Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Risk Analyst

$67 - $70 per hour

Eclaro

Overview Job Number: 26-01087 ECLARO is looking for a Cybersecurity Risk Analyst for our client in Manassas, VA . ECLARO’s client is a leading technology solutions provider, collaborating with customers to manage their needs and achieve success in their business goals. Position Overview Seeking a results-driven and analytically minded Cybersecurity Risk Analyst to serve a dual mission within the Cybersecurity team: owning Third-Party Risk Management (TPRM) operations and supporting the organization’s broader Cyber Governance & Risk. The successful consultant will be the Subject Matter Expert (SME) for the TPRM program, currently administered through the SAFe platform, and will be equally responsible for insider threat monitoring, custom cybersecurity awareness training development, awareness metrics reporting, Disaster Recovery (DR) coordination, and executive-level risk reporting. This role requires translating technical risk data into clear business intelligence, building Power BI dashboards and reports for leadership, and collaborating across IT, Operations, and Procurement. The ideal consultant brings hands-on TPRM experience, strong data visualization skills, and a passion for building programs that protect members, infrastructure, and operational continuity. Responsibilities Other related duties may be assigned. Third-Party Risk Management (TPRM) Operations Evaluate new and prospective vendors through structured cybersecurity risk assessments to determine cyber clearance eligibility before contract execution or system access. Serve as the primary SME and platform administrator for the TPRM solution (SAFe), maintaining data integrity, configuring risk workflows, and driving continuous platform optimization. Maintain and update the enterprise vendor inventory, tracking risk tier classification, assessment status, contract dates, and lifecycle position for all third parties. Execute structured vendor onboarding workflows, including security due diligence, contractual security requirements review, and formal risk acceptance documentation. Monitor and triage automated vendor security alerts generated through SAFe; analyze alert severity and communicate actionable risk intelligence to stakeholders on time. Manage vendor offboarding procedures, ensuring termination of data and system access, contractual closure, and record retention compliance. Conduct periodic reassessments and ongoing monitoring of in-scope vendors according to risk tiering methodology and assessment calendar. Develop and maintain Power BI dashboards and reports presenting vendor risk metrics, assessment completion rates, open risks, and trend analysis for leadership and risk committees. Cyber Governance, Risk & Insider Threat Support Insider Threat program by monitoring behavioral risk indicators, documenting escalation procedures, and maintaining governance records. Assist in the preparation of cybersecurity governance artifacts, including risk registers, policy documents, control metrics, and compliance reports aligned to NIST CSF and applicable regulatory frameworks. Generate periodic cyber risk reports for IT leadership, audit, and regulatory audiences, summarizing risk posture, open findings, control gaps, and remediation status. Build and maintain Power BI dashboards to visualize governance and risk metrics, control effectiveness trends, and risk KPIs across the organization. Participate in risk assessment activities and support internal control evaluations relevant to IT environments. Cybersecurity Awareness Training & Metrics Reporting Design and develop custom cybersecurity awareness training content tailored to the specific business operations and risk profiles of individual departments (e.g., Operations, Finance, Customer Engagement, Engineering). Collaborate with department leads to schedule, deploy, and track training completion across the organization. Administer phishing simulation campaigns; analyze results and produce actionable reports identifying at-risk user populations and trending behaviors. Build and maintain Power BI dashboards tracking cybersecurity awareness KPIs, including training completion rates, phishing click-through rates, repeat offender trends, and department-level performance over time. Prepare and present monthly and quarterly Cyber Awareness Reports for leadership, translating program metrics into clear risk narratives and recommended actions. Stay current with evolving social engineering tactics and regulatory guidance to keep training content timely and impactful. Evaluate training platform effectiveness and recommend enhancements. Disaster Recovery (DR) Coordination & Reporting Coordinate and facilitate Disaster Recovery testing exercises for core business applications in collaboration with IT Operations. Develop DR test plans, scoping documents, timelines, and stakeholder communication plans. Document test execution results, capture gaps or failures, and produce post-exercise reports for IT leadership and executives. Track remediation of