Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Risk Management Consultant

$131k - $218.3k

Deloitte

Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Work You’ll DoAs a Software Engineer III on the team, you will:Advise Government & Public Services clients in executing the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) lifecycle to mitigate cyber risk and threatsAdvise federal agency clients on cyber risk posture and RMF compliance strategies aligned to FISMA, NIST, and agency-specific requirementsLead the development and/or review of Authority to Operate (ATO) packages (e.g., System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms))Assess or develop an organization's cyber risk strategy as it relates to data risk, cyber risk management, risk frameworks and policies, and risk measures and reportingStrategically drive the development and execution of risk assessments and mitigation plans to enhance the client's ability to identify, evaluate, prioritize, and mitigate risksImplement risk management solutions aligned to the client's vision and strategic prioritiesDrive development and implementation of cyber strategies grounded in leading practices, industry frameworks, and targeted to the client's risk and business needsSynthesize technical findings and risk data into actionable reports and executive-level briefingsDevelop impactful presentations that support engagement goals, communicate technical findings clearly to both technical and executive audiencesDeliver key messages with clarity and confidence; tailor communication style to the audienceUnderstand how business functions operate and how industry trends impact a client's cyber posture and risk profileIdentify and evaluate complex business and technology risks, and connect findings to business impactProvide guidance and quality review to junior team members on RMF documentation, assessment artifacts, and deliverable developmentParticipate in team problem-solving efforts and offer ideas to address client challengesIdentify opportunities for efficiencies in work processes and innovative approaches to completing scope of workOwn assigned work products through final review, client submission, and resolution of quality-review commentsAssist in proposal development, as requestedA successful candidate would possess these skills:Ability to work independently and collaborate as part of a teamEffective written and verbal communication skillsMeticulous attention to detail and quality of work productAbility to build and sustain professional relationshipsAbility to lead projects or workstreamsAbility to manage and prioritize multiple tasks in a fast-paced and dynamic environmentStrong interpersonal skills and professional demeanorAbility to meet deadlinesAbility to provide clear guidance to othersThe TeamDeloitte’s Government & Public Services (GPS) practice – our people, ideas, technology and outcomes – is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.This opportunity sits within our Deloitte US Delivery Center model, which is dedicated to driving impactful business services. It leverages Deloitte’s scale and talent, as well as a center delivery model to provide high-quality, cost-effective service with standardized processes and procedures to service businesses across Deloitte.The Deloitte US Delivery Center has a small-business feel with a big-business impact. With the resources of Deloitte and a community feel, the delivery center model provides high-quality services to our clients. USDC professionals work out of one of our specific delivery center locations, and each location presents dynamic career opportunities for professionals to focus on their work with nominal travel requirements.QualificationsRequired: Bachelor’s degree in cybersecurity, information technology, information systems, computer science, risk management, business, mathematics, decision sciences, or a related field, or an equivalent combination of education, professional training, and relevant cybersecurity experience in accordance with applicable talent policies.Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future 4+ years of professional experience in cybersecurity, information assurance, governance, risk and compliance, cybersecurity risk management, or federal security compliance, including at least 2 years supporting NIST RMF or an equivalent authorization process including participation in at least one end-to-end authorization cycle or multiple lifecycle phases across two or more systems.2+ years of experience applying NIST RMF concepts and NIST SP 800-37 to information-system authorization, security assessment, or continuous-monitoring activities, including 1+ year applying NIST SP 800-53 controls. Experience with the NIST CSF, FedRAMP, or agency-specific security requirements is preferred.2+ years of experience implementing, documenting, assessing, or managing NIST SP 800-53 security controls, including at least 1 year preparing control narratives, reviewing implementation evidence, documenting assessment results, or tracking remediation activities.2+ years of experience developing, updating, or quality-reviewing cybersecurity policies, procedures, standards, or implementation guidance mapped to NIST SP 800-53 controls or an equivalent federal security baseline, including experience supporting at least one moderate-impact information system.At least 2 years of experience in RMF documentation and control implementation, plus at least 1 year in three of the following: system categorization, boundary definition, control tailoring, continuous monitoring, risk assessment, vulnerability management, or GRC tool administration.Ability to obtain and maintain the level of federal security clearance or Public Trust designation required for client engagements.Delivery Center Location & Travel Requirements:Hybrid Work Model: Operate under a hybrid system requiring residence within a commutable distance to one of the US Delivery Center locations (Gilbert, Lake Mary, or Mechanicsburg) or Geo-Hub locations (Atlanta, Charlotte, Dallas, Houston, and Philadelphia)Co-location Expectation: Spend up to 30% of working time co-located at an assigned office for orchestrated opportunities, including projects, practice sessions, training, and Moments That Matter at a Deloitte Delivery Center location, Geo-Hub location, approved site, or project locationTravel Requirement: Maximum of 10% overnight travel for client or project purposesRelocation Requirement: If relocation is necessary, complete the move within 12 weeks from the start date to reside within a commutable distancePreferred: Previous federal or government consulting experience.1+ year applying NIST SP 800-171, CMMC, or equivalent controlled-unclassified-information security requirements.1+ year of experience analyzing or documenting enterprise, mission-critical, cloud, or multi-system technology environments, including business processes, system dependencies, data flows, security vulnerabilities, or operational risks.1+ year of experience supporting a FedRAMP authorization, cloud security assessment, or RMF activity for AWS GovCloud, Azure Government, or an equivalent federal cloud environment.1+ year of experience delivering cybersecurity or RMF work in an Agile, hybrid-Agile, or iterative federal program environment, including sprint planning, backlog management, or incremental deliverable reviews.2+ years of experience in at least one technical domain relevant to RMF, such as security architecture, network security, cloud infrastructure, identity and access management, endpoint security, or vulnerability management.CISSP, CISM, CISA, or CEH certificationThe wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $131,000-$218,300.You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance. Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at View email address on click.appcast.io. Recruiting tips From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters. BenefitsAt Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you. Our people and culture Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work. Our purpose Deloitte’s purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Learn more. Professional development From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career. As used in this posting, "Deloitte" means Deloitte Transactions and Business Analytics LLP, a subsidiary of Deloitte LLP. Please see for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law. Requisition code: 366523 Job ID 366523 Engineering and Product | Software Engineering

