Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Risk Management Specialist

$100k - $150k

Steampunk

OverviewThe Cyber Risk Management Specialist (CRMS) will specialize in in-depth knowledge of the program's cyber security hygiene, DevSecOps, Risk Management Framework (RMF), Assessment and Authorization (A&A), Federal Risk and Authorization Management Program (FedRAMP) compliance, continuous ATO (cATO) and continuous monitoring. A solid grasp on confidentiality, integrity, and availability (CIA) security concepts is required. The candidate will be responsible for the technical implementation and enforcement of security hardening, vulnerability management, scan analysis, data analysis for metrics reporting, cloud environments, compliance with Federal regulation and policy, and commercial best practices relating to cyber security. The candidate must have the ability to be flexible and adaptive to a fast-paced, fluid business environment.ContributionsThe role requires strong procedural knowledge of NIST SP 800-37 Risk Management Framework (RMF) for Information Systems and Organization, NIST SP 800-53 Security and Privacy Controls for Information Systems and Organizations, NIST SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations, FedRAMP requirements, cloud environments, cloud cybersecurity architecture, compliance with Federal regulation and policy, and commercial best practices relating to cloud security. The CRMS is expected to efficiently learn and adapt to rapidly changing federal governance frameworks and standards of practice, to include risk treatments for modern and emerging technologies (e,g, AI, blockchain, microservices).The Cyber Risk Management Specialist performs a range of functions before, during, and after an authorization is granted:Integrate security into DevOps effectively at every stage of the software development life cycle (SDLC).Identify security holes and potential breaches, work through multifaceted security issues, and create effective solutions based on understanding of risk posture and treatments.Develop and implement tactical strategies for seamless automation to optimize the IT infrastructure.Apply specialized knowledge of financial audit standards, classified system IA requirements, and Privacy Act requirements.Implement the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework.Evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelinesApply in-depth, hands-on knowledge of the FedRAMP regulations, process, and requirements to lead project and initiative teams in accrediting cloud products and services. Support external audits, data calls, and the Authorization to Operate (ATO) process by coordinating with organization system owners, engineers, CSP’s and Third-Party Assessment Organizations (3PAO). Positively impact the organization’s goals and operational mission through various forms of metric performance measuring tools used to evaluate adherences to compliance.Advise clients on FedRAMP requirements and provide security guidance on the implementation of security compliance controls per technical, management, and operational requirements. Implement, monitor, and assess NIST SP 800-53 security controls for cloud environments to ensure compliance with FedRAMP requirements and governance models. Ensure ongoing compliance with FedRAMP policy and requirements through monthly deliverables, regular vulnerability scanning, penetration testing, contingency testing, and annual security assessments performed by a 3PAO.Support ATO, cATO, and continuous monitoring activities to include security documentation, audit log, security incidents, and risk assessment.Review and manage Plan of Action & Milestones (POA&M), to include remediation tracking and reporting.QualificationsRequiredAbility to obtain a U.S. government Security ClearanceMaster's Degree and 6 year of cyber and FISMA experience; ORBachelor's Degree and 8 years of cyber and FISMA experience; ORNo degree and 12 years of experience, 10 of which must be in cyber and FISMA Possesses at least one professional certification: CISSP, CASP, CISA, CISM or GSLCPreferredExperience in FISMA, cloud cybersecurity architecture, compliance with Federal regulation and policy, and commercial best practices relating to cloud security.Experience in Information Security processes to include RMF, FedRAMP, Compliance, Continuous Monitoring, and Annual Assessments.Certifications in one or more of the following: CISSP, CRICS, CCSP, CAP/CGRC.Certifications in one or more of the following: AWS Certified Solutions Architect, AWS Certified Security, Microsoft Certified Solutions Architect, MCSE Cloud Platform and InfrastructureExperience conducting assessments in a 3PAO, C3PAO, or risk auditing organization is desirable, but not required.Experience supporting systems in Agile environments.About steampunkSteampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $100,000 to $150,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here. Identity StatementAs part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company, we focus on investing in our employees to enable them to do the greatest work of their careers – and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visit .We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program. Job SummaryJob ID: 8006Clearance Requirement: Public Trust

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cyber Risk Management Specialist in McLean, VA vacancy
  • $155.6k - $306.8k

    Position Summary The Team: The mission of Quality and Risk Management (QRM) is to manage the risk in our growing and increasingly complex...  ...the firm’s assets and reputation. Work you’ll do Deloitte’s Cyber QRM team is seeking a Quality & Risk Manager who will be... 
    Cyber
    Contract work
    For subcontractor
    Work at office
    Local area

    Deloitte

    McLean, VA
    2 days ago
  • $115k - $165k

     ...to create extraordinary experiences, you belong at HITT.Senior Manager, Risk ManagementJob Description:The Senior Manager, Insurance & Risk...  ..., umbrella, professional liability, pollution liability, cyber, management liability, and builder’s risk across all HITT operating... 
    Cyber
    Full time
    Contract work
    Work experience placement
    For subcontractor
    Work at office
    Local area

