Risk Manager
$155k - $165kCVP (Customer Value Partners)
Cybersecurity Risk Manager
CVP is seeking a Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program. The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency's CIO and CISO in cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security reporting; and other information security-related tasks.
Responsibilities
- Identify, evaluate, and develop strategies for handling risks to reduce information security and privacy risk across the agency.
- Provide recommendations, guidance, planning, and implementation support for agency risk management activities and tools, and provide support as needed to enhance the agency's Information Security Program related to governance, optimizations, automation, and supporting tools.
- Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for Information Systems and Organizations and SP 800-39, Managing Information Security Risk (as revised).
- Conducting an enterprise risk assessment and developing an agency Information Security Risk Assessment Report that addresses all findings from the assessment
- Developing an agency Privacy and Security Roadmap that recommends privacy and information security capabilities based on risks identified in the agency's Information Security Risk Assessment Report
- Developing an agency Information Security Risk Management Plan that addresses how the agency will implement and perform risk management activities regarding risk tolerance, risk assessment, risk response, risk monitoring, and risk capabilities
- Providing risk management guidance to the agency offices for A&A activities as required, ensuring continuous risk monitoring of information security control implementation effectiveness and required information security compliance requirements
- Support the Information Security and Assurance Office (ISAO) in implementing and overseeing the organization's information security risk management and security assessment and authorization (A&A) activities.
- Advise the agency on how best to tailor the revised A&A process to handle non-traditional technologies including, but not limited to, cloud, mobile, and Internet of Things.
- Provide the agency recommendations on how it can continuously monitor and assess the security posture of agency information systems over time and alert agency decision makers when an information system presents an increased risk or eminent threat to agency data and/or operations.
- Develop guidance, templates, other tools, and advice to the program offices to support their risk management and ATO activities.
- Provide risk management and information security continuous monitoring program implementation recommendations to program offices
- Track and review Plans of Actions and Milestones (POA&Ms) agency-wide to identify areas of risk as a result of unimplemented POA&Ms, a buildup of risk-based decisions, or other cross-cutting issues observed as a result of its risk management support.
- Track the A&A status for all divisions and programs that have information systems to validate they meet the requirements to protect the agency's data and operations.
- Develop the required artifacts to complete security accreditation packages for OCIO information systems and perform any required assessments, as requested. The Contractor shall provide oversight and advisory support to agency program office personnel for completion of information system A&A packages, as requested.
- Follow NIST Federal Information Processing Standards (FIPS) and Special Publications (SPs) to include, but not limited to, FIPS 199 and 200, SP 800-39, SP 800-37, SP 800-137, SP 800-60, SP 800-53, SP 800-53A, SP 800-34, SP 800-30, and SP 800-18. The Contractor shall comply with all agency IT security and Privacy policies and standards including, and the agency Privacy Impact Assessment (PIA) requirements and associated templates.
Qualifications
- Minimum of six years' experience in cybersecurity. 10+ years' experience is preferred.
- Minimum of six years' experience leading and delivering in FISMA-based and FedRAMP Assessment and Authorization (A&A) programs for comparably sized federal agencies and programs. Seven plus years' experience is preferred.
- Shall have at least one of the following industry-recognized certifications:
- Certified Information System Security Professional (CISSP)
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- Familiarity with Information Technology Infrastructure Library (ITIL) Foundation Compliance (GRC) tool, continuous monitoring, and vulnerability management tools or services. Note: NIH currently uses CSAM.
- Demonstrated experience managing cybersecurity teams including personnel, workload, priorities, scheduling, and risks.
- Proven experience bringing innovative approaches to help reduce the FISMA workload and time to authorization/reauthorization through such methods as boundary consolidation, common control identification and re-use, automation, assessment readiness reviews, and digital transformation.
