Cyber Risk Management Specialist
$100k - $150kSteampunk
OverviewThe Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and Authorization (A&A), Federal Risk and Authorization Management Program (FedRAMP) compliance, continuous ATO (cATO) and continuous monitoring. A solid grasp on confidentiality, integrity, and availability (CIA) security concepts is required. The candidate will be responsible for the technical implementation and enforcement of security hardening, vulnerability management, scan analysis, data analysis for metrics reporting, cloud environments, compliance with Federal regulation and policy, and commercial best practices relating to cyber security. The candidate must have the ability to be flexible and adaptive to a fast-paced, fluid business environment.ContributionsThe role requires strong procedural knowledge of NIST SP 800-37 Risk Management Framework (RMF) for Information Systems and Organization, NIST SP 800-53 Security and Privacy Controls for Information Systems and Organizations, NIST SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations, FedRAMP requirements, cloud environments, cloud cybersecurity architecture, compliance with Federal regulation and policy, and commercial best practices relating to cloud security. The CRMS is expected to efficiently learn and adapt to rapidly changing federal governance frameworks and standards of practice, to include risk treatments for modern and emerging technologies (e,g, AI, blockchain, microservices).The Cyber Risk Management Specialist performs a range of functions before, during, and after an authorization is granted:Integrate security into DevOps effectively at every stage of the software development life cycle (SDLC).Identify security holes and potential breaches, work through multifaceted security issues, and create effective solutions based on understanding of risk posture and treatments.Develop and implement tactical strategies for seamless automation to optimize the IT infrastructure.Apply specialized knowledge of financial audit standards, classified system IA requirements, and Privacy Act requirements.Implement the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework.Evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelinesApply in-depth, hands-on knowledge of the FedRAMP regulations, process, and requirements to lead project and initiative teams in accrediting cloud products and services. Support external audits, data calls, and the Authorization to Operate (ATO) process by coordinating with organization system owners, engineers, CSP’s and Third-Party Assessment Organizations (3PAO). Positively impact the organization’s goals and operational mission through various forms of metric performance measuring tools used to evaluate adherences to compliance.Advise clients on FedRAMP requirements and provide security guidance on the implementation of security compliance controls per technical, management, and operational requirements. Implement, monitor, and assess NIST SP 800-53 security controls for cloud environments to ensure compliance with FedRAMP requirements and governance models. Ensure ongoing compliance with FedRAMP policy and requirements through monthly deliverables, regular vulnerability scanning, penetration testing, contingency testing, and annual security assessments performed by a 3PAO.Support ATO, cATO, and continuous monitoring activities to include security documentation, audit log, security incidents, and risk assessment.Review and manage Plan of Action & Milestones (POA&M), to include remediation tracking and reporting.QualificationsAbility to obtain a U.S. government Security ClearanceMaster's Degree and 6 year of cyber and FISMA experience; ORBachelor's Degree and 8 years of cyber and FISMA experience; ORNo degree and 12 years of experience, 10 of which must be in cyber and FISMA Possesses at least one professional certification: CISSP, CASP, CISA, CISM or GSLCPreferredExperience in FISMA, cloud cybersecurity architecture, compliance with Federal regulation and policy, and commercial best practices relating to cloud security.Experience in Information Security processes to include RMF, FedRAMP, Compliance, Continuous Monitoring, and Annual Assessments.Certifications in one or more of the following: CISSP, CRICS, CCSP, CAP/CGRC.Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform and InfrastructureExperience conducting assessments in a 3PAO, C3PAO, or risk auditing organization is desirable, but not required.Experience supporting systems in Agile environments.About steampunkSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $100,000 to $150,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here. Identity StatementAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit .We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program. Job SummaryJob ID: 8006Clearance Requirement: Public Trust
