updates. Manage client expectations, scope, risks, and escalation paths. Build and maintain strong relationships... 
    Temporary work
    Flexible hours

    SwiftCruit

    McLean, VA
    4 days ago
  •  ...Cyber Threat Hunter (TS/SCI Clearance Required) About Trellix Trellix is a global company redefining the future of cybersecurity. The company’s comprehensive, open, and native cybersecurity platform helps organizations confronted by today’s most advanced threats gain confidence... 

    109 Trellix Public Sector LLC

    Fairfax, VA
    4 days ago
  •  ...Artech is the 10th Largest IT Staffing Company in the US, according to Staffing Industry Analysts' 2012 annual report. Artech provides technical expertise to fill gaps in clients' immediate skill-sets availability, deliver emerging technology skill-sets, refresh existing... 
    Interim role
    Immediate start

    Artech Information System LLC

    Quantico, VA
    3 days ago
  • $85k - $141k

     ...patching timelines, remediation deadlines, and related federal cybersecurity and compliance requirements. Develop and maintain automated...  ...metrics to track remediation progress, compliance gaps, and asset risk. Prepare reports and briefings for leadership and federal... 
    Temporary work
    Flexible hours

    Guidehouse

    McLean, VA
    4 days ago
  • $82.6k - $162.8k

    Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions... 
    Local area
    Visa sponsorship

    Deloitte

    McLean, VA
    4 days ago
  • $105.4k - $207.8k

     ...expertise, to best support our clients.Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful... 
    Work experience placement
    Local area

    Deloitte

    McLean, VA
    5 days ago
  •  ...Cybersecurity Analyst Associate Seize your opportunity to make a personal impact as a Cybersecurity/Network Analyst supporting Department...  ...aligned with cybersecurity standards. # Identifies security risks and exposures, determines the causes of security violations... 

    General Dynamics

    Manassas Park, VA
    12 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Risk Analyst. Be the first to apply!