Cybersecurity Risk Management Analyst
$95k - $105kCherokee Federal
Cybersecurity Risk Management Analyst
Cherokee Federal is seeking a Cybersecurity Risk Management Analyst to support its contract with the U.S. National Science Foundation. This role supports Assessment and Authorization (A&A) and broader risk management activities within a federal Governance, Risk, and Compliance (GRC) program. The analyst supports system authorization efforts, risk analysis, and ongoing compliance in alignment with federal cybersecurity requirements.
The Cybersecurity Risk Management Analyst will be part of the Oversight and Compliance Team, which includes policy, A&A, continuity planning, privacy, training, and Security-Focused Configuration Management (SecCM) functions. This role works collaboratively with system owners, ISSOs, and technical teams to assess controls, evaluate risk, and contribute to a holistic view of organizational cybersecurity risk.
Compensation & Benefits : $95,000- $105,000
Estimated Starting Salary Range for Cybersecurity Risk Management Analyst:
Pay commensurate with experience.
Full time benefits include Medical, Dental, Vision, 401K, and other possible benefits as provided. Benefits are subject to change with or without notice.
Cybersecurity Risk Management Analyst Responsibilities Include:
* Create, manage, maintain, and improve NSF A&A documentation and processes (e.g., SSPs, SARs, POA&Ms, security inventories, PTAs, PIAs, and internal reports to management), ensuring completeness, accuracy, and alignment with NIST RMF (SP 800-37, SP 800-53 Rev. 5) and NSF standards.
* Perform control assessments by analyzing technical, procedural, and operational evidence; document results and support risk determinations, POA&M management, and ongoing authorization activities.
* Collaborate with system owners, ISSOs, and engineers to gather artifacts, validate control implementations, and maintain authorization packages across the system lifecycle.
* Conduct cybersecurity assessments and develop a continuous monitoring plan for cloud services in compliance with FedRAMP and other federal requirements.
* Evaluate External Services (e.g., SaaS, PaaS, IaaS) for inclusion within authorization boundaries by reviewing service documentation, analyzing controls, and documenting risks, dependencies, and shared responsibility models; review authorization packages from FedRAMP to assess applicability and identify gaps.
* Support continuous monitoring and SecCM activities by analyzing vulnerability and configuration data (e.g., scan results), validating remediation actions, and identifying trends or systemic risks across systems.
* Customize DISA STIGs and CIS Benchmarks to create and maintain standardized "gold" audit files for systems in use at NSF; leverage Tenable Security Center to support the Security-Focused Configuration Management process.
* Contribute to broader risk management efforts, including identifying cross-system or program-level risks, supporting audit and compliance activities (e.g., OIG), and incorporating findings from assessments, incidents, and external reviews into risk posture and reporting.
* Perform peer reviews of A&A artifacts and related documentation to ensure technical accuracy, consistency, and adherence to established standards; contribute to team deliverables and coordination across Cybersecurity Oversight and Compliance functions.
* Performs other job-related duties as assigned
Cybersecurity Risk Management Analyst Experience, Education, Skills, Abilities requested:
* Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience).
* 2-5 years of experience in cybersecurity, risk management, or A&A within a federal or regulated environment.
* CompTIA Security+ certification
* Working knowledge of the NIST Risk Management Framework (RMF) and associated publications (e.g., SP 800-53, SP 800-37, FIPS 199).
* Experience developing or maintaining A&A documentation (e.g., SSPs, SARs, POA&Ms).
* Familiarity with External Services assessments and/or FedRAMP authorization concepts.
* Demonstrated experience contributing to or reviewing at least one complete ATO package (e.g., SSP, SAR, POA&M lifecycle).
* Proven track record of logical and critical thinking, sophisticated writing skills, superior organizational skills, and excellent planning and time management skills.
* Strong attention to detail
* Must pass pre-employment qualifications of Cherokee Federal
Company Information:
Criterion is a part of Cherokee Federal - the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government's mission with compassion and heart. To learn more about Criterion, visit cherokee-federal.com.
Cherokee Federal is a military friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.
Similar searchable job titles :
* Cybersecurity Compliance Analyst
* Information Security Risk Analyst
* Governance, Risk & Compliance (GRC) Analyst
* Assessment & Authorization (A&A) Analyst
* Cybersecurity RMF Analyst
Keywords:
* NIST RMF
* ATO Documentation
* FedRAMP
* Risk Assessment
* Continuous Monitoring
Legal Disclaimer: All qualified applicants will receive consideration for employment without regard to protected veteran status, disability or any other status protected under applicable federal, state or local law. Many of our job openings require access to government buildings or military installations. Candidates must pass pre-employment qualifications of Cherokee Federal.
