Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity and Risk Analyst

Gormat

Clearance Requirement: Active Secret or higher clearance required; must be eligible for a Top Secret clearance if requested Background Investigation: Must successfully complete a DEA background investigation Position Summary The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and Penetration Testing (VAPT) team, responsible for identifying, analyzing, and mitigating cybersecurity risks across enterprise systems, networks, and applications. This role focuses on evaluating vulnerabilities, integrating threat intelligence, and supporting compliance efforts to ensure confidentiality, integrity, and availability of organizational data and services. The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation activities in alignment with federal security frameworks such as NIST SP 800-53, FISMA, and ISO/IEC 27001. They provide actionable reporting to leadership, enabling risk-based decision-making, and collaborate with cross-functional teams to improve security posture, mitigate threats, and ensure adherence to federal directives and policies. The Cybersecurity and Risk Analyst defines system security requirements for IT systems and applications and conducts comprehensive risk assessments of management, operational, and technical security controls and control enhancements that are present or inherited by an IT system. The analyst determines the overall effectiveness of security controls based on criteria from applicable NIST frameworks (e.g., NIST SP 800-53) and relevant guidance such as NIST SP 800-30. This role supports the Risk Management Framework (RMF) Security Assessment and Authorization (SAA) process through validation of security configurations to ensure compliance with applicable cybersecurity policies, requirements, and directives. The analyst ensures compliance with Security Technical Implementation Guidance (STIG), security benchmarks, and organizational security requirements. The role utilizes automated and manual scanning tools and manual testing methodologies to identify system vulnerabilities, noncompliance, and mitigation strategies. Vulnerability Assessment & Risk Evaluation Conduct vulnerability assessments across systems, applications, OT assets, and cloud environments using commercial and open-source tools. Analyze, validate, and prioritize vulnerabilities based on severity, exploitability, and business impact. Perform risk assessments on systems, applications, and ATO packages using frameworks such as NIST SP 800-30 and ISO 27005. Maintain risk registers and communicate risk likelihood and impact to system owners and leadership. Threat Analysis & Simulation Monitor and apply threat intelligence feeds to assess emerging threats and vulnerabilities. Participate in red team operations, adversary emulation, and penetration testing exercises. Correlate vulnerability threat data (e.g., CVEs, MITRE ATT&CK) to determine real-world exploitability. Provide analysis of zero-day vulnerabilities, advanced attack techniques, and potential organizational impacts. Policy, Compliance & Governance Support Ensure vulnerability management practices align with NIST SP 800-53, NIST SP 800-115, CIS Controls, and ISO 27001. Support internal and external audits by mapping findings to compliance frameworks (FISMA, HIPAA, PCI-DSS). Contribute to incident response readiness, business continuity, and disaster recovery planning. Review and provide input on system change requests, patching compliance, and binding operational directives. Reporting & Documentation Prepare detailed technical reports and executive summaries highlighting risks, vulnerabilities, and mitigations. Document risk mitigation strategies, vulnerability management processes, and audit support artifacts. Provide risk-related training and awareness to stakeholders, communicating technical risk in business terms. Collaboration & Continuous Improvement Partner with security engineers, SOC analysts, developers, and system owners to coordinate remediation. Participate in Change Control Boards (CCBs) to assess security impact of system changes. Recommend improvements to vulnerability, risk, and threat management processes. Stay current on evolving threat landscapes, vulnerability trends, and cybersecurity technologies. Required Qualifications A master's degree in information technology, cybersecurity, data science, information systems, or computer science from an ABET-accredited or CAE-designated institution fulfills the educational requirement. Minimum of eight (8) years of experience (YOE) in Information Technology (IT) / Information Security (IS). This includes any combination of experience from relevant IT and cybersecurity disciplines. Must have at least one (1) DoD 8140 certification for the respective area or the ability to obtain certification within six (6) months of onboarding. DoD 8140 certification must be maintained during the period of performance. Must have at least five (5) years of documented experience and/or education in IT or IS/Cybersecurity. Must successfully complete a DEA background investigation. Must possess an active Secret or higher clearance and be eligible for a Top Secret clearance if requested. Preferred Qualifications Experience supporting the following areas is preferred: DCWF Role 541 - Vulnerability Assessment Analyst. DCWF Role 622 - Secure Software Assessor. Vulnerability Assessment Analyst / Secure Software Assessor functions. Intermediate and advanced certifications related to cybersecurity roles, including: CompTIA: Cloud+, PenTest+, Security+ EC-Council: CEH