$115k - $165k
...to create extraordinary experiences, you belong at HITT.Senior Manager, Risk ManagementJob Description:The Senior Manager, Insurance & Risk... ..., umbrella, professional liability, pollution liability, cyber, management liability, and builder’s risk across all HITT operating...CyberFull timeContract workWork experience placementFor subcontractorWork at officeLocal area$134.5k - $265.1k
Position Summary Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional...CyberLocal areaVisa sponsorship- Capital One is seeking a Director, Cyber Risk and Analysis to lead state-of-the-art risk assessments and control programs within the Retail... ...strategies, prioritize risks, and drive innovations in risk management across technology domains. The role emphasizes deep expertise...CyberWork at office
$164.8k - $188.1k
...Manager, Cyber Risk & Analysis As a Manager, you will apply your technical expertise, risk management acumen, and project management skills to drive Risk Management Strategy for a major technology modernization program within Capital One's Retail Bank Division. This...CyberFull timePart timeLocal area$209.5k - $239.1k
...Director, Risk Management: Cyber & Third Party RiskCapital One, a Fortune 500 company and one of the nation's top 10 banks, offers a broad spectrum of financial products and services to consumers, small businesses and commercial clients. We are on the path to create one...CyberPermanent employmentFull timePart timeWork at officeLocal area- Capital One is seeking a Senior Manager to lead Cyber Risk & Analysis within Enterprise Services Risk Operations (ESRO). You will oversee end-to-end controls lifecycle management, design assessments for new controls, and guide a team of risk professionals to help lines...Cyber
$127.2k - $246.9k
...future as we are, join our team.KPMG is currently seeking a Manager, Security Governance, Risk and Compliance to join our Enterprise Security Services... ..., data, operations, artificial intelligence (AI), and cyber risk assessments; translate complex findings into actionable...CyberH1bLocal area- ...while building long-term capability within our client organizations. Position Overview SET Development is seeking a Cyber Security Product Risk Manager to support the security and resilience of space-based systems, including spacecraft and associated hardware. This...Cyber
$164.8k - $188.1k
The Enterprise Services Risk organization is expanding with a focus on attracting innovative... .... We operate at the forefront of risk management, providing support for novel and... ...sector. In this role As a Manager on the Cyber Tech & Product Risk team, you will apply...CyberFull timePart timeLocal areaShift work- ..., Airbus U.S. is the place where top talent wants to work.Position Summary: Airbus US is looking for a Cyber Security Product Risk Manager who works with specialists from the Cyber, Space Engineering, and Contracts departments to ensure our products meet the applicable...CyberContract workWork at officeLocal areaVisa sponsorship
$164.8k - $188.1k
...Overview Manager, Cyber Risk & Analysis| Retail Bank Job Description As a member of the Technology & Cyber Risk Management team within Capital One’s Business Risk Office, you will apply your analytical, risk management, and project management skills to support...CyberFull timePart timeWork at officeLocal area$200.7k - $229.1k
Cyber Third Party Risk Reduction (CTPRR) Senior Manager, Operations Manager The Cyber Third Party Risk Reduction (CTPRR) program defines the framework for the management of information security risks with third party engagements, supports contracting, conducts assessments...CyberFull timePart timeH1bLocal area- Required Qualifications:Experience with intelligence analysis principles or cyber threat intelligence (CTI) principles, including the ability to collect, analyze, and assess threat information.Specific experience conducting CTI analysis focused on China cyber threatsExperience...Cyber
$230.4k - $263k
...Overview Director, Cyber Risk & Analysis | Retail Bank Capital One, a Fortune 500 company and one of the nation’s top 10 banks,... ...One’s Retail Risk Office, you will apply your analytical, risk management, and project management skills to support Risk Management Strategy...CyberFull timePart timeWork at officeLocal area- ...adversaries, and partner with federal stakeholders to strengthen cyber resilience across complex infrastructures. Key... ...and hands‑on attack simulations. Deliver technical reporting, risk articulation, and executive‑level briefings. Collaborate with...CyberFull time
$180k - $225k