Vacancy posted 23 hours ago
Similar jobs that could be interesting for youBased on the Cybersecurity Risk Management Consultant in Rosslyn, VA vacancy
  • $74k - $124k

     ...Job Family : Finance & Accounting Consulting Travel Required : None Clearance...  ..., increase transparency and performance management, and comply with Federal laws and regulations...  ...testing to be performed based on the risk profile of the organization and specific... 
    Suggested
    Temporary work
    Work experience placement
    Flexible hours

    Guidehouse

    Washington DC
    5 hours ago
  • $99k - $225k

    Risk Management Framework Cybersecurity Analyst The Opportunity: Are you looking for an opportunity to share your experience in Risk Management Framework (RMF) and cybersecurity to support our country and safeguard our nation? As an RMF Cybersecurity Analyst, you will... 
    Suggested
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    5 hours ago
  •  ...role Clearance: Active Top Secret     Qualifications: - Provides analytical support to manage the increasing risk of supply chain compromise related to cybersecurity, whether intentional or unintentional. - Identifies, assesses, and mitigates the risks associated... 
    Suggested
    Long term contract
    Permanent employment
    Full time

    Maania Consultancy Services

    Washington DC
    22 days ago
  • $100k - $110k

     ...Title: Senior Business Technology Consultant /Virtual Chief Information Officer (vCIO...  ...Summary MainSpring is an award-winning cybersecurity & IT managed services firm headquartered in the...  ...in the areas of strategic planning, risk management and business process... 
    Suggested
    Full time
    Temporary work
    Work at office
    Immediate start

    MainSpring

    Washington DC
    a month ago
  • $95k - $105k

     ...Remote with occasional on-site support Connected Logistics is seeking a senior Risk and Compliance Analyst to support cybersecurity governance, enterprise risk management, compliance oversight, audit readiness, and continuous monitoring activities supporting the... 
    Suggested
    Contract work
    Remote work

