Cybersecurity Risk Analyst
$67 - $70 per hourEclaro
Overview Job Number: 26-01087 ECLARO is looking for a Cybersecurity Risk Analyst for our client in Manassas, VA . ECLARO’s client is a leading technology solutions provider, collaborating with customers to manage their needs and achieve success in their business goals. Position Overview Seeking a results-driven and analytically minded Cybersecurity Risk Analyst to serve a dual mission within the Cybersecurity team: owning Third-Party Risk Management (TPRM) operations and supporting the organization’s broader Cyber Governance & Risk. The successful consultant will be the Subject Matter Expert (SME) for the TPRM program, currently administered through the SAFe platform, and will be equally responsible for insider threat monitoring, custom cybersecurity awareness training development, awareness metrics reporting, Disaster Recovery (DR) coordination, and executive-level risk reporting. This role requires translating technical risk data into clear business intelligence, building Power BI dashboards and reports for leadership, and collaborating across IT, Operations, and Procurement. The ideal consultant brings hands-on TPRM experience, strong data visualization skills, and a passion for building programs that protect members, infrastructure, and operational continuity. Responsibilities Other related duties may be assigned. Third-Party Risk Management (TPRM) Operations Evaluate new and prospective vendors through structured cybersecurity risk assessments to determine cyber clearance eligibility before contract execution or system access. Serve as the primary SME and platform administrator for the TPRM solution (SAFe), maintaining data integrity, configuring risk workflows, and driving continuous platform optimization. Maintain and update the enterprise vendor inventory, tracking risk tier classification, assessment status, contract dates, and lifecycle position for all third parties. Execute structured vendor onboarding workflows, including security due diligence, contractual security requirements review, and formal risk acceptance documentation. Monitor and triage automated vendor security alerts generated through SAFe; analyze alert severity and communicate actionable risk intelligence to stakeholders on time. Manage vendor offboarding procedures, ensuring termination of data and system access, contractual closure, and record retention compliance. Conduct periodic reassessments and ongoing monitoring of in-scope vendors according to risk tiering methodology and assessment calendar. Develop and maintain Power BI dashboards and reports presenting vendor risk metrics, assessment completion rates, open risks, and trend analysis for leadership and risk committees. Cyber Governance, Risk & Insider Threat Support Insider Threat program by monitoring behavioral risk indicators, documenting escalation procedures, and maintaining governance records. Assist in the preparation of cybersecurity governance artifacts, including risk registers, policy documents, control metrics, and compliance reports aligned to NIST CSF and applicable regulatory frameworks. Generate periodic cyber risk reports for IT leadership, audit, and regulatory audiences, summarizing risk posture, open findings, control gaps, and remediation status. Build and maintain Power BI dashboards to visualize governance and risk metrics, control effectiveness trends, and risk KPIs across the organization. Participate in risk assessment activities and support internal control evaluations relevant to IT environments. Cybersecurity Awareness Training & Metrics Reporting Design and develop custom cybersecurity awareness training content tailored to the specific business operations and risk profiles of individual departments (e.g., Operations, Finance, Customer Engagement, Engineering). Collaborate with department leads to schedule, deploy, and track training completion across the organization. Administer phishing simulation campaigns; analyze results and produce actionable reports identifying at-risk user populations and trending behaviors. Build and maintain Power BI dashboards tracking cybersecurity awareness KPIs, including training completion rates, phishing click-through rates, repeat offender trends, and department-level performance over time. Prepare and present monthly and quarterly Cyber Awareness Reports for leadership, translating program metrics into clear risk narratives and recommended actions. Stay current with evolving social engineering tactics and regulatory guidance to keep training content timely and impactful. Evaluate training platform effectiveness and recommend enhancements. Disaster Recovery (DR) Coordination & Reporting Coordinate and facilitate Disaster Recovery testing exercises for core business applications in collaboration with IT Operations. Develop DR test plans, scoping documents, timelines, and stakeholder communication plans. Document test execution results, capture gaps or failures, and produce post-exercise reports for IT leadership and executives. Track remediation