Senior Analyst, Cyber Risk Quantification and GRC
$119k - $193kForrester
At Forrester, we’re trusted to work on trailblazing, mission critical problems that business and technology leaders face today. That’s why we’re always looking to empower talented individuals to perform at their best every single day. We’re proud of our community of smart people and vibrant voices who come together to do what’s right by our clients and each other. Our success is driven by curiosity, courage and customer obsession. The confidence and drive to be bold at work. Join us and build an extraordinary future. About This Role: Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk management leaders and their teams. The ideal candidate has a strong understanding of risk management roles, responsibilities, and the most important security and risk trends and their business and technology implications; deep knowledge and experience with risk management practices and methods; deep knowledge and expertise in cyber risk quantification; and deep experience in developing, maintaining, and communicating risk management artifacts including risk standards, procedures, appetite, registry, and business strategy. Expertise in compliance management, internal or external audit, and GRC platforms is strongly desired. The successful candidate researches and uncovers the strategies, technologies, and best practices of risk management that create a resilient and opportunity-seeking business. The Senior Analyst delivers these insights and recommendations in written reports, presentations, inquiries, guidance sessions, and custom advisory for risk leaders across industries and geographies. Our research is aimed at helping enterprise clients solve business problems and improve business results by applying principles and best practices. We also advise vendors on their strategies, roadmaps, and messaging in line with our market insights and our recommendations for enterprise clients. Job Description: The Senior Analyst works as part of a high-performing team with a strong emphasis on collaborating with others in all aspects of the job. The Senior Analyst is expected to: Develop a deep understanding of what Forrester clients require to be successful as risk management leaders and professionals with a focus on how they help their organizations develop risk management capabilities that enable a resilient and opportunity-seeking business. Conduct primary research into risk management capabilities, practices, touchpoints, and artifacts in the context of supporting C-suite executives, business leaders, and appropriate committees. Help define the future of risk management, including how risk leaders and professionals can work with other key business functions and support organizational success. Work with different focus areas across Forrester research teams to develop a complete research portfolio on risk management, providing both input to others’ research and writing reports incorporating expertise from across Forrester to provide a “big picture” view. Partner as appropriate with other Forrester analysts on broader risk topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk. Research/write/create approximately six to eight research projects per year — a mix of written reports, tools, webinars, videos, podcasts, infographics, and other intellectual property. Build visibility for their research and contribute to Forrester client communities. Consult with clients to apply Forrester’s research in the context of their specific business environment and help solve their problems through inquiry, guidance, and advisory engagements. Establish an industry presence as an influential speaker and thinker; build relationships with journalists who cover the sector; and participate in vendor briefings and field press inquiries as necessary. Job Requirements: Five to seven years as a research analyst, consultant, or practitioner where you have led or been involved in risk management, with a focus on cyber risk quantification, or an equal amount of time as product manager for vendors that serve the market. A deep intellectual curiosity about the effect of technology on the business landscape; solid business instincts and a practical understanding of what makes companies tick; and a creative view of markets, technologies, and attitudes combined with a fascination with the future. Superior listening, critical thinking, and writing skills as well as compelling presentation skills. The ability to take complex, disparate ideas and distill them into simple, provocative concepts — and be willing to take a stand on vendors and outcomes. The ability to travel up to 20% of the time. Please note that the base salary range indicated here is inclusive of all applicable US geographies listed in this requisition, with the exception of New York City and Georgia. This salary range is based upon the position as described in the job listing. The offered compensation may vary within this range and is dependent upon the successful candidate’s primary work location, experience, training, education, and credentials. Base salary range: $119,000 - $193,000 Base salary range for Georgia: $106,000 - $174,000 Base salary range for New York City, NY: $136,000 – $222,000 For employees based in Washington State, the percentage listed here is an estimated bonus target as a percentage of base salary, in accordance with the Forrester Employee Bonus plan. Individual and company performance, as well as other eligibility criteria, will determine the actual incentive amount. Bonus target: 10% For information on benefits, please visit: The application deadline is July 31, 2026. Please refer to the job posting on Forrester.com careers page if the deadline has been extended. #LI-JM1 We’re a network of knowledge and experience leading to richer, fuller careers. Here, we’re always learning. Whether you want to hone your strengths or discover new ones, Forrester is the place to go for it. It’s a place where everyone is given the tools, support, and runway they need to go far. We’ll be right there beside you, every step of the way. Let’s be bold, together. Explore #ForresterLife on: Instagram LinkedIn Glassdoor FLSA Status: Exempt Here at Forrester, we welcome people from all backgrounds and perspectives. Our aim is for all candidates to be able to fully participate in Forrester’s recruitment process. If you would like to discuss a reasonable accommodation, please reach out to View email address on click.appcast.io. Forrester Research, Inc. is an Equal Employment Opportunity Employer. As a federal contractor, Forrester encourages veterans and individuals with disabilities to apply for employment. Benefits at a Glance Benefits at a Glance - Cambridge At Forrester, we’re bold. We make big moves, transform businesses, and define the future. We’re the people who challenge, who innovate, who dare to discover. We’re a community of smart people and vibrant voices coming together to do what’s right by our clients and each other. Our success is driven by curiosity, courage, and customer obsession. Here you can be bold at work. Join us and build an extraordinary future. With you, we’re not just bold. We’re bold, together.