Desired Skills
- PMP Certification
- CISSP Certification
- Experience with Security Assessment Tools (Tenable Nessus, DBProtect, Wireshark, WebInspect)
- NIH/HHS experience
Location
- Rockville, MD (Hybrid)
Salary Band: $155-165k (Depending on experience)
About CVP
CVP is an award-winning healthcare and next-gen technology and consulting services firm solving critical problems for healthcare, national security, and public sector clients. We help organizations achieve lasting transformation.CVP is an Equal Opportunity Employer dedicated to actively recruiting individuals and providing advancement opportunities based on merit and legitimate job qualifications. We ensure that all associates receive equal opportunities based on their personal qualifications and job requirements. CVP strictly prohibits any form of discrimination or harassment.At CVP, we cultivate a work environment that encourages fairness, teamwork, and respect among all associated. We are committed to maintaining a workplace where everyone can grow both personally and professionally.
$86.72k - $119.24k
...Operational Risk Manager The Operational Risk Manager role is responsible for supporting the delivery and management of Mars Inc Operational Risk Programs such as Risk Engineering, Business Resilience, and other loss prevention programs. This position will support...SuggestedWork at office- ...Enterprise Risk (Financial) Hybrid | Tysons, VA (4 Days In-Office Per Week) Cherry Bekaert Recruiting & Staffing is partnered... ...and critical infrastructure resilience on a search for a Program Manager - Enterprise Risk . This role supports a high-visibility...SuggestedWork at officeShift work
$151.9k - $173.4k
Risk Manager As part of Enterprise Risk Management (ERM), you will work with talented associates to ensure our businesses effectively adhere to Capital One’s Risk Management Framework. This role focuses on the intersection of process management and risk management, where...SuggestedFull timePart timeLocal area$155k - $165k
Customer Value Partners, Inc. is seeking a Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program in Rockville, MD. The role involves assisting the Cybersecurity Program Manager with risk assessment, security policy development,...Suggested$151.9k - $173.4k
Risk Manager (US Card) As a Risk Manager on Capital One's Absolute Control Team (ACT), you will utilize your background in risk management, analysis, and process design to direct complex optimization initiatives for control testing and operations. Serving as a senior individual...SuggestedFull timePart timeLocal area$151.9k - $173.4k
...Overview Vertical Risk Manager: Card Risk We enable our Card business to innovate and deliver exceptional products and services in a well-managed risk ecosystem while ensuring we keep our promises to customers. As a Vertical Risk Manager at Capital One you’ll...Full timePart timeLocal area$100k - $120k
...Risk and Insurance Manager - Real Estate/Multi-Family Property Management The Risk and Insurance Manager is responsible for supporting the administration, implementation, and ongoing management of the Company’s risk management, insurance, safety, and claims programs...Full timeFor contractorsWork at officeLocal areaMonday to FridayShift workWeekend workEarly shift$155.6k - $306.8k
Position Summary The Team: The mission of Quality and Risk Management (QRM) is to manage the risk in our growing and increasingly complex business to improve financial performance and protect the firm’s assets and reputation. Work you’ll do Deloitte’s Cyber QRM team...Contract workFor subcontractorWork at officeLocal area- BullFrog AI, Inc in Gaithersburg, Maryland is seeking a Director of Investor Relations to enhance visibility and relationships within the investment community. This role offers a pathway to a VP position and requires strong skills in techbio and healthcare innovation. ...
- TPRM Risk Manager Capital One is seeking an experienced and self-motivated Manager to join our Third Party Risk Management team, within the second line of defence. The TPRM team is a dedicated group of professionals whose mission is to provide value-add, independent stewardship...
$134.5k - $265.1k
Position Summary Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional...Local areaVisa sponsorship$90k - $110k
...seeking a Senior Treasury Analyst based in North Bethesda, Maryland. This position is part of the team responsible for treasury management and accounts payable, and will primarily focus on supporting the Senior Manager with daily treasury and cash management functions...Temporary work- ...Location: Falls Church, VA Employment Type: Full-Time, Permanent Job Overview: We are seeking a Risk and Governance Manager to oversee technology-related risk processes within Investments & Capital Markets. In this role, you will work closely...Permanent employmentFull time
$149.81k
...functions. Based in Gaithersburg, US, you will report to the Project Management Team Leader for Global Medical Affairs and partner closely with... ...on key topics and initiatives, spotlighting progress, risks and decisions needed.Continuous Improvement: Identify and embed...Full timeTemporary workWork at officeLocal areaWorldwideFlexible hours3 days per week$151.9k - $173.4k
...Overview Risk Manager, Operational Risk Management As a Manager for Capital One’s Operational Risk Analytics, Innovation, and Reporting team, you will apply your strong communication skills, analytical expertise, and business knowledge to our highest profile programs...Full timePart timeLocal area$151.9k - $173.4k
...Risk Manager - Channels and Shared Services (Hybrid) As a Risk Manager in Capital One's Card Risk Team you will apply your risk management, project management and analytical skills to our highest profile risk initiatives. Risk Managers are at the front line of defense...Full timePart timeWork at officeLocal area- Capital One is seeking a dynamic Enterprise Payments Governance & Oversight Manager (Hybrid) to shape and execute our payments risk framework across RTP, ACH, and wire. You will bridge 1st and 2nd line defense, drive transformation, and implement cutting-edge monitoring...
