Cyber Risk Management Specialist
$100k - $150kSteampunk
OverviewThe Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and Authorization (A&A), Federal Risk and Authorization Management Program (FedRAMP) compliance, continuous ATO (cATO) and continuous monitoring. A solid grasp on confidentiality, integrity, and availability (CIA) security concepts is required. The candidate will be responsible for the technical implementation and enforcement of security hardening, vulnerability management, scan analysis, data analysis for metrics reporting, cloud environments, compliance with Federal regulation and policy, and commercial best practices relating to cyber security. The candidate must have the ability to be flexible and adaptive to a fast-paced, fluid business environment.ContributionsThe role requires strong procedural knowledge of NIST SP 800-37 Risk Management Framework (RMF) for Information Systems and Organization, NIST SP 800-53 Security and Privacy Controls for Information Systems and Organizations, NIST SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations, FedRAMP requirements, cloud environments, cloud cybersecurity architecture, compliance with Federal regulation and policy, and commercial best practices relating to cloud security. The CRMS is expected to efficiently learn and adapt to rapidly changing federal governance frameworks and standards of practice, to include risk treatments for modern and emerging technologies (e,g, AI, blockchain, microservices).The Cyber Risk Management Specialist performs a range of functions before, during, and after an authorization is granted:Integrate security into DevOps effectively at every stage of the software development life cycle (SDLC).Identify security holes and potential breaches, work through multifaceted security issues, and create effective solutions based on understanding of risk posture and treatments.Develop and implement tactical strategies for seamless automation to optimize the IT infrastructure.Apply specialized knowledge of financial audit standards, classified system IA requirements, and Privacy Act requirements.Implement the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework.Evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelinesApply in-depth, hands-on knowledge of the FedRAMP regulations, process, and requirements to lead project and initiative teams in accrediting cloud products and services. Support external audits, data calls, and the Authorization to Operate (ATO) process by coordinating with organization system owners, engineers, CSP’s and Third-Party Assessment Organizations (3PAO). Positively impact the organization’s goals and operational mission through various forms of metric performance measuring tools used to evaluate adherences to compliance.Advise clients on FedRAMP requirements and provide security guidance on the implementation of security compliance controls per technical, management, and operational requirements. Implement, monitor, and assess NIST SP 800-53 security controls for cloud environments to ensure compliance with FedRAMP requirements and governance models. Ensure ongoing compliance with FedRAMP policy and requirements through monthly deliverables, regular vulnerability scanning, penetration testing, contingency testing, and annual security assessments performed by a 3PAO.Support ATO, cATO, and continuous monitoring activities to include security documentation, audit log, security incidents, and risk assessment.Review and manage Plan of Action & Milestones (POA&M), to include remediation tracking and reporting.QualificationsRequiredAbility to obtain a U.S. government Security ClearanceMaster's Degree and 6 year of cyber and FISMA experience; ORBachelor's Degree and 8 years of cyber and FISMA experience; ORNo degree and 12 years of experience, 10 of which must be in cyber and FISMA Possesses at least one professional certification: CISSP, CASP, CISA, CISM or GSLCPreferredExperience in FISMA, cloud cybersecurity architecture, compliance with Federal regulation and policy, and commercial best practices relating to cloud security.Experience in Information Security processes to include RMF, FedRAMP, Compliance, Continuous Monitoring, and Annual Assessments.Certifications in one or more of the following: CISSP, CRICS, CCSP, CAP/CGRC.Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform and InfrastructureExperience conducting assessments in a 3PAO, C3PAO, or risk auditing organization is desirable, but not required.Experience supporting systems in Agile environments.About steampunkSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $100,000 to $150,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here. Identity StatementAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company, we focus on investing in our employees to enable them to do the greatest work of their careers – and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visit .We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program. Job SummaryJob ID: 8006Clearance Requirement: Public Trust