...DescriptionEverforth ECS is seeking a Senior Solutions Architect - Cyber Operations to work in a hybrid schedule in our Arlington,... ...detection and analysis, incident response, threat hunt, vulnerability management, and more. As a strategic advisor and operational leader,...CyberContract workLocal area$99k - $225k
Cyber Portfolio Manager, LeadThe Opportunity:As a cyber mission specialist, you understand how emerging technologies, advanced research, and mission‑driven innovation shape the future of national security. At Booz Allen, you’ll use your expertise in cybersecurity, advanced...CyberFull timeContract workPart timeWork at officeLocal areaRemote work- Required Qualifications:Eastern Europe-focused geopolitical and cyber threat intelligence experience Experience with cyber threat intelligence analysis principles in a government or commercial environment Knowledge of current and emerging Eastern Europe-related cyber adversaries...Cyber
$5,000 per month
...for this role. Imagine One Technology & Management, Ltd. is seeking four (4) Senior Cybersecurity... ...cybersecurity requirements development, cyber threat analysis, cyber engineering, cyber... ...combat systems. Developing cybersecurity risk assessment analysis and risk mitigation...Cyber- This contractor and subcontractor shall abide by the requirements of 41 CFR 60-1.4(a), 60-300.5(a) and 60-741.5(a). These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, ...CyberFor contractorsFor subcontractor
$140k - $160k
...DescriptionEverforth ECS is seeking a Mid Cyber Threat Intelligence (CTI) Analyst to join... ...campaigns, and emerging cybersecurity risks.Analyze vulnerabilities and assess potential... ...to cybersecurity teams and management.Participate in intelligence briefings and...Cyber$200k - $250k
Job DescriptionEverforth ECS is seeking a Deputy Program Manager, Cyber Mission Integration & Modernizationto work in a hybrid schedule in... ...designated mission areas within the broader portfolio.Manage program risks, dependencies, priorities, and execution activities across...Cyber- ...in 1998 and headquartered in Reston, VA. We offer IT solutions across the disciplines of program/project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have developed our methodologies and processes...Cyber
$160k - $180k
...DescriptionEverforth ECS is seeking a Senior Cyber Threat Intelligence (CTI) Analyst to join... ...Center (SOC), Incident Response, Vulnerability Management, and Executive Leadership teams to proactively identify and mitigate cyber risks.Key ResponsibilitiesThreat Intelligence...Cyber- ...Senior Legal Director, Cyber & Data Risk (Technology Advisory Legal) Responsibilities: Principal legal advisor to CISO and ISRM leadership... ...on risks in M&A, divestitures, partnerships, and sourcing; manage outside counsel as needed. Lead/develop cybersecurity...CyberImmediate start
- Raytheon Technologies in Arlington, Virginia, is seeking a cybersecurity professional with expertise in cyber incident management. The ideal candidate will have over 5 years of relevant experience and be knowledgeable in incident response methodologies. The position requires...Cyber
- ..., a fast-growing firm, specializes in IT/Digital Modernization, Cyber Security, NextGen IT, and Emerging Technology services. We provide... ...) and Professional Solutions Team is seeking a Senior Proposal Manager who is eager to learn and lead bids as a member of the A3T...CyberWork at office
$100k - $125k
...the field, with expertise in network security and a proven ability to communicate complex ideas clearly. Competitive salary between $100,000 - $125,000 is offered, alongside an opportunity to work on critical national security missions. #J-18808-Ljbffr Argo Cyber SystemsCyber- ...Prevention Intern role to gain hands-on experience supporting internal data protection operations in a Cyber Fusion Center environment. You will assist with DLP policy management, incident analysis, data classification initiatives, and reporting. You'll work with senior...CyberInternship
- ...is seeking a Technical Cyberspace SETA to provide onsite support at Arlington, VA. The candidate will advise the DARPA program manager on cyber warfare architecture, coordinate with government mission partners, and oversee contract execution while delivering status...CyberContract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Risk Management Specialist. Be the first to apply!
- director of risk management McLean, VA
- director credit risk McLean, VA
- enterprise risk manager McLean, VA
- operational risk manager McLean, VA
- risk management specialist McLean, VA
- risk management manager McLean, VA
- head of risk management McLean, VA
- risk management associate McLean, VA
- senior risk manager McLean, VA
- cyber sales McLean, VA




