Cyber Risk Management Specialist
$100k - $150kSteampunk
OverviewThe Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and Authorization (A&A), Federal Risk and Authorization Management Program (FedRAMP) compliance, continuous ATO (cATO) and continuous monitoring. A solid grasp on confidentiality, integrity, and availability (CIA) security concepts is required. The candidate will be responsible for the technical implementation and enforcement of security hardening, vulnerability management, scan analysis, data analysis for metrics reporting, cloud environments, compliance with Federal regulation and policy, and commercial best practices relating to cyber security. The candidate must have the ability to be flexible and adaptive to a fast-paced, fluid business environment.ContributionsThe role requires strong procedural knowledge of NIST SP 800-37 Risk Management Framework (RMF) for Information Systems and Organization, NIST SP 800-53 Security and Privacy Controls for Information Systems and Organizations, NIST SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations, FedRAMP requirements, cloud environments, cloud cybersecurity architecture, compliance with Federal regulation and policy, and commercial best practices relating to cloud security. The CRMS is expected to efficiently learn and adapt to rapidly changing federal governance frameworks and standards of practice, to include risk treatments for modern and emerging technologies (e,g, AI, blockchain, microservices).The Cyber Risk Management Specialist performs a range of functions before, during, and after an authorization is granted:Integrate security into DevOps effectively at every stage of the software development life cycle (SDLC).Identify security holes and potential breaches, work through multifaceted security issues, and create effective solutions based on understanding of risk posture and treatments.Develop and implement tactical strategies for seamless automation to optimize the IT infrastructure.Apply specialized knowledge of financial audit standards, classified system IA requirements, and Privacy Act requirements.Implement the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework.Evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelinesApply in-depth, hands-on knowledge of the FedRAMP regulations, process, and requirements to lead project and initiative teams in accrediting cloud products and services. Support external audits, data calls, and the Authorization to Operate (ATO) process by coordinating with organization system owners, engineers, CSP’s and Third-Party Assessment Organizations (3PAO). Positively impact the organization’s goals and operational mission through various forms of metric performance measuring tools used to evaluate adherences to compliance.Advise clients on FedRAMP requirements and provide security guidance on the implementation of security compliance controls per technical, management, and operational requirements. Implement, monitor, and assess NIST SP 800-53 security controls for cloud environments to ensure compliance with FedRAMP requirements and governance models. Ensure ongoing compliance with FedRAMP policy and requirements through monthly deliverables, regular vulnerability scanning, penetration testing, contingency testing, and annual security assessments performed by a 3PAO.Support ATO, cATO, and continuous monitoring activities to include security documentation, audit log, security incidents, and risk assessment.Review and manage Plan of Action & Milestones (POA&M), to include remediation tracking and reporting.QualificationsRequiredAbility to obtain a U.S. government Security ClearanceMaster's Degree and 6 year of cyber and FISMA experience; ORBachelor's Degree and 8 years of cyber and FISMA experience; ORNo degree and 12 years of experience, 10 of which must be in cyber and FISMA Possesses at least one professional certification: CISSP, CASP, CISA, CISM or GSLCPreferredExperience in FISMA, cloud cybersecurity architecture, compliance with Federal regulation and policy, and commercial best practices relating to cloud security.Experience in Information Security processes to include RMF, FedRAMP, Compliance, Continuous Monitoring, and Annual Assessments.Certifications in one or more of the following: CISSP, CRICS, CCSP, CAP/CGRC.Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform and InfrastructureExperience conducting assessments in a 3PAO, C3PAO, or risk auditing organization is desirable, but not required.Experience supporting systems in Agile environments.About steampunkSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $100,000 to $150,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here. Identity StatementAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company, we focus on investing in our employees to enable them to do the greatest work of their careers – and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visit .We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program. Job SummaryJob ID: 8006Clearance Requirement: Public Trust