of identified DR gaps to closure; maintain updated DR runbooks, test records, and lessons-learned logs. Assist in the broader Business Continuity Planning (BCP) process as it pertains to cybersecurity resilience and recovery readiness. SharePoint Intranet & Stakeholder Dashboard Publishing Design, build, and maintain SharePoint sites and pages serving as the centralized hub for cybersecurity communications, dashboards, and reporting artifacts. Embed and publish Power BI reports into SharePoint pages, ensuring access to live dashboards without requiring Power BI licensing. Develop audience-specific SharePoint pages for distinct stakeholder groups with role-based access controls. Maintain separate SharePoint views for TPRM metrics, cyber awareness training, governance and risk posture indicators, and DR testing results. Collaborate with department heads to translate reporting needs into intuitive, self-service SharePoint dashboard pages. Establish a publishing cadence for dashboard refreshes and narrative updates. Apply SharePoint governance best practices, including naming conventions, version control, content lifecycle management, and access review procedures. Coordinate with IT infrastructure and Microsoft 365 administrators for site provisioning and integration with Power BI Service. Internal Communicate within the department and with other departments to ensure achievement of goals and standards; provide high-level service; coordinate activities; and improve the knowledge base of policies and programs. Participate in staff meetings to develop and implement plans; monitor and revise strategies; and contribute to policies and procedures. External Provide high-quality customer service to external customers and maintain professional relationships with customers and the public. Required Qualifications Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or a closely related field. Equivalent combination of education and professional experience will be considered. Minimum 3-5 years of progressive experience in cybersecurity, IT risk management, or a related GRC discipline. Demonstrated experience operating or administering a formal TPRM program or third-party risk platform. Proven ability to build Power BI reports and dashboards that translate security data into executive-ready metrics. Experience developing and delivering cybersecurity awareness training and reporting program metrics. Familiarity with Disaster Recovery planning, tabletop exercises, or DR test coordination. Power BI Report & Dashboard Development Vendor Risk Assessment & Lifecycle Management TPRM Platform Administration (SAFe or Equivalent) GRC Documentation & Control Mapping Security Questionnaire Evaluation (SIG, Custom) Phishing Simulation Analysis & Reporting Cyber Awareness Metrics Tracking & Presentation DR Test Planning, Facilitation & Post-Exercise Reporting Insider Threat Monitoring Support Advanced Microsoft Excel (Pivot Tables, Data Models) Executive-Ready PowerPoint Presentations SharePoint Site Management Clear written & verbal communication at all org levels. Executive-Level Risk Storytelling & Data Narration Cross-Functional Stakeholder Engagement Analytical Thinking & Risk Prioritization Project Coordination & Deadline Management Detail Orientation & Documentation Discipline Ability to manage multiple concurrent workstreams. Vendor Relationship Professionalism Collaborative team player with independent initiative. Adaptability in a fast-paced utility environment. Continuous learning mindset in evolving threat landscape. SharePoint site design and intranet page development. Preferred Skills Experience in a regulated industry (electric utility, energy, financial services, or healthcare). Hands-on experience with the SAFe TPRM platform or comparable solutions (One Trust, Process Unity, Prevalent, BitSight, Security Scorecard). Working knowledge of NIST CSF (v2.0), NIST SP 800-161 (C-SCRM), or ISO / IEC 27036 supply chain risk standards. Familiarity with Insider Threat frameworks and behavioral analytics monitoring. Experience with Business Continuity Management frameworks (ISO 22301). Background in Learning Management System (LMS) administration and instructional design principles for security awareness content. Advanced Power BI skills: DAX measures, row-level security, scheduled refresh, paginated reports. Certifications: PL-300, CTPRP, Security+ or equivalent. PL-300: Microsoft Power BI Data Analyst CTPRP: Certified Third Party Risk Professional Security+: CompTIA Security+ Pay Rate $67 - $70 / Hour Benefits 401k Retirement Savings Plan administered by Merrill Lynch Commuter Check Pretax Commuter Benefits Eligibility to purchase Medical, Dental & Vision Insurance through ECLARO How to Apply If interested, you may contact: Tim Cusick View email address on click.appcast.io View phone number on click.appcast.io Tim Cusick | LinkedIn Equal Opportunity Employer ECLARO values diversity and does not discriminate based on Race, Color, Religion, Sex, Sexual Orientation, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status, in compliance with all applicable laws. #J-18808-Ljbffr