- ...Req ID: 77811 Location: Tulsa -TUL Areas of Interest: Risk Management; Audit; Data; Information Security; Portfolio Management; Project Management; Risk Management, BSA/AML; Risk Management, Compliance Pay Transparency Salary Range: Not Available Application...SuggestedWork at office
- A leading financial services company in Tulsa is seeking a Vendor Risk Management Consultant II responsible for executing third-party risk management programs. The ideal candidate will have a Bachelor's Degree and 3-5 years of experience in vendor risk or compliance. This...Suggested
- ...guidance and conduct independent control assessments within the Cybersecurity GRC function. The primary focus will be on the design,... ...on-prem environments. The role also emphasizes comprehensive risk management, including the identification, assessment, and management of...SuggestedWork at officeLocal area
- Sky Mavis is seeking a Sr. GRC Analyst for third-party and human risk management in Tulsa, Oklahoma. This role focuses on identifying and mitigating risks from external vendors while implementing a strong security awareness program to cultivate a security-first culture....Suggested
$110k - $150k
...responses and pricing for RFPs, proposals, and presentations. Manages the design of service programs ensuring client need fulfillment.... ...'s degree with major in Business Administration, Finance or Risk Management preferred. Licenses as required. Possession of, or progress...SuggestedLocal areaFlexible hours- ...event of a disaster. The BDE educates property owners and facility managers on the value of proactive disaster planning, ensuring that terms align with the company’s capabilities and the client’s risk management protocols. Preferred Vendor Programs (PVPs) The BDE works...Contract work
$91k - $321.5k
...Specialty/Competency: IFS - Risk & Quality (R&Q) Industry/Sector: Not Applicable Time Type: Full time Travel Requirements... ...risk and compliance focus on maintaining regulatory compliance and managing risks for clients, providing advice, and solutions. They help...Full timeContract workH1b- ...Job Title Job Description Perform professional duties in managing the application of various systems in support the hydropower maintenance management and business investment plans for the 24 power plants that comprise the Southwestern Power Administration's Power...
- ...Vendor Management Analyst Location: Temple Terrace, FL / Tulsa, OK or anywhere in USA (Hybrid - every Tuesday in office) Duration: 30 months Vendor Management Center (VMC): Responsible for all administrative and audit related functions for Third Party Vendors...Contract workLocal areaNight shiftWeekend workAfternoon shift
- ...operations run smoothly. With services like financial reporting, cost management, risk management, payroll, and vendor management, this dynamic team... ...is on point and thriving. Job Description The Capital Analyst II is primarily responsible for measuring, assessing, and...Work at office
- ...operates TransFund and Cavanal Hill Investment Management, Inc. BOKF, NA operates banking divisions... ...financial reporting, cost management, risk management, payroll, and vendor... ...point and thriving. Job Description The Sr. Analyst, Control Operations will use their knowledge...
$90k - $250k
FINANCIAL ADVISOR - WEALTH MANAGEMENT ADVISOR Remote / Hybrid, United States | Full-Time | Salary: $90,000 - $250,000 per year (W-2; Commission... ..., portfolio management, investment advisory services, and risk management strategies within a structured regulatory framework....Full timeRemote workFlexible hours- ...IT Business Analyst Ameristar Perimeter Security USA, an ASSA ABLOY branded company, is looking for IT Business Analyst. The IT... ...quote-to-cash (Q2C), procure-to-pay (P2P) and inventory/warehouse management. The role spans the tactical, day-to-day work of discovering,...Work experience placementWork at office
- ...ongoing growth and success. WHAT WE'RE LOOKING FOR The Risk Advisor is responsible for new insurance account production and... ...transitions sold clients to the designated client service/account management team. Serves as client's valued advisor, building a...Work at officeLocal area
$67.15k - $73.03k
...Strong attention to detail, organizational skills, and ability to manage multiple projects simultaneously. Ability to work... ...Qualifications Tableau or Power BI, Business Analysis/Analyst, Python, or SQL certifications. Master's degree business Analytics...Full timeWork experience placementWork at officeMonday to Friday$84k - $126k
...JOB SUMMARY Job Profile Summary As a Retirement Plans Analyst - Senior, you will be a key part of the Retirement Plans team... ...changes in plan design Provide information and guidance to management, employees, retirees, regulatory agencies, consultants/actuaries...Work experience placementWork at office$96.4k - $120.5k