$151.9k - $173.4k
...Overview Risk Manager, Enterprise Payments Risk Management Do you want to be part of an organization that’s dedicated to helping Capital One identify, manage and effectively mitigate risk – for our customers, our communities and our associates? As part of Operational...Full timePart timeLocal area$101.12k - $139.04k
...Job Description: The Global Risk Financing Manager will reinforce the Corporate Risk Management philosophy to Mars, Incorporated's global business units with the purpose of 1) protecting human assets, 2) preventing loss to the corporation's physical assets, and 3...Contract workFor contractorsWork experience placementLocal area$101.12k - $139.04k
Position Overview The Global Risk Financing Manager will reinforce the Corporate Risk Management philosophy within Mars, Incorporated's global business units with the purpose of protecting human assets, preventing loss to the corporation's physical assets, and transferring...Contract workLocal area$200.7k - $229.1k
...Overview Cyber Third Party Risk Reduction (CTPRR) Senior Manager, Operations Manager The Cyber Third Party Risk Reduction (CTPRR) program defines the framework for the management of information security risks with third party engagements, supports contracting, conducts...Full timePart timeH1bLocal area- Mars Incorporated is seeking an Operational Risk Manager to lead global risk programs, including risk engineering, business resilience, and loss prevention. You will partner with internal teams, external consultants, insurers, and risk engineers to quantify and minimize...
$161.5k - $184.3k
Sr. Risk Manager, Well Managed Team - Business Cards & Payments Level: Senior Manager, People Leader Locations: Richmond - VA, McLean - VA, Plano - TX, or New York - NY. Type: This is a Hybrid position. In Business Cards and Payments, we’re on a mission to pave the...Full timePart timeWork at officeLocal area$151.9k - $173.4k
Card Vertical Risk Manager: Network Operations The Card Risk Vertical Manager (VRM) role will support Card leadership in the primary areas of strategic network governance, relationship risk, and Network Conflict Risk. In this role, you will lead, advise, and innovate on...Full timePart timeWork at officeLocal area- Capital One seeks a Manager, Risk Management in ORCA to lead 2nd line risk challenge activities across risk assessment processes such as RCSA, PLA, and PRA. You will document results, analyze data to identify risks, and drive remediation plans while serving as a SME to...
$164.8k - $188.1k
...Overview Manager, Product Management - Personal Loans Application Fraud Decisioning Product Management at Capital One is a booming... ...having fun? About the Role Personal loans introduces a unique risk relative to credit cards in that personal loans are disbursed in...Full timePart timeLocal area- ...evidence generation, launches, and scientific exchange. The role emphasizes leadership and cross-functional collaboration. You will unify tumor strategy, create dashboards, and mentor Indication Project Managers to improve decision speed and #J-18808-Ljbffr Jobleads-US
$100k - $150k
OverviewThe Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and Authorization (A&A), Federal Risk and Authorization Management Program (FedRAMP)...Flexible hours- Capital One is seeking a Business Manager for Risk Foundations (ERM) in McLean, VA. The role focuses on strategic leadership, analytics, and driving risk-informed decisions across enterprise risk management. You will collaborate with partners, develop business strategies...
- Cherry Bekaert seeks a CFO Advisory Director to lead accounting advisory engagements, oversee delivery timelines, and identify risks to assure high-quality client outcomes. The role requires deep knowledge of US GAAP, IFRS, and SOX, with a strong business mindset and ability...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Risk Manager. Be the first to apply!