    Connected Logistics

    Springfield, VA
    3 days ago
  •  ...Enterprise Risk Management Analyst We are seeking an Enterprise Risk Management Analyst to support the Department of State IT Governance Support Services Bureau of Consular Affairs. This position supports the decision-making framework for addressing several enterprise... 
    Work at office

    Ryde Technologies

    Washington DC
    5 days ago
  • $69.4k - $158k

     ...Risk Management Analyst The Opportunity: Use your industry or domain expertise to assess risk posture to develop innovative solutions to complex problems supporting a dynamic Navy Middle Tier Acquisition ( MTA ) technical program focused on rapid prototyping and... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    BOOZ, ALLEN & HAMILTON, INC.

    Washington DC
    2 days ago
  • $69.4k - $158k

     ...The Opportunity:Use your industry or domain expertise to assess risk posture to develop innovative solutions to complex problems...  ...who is excited to help build a lean, effective Acquisition Risk Management process without the heavy bureaucracy of traditional ACAT programs... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    4 days ago
  • $63.77 per hour

     ...Job Title: Sr Risk Management Analyst Location: Washington, DC Type: Contract Compensation: $63.77 per hour Work Model: Hybrid – onsite and remote Responsibilities Provide advisory support in the completion of divisional risk... 
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Local area
    Remote work

    System One

    Washington DC
    29 days ago
  •  ...A consulting firm specializing in financial crime risk management is seeking professionals in Washington, DC. You'll provide consulting services to government clients, analyzing transactions and training investigators in areas like AML and economic sanctions. The ideal... 

    Portastrategies

    Washington DC
    1 day ago
  • $43k - $44.63k

     ...Headquartered in Alpharetta, Georgia, DataScan stands at the forefront of delivering cutting-edge wholesale asset financing and inventory risk management solutions. Our commitment lies in empowering lenders to efficiently oversee their operations and manage risk through our... 
    Temporary work
    Live in
    Immediate start
    Flexible hours
    Night shift

    DataScan

    Washington DC
    4 days ago
  •  ...Grant Management And Administration Consultant (Foreign Aid / Technical Assistance Sector) ProSidian is a Management and Operations Consulting Services...  ...focus on the broad spectrum of Enterprise Solutions for Risk Management | Compliance | Business Processes | IT Effectiveness... 
    Work at office
    Remote work

    ProSidian Consulting

    Washington DC
    3 days ago
  •  ...A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating... 
    Remote work

    Districttechgroup

    Washington DC
    4 days ago
  • $80k - $128k

     ...Risk And Vulnerability Analyst Peraton is currently seeking a Risk and Vulnerability...  ...Required: Bachelor's degree in Cybersecurity, Information Technology, or related field...  ...experience in security operations, vulnerability management, or risk analysis. Hands-on... 
    Contract work
    Shift work

    Peraton

    Washington DC
    5 days ago
  •  ...and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM...  ...sessions. Track project actions, risks, issues, decisions, and deliverables to...  ...customer requirements. Support change management activities, including impact assessments... 
    For contractors
    Work at office

    Electrosoft

    Arlington, VA
    5 days ago
  •  ...Security (OIT/OIS) program covering enterprise cybersecurity architecture and engineering. We are seeking Risk and Compliance Analysts to own the risk, compliance...  ...up and operate a full Cyber Supply Chain Risk Management program, and report against specific data quality... 
    Full time
    Contract work
    Interim role
    Work at office
    Remote work

    Triumph Enterprises

    Washington DC
    4 days ago
  • $100k - $129.02k

     ...Management Analyst II This position requires an active Secret clearance...  ...assistance awards, In consultation with program staff, evaluate...  ...help resolve compliance or risk issues. Coordinate with program...  ...Technologies Artificial Intelligence Cybersecurity Foreign Policy Legal... 
    Full time
    Contract work
    Work at office

    Cherokee Federal

    Washington DC
    3 days ago
  •  ...Senior Management Analyst POSITION SUMMARY Aleknagik Technology, LLC (ATL) is seeking a Senior Management Analyst to provide Mission...  ...to the Defense Health Agency (DHA). This position supports risk management, critical infrastructure protection, continuity planning... 
    Contract work

