Risk Manager
$155k - $165kCVP (Customer Value Partners)
Cybersecurity Risk Manager
CVP is seeking a Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program. The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency's CIO and CISO in cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security reporting; and other information security-related tasks.
Responsibilities
- Identify, evaluate, and develop strategies for handling risks to reduce information security and privacy risk across the agency.
- Provide recommendations, guidance, planning, and implementation support for agency risk management activities and tools, and provide support as needed to enhance the agency's Information Security Program related to governance, optimizations, automation, and supporting tools.
- Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for Information Systems and Organizations and SP 800-39, Managing Information Security Risk (as revised).
- Conducting an enterprise risk assessment and developing an agency Information Security Risk Assessment Report that addresses all findings from the assessment
- Developing an agency Privacy and Security Roadmap that recommends privacy and information security capabilities based on risks identified in the agency's Information Security Risk Assessment Report
- Developing an agency Information Security Risk Management Plan that addresses how the agency will implement and perform risk management activities regarding risk tolerance, risk assessment, risk response, risk monitoring, and risk capabilities
- Providing risk management guidance to the agency offices for A&A activities as required, ensuring continuous risk monitoring of information security control implementation effectiveness and required information security compliance requirements
- Support the Information Security and Assurance Office (ISAO) in implementing and overseeing the organization's information security risk management and security assessment and authorization (A&A) activities.
- Advise the agency on how best to tailor the revised A&A process to handle non-traditional technologies including, but not limited to, cloud, mobile, and Internet of Things.
- Provide the agency recommendations on how it can continuously monitor and assess the security posture of agency information systems over time and alert agency decision makers when an information system presents an increased risk or eminent threat to agency data and/or operations.
- Develop guidance, templates, other tools, and advice to the program offices to support their risk management and ATO activities.
- Provide risk management and information security continuous monitoring program implementation recommendations to program offices
- Track and review Plans of Actions and Milestones (POA&Ms) agency-wide to identify areas of risk as a result of unimplemented POA&Ms, a buildup of risk-based decisions, or other cross-cutting issues observed as a result of its risk management support.
- Track the A&A status for all divisions and programs that have information systems to validate they meet the requirements to protect the agency's data and operations.
- Develop the required artifacts to complete security accreditation packages for OCIO information systems and perform any required assessments, as requested. The Contractor shall provide oversight and advisory support to agency program office personnel for completion of information system A&A packages, as requested.
- Follow NIST Federal Information Processing Standards (FIPS) and Special Publications (SPs) to include, but not limited to, FIPS 199 and 200, SP 800-39, SP 800-37, SP 800-137, SP 800-60, SP 800-53, SP 800-53A, SP 800-34, SP 800-30, and SP 800-18. The Contractor shall comply with all agency IT security and Privacy policies and standards including, and the agency Privacy Impact Assessment (PIA) requirements and associated templates.
Qualifications
- Minimum of six years' experience in cybersecurity. 10+ years' experience is preferred.
- Minimum of six years' experience leading and delivering in FISMA-based and FedRAMP Assessment and Authorization (A&A) programs for comparably sized federal agencies and programs. Seven plus years' experience is preferred.
- Shall have at least one of the following industry-recognized certifications:
- Certified Information System Security Professional (CISSP)
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- Familiarity with Information Technology Infrastructure Library (ITIL) Foundation Compliance (GRC) tool, continuous monitoring, and vulnerability management tools or services. Note: NIH currently uses CSAM.
- Demonstrated experience managing cybersecurity teams including personnel, workload, priorities, scheduling, and risks.
- Proven experience bringing innovative approaches to help reduce the FISMA workload and time to authorization/reauthorization through such methods as boundary consolidation, common control identification and re-use, automation, assessment readiness reviews, and digital transformation.
Desired Skills
- PMP Certification
- CISSP Certification
- Experience with Security Assessment Tools (Tenable Nessus, DBProtect, Wireshark, WebInspect)
- NIH/HHS experience
Location
- Rockville, MD (Hybrid)
Salary Band: $155-165k (Depending on experience)
About CVP
CVP is an award-winning healthcare and next-gen technology and consulting services firm solving critical problems for healthcare, national security, and public sector clients. We help organizations achieve lasting transformation.CVP is an Equal Opportunity Employer dedicated to actively recruiting individuals and providing advancement opportunities based on merit and legitimate job qualifications. We ensure that all associates receive equal opportunities based on their personal qualifications and job requirements. CVP strictly prohibits any form of discrimination or harassment.At CVP, we cultivate a work environment that encourages fairness, teamwork, and respect among all associated. We are committed to maintaining a workplace where everyone can grow both personally and professionally.