$155.6k - $306.8k
Position Summary The Team: The mission of Quality and Risk Management (QRM) is to manage the risk in our growing and increasingly complex... ...the firm’s assets and reputation. Work you’ll do Deloitte’s Cyber QRM team is seeking a Quality & Risk Manager who will be...CyberContract workFor subcontractorWork at officeLocal area$115k - $165k
...to create extraordinary experiences, you belong at HITT.Senior Manager, Risk ManagementJob Description:The Senior Manager, Insurance & Risk... ..., umbrella, professional liability, pollution liability, cyber, management liability, and builder’s risk across all HITT operating...CyberFull timeContract workWork experience placementFor subcontractorWork at officeLocal area$134.5k - $265.1k
Position Summary Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional...CyberLocal areaVisa sponsorship$197.3k - $225.1k
...Manager, SRE Risk Advisory and Oversight Capital One is one of the fastest growing organizations in the world today, powered by our passion... ...Management, Software Engineering, Site Reliability Engineering, or Cyber Risk Management At least 2 years of experience with cloud...CyberFull timePart timeLocal area- ...MANTECH seeks a motivated, career and customer-oriented Cyber Incident Response Analyst to join our team in McLean, Virginia .... ...Response and Mitigation Threat Intelligence and Vulnerability Management Reporting and Documentation Minimum Qualifications: ~...CyberShift workNight shiftDay shiftAfternoon shift
$180k - $225k
...DescriptionEverforth ECS is seeking a Senior Solutions Architect - Cyber Operations to work in a hybrid schedule in our Arlington,... ...detection and analysis, incident response, threat hunt, vulnerability management, and more. As a strategic advisor and operational leader,...CyberContract workLocal area- ...A cybersecurity and data operations firm is seeking Cyber Eviction Analysts to support the DHS's Hunt and Incident Response Team. The role requires extensive experience in incident response and the ability to think independently. Candidates must have a strong understanding...Cyber
- ...adversaries, and partner with federal stakeholders to strengthen cyber resilience across complex infrastructures. Key... ...and hands‑on attack simulations. Deliver technical reporting, risk articulation, and executive‑level briefings. Collaborate with...CyberFull time
$122.2k - $174.6k
...help build your skills and capabilities.SummaryThe Enterprise Risk Management (ERM) Leader is responsible for developing and maturing the organization... ...aligned to COSO, ISO 31000, and integrated with NIST-based cyber risk practices.Define and maintain enterprise risk appetite...CyberFull timeRemote workFlexible hours- ...Jobtailor in McLean, VA is seeking a Cyber Security Operations Center analyst to analyze network protocols and infrastructure, conduct log investigation and incident handling, and identify and stop malicious actors targeting Capital One's infrastructure. You will train...Cyber
$200k - $250k
Job DescriptionEverforth ECS is seeking a Deputy Program Manager, Cyber Mission Integration & Modernizationto work in a hybrid schedule in... ...designated mission areas within the broader portfolio.Manage program risks, dependencies, priorities, and execution activities across...Cyber- ...in 1998 and headquartered in Reston, VA. We offer IT solutions across the disciplines of program/project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have developed our methodologies and processes...Cyber
$155k - $180k
...enforcementAdminister and optimize Cisco Firepower and Firepower Management Center (FMC), including policy administration, rule management,... .../Disability Status/Veteran Status Job SummaryCategory: IT / Cyber Security / Network SystemsPosition Type: Full-TimeRemote: NoClearance...Cyber- ...federal government organizations on national cybersecurity programs. You will collaborate with clients to plan, defend, and respond to cyber threats, delivering analyses, briefings, and trainings. The role requires a Bachelor's degree (Master's preferred) and 3+ years in...Cyber
- ...Job Title: Risk Manager Location: Washington, DC Metropolitan Area (Onsite) Employment Type: Full-Time Clearance: ActiveTS... ...associated with large, complex federal initiatives involving cyber operations, IT modernization, and mission systems. The...CyberFull timeContract workTemporary workWork at officeLocal areaImmediate startHome officeFlexible hours
$86.8k - $198k