- ...services provider is seeking a Cybersecurity Analyst in Alexandria, VA, focused on governance, risk, and compliance (GRC) activities. The ideal candidate should have a... ...minimum of 10 years of relevant experience and senior-level cybersecurity certifications. You will lead...Senior
- Nucorevision, Inc is seeking a Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst in Washington, D.C. This role involves managing cybersecurity risks for a Federal Agency by ensuring the security and reliability of ICT/OT products across their lifecycle....CyberSeniorRemote work3 days per week
- Job Description The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) by managing cybersecurity risks associated with the Agency's complex, globally distributed, and interconnected supply...CyberSeniorWork at office
$94.2k
...teams and other areas necessary to identify risks to the business and drive solutions... ...Framework (HITRUST CSF), or the NIST 800-83 cyber security framework ~ Experience supporting... ...experience ~ Governance Risk and Compliance (GRC) tool experience such as ARCHER ~ In-...CyberSeniorFor contractorsLocal areaRemote work$185k
...Overview Senior Supply Chain Risk Management (SCRM) Analyst/Engineer LOCATION : Arlington,VA JOB STATUS:... ...management, intelligence analysis, cyber threat assessment, and cross-functional... ...characterization, or cyber risk quantification efforts. Working knowledge of...CyberSeniorFull timeWork at office- A leading federal services provider is seeking a Cybersecurity Analyst in Alexandria, VA. This role includes managing governance, risk, and compliance activities to ensure compliance with DoD requirements. The ideal candidate will have at least 10 years of relevant experience...Senior
- ...Holdings, a Pequot Company, is seeking a Management Analyst to support the Cybersecurity and Infrastructure... ...Programs. The role involves providing research and cyber-physical security analytic support to reduce risks posed by small unmanned aircraft systems. The ideal...CyberSeniorContract workWork at office
- TAD PGS, Inc. has an outstanding contract position for a Senior Cybersecurity Supply Chain Risk Management Analyst in the Washington, DC area. The role involves analyzing supply chain cybersecurity risks and provides support for procurement documentation related to high...CyberSeniorContract work
$164.38k - $189.75k
...Risk Mitigation Specialist Senior Our work depends on a Risk Mitigation Specialist Senior to engage in defense and security efforts within the Pacific... ...capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients,...CyberSeniorTemporary workImmediate startRemote workWorldwideFlexible hours- ...Senior Analyst, Cybersecurity Governance, Risk and Compliance, Washington, DC The Senior Analyst, Cybersecurity Governance Risk & Compliance will administer... ...and ongoing monitoring) and supporting broader GRC efforts. This position is 100% Onsite and not open for...SeniorWork experience placement
- Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst Job Description The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports a Federal... ..., evaluating supplier risk, and identifying Cyber Information Security Agency (CISA) Known...CyberSeniorRemote work
$160k
...Senior Enterprise Risk Manager Denver, CO or Long Beach, CA or Washington... ...in industry-standard risk quantification and assessment methodologies... ...FAIR methodology to quantify cyber and operational risk in... ...such as Jira, Confluence, GRC platforms, and MS Project....CyberSeniorPermanent employmentContract work$77k - $202k
...Requirements: Up to 60% At PwC, our people in risk and compliance focus on maintaining... ...requirements. Opportunity As part of the Cyber, Strategy, Risk & Compliance team you are... ...industry frameworks and methodologies. As a Senior Associate you are expected to analyze complex...CyberSeniorFull time$91k - $321.5k
...Specialty/Competency: IFS - Risk & Quality (R&Q) Industry/Sector: Not Applicable... ...Contract Specialist - Managed Services - Senior Manager, you will lead initiatives in enterprise... ...maintenance application managed services, (3) cyber managed services, or (4) risk & regulatory...CyberSeniorFull timeContract workH1b- ...Significant experience with full cycle Risk Management processes, including cATO, Risk... ...functional application via Service Now IRM/GRC environment. Significant experience with... ...experience. Required Skills : Business Analysis Additional Skills : Business Analyst
$84k - $100k
...GRC Analyst Uplight is creating a new category of energy. We make software that manages energy resources in homes and businesses—including... ...! How you will make an impact: Manage 3rd party/vendor risk management assessments Assist sales and operations functions...Local areaFlexible hoursShift work- ...The Governance, Risk, and Compliance (GRC) Analyst supporting federal and customer programs is responsible for evaluating, documenting, and operationalizing cybersecurity and compliance requirements across the organization. This position works across contractual obligations...Contract work
- ...Provides direct support to the Director Security Governance, Risk and Compliance and security shared service team by assuring information... ..., and various security solutions. ~ Experience in working with GRC systems/modules. ~ Experience in working across enterprises...