    HITT CONTRACTING

    Falls Church, VA
    3 days ago
  • $134.5k - $265.1k

    Position Summary Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional... 
    Cyber
    Local area
    Visa sponsorship

    Deloitte

    McLean, VA
    1 day ago
  • Title:Director, Risk ManagementWe are KBRWhen you become part of our KBR team, your opportunities...  ...and readiness to advanced research, cyber, logistics, and life-cycle sustainment,...  ....About the RoleThe Director, Risk Management provides strategic leadership for KBR's global... 
    Cyber
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Remote work
    Relocation package
    Flexible hours

    KBR

    Arlington, VA
    1 day ago
  • Cybersecurity and Infrastructure Security Agency (CISA) in Arlington, VA seeks a Senior Executive Service (SES) level candidate for the Risk Services Division. The role emphasizes developing and applying risk analyses, modeling and decision-support processes, and driving... 
    Cyber

    US Cybersecurity and Infrastructure Security Agency

    Arlington, VA
    5 days ago
  • Capital One seeks a Director, Cyber Technical to lead second-line risk oversight for Brex integration in a fast-paced fintech environment. You will oversee cloud and application architectures, AI governance, and security standards while partnering with CTOs and risk officers... 
    Cyber

    Capital One

    Mc Lean, VA
    5 days ago
  • Capital One seeks a Director, Cyber Risk & Analysis in Retail Bank to lead technology and cyber risk management across the Retail Risk Office. You will steer risk assessments, governance, and controls, while championing innovative approaches and AI governance to strengthen... 
    Cyber
    Work at office

    Capital One

    Mc Lean, VA
    3 days ago
  • Capital One is seeking a Director, Cyber Risk and Analysis to lead state-of-the-art risk assessments and control programs within the Retail...  ...strategies, prioritize risks, and drive innovations in risk management across technology domains. The role emphasizes deep expertise... 
    Cyber
    Work at office

    Capital One National Association

    Mc Lean, VA
    3 days ago
  • $229.9k - $262.4k

     ...Overview Senior Manager, SRE Risk Advisory and Oversight Capital One is one of the fastest growing organizations in the world today,...  ...worked. McLean, VA: $229,900 - $262,400 for Sr Manager, Cyber Technical New York, NY: $250,800 - $286,200 for Sr Manager... 
    Cyber
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    more than 2 months ago
  • A leading financial services firm in McLean is seeking a Manager to join their Cyber Tech & Product Risk team. The role involves applying risk management expertise to enhance the organization's cyber risk profile and drive strategic change. Responsibilities include risk... 
    Cyber

    Capital One

    Mc Lean, VA
    2 days ago
  • $164.8k - $188.1k

     ...Overview Manager, Cyber Risk & Analysis As a Manager, you will apply your technical expertise, risk management acumen, and project management skills to drive Risk Management Strategy for a major technology modernization program within Capital One’s Retail Bank Division... 
    Cyber
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    10 days ago
  •  ...while building long-term capability within our client organizations. Position Overview SET Development is seeking a Cyber Security Product Risk Manager to support the security and resilience of space-based systems, including spacecraft and associated hardware. This... 
    Cyber

    SET Development

    Arlington, VA
    a month ago
  •  ..., Airbus U.S. is the place where top talent wants to work.Position Summary: Airbus US is looking for a Cyber Security Product Risk Manager who works with specialists from the Cyber, Space Engineering, and Contracts departments to ensure our products meet the applicable... 
    Cyber
    Contract work
    Work at office
    Local area
    Visa sponsorship

    AIRBUS U.S. Space & Defense, Inc.

    Arlington, VA
    12 days ago
  • $200.7k - $229.1k

     ...Overview Cyber Third Party Risk Reduction (CTPRR) Senior Manager, Operations Manager The Cyber Third Party Risk Reduction (CTPRR) program defines the framework for the management of information security risks with third party engagements, supports contracting, conducts... 
    Cyber
    Full time
    Part time
    H1b
    Local area

    Capital One

    McLean, VA
    a month ago
  • $177.7k - $202.8k

     ...Overview Senior Manager, Risk Management - Policy Analyst Capital One is one of the fastest growing organizations in the world today...  ...first and second lines of defense such as the Technology and Cyber organizations, Enterprise Data, Divisional Data Risk Officers,... 
    Cyber
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    8 days ago
  • $151.9k - $173.4k

     ...Overview Manager, Risk Management: Card Data Management Do you like working in the spotlight? Are you ready to work on the front line...  ...Risk Management experience in support of financial services, cyber, technology, or data management At least 3 years of Project... 
    Cyber
    Full time
    Part time
    Currently hiring
    Local area