...JDDT), Universal Joint Task List Tool (UTDT), Joint Publication Management Tool (JPMT), Joint Terminology Master Database (JTMD), Joint... ...software engineering or cybersecurity - DoDM 8140.03 Defense Cyber Work Force Work Role 621-Intermediate Software Developer Certification...CyberFull timeContract workPart timeWork at officeLocal areaRemote work- ..., a fast-growing firm, specializes in IT/Digital Modernization, Cyber Security, NextGen IT, and Emerging Technology services. We provide... ...) and Professional Solutions Team is seeking a Senior Proposal Manager who is eager to learn and lead bids as a member of the A3T...CyberWork at office
$86k - $138k
ResponsibilitiesPeraton is hiring an experienced Cyber Intelligence Analyst for our Federal Strategic Cyber Programs.Location: Rosslyn, VA. Hybrid may be possible.In this role, you will: Perform consolidated and comprehensive information and intelligence analysis of threat...CyberContract workWorldwideShift work$104k - $166k
ResponsibilitiesPeraton is Cyber Threat Analyst - Global Threat Analysis (GTA) for its' Federal Strategic Cyber program.Location: Arlington... ...to work in a fast-paced, mission-critical environment while managing multiple priorities.U.S. citizenship required. Active Top...CyberFull timeContract workOverseasShift work- ...disparate systems through APIs, automation, dashboards, workflows, and data pipelines to improve cyber hygiene, incident detection, operational visibility, and risk management.The Cybersecurity Integration Engineer partners with cybersecurity operations, infrastructure,...Cyber
$80k - $128k
ResponsibilitiesPeraton is seeking a NOSC Cyber Analyst to support our customer onsite in Arlington, Va. Responsibilities include:Coordinate... ...and are receiving or generating alerts.Identify security risks and exposures, determine causes of security violations, and suggest...CyberContract workShift work- ...1K, an Employee Stock Purchase Plan (ESPP) through Tetra Tech, and more! Responsibilities: The Program Manager will be responsible for executing and overseeing cyber contracts and resources on cyber projects and ensuring high performance for our federal customers. In addition...CyberContract work
- ...Senior Detection Engineer/Splunk Content Developer to enhance cyber security efforts. The role requires at least 5 years of experience... ...a Bachelor’s degree or equivalent. Responsibilities include managing network defense systems and identifying gaps in coverage. This...Cyber
$112k - $179k
ResponsibilitiesPeraton is currently hiring Sr Industrial Control System Cyber Threat Intelligence Analyst for its Federal Strategic Cyber programs.Location: On-site role in Arlington, VA.In this role, you will:Fuse multiple intelligence sources to develop products, recommendations...CyberContract workCurrently hiringShift work- ...Engineer within the Cybersecurity group for the Technology Exposure Management Engineering team. The successful candidate will lead, implement... ...coding practices align with scalable enterprise solutions for our client's Cyber Security Vulnerability Remediation applications....Cyber
- ...A growing decision analytics firm is seeking a Junior Cyber Risk Data Engineer/Analyst in Arlington, VA. This role emphasizes data-driven capabilities in cyber risk management, where you'll manage risk assessment data, connect with external threat databases, and assist...Cyber
$170k - $180k
...DescriptionEverforth ECS is seeking a Senior Cyber Incident Analyst to work in our Arlington... ...supporting cyber threats and incident management, have expert-level communications skills... ...cybersecurity principles, threat intelligence, and risk management. The ideal candidate will...CyberWork at office3 days per week- ...in 1998 and headquartered in Reston, VA. We offer IT solutions across the disciplines of program/project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have developed our methodologies and processes...Cyber
- A cybersecurity solutions provider is seeking a Jr Industrial Control System Cyber Threat Intelligence Analyst in Arlington, VA. The ideal candidate should hold a Bachelor's degree with at least 2 years of relevant experience and have hands-on capabilities in cyber incident...Cyber
- ...Cyber Network Forensic Analyst III, TS/SCI Raytheon Technologies provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity...CyberImmediate startRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Risk Management Specialist. Be the first to apply!
- senior risk manager McLean, VA
- operational risk manager McLean, VA
- risk management manager McLean, VA
- director credit risk McLean, VA
- risk management associate McLean, VA
- head of risk management McLean, VA
- enterprise risk manager McLean, VA
- risk management specialist McLean, VA
- director of risk management McLean, VA
- cyber McLean, VA



