Cyber Risk Management Specialist
$100k - $150kSteampunk
OverviewThe Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and Authorization (A&A), Federal Risk and Authorization Management Program (FedRAMP) compliance, continuous ATO (cATO) and continuous monitoring. A solid grasp on confidentiality, integrity, and availability (CIA) security concepts is required. The candidate will be responsible for the technical implementation and enforcement of security hardening, vulnerability management, scan analysis, data analysis for metrics reporting, cloud environments, compliance with Federal regulation and policy, and commercial best practices relating to cyber security. The candidate must have the ability to be flexible and adaptive to a fast-paced, fluid business environment.ContributionsThe role requires strong procedural knowledge of NIST SP 800-37 Risk Management Framework (RMF) for Information Systems and Organization, NIST SP 800-53 Security and Privacy Controls for Information Systems and Organizations, NIST SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations, FedRAMP requirements, cloud environments, cloud cybersecurity architecture, compliance with Federal regulation and policy, and commercial best practices relating to cloud security. The CRMS is expected to efficiently learn and adapt to rapidly changing federal governance frameworks and standards of practice, to include risk treatments for modern and emerging technologies (e,g, AI, blockchain, microservices).The Cyber Risk Management Specialist performs a range of functions before, during, and after an authorization is granted:Integrate security into DevOps effectively at every stage of the software development life cycle (SDLC).Identify security holes and potential breaches, work through multifaceted security issues, and create effective solutions based on understanding of risk posture and treatments.Develop and implement tactical strategies for seamless automation to optimize the IT infrastructure.Apply specialized knowledge of financial audit standards, classified system IA requirements, and Privacy Act requirements.Implement the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework.Evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelinesApply in-depth, hands-on knowledge of the FedRAMP regulations, process, and requirements to lead project and initiative teams in accrediting cloud products and services. Support external audits, data calls, and the Authorization to Operate (ATO) process by coordinating with organization system owners, engineers, CSP’s and Third-Party Assessment Organizations (3PAO). Positively impact the organization’s goals and operational mission through various forms of metric performance measuring tools used to evaluate adherences to compliance.Advise clients on FedRAMP requirements and provide security guidance on the implementation of security compliance controls per technical, management, and operational requirements. Implement, monitor, and assess NIST SP 800-53 security controls for cloud environments to ensure compliance with FedRAMP requirements and governance models. Ensure ongoing compliance with FedRAMP policy and requirements through monthly deliverables, regular vulnerability scanning, penetration testing, contingency testing, and annual security assessments performed by a 3PAO.Support ATO, cATO, and continuous monitoring activities to include security documentation, audit log, security incidents, and risk assessment.Review and manage Plan of Action & Milestones (POA&M), to include remediation tracking and reporting.QualificationsAbility to obtain a U.S. government Security ClearanceMaster's Degree and 6 year of cyber and FISMA experience; ORBachelor's Degree and 8 years of cyber and FISMA experience; ORNo degree and 12 years of experience, 10 of which must be in cyber and FISMA Possesses at least one professional certification: CISSP, CASP, CISA, CISM or GSLCPreferredExperience in FISMA, cloud cybersecurity architecture, compliance with Federal regulation and policy, and commercial best practices relating to cloud security.Experience in Information Security processes to include RMF, FedRAMP, Compliance, Continuous Monitoring, and Annual Assessments.Certifications in one or more of the following: CISSP, CRICS, CCSP, CAP/CGRC.Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform and InfrastructureExperience conducting assessments in a 3PAO, C3PAO, or risk auditing organization is desirable, but not required.Experience supporting systems in Agile environments.About steampunkSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $100,000 to $150,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here. Identity StatementAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit .We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program. Job SummaryJob ID: 8006Clearance Requirement: Public Trust