- ...Cybersecurity Risk Management Position Position is in the Cybersecurity... ...security coverage gaps. Cyber security business and systems... ...registers. Experience with GRC (Governance, Risk, and... ...experience with direct Business Analyst experience. Excellent interpersonal...CyberSeniorWork experience placement
$140k - $165k
...Prisons (BOP) Contract: IT Cyber Security Support... ...Overview We are seeking a Senior Authorization to... ...compliance with FISMA, NIST Risk Management Framework (RMF... ...Mentor junior security analysts and ISSOs on ATO... ...Qualys, or equivalent) GRC platforms (CSAM, Xacta,...CyberSeniorContract workWork at officeRemote workMonday to Friday$189k - $225k
...Job Description Job Description About the Role: The GRC Analyst, Federal & Customer Programs is responsible for the hands-on analysis... ...operational execution of the company's security governance, risk, and compliance obligations. This role sits at the intersection...Ongoing contractContract workFor contractorsFor subcontractorWork at office3 days per week- GoTo Meeting is seeking a GRC Analyst, Federal & Customer Programs, to manage security governance, risk, and compliance obligations. Responsibilities include analyzing contracts, mapping obligations to compliance frameworks, and producing compliance matrices. The ideal...
- ...must include: # Prior work in a technical cybersecurity risk management function at organizations with security related regulatory... ...in a team/task force as a team member or leader, and with senior staff and managers. # Ability to work well under pressure and...CyberSenior
$107.9k - $195.05k
...sector is seeking an experienced Senior SCRM SBOM Analyst to support the delivery,... ...outdated components, and supply chain risks. Support integration of SBOM... ...analysis, analyze end-to-end cyber supply chain risks ~ Proficient using GRC tools such as eMASS ~...CyberSeniorLocal areaImmediate start- ...maintain system security and oversee cyber implementation. The role... ...Exchange), and NIST 800-37 r2 (Risk Management Framework for Information... ...and the program as well as DoW senior leadership. Reporting of... ...with eMASS, Xacta and/or other GRC tools. Experience with Federal...CyberSeniorFull timeWork at office
$113k - $188k
...Job Family : Cyber Consulting Travel Required : Up to 10% Clearance Required... ...and best practices for cyber security and risk management to strengthen an organizations... ...of Governance Risk and Compliance (GRC) requirements, standards, and guidelines governing...CyberSeniorFull timeTemporary workFlexible hours- Capital One National Association is seeking a Senior Associate for Cyber Risk & Analysis in McLean, VA. You will evaluate technology functions and cybersecurity risks while performing audits for critical technology areas. The ideal candidate has at least 2 years of experience...CyberSenior
$107.9k - $195.05k
...is seeking an experienced Senior Continuous Monitoring Analyst to support the delivery, enhancement... ...Milestones (POA&Ms) within GRC tools (e.g., eMASS).... ...to support Government risk-based decision making. Coordinate... ...for Intermediate Cyber Defense Analyst roles (e.g....CyberSeniorLocal areaImmediate start- ...candidate will be required to have US Citizenship and the ability to obtain a Public Trust Clearance, along with significant experience in cyber threat intelligence analysis. The role demands expertise in evaluating threat intelligence, producing comprehensive reports, and...CyberSenior
$141.5k - $236k
...Senior Information System Security Officer Unlock the secrets of... ...vulnerability scans according to risk assessment parameters Manage... ...Governance, Risk, and Compliance (GRC) application to support... ...Science, Cybersecurity, or other cyber discipline Clearance Requirements...CyberSeniorHourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Analyst, Cyber Risk Quantification and GRC. Be the first to apply!
- transaction risk analyst Washington DC
- operational risk consultant Washington DC
- governance risk & compliance analyst Washington DC
- it risk analyst Washington DC
- information risk analyst Washington DC
- risk compliance officer Washington DC
- operational risk specialist Washington DC
- risk analyst Washington DC
- third party risk analyst Washington DC
- senior quantitative risk analyst Washington DC


