Cybersecurity and Risk Analyst
Gormat
Job Description
Job Description
Clearance Requirement: Active Secret or higher clearance required; must be eligible for a Top Secret clearance if requested
Background Investigation: Must successfully complete a DEA background investigation
Position Summary
The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and Penetration Testing (VAPT) team, responsible for identifying, analyzing, and mitigating cybersecurity risks across enterprise systems, networks, and applications. This role focuses on evaluating vulnerabilities, integrating threat intelligence, and supporting compliance efforts to ensure confidentiality, integrity, and availability of organizational data and services.
The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation activities in alignment with federal security frameworks such as NIST SP 800-53, FISMA, and ISO/IEC 27001. They provide actionable reporting to leadership, enabling risk-based decision-making, and collaborate with cross-functional teams to improve security posture, mitigate threats, and ensure adherence to federal directives and policies.
The Cybersecurity and Risk Analyst defines system security requirements for IT systems and applications and conducts comprehensive risk assessments of management, operational, and technical security controls and control enhancements that are present or inherited by an IT system. The analyst determines the overall effectiveness of security controls based on criteria from applicable NIST frameworks (e.g., NIST SP 800-53) and relevant guidance such as NIST SP 800-30.
This role supports the Risk Management Framework (RMF) Security Assessment and Authorization (SAA) process through validation of security configurations to ensure compliance with applicable cybersecurity policies, requirements, and directives. The analyst ensures compliance with Security Technical Implementation Guidance (STIG), security benchmarks, and organizational security requirements. The role utilizes automated and manual scanning tools and manual testing methodologies to identify system vulnerabilities, noncompliance, and mitigation strategies.
Duties and Responsibilities
Vulnerability Assessment & Risk Evaluation- Conduct vulnerability assessments across systems, applications, OT assets, and cloud environments using commercial and open-source tools.
- Analyze, validate, and prioritize vulnerabilities based on severity, exploitability, and business impact.
- Perform risk assessments on systems, applications, and ATO packages using frameworks such as NIST SP 800-30 and ISO 27005.
- Maintain risk registers and communicate risk likelihood and impact to system owners and leadership.
- Monitor and apply threat intelligence feeds to assess emerging threats and vulnerabilities.
- Participate in red team operations, adversary emulation, and penetration testing exercises.
- Correlate vulnerability threat data (e.g., CVEs, MITRE ATT&CK) to determine real-world exploitability.
- Provide analysis of zero-day vulnerabilities, advanced attack techniques, and potential organizational impacts.
- Ensure vulnerability management practices align with NIST SP 800-53, NIST SP 800-115, CIS Controls, and ISO 27001.
- Support internal and external audits by mapping findings to compliance frameworks (FISMA, HIPAA, PCI-DSS).
- Contribute to incident response readiness, business continuity, and disaster recovery planning.
- Review and provide input on system change requests, patching compliance, and binding operational directives.
- Prepare detailed technical reports and executive summaries highlighting risks, vulnerabilities, and mitigations.
- Document risk mitigation strategies, vulnerability management processes, and audit support artifacts.
- Provide risk-related training and awareness to stakeholders, communicating technical risk in business terms.
- Partner with security engineers, SOC analysts, developers, and system owners to coordinate remediation.
- Participate in Change Control Boards (CCBs) to assess security impact of system changes.
- Recommend improvements to vulnerability, risk, and threat management processes.
- Stay current on evolving threat landscapes, vulnerability trends, and cybersecurity technologies.
Required Qualifications
- A master's degree in information technology, cybersecurity, data science, information systems, or computer science from an ABET-accredited or CAE-designated institution fulfills the educational requirement.
- Minimum of eight (8) years of experience (YOE) in Information Technology (IT) / Information Security (IS).
- This includes any combination of experience from relevant IT and cybersecurity disciplines.
- Must have at least one (1) DoD 8140 certification for the respective area or the ability to obtain certification within six (6) months of onboarding.
- DoD 8140 certification must be maintained during the period of performance.
- Must have at least five (5) years of documented experience and/or education in IT or IS/Cybersecurity.
- Must successfully complete a DEA background investigation.
- Must possess an active Secret or higher clearance and be eligible for a Top Secret clearance if requested.