    Capital One

    McLean, VA
    7 days ago
  • $164.8k - $188.1k

     ...Overview Manager, Cyber Risk & Analysis| Retail Bank Job Description As a member of the Technology & Cyber Risk Management team within Capital One’s Business Risk Office, you will apply your analytical, risk management, and project management skills to support... 
    Cyber
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    10 days ago
  • $197.3k - $225.1k

     ...Overview Risk Manager, Endpoint Security Capital One is one of the fastest growing organizations in the world today, powered by our...  ...individual will have the ability to use technical skills and cyber subject matter expertise to provide effective oversight, credible... 
    Cyber
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    a month ago
  • $164.8k - $188.1k

    The Enterprise Services Risk organization is expanding with a focus on attracting innovative...  .... We operate at the forefront of risk management, providing support for novel and...  ...sector. In this role As a Manager on the Cyber Tech & Product Risk team, you will apply... 
    Cyber
    Full time
    Part time
    Local area
    Shift work

    Capital One

    Mc Lean, VA
    5 days ago
  • $230.4k - $263k

     ...Overview Director, Cyber Risk & Analysis | Retail Bank Capital One, a Fortune 500 company and one of the nation’s top 10 banks,...  ...One’s Retail Risk Office, you will apply your analytical, risk management, and project management skills to support Risk Management Strategy... 
    Cyber
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    22 days ago
  • $230.4k - $263k

     ...Overview Director, Card Tech Risk Advisor As a Director, Technology in Capital One’s Card Risk Office, you will apply your risk management, technology, and cyber expertise to the company’s Card Technology division. You will partner across the divisional senior leaders... 
    Cyber
    Permanent employment
    Full time
    Part time
    Work at office
    Local area

    Capital One

    McLean, VA
    8 days ago
  •  ...adversaries, and partner with federal stakeholders to strengthen cyber resilience across complex infrastructures.   Key...  ...and hands‑on attack simulations. Deliver technical reporting, risk articulation, and executive‑level briefings. Collaborate with... 
    Cyber
    Full time

    Apogee Global Rms

    Arlington, VA
    21 hours ago
  • $180k - $225k

     ...DescriptionEverforth ECS is seeking a Senior Solutions Architect - Cyber Operations to work in a hybrid schedule in our Arlington,...  ...detection and analysis, incident response, threat hunt, vulnerability management, and more.   As a strategic advisor and operational leader,... 
    Cyber
    Contract work
    Local area

    ECS Federal

    Arlington, VA
    1 day ago
  •  ...Cybersecurity Analyst will monitor Air Gapped Security Fabrics through managed SECOPs Tools.   Responsibilities include but are not...  ...Diploma with 3+ years of experience in Security Operations, Cyber Security, and/or Systems Administration. Experience with SIEM... 
    Cyber
    Work at office
    Local area
    Shift work
    Night shift

    MANTECH

    Tysons, VA
    -137
  •  ...A cybersecurity solutions provider is seeking a Jr Industrial Control System Cyber Threat Intelligence Analyst in Arlington, VA. The ideal candidate should hold a Bachelor's degree with at least 2 years of relevant experience and have hands-on capabilities in cyber incident... 
    Cyber

    Peraton

    Arlington, VA
    2 days ago
  • Required Qualifications:Eastern Europe-focused geopolitical and cyber threat intelligence experience Experience with cyber threat intelligence analysis principles in a government or commercial environment Knowledge of current and emerging Eastern Europe-related cyber adversaries... 
    Cyber

    Maania Consultancy Services

    Arlington, VA
    1 day ago
  •  ...Booz Allen Hamilton is seeking a Civil Cyber Solutions Architect Director to spearhead visioning, architecture, development, and implementation of strategic cybersecurity solutions for Federal Civil and State & Local markets. You will work closely with government clients... 
    Cyber
    Local area

    Booz Allen Hamilton

    McLean, VA
    2 days ago
  • $5,000 per month

     ...for this role. Imagine One Technology & Management, Ltd. is seeking four (4) Senior Cybersecurity...  ...cybersecurity requirements development, cyber threat analysis, cyber engineering, cyber...  ...combat systems. Developing cybersecurity risk assessment analysis and risk mitigation... 
    Cyber

    Imagine One

    Arlington, VA
    21 hours ago
  •  ...Herndon, VA. This role is critical for designing, developing, and analyzing low-level Windows components to support national security and cyber defense missions.Key Responsibilities:Design and implement software components in the Windows kernel space.Perform reverse... 
    Cyber

    Cohere Technology Group

    Arlington, VA
    2 days ago
  •  ...federal government organizations on national cybersecurity programs. You will collaborate with clients to plan, defend, and respond to cyber threats, delivering analyses, briefings, and trainings. The role requires a Bachelor's degree (Master's preferred) and 3+ years in... 
    Cyber

    Lafayette Group

    Arlington, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Risk Management Specialist. Be the first to apply!