GIAC: GCED, GCIH, GCSA, GICSP, GSEC

Additional Position Information This position requires working onsite five (5) days per week. Work site locations include DEA Arlington HQ, Merrifield, Lorton, Chantilly, El Paso, or other DEA satellite offices (availability dependent), typically in close geographic proximity to the candidate's home location. Core business hours are between 10:00 AM and 3:00 PM, allowing flexibility for start and end times outside this window. Depending on position requirements, some roles may require working within a specific shift. #J-18808-Ljbffr Gormat

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity and Risk Analyst in Arlington, VA vacancy
  •  ...Phase2 Technology in Arlington, Virginia is looking for an experienced information security risk specialist to mitigate complex cybersecurity threats. This role requires collaboration with stakeholders to assess cybersecurity postures, leveraging eMASS and RMF for effective... 
    Suggested
    Remote work

    Phase2 Technology

    Arlington, VA
    3 days ago
  •  .... We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable...  ..., ownership, and execution over bureaucracy. Title: Risk and Vulnerability Analyst II Location: Washington, DC or Chandler, AZ Terms: Full... 
    Suggested
    Full time
    Work experience placement
    Flexible hours

    Revolutional

    Washington DC
    5 days ago
  • $80k - $128k

     ...Analysis Clearance: Secret Peraton is currently seeking a Risk and Vulnerability Analyst. Location: Chandler, AZ or Washington DC. The Risk and...  .... Required Qualifications Bachelor's degree in Cybersecurity, Information Technology, or related field. An additional... 
    Suggested
    Contract work
    Shift work

    Peraton

    Washington DC
    5 days ago
  • Tyto Athene, LLC is seeking a mid-level Supply Chain Risk Management Analyst to support law enforcement clients in Arlington, Virginia. This...  ...expertise in risk management and a solid understanding of cybersecurity, particularly in securing technology supply chains. The ideal... 
    Suggested
    Full time

    TryApplyNow

    Arlington, VA
    5 days ago
  • $80k - $128k

    A leading national security company is seeking a Risk and Vulnerability Analyst to support the Security Operations Center by identifying and analyzing...  ...risks. This position requires a Bachelor's degree in Cybersecurity or similar, at least 2 years in security operations, and... 
    Suggested

    Peraton

    Washington DC
    5 days ago
  • $110k - $130k

     ...desired outcomes, and commitment to Innovation ensures responsive and long-lasting results. Job Description Senior Cybersecurity Supply Chain Risk Management Analyst to support OCIO's focus on the information, communications, and operational technology (ICT/OT) users who... 
    Full time

    Resilient Solutions Plus, LLC

    Washington DC
    4 days ago
  •  ...collaboration, career growth, and winning ideas. Military Veterans Encouraged to Apply. Job Description The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) by managing cybersecurity risks... 
    For contractors
    Work at office

    Network Designs

    Washington DC
    1 day ago
  • TAD PGS, Inc. has an outstanding contract position for a Senior Cybersecurity Supply Chain Risk Management Analyst in the Washington, DC area. The role involves analyzing supply chain cybersecurity risks and provides support for procurement documentation related to high... 
    Contract work

    TAD PGS, Inc.

    Washington DC
    1 day ago
  • Network Designs, Inc. is looking for a Senior Cybersecurity Supply Chain Risk Management Analyst in Washington D.C. to oversee cybersecurity risks related to the agency's supply chain of ICT/OT products. The ideal candidate will have a strong background in cybersecurity... 

    Network Designs, Inc.

    Washington DC
    2 days ago
  • We have an outstanding contract position for a Senior Cybersecurity Supply Chain Risk Management Analyst to join a leading company located in the Washington, DC surrounding area. US Citizenship is required. Candidate must possess an Active Top Secret/SCI Security Clearance... 
    Contract work

    Tad PGS

    Washington DC
    1 day ago
  • $109k - $124.4k

    Senior Associate, Cyber Governance & Risk - Cyber Exceptions Analyst Security is essential to what we do at Capital One, from protecting customer...  ...their security limitations. You enjoy solving tough cybersecurity problems in an iterative, team environment. You will help... 
    Full time
    Part time
    H1b
    Local area

    Capital One National Association

    Mc Lean, VA
    4 days ago
  • $80k - $105k

    G3 Innovative Solutions, LLC in Washington, DC is seeking a Mid-Level Cybersecurity Supply Chain Risk Management Analyst to support the information and operational technology sectors. You'll analyze procurement documentation for high-risk ICT/OT products, ensuring their... 

    Resilient Solutions Plus, LLC

    Washington DC
    5 days ago
  • $130k - $160k

    Danaher Corporation is seeking a Senior Cybersecurity Risk Analyst responsible for managing third-party risk activities across the vendor lifecycle. In this fully remote role, you'll collaborate with Legal, Privacy, and Procurement teams while ensuring data quality in... 
    Remote job

    Danaher Corporation

    Washington DC
    5 days ago
  • Maania Consultancy Services is seeking an experienced professional in Washington, DC, to provide analytical support in managing cybersecurity risks within supply chains. Ideal candidates will have a background in IT, combined with a bachelor's degree, relevant... 