identified DR gaps to closure; maintain updated DR runbooks, test records, and lessons-learned logs. Assist in the broader Business Continuity Planning (BCP) process as it pertains to cybersecurity resilience and recovery readiness. SharePoint Intranet & Stakeholder Dashboard Publishing Design, build, and maintain SharePoint sites and pages serving as the centralized hub for cybersecurity communications, dashboards, and reporting artifacts. Embed and publish Power BI reports into SharePoint pages, ensuring access to live dashboards without requiring Power BI licensing. Develop audience-specific SharePoint pages for distinct stakeholder groups with role-based access controls. Maintain separate SharePoint views for TPRM metrics, cyber awareness training, governance and risk posture indicators, and DR testing results. Collaborate with department heads to translate reporting needs into intuitive, self-service SharePoint dashboard pages. Establish a publishing cadence for dashboard refreshes and narrative updates. Apply SharePoint governance best practices, including naming conventions, version control, content lifecycle management, and access review procedures. Coordinate with IT infrastructure and Microsoft 365 administrators for site provisioning and integration with Power BI Service. Internal Communicate within the department and with other departments to ensure achievement of goals and standards; provide high-level service; coordinate activities; and improve the knowledge base of policies and programs. Participate in staff meetings to develop and implement plans; monitor and revise strategies; and contribute to policies and procedures. External Provide high-quality customer service to external customers and maintain professional relationships with customers and the public. Required Qualifications Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or a closely related field. Equivalent combination of education and professional experience will be considered. Minimum 3-5 years of progressive experience in cybersecurity, IT risk management, or a related GRC discipline. Demonstrated experience operating or administering a formal TPRM program or third-party risk platform. Proven ability to build Power BI reports and dashboards that translate security data into executive-ready metrics. Experience developing and delivering cybersecurity awareness training and reporting program metrics. Familiarity with Disaster Recovery planning, tabletop exercises, or DR test coordination. Power BI Report & Dashboard Development Vendor Risk Assessment & Lifecycle Management TPRM Platform Administration (SAFe or Equivalent) GRC Documentation & Control Mapping Security Questionnaire Evaluation (SIG, Custom) Phishing Simulation Analysis & Reporting Cyber Awareness Metrics Tracking & Presentation DR Test Planning, Facilitation & Post-Exercise Reporting Insider Threat Monitoring Support Advanced Microsoft Excel (Pivot Tables, Data Models) Executive-Ready PowerPoint Presentations SharePoint Site Management Clear written & verbal communication at all org levels. Executive-Level Risk Storytelling & Data Narration Cross-Functional Stakeholder Engagement Analytical Thinking & Risk Prioritization Project Coordination & Deadline Management Detail Orientation & Documentation Discipline Ability to manage multiple concurrent workstreams. Vendor Relationship Professionalism Collaborative team player with independent initiative. Adaptability in a fast-paced utility environment. Continuous learning mindset in evolving threat landscape. SharePoint site design and intranet page development. Preferred Skills Experience in a regulated industry (electric utility, energy, financial services, or healthcare). Hands-on experience with the SAFe TPRM platform or comparable solutions (One Trust, Process Unity, Prevalent, BitSight, Security Scorecard). Working knowledge of NIST CSF (v2.0), NIST SP 800-161 (C-SCRM), or ISO / IEC 27036 supply chain risk standards. Familiarity with Insider Threat frameworks and behavioral analytics monitoring. Experience with Business Continuity Management frameworks (ISO 22301). Background in Learning Management System (LMS) administration and instructional design principles for security awareness content. Advanced Power BI skills: DAX measures, row-level security, scheduled refresh, paginated reports. Certifications: PL-300, CTPRP, Security+ or equivalent. PL-300: Microsoft Power BI Data Analyst CTPRP: Certified Third Party Risk Professional Security+: CompTIA Security+ Pay Rate $67 - $70 / Hour Benefits 401k Retirement Savings Plan administered by Merrill Lynch Commuter Check Pretax Commuter Benefits Eligibility to purchase Medical, Dental & Vision Insurance through ECLARO How to Apply If interested, you may contact: Tim Cusick View email address on click.appcast.io View phone number on click.appcast.io Tim Cusick | LinkedIn Equal Opportunity Employer ECLARO values diversity and does not discriminate based on Race, Color, Religion, Sex, Sexual Orientation, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status, in compliance with all applicable laws. #J-18808-Ljbffr