Preferred Qualifications
Experience supporting the following areas is preferred:
- DCWF Role 541 - Vulnerability Assessment Analyst.
- DCWF Role 622 - Secure Software Assessor.
- Vulnerability Assessment Analyst / Secure Software Assessor functions.
- Intermediate and advanced certifications related to cybersecurity roles, including:
- CompTIA: Cloud+, PenTest+, Security+
- EC-Council: CEH
- GIAC: GCED, GCIH, GCSA, GICSP, GSEC
Additional Position Information
This position requires working onsite five (5) days per week. Work site locations include DEA Arlington HQ, Merrifield, Lorton, Chantilly, El Paso, or other DEA satellite offices (availability dependent), typically in close geographic proximity to the candidate's home location.
Core business hours are between 10:00 AM and 3:00 PM, allowing flexibility for start and end times outside this window. Depending on position requirements, some roles may require working within a specific shift.
Job Posted by ApplicantPro- ...Phase2 Technology in Arlington, Virginia is looking for an experienced information security risk specialist to mitigate complex cybersecurity threats. This role requires collaboration with stakeholders to assess cybersecurity postures, leveraging eMASS and RMF for effective...SuggestedRemote work
$80k - $128k
...Analysis Clearance: Secret Peraton is currently seeking a Risk and Vulnerability Analyst. Location: Chandler, AZ or Washington DC. The Risk and... .... Required Qualifications Bachelor's degree in Cybersecurity, Information Technology, or related field. An additional...SuggestedContract workShift work- ...Cyber And It Security Risk Analyst Location: Bethesda, MD Contract: 12 Months Position Summary We are seeking a Cyber and... ...to identify, measure, and monitor information security and cybersecurity risks, including reporting on performance against established...SuggestedContract workFor contractors
$80k - $100k
...Kearney & Company is seeking a skilled and vigilant Cybersecurity Risk Analyst to join our dynamic team. The Cybersecurity Risk Analyst is responsible for identifying, assessing, and monitoring risks across the organization. This role helps strengthen the company’s security...SuggestedLocal areaFlexible hours$62k - $141k
...Job Number: R0242703 Cybersecurity Risk Analyst The Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the global enterprise. In all of this "cyber noise," how can these...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating...Remote job
$90k - $140k
.... We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable... ..., ownership, and execution over bureaucracy. Title: Risk and Vulnerability Analyst II Location: Washington, DC or Chandler, AZ Terms...Full timeWork experience placementFlexible hours$62k - $141k
Job Number: R0242703 Cybersecurity Risk Analyst The Opportunity Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the global enterprise. In all of this "cyber noise," how can these organizations...Contract workLocal area$100k - $150k
...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location: 50 miles of McLean, Virginia Position is contingent upon contract award Ops Tech Alliance is seeking a Cybersecurity Risk Analyst to support enterprise cybersecurity...Full timeContract work- ...Requirements: ~ Provides analytical support to manage the increasing risk of supply chain compromise related to cybersecurity, whether intentional or unintentional. ~ Identifies, assesses, and mitigates the risks associated with the distributed and interconnected...Full time
- ...career growth, and winning ideas. Military Veterans Encouraged to Apply. Job Description: The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) by managing cybersecurity risks...For contractorsWork at office
- ...Job Description Job Description Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst Location: Washington, DC Schedule: Onsite, 5 days/week Position Type: Direct Hire Clearance Required: Active TS clearance required at time of application...
$110.18k - $183.63k
...want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington, Virginia (US-VA), United States (US). Job Summary: The Cybersecurity and Risk...Temporary workWork at officeRemote workFlexible hours- ...Overview Junior Risk Analyst - Position Description. Join a team that’s shaping the future of Navy support. ICI Services—a 100% employee-owned company proudly celebrating 26 years of excellence—is seeking a Junior Risk Analyst to immediately support our PMS 410 Frigate...Temporary workFor contractorsImmediate startFlexible hours
- ...We are seeking an experienced predictive risk modeler to perform risk assessment on FHA multifamily housing portfolio. To perform in this role, the potential candidate will need skills in econometrics, statistical analysis, and modelling. The main responsibilities include...