$164.8k - $188.1k
...Manager, Cyber Risk & Analysis As a Manager, you will apply your technical expertise, risk management acumen, and project management skills to drive Risk Management Strategy for a major technology modernization program within Capital One's Retail Bank Division. This...CyberFull timePart timeLocal area$209.5k - $239.1k
...Director, Risk Management: Cyber & Third Party RiskCapital One, a Fortune 500 company and one of the nation's top 10 banks, offers a broad spectrum of financial products and services to consumers, small businesses and commercial clients. We are on the path to create one...CyberPermanent employmentFull timePart timeWork at officeLocal area- ...while building long-term capability within our client organizations. Position Overview SET Development is seeking a Cyber Security Product Risk Manager to support the security and resilience of space-based systems, including spacecraft and associated hardware. This...Cyber
$182.5k - $208.3k
...Overview Senior Manager, Cyber Risk & Analysis- Enterprise Services Risk Operations The Enterprise Services Risk Operations (ESRO) organization is expanding with a focus on attracting innovative, pioneering, collaborative, and highly skilled professionals. We operate...CyberFull timePart timeLocal area- ...United States. Work locations: Arlington or Herndon, VA.Position Summary: Airbus US is looking for a Cyber Security Product Risk Manager to who works with specialists from the Cyber, Space Engineering, and Contracts departments to ensure our products meet the applicable...CyberContract workWork at officeLocal areaVisa sponsorship
$164.8k - $188.1k
...Overview Manager, Cyber Risk & Analysis| Retail Bank Job Description As a member of the Technology & Cyber Risk Management team within Capital One’s Business Risk Office, you will apply your analytical, risk management, and project management skills to support...CyberFull timePart timeWork at officeLocal area$230.4k - $263k
...Overview Director, Cyber Risk & Analysis | Retail Bank Capital One, a Fortune 500 company and one of the nation’s top 10 banks,... ...One’s Retail Risk Office, you will apply your analytical, risk management, and project management skills to support Risk Management Strategy...CyberFull timePart timeWork at officeLocal area- ...adversaries, and partner with federal stakeholders to strengthen cyber resilience across complex infrastructures. Key... ...and hands‑on attack simulations. Deliver technical reporting, risk articulation, and executive‑level briefings. Collaborate with...CyberFull time
- This contractor and subcontractor shall abide by the requirements of 41 CFR 60-1.4(a), 60-300.5(a) and 60-741.5(a). These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, ...CyberFor contractorsFor subcontractor
- ...Senior Legal Director, Cyber & Data Risk (Technology Advisory Legal) Responsibilities: Principal legal advisor to CISO and ISRM leadership... ...on risks in M&A, divestitures, partnerships, and sourcing; manage outside counsel as needed. Lead/develop cybersecurity...CyberImmediate start
- ...Cyber Security Engineer Duration: 12+ months Location: Plano, TX / McLean, VA / Richmond, VA / Chicago, IL Manager Call Notes: • 10 years of experience in Cyber Security Engineering • Experience with risk security, information security • This is an integration...CyberImmediate start
- Vets Hired seeks a Principal Solutions Architect to lead the development of innovative, mission-focused technical solutions for large federal and defense opportunities. You will serve as the technical lead across capture, proposal, business development, operations, and...Cyber
- ...Required Qualifications: Experience with intelligence analysis principles or cyber threat intelligence (CTI) principles, including the ability to collect, analyze, and assess threat information. Specific experience conducting CTI analysis focused on China cyber threats...CyberFull time
- ...Support audits, security questionnaires, controls work, and broader compliance-related efforts while keeping focus on practical risk reduction. Help identify and close gaps between documented security posture and operational reality. Partner with internal technical...CyberImmediate start
- ...support a national cybersecurity organization client in Arlington, VA. This organization focuses on reducing risk to national infrastructure and growing resilience to cyber and physical infrastructure for the United States.Benefits include competitive PTO, 11 Paid Government...Cyber
- ...Job Description Job Description CyberLinx Solutions LLC is seeking a forward thinking Cybersecurity GRC Lead / Cyber Risk Manager responsible for leading the organization’s cybersecurity governance, risk, and compliance (GRC) program. This role oversees enterprise...Cyber
$5,000 per month