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity Risk Analyst in Manassas, VA vacancy
  • $85k - $110k

     ...innovation and customer success. Responsibilities An Average Day: As the Cybersecurity Analyst I you will enhance the organization's cybersecurity posture by performing comprehensive risk assessment and improving incidents response protocols. In this role you will... 
    Suggested
    Immediate start

    American Systems

    Manassas, VA
    3 days ago
  • $100k - $150k

     ...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location: 50 miles of McLean, Virginia Position is contingent upon contract award Ops Tech Alliance is seeking a Cybersecurity Risk Analyst to support enterprise cybersecurity... 
    Suggested
    Full time
    Contract work

    Ops Tech Alliance

    McLean, VA
    3 hours ago
  • $74.8k - $130.9k

     ...talent and redefine what’s possible. Job Description: Risk Analyst Parsons is seeking a Risk Analyst to become a key member...  ...combining unique technologies with deep domain expertise across cybersecurity, missile defense, space, connected infrastructure,... 
    Suggested
    Contract work
    For subcontractor
    Local area
    Worldwide
    Flexible hours

    Parsons Corporation

    Centreville, VA
    1 day ago
  • $64.47 per hour

     ...Position Title: Enterprise Risk Analyst The experienced Risk Analyst role executes the VA Enterprise Risk Analysis process using a custom...  ...outcomes for the ERA process. You Have: Experience with Cybersecurity, risk management, or risk assessment for complex systems Experience... 
    Suggested
    Hourly pay
    For contractors
    Work experience placement

    AMERICAN MANAGEMENT GROUP

    Manassas, VA
    9 hours ago
  • Bridge Core (BCore) is seeking a Cybersecurity Analyst in McLean, VA. The ideal candidate should have at least 1 year of experience in cybersecurity roles and possess an active TS/SCI clearance with polygraph. Responsibilities include utilizing SIEM systems for threat analysis... 
    Suggested
    Shift work
    Afternoon shift

    Bridge Core

    McLean, VA
    3 days ago
  • MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia. Our team provides 24x7x365 cybersecurity support to one of the most coveted targets in the world. The Cyber Incident Response Analyst will work... 
    Shift work
    Night shift
    Day shift
    Afternoon shift

    ManTech

    McLean, VA
    10 hours ago
  • $130k - $160k

    Overview Amentum is seeking a Cybersecurity Analyst to support our McLean, VA customer. The role focuses on performing assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) for a federal civilian agency. The analyst will develop, review... 

    PAE Government Services Inc.

    McLean, VA
    1 day ago
  • Overview Cybersecurity Analyst – McLean, VA. TS/SCI clearance with polygraph required. Bridge Core is seeking a skilled analyst to support government agencies in cyberspace. Responsibilities We are seeking a skilled and motivated Cybersecurity Analyst to join our team... 
    Shift work
    Night shift
    Afternoon shift

    Bridge Core

    McLean, VA
    1 day ago
  •  ...Cybersecurity Analyst LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship...  ..., and a proactive approach to identifying and mitigating risks. If you're passionate about protecting digital environments... 
    Temporary work
    For contractors
    Immediate start
    Flexible hours

    Cymertek

    Chantilly, Loudoun County, VA
    3 days ago
  • $99k - $225k

     ...Job Number: R0239024 Enterprise Cybersecurity Analyst The Opportunity : Support mission-critical cybersecurity operations for Booz Allen...  ...vulnerability scanning, remediation workflows, or risk assessments Ability to collaborate with IT, risk, and operations... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    4 days ago
  •  ...Description: Secure and resilient cybersecurity is critical to national defense and mission success. Valencor LLC (Valencor) is seeking a Cybersecurity Analyst with expertise in Risk Management Framework (RMF), Zero Trust Architecture (ZTA), and Data-Centric Security... 

    VALENCOR, LLC

    Chantilly, Loudoun County, VA
    2 days ago
  • ## Cybersecurity Operations AnalystApplylocations: US - VA, McLeantime type: Full timeposted on...  ...War (DoW). The Cybersecurity Operations Analyst will be responsible for conducting...  ...routine cybersecurity reporting to support risk mitigation and operational awareness.* Conduct... 
    Temporary work
    Flexible hours

    Dovel Technologies

    McLean, VA
    1 day ago
  •  ...finance technology, today announced the acquisition of DataScan, a trusted North American leader in wholesale finance and inventory risk management. About DataScan: Headquartered in Alpharetta, Georgia, DataScan stands at the forefront of delivering cutting-edge wholesale... 
    Work at office
    Local area
    Immediate start
    Flexible hours
    Night shift

    DataScan

    Centreville, VA
    1 day ago
  • $98k - $148k

     ...Freddie Mac seeks an experienced individual contributor in operational risk management to help manage non-financial risks effectively. You will be responsible for identifying risks, preparing assessments, and supporting oversight activities. Ideal candidates possess 5... 

    Freddie Mac

    McLean, VA
    9 hours ago
  • $96.5k - $110.1k

     ...As a Sr. Risk Specialist in Capital One’s Operations Risk Management (ORM) group, you will apply your Data Quality and Data Management...  ...that would be beneficial in resolving the issues. Partner with analyst teams as a subject matter expert to support the deployment, monitoring... 
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    9 hours ago
  • Risk and Compliance Systems Analyst – Apex Systems Job #: 3015294 Site: Headquarters (HDQ) Business Unit: Fin Tech & Prod Mgmt Description: Hybrid – 3 days per week on site at HDQ (Vienna, VA) preferred; team will consider GPO (Pensacola, FL) for the right candidate... 
    For contractors
    3 days per week

    Apex Systems

    Fairfax, VA
    5 days ago
  •  ...Senior Risk Analyst Immediate need for a talented Senior Risk Analyst with experience in the Banking & Financial Industry. This is a 06+ Months Contract opportunity with long-term potential and is located in McLean, VA. Please review the job description below. Key... 
    Contract work
    Immediate start

    Pyramid Consulting

    McLean, VA
    5 days ago
  •  ...The Compliance and Risk Analyst assists the IT Program Manager in the registration of all Application and Database Management Systems (DADMS) for inclusion into the investment portfolio. Responsibilities Use the IT portfolio tool to manage the compliance of Secretariat... 
    Temporary work
    Work at office
    Flexible hours

    Integral Federal, Inc.