$155.6k - $306.8k
Position Summary The Team: The mission of Quality and Risk Management (QRM) is to manage the risk in our growing and increasingly complex... ...the firm’s assets and reputation. Work you’ll do Deloitte’s Cyber QRM team is seeking a Quality & Risk Manager who will be...CyberContract workFor subcontractorWork at officeLocal area$115k - $165k
...to create extraordinary experiences, you belong at HITT.Senior Manager, Risk ManagementJob Description:The Senior Manager, Insurance & Risk... ..., umbrella, professional liability, pollution liability, cyber, management liability, and builder’s risk across all HITT operating...CyberFull timeContract workWork experience placementFor subcontractorWork at officeLocal area$134.5k - $265.1k
Position Summary Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional...CyberLocal areaVisa sponsorship- Title:Director, Risk ManagementWe are KBRWhen you become part of our KBR team, your opportunities... ...and readiness to advanced research, cyber, logistics, and life-cycle sustainment,... ....About the RoleThe Director, Risk Management provides strategic leadership for KBR's global...CyberFull timeContract workTemporary workWork at officeLocal areaRemote workRelocation packageFlexible hours
- Cybersecurity and Infrastructure Security Agency (CISA) in Arlington, VA seeks a Senior Executive Service (SES) level candidate for the Risk Services Division. The role emphasizes developing and applying risk analyses, modeling and decision-support processes, and driving...Cyber
- Capital One seeks a Director, Cyber Technical to lead second-line risk oversight for Brex integration in a fast-paced fintech environment. You will oversee cloud and application architectures, AI governance, and security standards while partnering with CTOs and risk officers...Cyber
- Capital One seeks a Director, Cyber Risk & Analysis in Retail Bank to lead technology and cyber risk management across the Retail Risk Office. You will steer risk assessments, governance, and controls, while championing innovative approaches and AI governance to strengthen...CyberWork at office
- Capital One is seeking a Director, Cyber Risk and Analysis to lead state-of-the-art risk assessments and control programs within the Retail... ...strategies, prioritize risks, and drive innovations in risk management across technology domains. The role emphasizes deep expertise...CyberWork at office
$229.9k - $262.4k
...Overview Senior Manager, SRE Risk Advisory and Oversight Capital One is one of the fastest growing organizations in the world today,... ...worked. McLean, VA: $229,900 - $262,400 for Sr Manager, Cyber Technical New York, NY: $250,800 - $286,200 for Sr Manager...CyberFull timePart timeLocal area- A leading financial services firm in McLean is seeking a Manager to join their Cyber Tech & Product Risk team. The role involves applying risk management expertise to enhance the organization's cyber risk profile and drive strategic change. Responsibilities include risk...Cyber
$164.8k - $188.1k
...Overview Manager, Cyber Risk & Analysis As a Manager, you will apply your technical expertise, risk management acumen, and project management skills to drive Risk Management Strategy for a major technology modernization program within Capital One’s Retail Bank Division...CyberFull timePart timeLocal area- ...while building long-term capability within our client organizations. Position Overview SET Development is seeking a Cyber Security Product Risk Manager to support the security and resilience of space-based systems, including spacecraft and associated hardware. This...Cyber
- ..., Airbus U.S. is the place where top talent wants to work.Position Summary: Airbus US is looking for a Cyber Security Product Risk Manager who works with specialists from the Cyber, Space Engineering, and Contracts departments to ensure our products meet the applicable...CyberContract workWork at officeLocal areaVisa sponsorship
$200.7k - $229.1k
...Overview Cyber Third Party Risk Reduction (CTPRR) Senior Manager, Operations Manager The Cyber Third Party Risk Reduction (CTPRR) program defines the framework for the management of information security risks with third party engagements, supports contracting, conducts...CyberFull timePart timeH1bLocal area$177.7k - $202.8k
...Overview Senior Manager, Risk Management - Policy Analyst Capital One is one of the fastest growing organizations in the world today... ...first and second lines of defense such as the Technology and Cyber organizations, Enterprise Data, Divisional Data Risk Officers,...CyberFull timePart timeLocal area$151.9k - $173.4k
...Overview Manager, Risk Management: Card Data Management Do you like working in the spotlight? Are you ready to work on the front line... ...Risk Management experience in support of financial services, cyber, technology, or data management At least 3 years of Project...CyberFull timePart timeCurrently hiringLocal area$164.8k - $188.1k