    ATL Professional Services LLC

    Falls Church, VA
    4 days ago
  •  ...Management Analyst (Journeyman) Xenith Solutions is a small family focused business where...  ...management, strategic planning, risk management, and process improvement methodologies...  ...and relevant Solutions and Business Consulting support to our customers as a key partner... 
    For contractors
    Work at office
    Local area

    Xenith Solutions

    Washington DC
    17 hours ago
  •  ...Paid time off Role Overview: The Federal Financial Management Consultant provides beginning-to-end audit remediation and sustainment...  ...automation.   Key Responsibilities: Internal Controls & Risk Management (OMB A-123): Execute the full annual cycle of... 

    Silverthorne Advisory Group LLC

    Washington DC
    a month ago
  •  ...of Information Act (FOIA) processing, records management, and transparency compliance.     The Senior Management Consultant will serve in a senior advisory capacity, providing...  ...compliance while balancing transparency, risk management, and mission requirements.     Our... 

    Chenega Corporation

    Washington DC
    10 days ago
  •  ...Description Job Description Evolver is an information technology, cybersecurity, and digital transformation company supporting national...  .... The Discovery Business & System Analyst will document and manage new and existing business processes in order to facilitate training... 
    Flexible hours

    Evolver Federal

    Washington DC
    6 days ago
  • $110.18k - $183.63k

     ...apply now. We are currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington...  ...Support # Ensure vulnerability management practices align with NIST SP 800-53,...  ...centers and application services. our consulting and Industry solutions help organizations... 
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA, Inc.

    Arlington, VA
    6 days ago
  • $69.4k - $158k

     ...Job Number: R0244360 Risk Management Analyst The Opportunity Use your industry or domain expertise to assess risk posture to develop innovative solutions to complex problems supporting a dynamic Navy Middle Tier Acquisition (MTA) technical program focused on rapid prototyping... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    4 days ago
  •  ...Supported Client/Agency: Department of Homeland Security (DHS) / Cybersecurity and Infrastructure Security Agency (CISA) Description...  ...Enterprises is seeking an experience Stakeholder and Records Management Analyst. The ideal candidate will have substantial experience... 
    Full time
    Work at office
    Remote work

    Chimera Enterprises International

    Arlington, VA
    28 days ago
  •  ...assuming Product Owner responsibilities when required. Project Management Act as the key interface between business stakeholders and...  ...of the energy trading markets requires excellence in risk management and a culture of innovation. Our people flourish... 
    Permanent employment
    Full time
    Worldwide
    Visa sponsorship
    Work visa

    Total Energies

    Washington DC
    a month ago
  •  ...client communication, and case-status tracking. Deadline Management: Monitoring USCIS filing deadlines, interview...  ...company, is a global leader in legal staffing, eDiscovery, risk management, and legal consulting services. The company supports multinational law firms... 
    Temporary work
    Work at office
    Immediate start
    Remote work
    2 days per week

    Lawyers On Demand, a Consilio Company

    Washington DC
    7 days ago
  •  ...) specializing in delivering innovative IT consulting, staff augmentation, Agile transformation, cloud modernization, cybersecurity, and enterprise technology solutions to federal...  ...individual will work closely with project managers, product owners, developers, and Scrum... 
    Full time
    Contract work
    Work at office

    Diverse Agile Solutions

    Washington DC
    a month ago
  •  ...Job Description Job Description Senior Management Analyst Job Summary: The Senior Management Analyst provides critical support to the...  ...and continuity planning efforts. The role involves conducting risk assessments, identifying critical infrastructure and assets, and... 
    Contract work

    Aleknagik Technology

    Falls Church, VA
    6 days ago
  • $80k - $179.4k

     ...company’s success. As a Business Development Manager III within PNC's Financial Wellness...  ...qualify, and advance opportunities using a consultative sales approach, leading efforts from...  ...works with clients with advanced levels of risk and complexity of needs. Works... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Flexible hours

    PNC

    Washington DC
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Risk Management Consultant. Be the first to apply!