$86.72k - $119.24k
...Job Description: The Operational Risk Manager role is responsible for supporting the delivery and management of Mars Inc Operational Risk Programs such as Risk Engineering, Business Resilience, and other loss prevention programs. This position will support the timely...SuggestedWork at office$114.07k - $192.8k
...Operational Risk Manager Location : Location US-MD-Bethesda ID 2026-2237 Location : Address 7500 Old Georgetown Road Position Type Full Time Regular Business Unit Description Risk and Compliance Overview We...SuggestedFull timeWork at officeRemote workFlexible hours$151.9k - $173.4k
Risk Manager As part of Enterprise Risk Management (ERM), you will work with talented associates to ensure our businesses effectively adhere to Capital One’s Risk Management Framework. This role focuses on the intersection of process management and risk management, where...SuggestedFull timePart timeLocal area- ...Capital One is seeking a Risk Manager for its Control Methodology Team in McLean, VA. This role involves managing the Enterprise Independent Risk Management (IRM) Control Challenge Program and developing enhancements to risk processes. The ideal candidate will have significant...Suggested
- ...Cherry Bekaert is recruiting for a Financial Risk Program Manager to join the Financial Risk Programs team. The role blends program management with hands-on contributions to analytical and operational deliverables, working with Senior Directors and coordinating with public...Suggested
- ...Capital One in McLean, VA seeks a Senior Risk Associate to join Risk Infrastructure and Governance. You will lead policy development... ...communication, autonomous work style, and proactive program management in a dynamic environment with opportunities to influence risk governance...
$177.7k - $202.8k
Senior Risk Manager Capital One’s Enterprise Risk Management (ERM) Team has responsibility for helping the overall organization identify, manage, and mitigate key risks that may keep the company from achieving its strategic objectives. The Corporate Policy Office (CPO...Full timePart timeWork at officeLocal area$161.5k - $184.3k
## Senior Manager, Enterprise Risk Data ManagementApplylocations: McLean, VA: Richmond, VA: Chicago, IL: New York, NY: Riverwoods, ILtime type: Full timeposted on: Posted Todayjob requisition id: R244656Senior Manager, Enterprise Risk Data ManagementAs a Second Line Risk...Full timePart timeLocal area$138.1k - $157.7k
...Risk Manager, Business Continuity and Resilience Risk Management Do you want to be part of an organization that is dedicated to helping Capital One identify, manage, and effectively mitigate risk - for our customers, our communities, and our associates? Capital One...Full timePart timeLocal area$87.7k - $100.1k
...Senior Associate, Risk Manager Are you ready to lead from the front line of a top 10 bank? Do you thrive in a high-visibility environment where your strategic relationship-building translates directly into innovative risk solutions? As a Senior Risk Associate at Capital...Full timePart timeLocal area- ...Description As a Healthcare Financial/Actuarial Associate Manager you will contribute to a wide variety of complex analyses and projects... ...direction on benefit plan analysis, design, cost avoidance, risk and funding strategies Contributes to vendor financial...Temporary workWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hours
$151.9k - $173.4k
...Risk Manager - Channels and Shared Services (Hybrid) As a Risk Manager in Capital One’s Card Risk Team you will apply your risk management, project management and analytical skills to our highest profile risk initiatives. Risk Managers are at the front line of defense...Full timePart timeWork at officeLocal area$90k - $110k
...seeking a Senior Treasury Analyst based in North Bethesda, Maryland. This position is part of the team responsible for treasury management and accounts payable, and will primarily focus on supporting the Senior Manager with daily treasury and cash management functions...Temporary workWork experience placement$197.3k - $225.1k
...Manager, SRE Risk Advisory and Oversight Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers. We are serious about technology, we dream big, and we execute: Capital One moved our entire enterprise to the...Full timePart timeLocal area$151.9k - $173.4k
...Overview Vertical Risk Manager: Card Risk We enable our Card business to innovate and deliver exceptional products and services in a well-managed risk ecosystem while ensuring we keep our promises to customers. As a Vertical Risk Manager at Capital One you’ll...Full timePart timeLocal area- ...Walter Reed National Military Medical Center in Bethesda, Maryland, seeks a Risk Assessment Specialist to support hospital risk management activities in both inpatient and outpatient care. The position requires a Bachelor's degree in a health-related field and at least...