...Overview Manager, Cyber Risk & Analysis| Retail Bank Job Description As a member of the Technology & Cyber Risk Management team within Capital One’s Business Risk Office, you will apply your analytical, risk management, and project management skills to support...CyberFull timePart timeWork at officeLocal area$197.3k - $225.1k
...Overview Risk Manager, Endpoint Security Capital One is one of the fastest growing organizations in the world today, powered by our... ...individual will have the ability to use technical skills and cyber subject matter expertise to provide effective oversight, credible...CyberFull timePart timeLocal area$164.8k - $188.1k
The Enterprise Services Risk organization is expanding with a focus on attracting innovative... .... We operate at the forefront of risk management, providing support for novel and... ...sector. In this role As a Manager on the Cyber Tech & Product Risk team, you will apply...CyberFull timePart timeLocal areaShift work$230.4k - $263k
...Overview Director, Cyber Risk & Analysis | Retail Bank Capital One, a Fortune 500 company and one of the nation’s top 10 banks,... ...One’s Retail Risk Office, you will apply your analytical, risk management, and project management skills to support Risk Management Strategy...CyberFull timePart timeWork at officeLocal area$230.4k - $263k
...Overview Director, Card Tech Risk Advisor As a Director, Technology in Capital One’s Card Risk Office, you will apply your risk management, technology, and cyber expertise to the company’s Card Technology division. You will partner across the divisional senior leaders...CyberPermanent employmentFull timePart timeWork at officeLocal area- ...adversaries, and partner with federal stakeholders to strengthen cyber resilience across complex infrastructures. Key... ...and hands‑on attack simulations. Deliver technical reporting, risk articulation, and executive‑level briefings. Collaborate with...CyberFull time
$180k - $225k
...DescriptionEverforth ECS is seeking a Senior Solutions Architect - Cyber Operations to work in a hybrid schedule in our Arlington,... ...detection and analysis, incident response, threat hunt, vulnerability management, and more. As a strategic advisor and operational leader,...CyberContract workLocal area- ...Cybersecurity Analyst will monitor Air Gapped Security Fabrics through managed SECOPs Tools. Responsibilities include but are not... ...Diploma with 3+ years of experience in Security Operations, Cyber Security, and/or Systems Administration. Experience with SIEM...CyberWork at officeLocal areaShift workNight shift
- ...A cybersecurity solutions provider is seeking a Jr Industrial Control System Cyber Threat Intelligence Analyst in Arlington, VA. The ideal candidate should hold a Bachelor's degree with at least 2 years of relevant experience and have hands-on capabilities in cyber incident...Cyber
- Required Qualifications:Eastern Europe-focused geopolitical and cyber threat intelligence experience Experience with cyber threat intelligence analysis principles in a government or commercial environment Knowledge of current and emerging Eastern Europe-related cyber adversaries...Cyber
- ...Booz Allen Hamilton is seeking a Civil Cyber Solutions Architect Director to spearhead visioning, architecture, development, and implementation of strategic cybersecurity solutions for Federal Civil and State & Local markets. You will work closely with government clients...CyberLocal area
$5,000 per month
...for this role. Imagine One Technology & Management, Ltd. is seeking four (4) Senior Cybersecurity... ...cybersecurity requirements development, cyber threat analysis, cyber engineering, cyber... ...combat systems. Developing cybersecurity risk assessment analysis and risk mitigation...Cyber- ...Herndon, VA. This role is critical for designing, developing, and analyzing low-level Windows components to support national security and cyber defense missions.Key Responsibilities:Design and implement software components in the Windows kernel space.Perform reverse...Cyber
- ...federal government organizations on national cybersecurity programs. You will collaborate with clients to plan, defend, and respond to cyber threats, delivering analyses, briefings, and trainings. The role requires a Bachelor's degree (Master's preferred) and 3+ years in...Cyber
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Risk Management Specialist. Be the first to apply!
- director of risk management McLean, VA
- risk management specialist McLean, VA
- director credit risk McLean, VA
- enterprise risk manager McLean, VA
- senior risk manager McLean, VA
- risk management associate McLean, VA
- head of risk management McLean, VA
- operational risk manager McLean, VA
- risk management manager McLean, VA
- cyber McLean, VA