...leadership than documentation, this is it. Sr. IT Business Analyst – Sales Enablement The Business Analyst role sits at the intersection... .... You’ll partner day‑to‑day with both IT and Business Product Managers and Owners to help shape product direction, define what value...Full timeShift work- Job Summary: Responsible for design, configuration, testing, validation, training and support of Workday application and/or other assigned applications. Job Responsibilities: Design and maintain system configuration by evaluating feasibility of modifications...Weekend work
- ...The Business Analyst, Pricing and Underwriting , is responsible for the compilation, analysis, and reporting of data to support pricing... ...contracts for Specialty services within a Pharmacy Benefit Manager (PBM) setting. Partner cross-functionally with Underwriting, Finance...Full timeTemporary workWork at officeRemote workWork from home
$80.6k - $145.5k
...how we're UNSTOPPABLE for our employees! The Senior Business Analyst - Fiber Market & Regional Performance supports strategic decision... ...responsible for other duties/projects as assigned by business management as needed Knowledge, Skills, and Abilities Strong...Full timeTemporary workPart timeWork experience placementLocal areaFlexible hours- ...Vast Bank is looking to hire a Business Analyst, Tokenized Deposits! About Vast Bank We’re... ...between product, technology, operations, risk, and compliance teams to support the development... ...Bachelor’s Degree in Finance, Business Management, Information Systems, Banking or related...Full timeWork at officeLocal areaRemote workWork from home
- A healthcare solutions provider committed to inclusivity is looking for a candidate for a data analysis role in Tulsa, Oklahoma. The job involves supporting business initiatives through thorough data evaluation and improving processes within the healthcare sector. Ideal...Remote jobFlexible hours
- ...goals and contribute to our success.To succeed as a business analyst, you should be committed to providing efficient, reliable support... ...be trustworthy, thorough, and courteous with excellent time management skills.Principal Duties1. Adhere to all applicable Bank policies...Full timeWork experience placementWork at officeMonday to Friday
- System One is looking for a Business Analyst - SAP based in Tulsa, Oklahoma. The role involves owning IT business processes, engaging stakeholders, and recommending improvements in payment processes. Candidates should have a Bachelor’s degree, 6-8 years of experience, and...
- ...analysis or data analysis experience. Advanced knowledge of Microsoft Applications, including Excel and Access preferred. Project management experience preferred. Benefits and Payment Configuration: Encounters: Bachelor’s degree in related field or equivalent...Local areaRemote workFlexible hours
- Cooperates with: Operations, Engineering, Field Service, Proj. Management, Finance Primary Responsibility: We are seeking an experienced and detail-oriented Business Analyst to support and evolve our data, reporting, and analytics platforms as part of the Operations team...Flexible hours
$58k - $86k
...industry. At ONEOK, you'll contribute to delivering energy products and services that power progress while gaining hands-on measurement analyst experience while supporting field technicians. We're looking for candidates based in the Tulsa, Oklahoma area, or be willing to...Work experience placementWork at officeWork from homeRelocation- ...community with care and respect. Overview Responsible for managing supply chain responsibilities and coordinating manufacturing and... ...Ability to understand constraints, critical path analysis and risk mitigation Reading engineering drawings and understanding the...Live in
$90k - $100k
...Job Title: Business Analyst Location: Tulsa or Oklahoma City, Oklahoma Type: Direct Hire Compensation: $90,000.00 - $100,000.00 Contractor Work Model: Onsite - onsite Hours: 40.0 Overview We are seeking a highly skilled Technical Data Business Analyst...Full timeFor contractorsFor subcontractorWork at officeLocal area- ...Senior Technical Business Analyst Job Category: Information Technology Full-Time On-site EMSA West Division 6205 S Sooner... ...Responsibilities ~ This position does not have supervisory or management responsibilities of other employees. Physical Demands...Full timeWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Risk Management Analyst. Be the first to apply!
- it risk analyst Tulsa, OK
- risk analyst Tulsa, OK
- risk officer Tulsa, OK
- risk consultant Tulsa, OK
- business analyst part time remote Tulsa, OK
- senior business analyst contract Tulsa, OK
- business development analyst Tulsa, OK
- knowledge management analyst Tulsa, OK
- deloitte business technology analyst Tulsa, OK
- business analyst Tulsa, OK


