Cybersecurity and Risk Analyst
Gormat
Clearance Requirement: Active Secret or higher clearance required; must be eligible for a Top Secret clearance if requested Background Investigation: Must successfully complete a DEA background investigation Position Summary The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and Penetration Testing (VAPT) team, responsible for identifying, analyzing, and mitigating cybersecurity risks across enterprise systems, networks, and applications. This role focuses on evaluating vulnerabilities, integrating threat intelligence, and supporting compliance efforts to ensure confidentiality, integrity, and availability of organizational data and services. The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation activities in alignment with federal security frameworks such as NIST SP 800-53, FISMA, and ISO/IEC 27001. They provide actionable reporting to leadership, enabling risk-based decision-making, and collaborate with cross-functional teams to improve security posture, mitigate threats, and ensure adherence to federal directives and policies. The Cybersecurity and Risk Analyst defines system security requirements for IT systems and applications and conducts comprehensive risk assessments of management, operational, and technical security controls and control enhancements that are present or inherited by an IT system. The analyst determines the overall effectiveness of security controls based on criteria from applicable NIST frameworks (e.g., NIST SP 800-53) and relevant guidance such as NIST SP 800-30. This role supports the Risk Management Framework (RMF) Security Assessment and Authorization (SAA) process through validation of security configurations to ensure compliance with applicable cybersecurity policies, requirements, and directives. The analyst ensures compliance with Security Technical Implementation Guidance (STIG), security benchmarks, and organizational security requirements. The role utilizes automated and manual scanning tools and manual testing methodologies to identify system vulnerabilities, noncompliance, and mitigation strategies. Vulnerability Assessment & Risk Evaluation Conduct vulnerability assessments across systems, applications, OT assets, and cloud environments using commercial and open-source tools. Analyze, validate, and prioritize vulnerabilities based on severity, exploitability, and business impact. Perform risk assessments on systems, applications, and ATO packages using frameworks such as NIST SP 800-30 and ISO 27005. Maintain risk registers and communicate risk likelihood and impact to system owners and leadership. Threat Analysis & Simulation Monitor and apply threat intelligence feeds to assess emerging threats and vulnerabilities. Participate in red team operations, adversary emulation, and penetration testing exercises. Correlate vulnerability threat data (e.g., CVEs, MITRE ATT&CK) to determine real-world exploitability. Provide analysis of zero-day vulnerabilities, advanced attack techniques, and potential organizational impacts. Policy, Compliance & Governance Support Ensure vulnerability management practices align with NIST SP 800-53, NIST SP 800-115, CIS Controls, and ISO 27001. Support internal and external audits by mapping findings to compliance frameworks (FISMA, HIPAA, PCI-DSS). Contribute to incident response readiness, business continuity, and disaster recovery planning. Review and provide input on system change requests, patching compliance, and binding operational directives. Reporting & Documentation Prepare detailed technical reports and executive summaries highlighting risks, vulnerabilities, and mitigations. Document risk mitigation strategies, vulnerability management processes, and audit support artifacts. Provide risk-related training and awareness to stakeholders, communicating technical risk in business terms. Collaboration & Continuous Improvement Partner with security engineers, SOC analysts, developers, and system owners to coordinate remediation. Participate in Change Control Boards (CCBs) to assess security impact of system changes. Recommend improvements to vulnerability, risk, and threat management processes. Stay current on evolving threat landscapes, vulnerability trends, and cybersecurity technologies. Required Qualifications A master's degree in information technology, cybersecurity, data science, information systems, or computer science from an ABET-accredited or CAE-designated institution fulfills the educational requirement. Minimum of eight (8) years of experience (YOE) in Information Technology (IT) / Information Security (IS). This includes any combination of experience from relevant IT and cybersecurity disciplines. Must have at least one (1) DoD 8140 certification for the respective area or the ability to obtain certification within six (6) months of onboarding. DoD 8140 certification must be maintained during the period of performance. Must have at least five (5) years of documented experience and/or education in IT or IS/Cybersecurity. Must successfully complete a DEA background investigation. Must possess an active Secret or higher clearance and be eligible for a Top Secret clearance if requested. Preferred Qualifications Experience supporting the following areas is preferred: DCWF Role 541 - Vulnerability Assessment Analyst. DCWF Role 622 - Secure Software Assessor. Vulnerability Assessment Analyst / Secure Software Assessor functions. Intermediate and advanced certifications related to cybersecurity roles, including: CompTIA: Cloud+, PenTest+, Security+ EC-Council: CEH