$100k - $150k
...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location: 50 miles of McLean, Virginia Position is contingent upon contract award Ops Tech Alliance is seeking a Cybersecurity Risk Analyst to support enterprise cybersecurity...SuggestedContract work$85k - $110k
...innovation and customer success. Responsibilities An Average Day:As the Cybersecurity Analyst I you will enhance the organization’s cybersecurity posture by performing comprehensive risk assessment and improving incidents response protocols. In this role you will...SuggestedImmediate start$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$86.8k - $198k
Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by utilizing enterprise-level vulnerability scanning and assessment tools to identify internally and externally facing vulnerabilities...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$74.8k - $130.9k
...talent and redefine what’s possible. Job Description: Risk Analyst Parsons is seeking a Risk Analyst to become a key member... ...combining unique technologies with deep domain expertise across cybersecurity, missile defense, space, connected infrastructure,...SuggestedContract workFor subcontractorLocal areaWorldwideFlexible hours$99k - $225k
Enterprise Cybersecurity AnalystThe Opportunity:Support mission-critical cybersecurity operations for Booz Allen's Impact Level 5 (IL5) environment... ...supporting vulnerability scanning, remediation workflows, or risk assessments Ability to collaborate with IT, risk, and...Full timeContract workPart timeWork at officeLocal areaRemote work$86.8k - $198k
Enterprise Cybersecurity Product AnalystThe Opportunity:As an Enterprise Cybersecurity Product Analyst, you will support Booz Allen's Enterprise Cybersecurity (ECS) Product Security... ...expectations.Track product security risks and mitigation actions, and communicate status...Full timeContract workPart timeWork at officeLocal areaRemote work- ...MANTECH seeks a motivated, career and customer-oriented Cybersecurity Analyst - Nights to join our team in Tysons, VA The Cybersecurity Analyst will monitor Air Gapped Security Fabrics through managed SECOPs Tools. Responsibilities include but are...Work at officeLocal areaShift workNight shift
- ...MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia . Our team provides 24x7x365 cybersecurity support to one of the most coveted targets in the world. The Cyber Incident Response Analyst will work...Shift workNight shiftDay shiftAfternoon shift
- ...Cybersecurity Analyst LOCATION Chantilly, VA 20151 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship... ..., and a proactive approach to identifying and mitigating risks. If you're passionate about protecting digital environments...Temporary workFor contractorsImmediate startFlexible hours
$130k - $160k
...Amentum is seeking a Cybersecurity Analyst to join our team and support our McLean, VA customer. We are looking for team members who are... ...perform assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) on behalf of a federal civilian...Hourly payCivilian ContractorContract workFor contractorsWork at officeLocal area- ...Bridge Core (BCore) is seeking a Cybersecurity Analyst in McLean, VA. The ideal candidate should have at least 1 year of experience in cybersecurity roles and possess an active TS/SCI clearance with polygraph. Responsibilities include utilizing SIEM systems for threat...Shift workAfternoon shift
$130k - $160k
...Overview Amentum is seeking a Cybersecurity Analyst to support our McLean, VA customer. The role focuses on performing assessment and authorization (A&A) efforts under the NIST Risk Management Framework (RMF) for a federal civilian agency. The analyst will develop, review...- ...Cybersecurity Analyst We are seeking a dedicated and detail-oriented Cybersecurity Analyst to join our team and help safeguard our systems... ...skills, and a proactive approach to identifying and mitigating risks. If you're passionate about protecting digital environments...Temporary workFor contractorsImmediate startFlexible hours
$120k - $179k
...Cybersecurity Analyst Bridge Core provides high energy, unified teams; technology integration experience; and innovative approaches, to enable our clients' mission. We enable our clients' mission by integrating innovative technologies and implementing adoption processes...Shift workNight shiftWeekend workAfternoon shift- ...Overview Cybersecurity Analyst – McLean, VA. TS/SCI clearance with polygraph required. Bridge Core is seeking a skilled analyst to support government agencies in cyberspace. Responsibilities We are seeking a skilled and motivated Cybersecurity Analyst to join our team....Shift workNight shiftAfternoon shift
- ...Description: Secure and resilient cybersecurity is critical to national defense and mission success. Valencor LLC (Valencor) is seeking a Cybersecurity Analyst with expertise in Risk Management Framework (RMF), Zero Trust Architecture (ZTA), and Data-Centric Security...