- ...financial complexity for our members. We’re transforming wealth management through the perfect blend of cutting-edge technology and human... ...dollars of AUM into alternative strategies in line with member risk profiles and overall portfolio construction. Drive automation...Work at officeRelocationMonday to Friday
$151.9k - $173.4k
...Overview Risk Manager, Operational Risk Management As a Manager for Capital One’s Operational Risk Analytics, Innovation, and Reporting team, you will apply your strong communication skills, analytical expertise, and business knowledge to our highest profile programs...Full timePart timeLocal area$177.7k - $202.8k
...Senior Manager, Risk Management - Card Data As a Senior Manager on the Card Data Management team, you will lead a team of professionals dedicated to ensuring that US Card’s most critical data is well-managed, high-quality, and adheres to enterprise data management policies...Full timePart timeLocal area$245.1k - $279.8k
...Senior Director, Commercial Risk Review Capital One’s Credit Review organization is a third line of defense function that is responsible... ...and maintaining working relationships with line of business management and key associates within Risk Management. Responsibilities:...Full timePart timeLocal area$80k - $90k
Job Description: Merrill Wealth Management is a leading provider of comprehensive wealth management and investment products and services... ...prospects based on their objectives, resources, time horizon, risk profile and preferences * Balancing investment growth,...Full timeInterim roleWork at officeLocal areaImmediate startShift workDay shift$177.7k - $202.8k
...Senior Manager, Community Investment Portfolio - Grant Operations Global Enterprise Affairs works with many external and internal stakeholders... ..., ensuring a well managed process with appropriate controls and risk awareness. In this role, you’ll be expected to demonstrate...Full timePart timeWork at officeLocal area- ...Are you an experienced, energetic, and innovative Security Portfolio Manager with a proven record of success managing guard forces at multiple sites? Then we want to talk to you! The ideal candidate is energetic, detailed oriented, possesses excellent customer service...Contract work
$164.8k - $188.1k
...Business Manager - Strategic Risk: Insights & Analysis As a Business Analysis Manager at Capital One, you will apply your strategic and analytical skills to major company challenges. You'll team with world-class professionals to develop and test strategies that ultimately...Full timeTemporary workPart timeLocal area$101.12k - $139.04k
...Job Description: The Global Risk Financing Manager will reinforce the Corporate Risk Management philosophy to Mars, Incorporated's global business units with the purpose of 1) protecting human assets, 2) preventing loss to the corporation's physical assets, and 3...Contract workFor contractorsWork experience placementLocal area$151.9k - $173.4k
...Overview Risk Manager, Enterprise Payments Risk Management Do you want to be part of an organization that’s dedicated to helping Capital One identify, manage and effectively mitigate risk – for our customers, our communities and our associates? As part of Operational...Full timePart timeLocal area$164.8k - $188.1k
...Business Manager - Strategic Risk: Insights & Analysis As a Business Analysis Manager at Capital One, you will apply your strategic and analytical skills to major company challenges. You'll team with world‑class professionals to develop and test strategies that ultimately...Full timeTemporary workPart timeLocal area$265k - $325k
...based on the number of completed transactions globally. As a Managing Director in the Healthcare Investment Banking group, you’ll provide... ...key issues and potential areas of valuation and transaction risk within engagements. Perform in‑depth sector market and company...Work experience placementSummer holidayWork at officeFlexible hours$110k - $120k
...capital adequacy, profitability, liquidity, and sound financial management. Since 2011, NeighborWorks Capital has consistently received... ...Performance Rating, demonstrating its robust financial capability and risk management acumen. The organization actively promotes a...Permanent employmentWork at office$95k - $105k
...oriented and organized Senior Treasury Analyst to join our Treasury team. This individual will play a key role in supporting daily cash management operations, payment processing, and leveraging our Treasury Management System (Kyriba) for analytics and process improvement...Daily paidFull timeWork experience placementWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Risk Manager. Be the first to apply!