GIAC: GCED, GCIH, GCSA, GICSP, GSEC
Additional Position Information This position requires working onsite five (5) days per week. Work site locations include DEA Arlington HQ, Merrifield, Lorton, Chantilly, El Paso, or other DEA satellite offices (availability dependent), typically in close geographic proximity to the candidate's home location. Core business hours are between 10:00 AM and 3:00 PM, allowing flexibility for start and end times outside this window. Depending on position requirements, some roles may require working within a specific shift. #J-18808-Ljbffr Gormat- ...Phase2 Technology in Arlington, Virginia is looking for an experienced information security risk specialist to mitigate complex cybersecurity threats. This role requires collaboration with stakeholders to assess cybersecurity postures, leveraging eMASS and RMF for effective...SuggestedRemote work
- .... We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable... ..., ownership, and execution over bureaucracy. Title: Risk and Vulnerability Analyst II Location: Washington, DC or Chandler, AZ Terms: Full...SuggestedFull timeWork experience placementFlexible hours
$80k - $128k
...Analysis Clearance: Secret Peraton is currently seeking a Risk and Vulnerability Analyst. Location: Chandler, AZ or Washington DC. The Risk and... .... Required Qualifications Bachelor's degree in Cybersecurity, Information Technology, or related field. An additional...SuggestedContract workShift work- Tyto Athene, LLC is seeking a mid-level Supply Chain Risk Management Analyst to support law enforcement clients in Arlington, Virginia. This... ...expertise in risk management and a solid understanding of cybersecurity, particularly in securing technology supply chains. The ideal...SuggestedFull time
$80k - $128k
A leading national security company is seeking a Risk and Vulnerability Analyst to support the Security Operations Center by identifying and analyzing... ...risks. This position requires a Bachelor's degree in Cybersecurity or similar, at least 2 years in security operations, and...Suggested$110k - $130k
...desired outcomes, and commitment to Innovation ensures responsive and long-lasting results. Job Description Senior Cybersecurity Supply Chain Risk Management Analyst to support OCIO's focus on the information, communications, and operational technology (ICT/OT) users who...Full time- ...collaboration, career growth, and winning ideas. Military Veterans Encouraged to Apply. Job Description The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) by managing cybersecurity risks...For contractorsWork at office
- TAD PGS, Inc. has an outstanding contract position for a Senior Cybersecurity Supply Chain Risk Management Analyst in the Washington, DC area. The role involves analyzing supply chain cybersecurity risks and provides support for procurement documentation related to high...Contract work
- Network Designs, Inc. is looking for a Senior Cybersecurity Supply Chain Risk Management Analyst in Washington D.C. to oversee cybersecurity risks related to the agency's supply chain of ICT/OT products. The ideal candidate will have a strong background in cybersecurity...
- We have an outstanding contract position for a Senior Cybersecurity Supply Chain Risk Management Analyst to join a leading company located in the Washington, DC surrounding area. US Citizenship is required. Candidate must possess an Active Top Secret/SCI Security Clearance...Contract work
$109k - $124.4k
Senior Associate, Cyber Governance & Risk - Cyber Exceptions Analyst Security is essential to what we do at Capital One, from protecting customer... ...their security limitations. You enjoy solving tough cybersecurity problems in an iterative, team environment. You will help...Full timePart timeH1bLocal area$80k - $105k
G3 Innovative Solutions, LLC in Washington, DC is seeking a Mid-Level Cybersecurity Supply Chain Risk Management Analyst to support the information and operational technology sectors. You'll analyze procurement documentation for high-risk ICT/OT products, ensuring their...$130k - $160k
Danaher Corporation is seeking a Senior Cybersecurity Risk Analyst responsible for managing third-party risk activities across the vendor lifecycle. In this fully remote role, you'll collaborate with Legal, Privacy, and Procurement teams while ensuring data quality in...Remote job- Maania Consultancy Services is seeking an experienced professional in Washington, DC, to provide analytical support in managing cybersecurity risks within supply chains. Ideal candidates will have a background in IT, combined with a bachelor's degree, relevant...
- Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst Location: Washington, DC Schedule: Onsite, 5 days/week Position Type: Direct Hire Clearance Required: Active TS clearance required at time of application. Must be willing and able to obtain SCI access...
$177.7k - $202.8k
## Senior Manager, Risk Management - Policy AnalystApplylocations: McLean, VA: Richmond... ...technology, we equally prioritize cybersecurity, reliability, software quality, and data... ...reliability engineering, technology, data analyst, data scientist, and risk management professionals...Full timePart timeLocal area- ...A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating...Remote work
- TikTok is hiring a Security Strategy, Risk and Resilience Controls Management Specialist in Washington, DC. This role focuses on managing cybersecurity risks, assessing compliance with security frameworks like ISO 27001 and SOC 2, and fostering collaboration with teams...
- ...Cyber And It Security Risk Analyst Location: Bethesda, MD Contract: 12 Months Position Summary We are seeking a Cyber and... ...to identify, measure, and monitor information security and cybersecurity risks, including reporting on performance against established...Contract workFor contractors
$62k - $141k
...Job Number: R0242703 Cybersecurity Risk Analyst The Opportunity Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the global enterprise. In all of this "cyber noise," how can these organizations...Contract workLocal area$62k - $141k
...this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you. We need your... ...active role in information security while growing your skills in cybersecurity.Work with us as we protect our nation’s cyber infrastructure....Full timeContract workPart timeWork at officeLocal areaRemote work- ...offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship provides the potential...Full timeInternship
$189k - $225k
Spire is seeking a GRC Analyst in Washington, DC to manage cybersecurity governance, risk, and compliance requirements. This role involves thorough contract analysis, policy support, and cross-functional collaboration. Candidates should have at least five years of experience...Contract work- Booz Allen Hamilton is seeking an information security risk specialist in the United States to turn complex cyber threats into actionable... ...decks for senior leaders. The role requires 5+ years in cybersecurity, DoD-related work, and strong communication skills for...
- Phase2 Technology is seeking a Cybersecurity Risk Analyst in Alexandria, Virginia, to help clients understand and mitigate their cyber risks. You'll work closely with enterprises to develop tailored risk management strategies and deliver actionable insights through presentations...
- EAB is looking for an Information Assurance (IA) Analyst to assess risks related to technology applications and third-party providers. The role... ...Richmond, VA, this position is ideal for early-career individuals eager to grow in the cybersecurity field. #J-18808-Ljbffr EAB
- JCD Staffing is seeking a Senior Cybersecurity Supply Chain Risk Management Analyst in Washington, DC, to support federal cybersecurity initiatives. This role focuses on identifying and mitigating risks related to complex supply chains, requiring an active TS clearance...
- Booz Allen Hamilton is seeking an information security risk specialist to translate complex cyber risks into actionable plans for federal clients. You will collaborate with military leaders and SMEs to assess threats, write executive-grade materials, and guide action plans...
- Booz Allen Hamilton is seeking an information security risk specialist to translate complex cyber concepts for federal clients and... ...to mitigate threats. Ideal candidates have extensive cybersecurity risk experience, the ability to draft senior-level documents,...Remote job
- ...We are seeking an experienced predictive risk modeler to perform risk assessment on FHA multifamily housing portfolio. To perform in this role, the potential candidate will need skills in econometrics, statistical analysis, and modelling. The main responsibilities include...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity and Risk Analyst. Be the first to apply!
- cyber security specialist Arlington, VA
- cyber security consultant Arlington, VA
- senior quantitative risk analyst Arlington, VA
- it risk analyst Arlington, VA
- risk consultant Arlington, VA
- operational risk consultant Arlington, VA
- risk analyst Arlington, VA
- risk officer Arlington, VA
- operational risk specialist Arlington, VA
- risk Arlington, VA