...Opportunities Today Stanley Martin Holdings is creating a dedicated risk management function to support a rapidly growing and expanding enterprise... ...liability, umbrella/excess liability, builder’s risk, cyber liability, directors’ and officers’ liability, fiduciary...CyberTemporary workFor subcontractorWork at officeLocal areaRemote workWork from homeFlexible hours- ...Scorpion Therapeutics seeks a Senior Legal Director to advise on cybersecurity, data risk, and technology initiatives. You will partner with CISO/ISRM leadership, translating complex regulations into actionable business guidance and directing incident response and regulatory...CyberContract work
- ...Capital One in McLean, VA is seeking a Director of IAM Cyber Product to lead security product strategy, align with engineering and... ...executives, and ensure security solutions enable business growth while managing risk. This role requires bold thinking, collaboration, and a...Cyber
- ...About the Position Clark Creative Solutions is seeking a Cyber Program Analyst to support cybersecurity initiatives, cyber readiness... ...of cybersecurity principles and information assurance ~ Risk Management Framework (RMF) familiarity ~ NIST guidance knowledge ~...CyberFull time
- ...Cyber Analyst Principal GDIT is seeking a highly skilled and multi-faceted Cyber Analyst Principal for a critical contract role... ...extensive, hands-on experience navigating the Intel Community (IC) Risk Management Framework (RMF) requirements for classified commercial cloud...CyberFull timeContract work
- ...for the delivery of highly-complex secure systems, cyber applications, technical projects and regulatory and risk requirements. Facilitates process engineering,... ...challenges and enhance the control environment. Actively manages and escalates risk and customer-impacting issues...CyberRemote work
- ...Executive Director, Market Risk for Credit Trading About the Company Globally-recognized... ...Services Retail Insurance Asset Management B2B Consulting & Professional... ...banking information technology cyber security and cyber security Business...Cyber
- ...Internet Service Providers (ISPs), cloud providers, OEM vendors, managed service providers, or other third-party service providers.... ...providing comprehensive 24x7x365 Network Operations Center (NOC) and Cyber Security Operations Center (CSOC) services. Experience maintaining...CyberContract workLocal areaNight shift
- ...Development Engineers in Test (SDET) to design, build, and maintain scalable automated testing capabilities for embedded hardware, cyber platforms, and operational software systems. This role focuses on developing robust test infrastructure, improving product reliability...Cyber
$50 per week
...while being technically challenged to grow! Responsibilities: Design and develop dynamic Enterprise Web and Mobile applications Cyber Security, Supply Chain/Logistics, or Finance for a variety of clients like Verizon, Capital One, and Cardinal Health in small teams....CyberWork from homeNight shift- ...contracting company, has an exciting opportunity for a Portfolio Manager to join our team in McLean, VA. The ideal Portfolio Manager will... ...the Government market in the fields of information technology, cyber security, AI/ML, GIS, and/or data analytics solutions and servicesStrong...CyberContract workImmediate startFlexible hours
- ...Job Description Job Description Job Title: Risk Manager Location: Washington, DC Metropolitan Area (Onsite) Employment Type... ...associated with large, complex federal initiatives involving cyber operations, IT modernization, and mission systems. The Risk...CyberFull timeContract workTemporary workWork at officeLocal areaImmediate startHome officeFlexible hours
- ...locations Required Education: ~ BS Computer Science, Cyber Security, Computer Engineering, or related degree; or HS Diploma... ...DigiFlight's competitive benefits package allows employees to manage their personal and professional portfolios through a variety of...CyberTemporary workFlexible hours
- ...Government agencies and critical infrastructure owners who experience cyber-attacks. Solutions³ LLC provides advanced technical assistance,... ...within the network environment or enclave Notify designated managers, cyber incident responders, and cybersecurity service provider...CyberFor contractorsImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Risk Management Specialist. Be the first to apply!
- director of risk management McLean, VA
- director credit risk McLean, VA
- enterprise risk manager McLean, VA
- operational risk manager McLean, VA
- risk management specialist McLean, VA
- risk management manager McLean, VA
- head of risk management McLean, VA
- risk management associate McLean, VA
- senior risk manager McLean, VA
- cyber sales McLean, VA