$132k - $178k
...Enterprise Risk Analyst Denver, CO or Long Beach, CA or Washington, DC or SF Bay Area Space is a warfighting domain. True Anomaly... ...on schedule. Monitor vendor risk signals including cybersecurity advisories, regulatory actions, and contractual compliance status...Permanent employmentContract workWork at office- ...Senior Risk Analyst Immediate need for a talented Senior Risk Analyst with experience in the Banking & Financial Industry. This is a 06+ Months Contract opportunity with long-term potential and is located in McLean, VA. Please review the job description below. Key...Contract workImmediate start
- ...our mission every day - to inspire people, create cool stuff, and make a lasting impact on the world! Position Overview The Risk Management Analyst supports the identification, assessment, and communication of discrete and overall program and project risk across cost,...Temporary workWork at officeLocal area
$70k - $90k
...Coburn, a large full-service law firm with offices in eight cities across the U.S., is in search of a full-time non-exempt Risk Management Analyst to join its St. Louis or Washington D.C. office. With over 450 attorneys and experience in 50 areas of law, Thompson Coburn...Full timeTemporary workWork at officeRemote work- ...Risk Management Analyst Strategic Insight, Ltd. is seeking a Risk Management Analyst to support our US Navy client. The job is on-site at the Navy Yard, supporting the Cruiser / Destroyer group in DPAE Modernization and Sustainment office and working directly with the...Contract workFor contractorsWork experience placementInterim roleWork at office
- ...Enterprise Risk Management Analyst We are seeking an Enterprise Risk Management Analyst to support the Department of State IT Governance Support Services Bureau of Consular Affairs. This position supports the decision-making framework for addressing several enterprise...Work at office
- ...The Compliance and Risk Analyst assists the IT Program Manager in the registration of all Application and Database Management Systems (DADMS) for inclusion into the investment portfolio. Responsibilities Use the IT portfolio tool to manage the compliance of Secretariat...Temporary workWork at officeFlexible hours
$86.8k - $198k
...Overview The Opportunity: Manage the application of analytical risk management principles that enable organizations to achieve mission... ...and technical competencies. Position Job Title: Risk Management Analyst, Lead You Have 8+ years experience standing up and managing a...Full timeContract workPart timeWork at officeLocal areaRemote work- A health-focused AI company is seeking a Risk Adjustment Analyst to improve AI chatbots. The role requires expertise in healthcare, including fields like Revenue Cycle Management and Pharmacy Operations. Responsibilities include evaluating AI outputs for accuracy and providing...Hourly payFor contractorsRemote workFlexible hours
$60k
...without dual citizenship. This role is remote. The Risk, Quality, and Performance Analyst serves as the Risk, Quality, and Performance Analyst supporting... ...Coordinate with program management, operations, and cybersecurity teams to support service reviews, performance...Contract workRemote work$180k - $250k
...capabilities. We are pleased to announce the opening for a Senior Analyst, who will join our Engineering Services Division in the... ...rapidly growing technology company operating in missile defense, cybersecurity, test range modernization, biotechnology, and space control marketspaces...Temporary workWork experience placementFlexible hours- ...Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...Full timeRemote work
- ...Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments... ...delivering cyber solutions to effectively manage risk & the business of cyber for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in support of a mission...
- ...A cybersecurity consulting firm is seeking an Incident Response Analyst to support incident management for federal contracts. The role includes event triage, incident investigations, and close coordination with federal cybersecurity teams. Ideal candidates will have experience...Remote work
- ...alternative application process. Mobile Threat & Forensics Analyst FullTime Cybersecurity Serv Washington, DC, US Location: Arlington, VA (Hybrid:... ...of emerging threats, malware trends, and mobile security risks impacting enterprise environments Required Qualifications...Full timeRemote workMonday to Friday
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity and Risk Analyst. Be the first to apply!
- cyber security consultant Arlington, VA
- cyber security specialist Arlington, VA
- risk intern Arlington, VA
- risk adjustment Arlington, VA
- risk assurance Arlington, VA
- technology risk Arlington, VA
- high risk Arlington, VA
- risk Arlington, VA
- cybersecurity Arlington, VA
- work from home cyber security Arlington, VA