    Maania Consultancy Services

    Washington DC
    1 day ago
  • Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst Location: Washington, DC Schedule: Onsite, 5 days/week Position Type: Direct Hire Clearance Required: Active TS clearance required at time of application. Must be willing and able to obtain SCI access... 

    JCD Staffing

    Washington DC
    1 day ago
  • $177.7k - $202.8k

    ## Senior Manager, Risk Management - Policy AnalystApplylocations: McLean, VA: Richmond...  ...technology, we equally prioritize cybersecurity, reliability, software quality, and data...  ...reliability engineering, technology, data analyst, data scientist, and risk management professionals... 
    Full time
    Part time
    Local area

    Capital One

    Mc Lean, VA
    5 days ago
  •  ...A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating... 
    Remote work

    Districttechgroup

    Washington DC
    1 day ago
  • TikTok is hiring a Security Strategy, Risk and Resilience Controls Management Specialist in Washington, DC. This role focuses on managing cybersecurity risks, assessing compliance with security frameworks like ISO 27001 and SOC 2, and fostering collaboration with teams... 

    Tik Tok

    Washington DC
    4 days ago
  •  ...Cyber And It Security Risk Analyst Location: Bethesda, MD Contract: 12 Months Position Summary We are seeking a Cyber and...  ...to identify, measure, and monitor information security and cybersecurity risks, including reporting on performance against established... 
    Contract work
    For contractors

    InteliX Systems

    Bethesda, MD
    4 days ago
  • $62k - $141k

     ...Job Number: R0242703 Cybersecurity Risk Analyst The Opportunity Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the global enterprise. In all of this "cyber noise," how can these organizations... 
    Contract work
    Local area

    Phase2 Technology

    Alexandria, VA
    3 days ago
  • $62k - $141k

     ...this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you. We need your...  ...active role in information security while growing your skills in cybersecurity.Work with us as we protect our nation’s cyber infrastructure.... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Alexandria, VA
    7 hours ago
  •  ...offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship provides the potential... 
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    4 days ago
  • $189k - $225k

    Spire is seeking a GRC Analyst in Washington, DC to manage cybersecurity governance, risk, and compliance requirements. This role involves thorough contract analysis, policy support, and cross-functional collaboration. Candidates should have at least five years of experience... 
    Contract work

    Spire

    Washington DC
    5 days ago
  • Booz Allen Hamilton is seeking an information security risk specialist in the United States to turn complex cyber threats into actionable...  ...decks for senior leaders. The role requires 5+ years in cybersecurity, DoD-related work, and strong communication skills for... 

    Booz Allen Hamilton

    Alexandria, VA
    1 day ago
  • Phase2 Technology is seeking a Cybersecurity Risk Analyst in Alexandria, Virginia, to help clients understand and mitigate their cyber risks. You'll work closely with enterprises to develop tailored risk management strategies and deliver actionable insights through presentations... 

    Phase2 Technology

    Alexandria, VA
    3 days ago
  • EAB is looking for an Information Assurance (IA) Analyst to assess risks related to technology applications and third-party providers. The role...  ...Richmond, VA, this position is ideal for early-career individuals eager to grow in the cybersecurity field. #J-18808-Ljbffr EAB

    EAB

    Washington DC
    2 days ago
  • JCD Staffing is seeking a Senior Cybersecurity Supply Chain Risk Management Analyst in Washington, DC, to support federal cybersecurity initiatives. This role focuses on identifying and mitigating risks related to complex supply chains, requiring an active TS clearance... 

    JCD Staffing

    Washington DC
    1 day ago
  • Booz Allen Hamilton is seeking an information security risk specialist to translate complex cyber risks into actionable plans for federal clients. You will collaborate with military leaders and SMEs to assess threats, write executive-grade materials, and guide action plans... 

    Booz Allen Hamilton

    Alexandria, VA
    4 days ago
  • Booz Allen Hamilton is seeking an information security risk specialist to translate complex cyber concepts for federal clients and...  ...to mitigate threats. Ideal candidates have extensive cybersecurity risk experience, the ability to draft senior-level documents,... 
    Remote job

    Phase2 Technology

    Alexandria, VA
    1 day ago
  •  ...We are seeking an experienced predictive risk modeler to perform risk assessment on FHA multifamily housing portfolio. To perform in this role, the potential candidate will need skills in econometrics, statistical analysis, and modelling. The main responsibilities include... 

    Aegis Corps

    Washington DC
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity and Risk Analyst. Be the first to apply!