    McLean, VA
    5 days ago
  • $85k - $141k

     ...patching timelines, remediation deadlines, and related federal cybersecurity and compliance requirements. Develop and maintain automated...  ...to track remediation progress, compliance gaps, and asset risk. Prepare reports and briefings for leadership and federal oversight... 
    Temporary work
    Flexible hours

    Guidehouse

    McLean, VA
    9 hours ago
  • $124.22k - $131.01k

     ...understanding of systems engineering concepts, principles, and theories Proficient understanding of cyber security specifications such as Risk Management Framework (RMF), DIACAP, STIGs and other government security specifications and guidelines Proficient knowledge of... 
    Work at office
    Flexible hours

    General Dynamics

    Manassas Park, VA
    4 days ago
  •  ...Assist in maintaining and updating HQ's AFOSI Governance, Risk and Compliance (GRC) application for assessing/managing risk,...  ...Splunk or ArcSight. Must possess analytical skills to troubleshoot cybersecurity issues and the ability to conceptualize server infrastructures... 
    Full time
    Work at office
    Immediate start

    Navstar

    Quantico, VA
    5 days ago
  • Artech is the 10th Largest IT Staffing Company in the US, according to Staffing Industry Analysts' 2012 annual report. Artech provides technical expertise to fill gaps in clients' immediate skill-sets availability, deliver emerging technology skill-sets, refresh existing... 
    Interim role
    Immediate start

    Artech Information System LLC

    Quantico, VA
    1 day ago
  • Responsibilities As an Actuary, you’ll work directly with the Managing Actuary and own broad range of responsibilities including reserve reviews, rate reviews and rate filing support, premium calculations, predictive modeling and presenting actuarial analyses to company...
    Full time

    W. R. Berkley

    Manassas, VA
    5 days ago
  •  ...LLC is a veteran-owned small business that maintains a team of cybersecurity experts committed to protecting complicated data and...  ...decision makers with the most accurate assessment of residual risk possible. We work with our clients to solve the toughest challenges... 

    WarCollar Industries

    Centreville, VA
    1 day ago
  •  ...benefits package. Position Title: Senior Cyber-Security Analyst / Navy Validator Location: Onsite in Arlington, VA...  ...and Authorization of ONR systems and networks. Implements Navy Risk Management Framework (RMF) Implementation Plan IAW DODI 8510.01.... 
    For contractors
    Work at office
    Local area
    Immediate start

    Saliense Consulting LLC

    McLean, VA
    7 days ago
  • $110k - $215k

     ...performance! Core One is seeking Senior Cyber Security Analyst to support our IC program. This position requires...  ..., technical development programs, information cybersecurity policies, and regulations. Knowledge of risk management standards, CNSSP 1253, FIPS 140-2, 199,... 
    Full time
    Contract work

    Core One

    Chantilly, Loudoun County, VA
    1 day ago
  • $120.8k - $137.9k

     ...Principal Risk Specialist As a Principal Risk Associate at Capital One you'll be responsible for working with business partners to identify and mitigate potential risks. Principal Risk Associates at Capital One are highly motivated Risk Management professionals... 
    Full time
    Part time
    Work at office
    Local area

    Capital One Financial Corp

    McLean, VA
    2 days ago
  • $117.3k - $133.9k

     ...Principal, Risk Specialist Does the idea of working with and guiding professional, highly trained accountants, product, technology and other professionals inspire you? Are you a professional with a demonstrated ability to guide and support complex projects? Would you... 
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    2 days ago
  • $120.8k - $137.9k

     ...Principal Risk Specialist - Operational Risk Challenge & Advisory As a Principal Risk Specialist at Capital One you'll be responsible for working with business partners to identify and mitigate potential risks to Capital One. You will be the front line of defense to... 
    Full time
    Part time
    Work at office
    Local area

    Capital One Financial Corp

    McLean, VA
    5 days ago
  • $120.8k - $137.9k

     ...Principal Risk Specialist | Enterprise Payments Do you like working in the spotlight? Are you ready to work on the front line of a top 10 Bank? Can you build relationships as well as develop and implement innovative solutions? As a Principal Risk Specialist in the Retail... 
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Risk Analyst. Be the first to apply!