$69.4k - $158k
Risk Management AnalystThe Opportunity:Use your industry or domain expertise to assess risk posture to develop innovative solutions to complex problems supporting a dynamic Navy Middle Tier Acquisition (MTA) technical program focused on rapid prototyping and fielding across...Full timeContract workPart timeWork at officeLocal areaRemote work$104.8k - $192.2k
...to build a better working world.Government and Public Sector - Cybersecurity - Penetration Tester - Senior ConsultantFrom strategy to... ...identity attack vectors to identify systemic security weaknesses.Risk Identification and Escalation- Escalate critical and high-risk...For contractorsSummer holidayWork at officeLocal areaFlexible hours- ...Senior Risk Analyst Immediate need for a talented Senior Risk Analyst with experience in the Banking & Financial Industry. This is a 06+ Months Contract opportunity with long-term potential and is located in McLean, VA. Please review the job description below. Key...Contract workImmediate start
$69.4k - $158k
...Job Number: R0244360 Risk Management Analyst The Opportunity: Use your industry or domain expertise to assess risk posture to develop innovative solutions to complex problems supporting a dynamic Navy Middle Tier Acquisition (MTA) technical program focused on rapid...Full timeContract workPart timeWork at officeLocal areaRemote work- FVCbank in Manassas, VA is seeking a Fraud Analyst to identify, investigate, and mitigate financial crime risks. You will lead complex fraud investigations, guide high‑risk activity, and ensure compliance with regulatory requirements and internal controls. Ideal candidates...
- ...Guidance.Assist in maintaining and updating HQ's AFOSI Governance, Risk and Compliance (GRC) application for assessing/managing risk,... ...or ArcSight. Must possess analytical skills to troubleshoot cybersecurity issues and the ability to conceptualize server infrastructures...Full timeWork at officeImmediate start
- ...Compliance And Risk Analyst The Compliance And Risk Analyst assists the IT Program Manager in the registration of all Application and Database Management Systems (DADMS) for inclusion into the investment portfolio. Responsibilities Use the IT portfolio tool...Temporary workWork at officeImmediate startFlexible hours
- ...lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise... ...partners. We are seeking a motivated analyst to support the development of advanced... ...dynamics from regulatory, supervisory, and risk management perspectives.The ideal...InternshipLocal area
$111.2k - $126.9k
...Overview Sr. Associate, Capital Markets & Risk - Systems Analyst The Treasury Systems & Business Solutions team, a department within Treasury that falls under Capital Markets and Risk organization, consists of business process and system experts who are passionate...Full timePart timeLocal area$88.4k - $154.7k
...possible.Job Description:Are you ready to uncover the “needle in the haystack of needles”? Parsons is seeking a skilled Network Targeting Analyst to join our team! In this role, you’ll work with development teams and mission owners to identify and interpret critical data that...Flexible hours- ...Essential Duties and Responsibilities: - Serve as the Risk, Quality, and Performance Analyst, ensuring compliance with service quality, performance... ...- Coordinate with program management, operations, and cybersecurity teams to support service reviews, performance...Minimum wageContract workTemporary workWork experience placementRemote work
- ...Methodology and Unified Facilities Criteria (UFC) 4-010-06, Cybersecurity of Facility-Related Control Systems. Assist in... ...alongside other cybersecurity engineers and Risk Management Framework (RMF) analysts. Additional Preferred Qualifications: •...
- Vacancy: Security Risk Analyst The Security Risk Analyst specializes in audit coordination, fulfillment of auditor document requests, and in ensuring that information reflecting security compliance is in place and is conveyed to auditors. May 15, 2023U.S. citizenship...Work experience placementWork at officeRemote workWork from home
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Risk Analyst. Be the first to apply!
- risk adjustment Manassas, VA
- technology risk Manassas, VA
- risk assurance Manassas, VA
- high risk Manassas, VA
- risk Manassas, VA
- cybersecurity software engineer Manassas, VA
- cybersecurity administrator Manassas, VA
- remote cyber security Manassas, VA
- cyber security Manassas, VA
- cybersecurity specialist Manassas, VA


