Enterprise Cybersecurity Vulnerability Risk Analyst
$99k - $225kBooz Allen Hamilton
Enterprise Cybersecurity Vulnerability Risk AnalystThe Opportunity:Cyber threats are everywhere, and vulnerabilities can create risk quickly when findings are not reviewed, prioritized, tracked, and resolved through clear ownership. In all of this cyber noise, how can organizations make practical, risk-informed decisions about vulnerability remediation, deferrals, exceptions, and appeals? The answer is you — an information security risk specialist who can help turn complex vulnerability information into clear decisions and accountable action.As a Vulnerability Exception and Deferral Analyst on our Enterprise IT and Cyber Risk team, you’ll manage the operational lifecycle of vulnerability exceptions, deferrals, appeals, and related risk decisions. You’ll review technical and business justifications, validate mitigating controls, assess risk impact, and help determine whether requests align with enterprise standards, risk tolerance, and compliance expectations. You’ll partner with vulnerability management, cyber architecture and engineering, hosting, network services, business information security officers, technical risk officers, product owners, and system owners to support timely, consistent, and defensible remediation decisions.You’ll use ServiceNow and related workflow tools to track vulnerability risk decisions, maintain accurate records, identify aging or bottlenecked items, and generate reporting on exception trends, workflow metrics, remediation status, and recurring risk themes. You’ll help improve the consistency and maturity of the vulnerability exception and deferral program by strengthening intake criteria, decision documentation, escalation paths, and operational reporting. This is your opportunity to support a high-impact cyber risk process while broadening your skills in vulnerability management, cloud security, risk governance, and workflow automation.Work with us as we protect the enterprise by strengthening how vulnerability risk is evaluated, tracked, escalated, and remediated. Due to the nature of work performed within this facility, U.S. citizenship is required.Join us. The world can’t wait.You Have:5+ years of experience supporting cybersecurity operations, vulnerability management, security findings management, technology risk, cyber risk, or remediation trackingExperience managing the lifecycle of security findings or vulnerabilities, including intake, assignment, tracking, aging, reporting, escalation, remediation coordination, or closure validationExperience evaluating vulnerability deferrals, exceptions, appeals, risk acceptances, or remediation delays, including review of technical and business justificationsExperience assessing mitigating controls, service level agreement compliance, risk-based prioritization, or risk-based decisioning for vulnerability findingsExperience using workflow platforms such as ServiceNow to manage vulnerability response, risk management, ITSM, CMDB, issue tracking, or remediation workflowsKnowledge of vulnerability management concepts, cloud security findings, Cloud Security Posture Management, remediation workflows, and operational risk reportingAbility to translate technical vulnerability data into clear risk summaries, workflow metrics, exception trends, and status updates for technical teams and risk governance forumsAbility to coordinate across technical and business teams during fast-paced remediation decision cyclesHS diploma or GEDNice If You Have:Experience with ServiceNow Vulnerability Response, Integrated Risk Management, ITSM, CMDB, or workflow automationExperience supporting cloud security or CSPM findings in AWS, Azure, Google Cloud Platform, or hybrid cloud environmentsExperience facilitating cross-functional huddles with cyber architecture and engineering, vulnerability management, hosting, network, BISO, technical risk, product, or system owner teamsKnowledge of security controls and alignment to regulations or frameworks, including NIST SP 800-53, NIST SP 800-171, FedRAMP, CMMC, SOC 2, or similar frameworksKnowledge of incident-style escalation handling, including rapid evaluation of critical or urgent vulnerabilities and coordination with on-call personnelAbility to identify operational trends, data quality issues, workflow bottlenecks, and process maturity opportunitiesAbility to manage competing priorities, drive tasks to closure with minimal supervision, and operate effectively in a developing or evolving risk management environmentAbility to support priority incidents or urgent remediation decisions outside normal working hours if required.Bachelor’s degreeCertifications in cybersecurity, risk, cloud, vulnerability management, or ServiceNow, including CISSP, CGRC, CRISC, Security+, AWS, Azure, or specialized ServiceNow certificationsCompensationAt Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.Identity StatementAs part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Candidate AI Usage PolicyAI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work ModelOur people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.Commitment to Non-DiscriminationAll qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.SummaryLocation: McLean, VAType: Full time
$99k - $225k
Enterprise Cybersecurity AI Risk AnalystThe Opportunity: Cyber threats are everywhere, and the rapid evolution of artificial intelligence is changing... ...risk into clear, manageable actions.As an AI Cyber Risk Analyst on our Enterprise IT and Cyber Risk team, you’ll support...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$80k - $128k
ResponsibilitiesPeraton is currently seeking a Risk and Vulnerability Analyst.Location: Chandler, AZ or... ...and security risks across enterprise, cloud, and application environments... ...QualificationsRequired: Bachelor’s degree in Cybersecurity, Information Technology, or related...SuggestedContract workShift work$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$86.8k - $198k
Enterprise Cybersecurity Product AnalystThe Opportunity:As an Enterprise Cybersecurity Product Analyst, you will support Booz Allen's Enterprise Cybersecurity (ECS) Product Security function... ...expectations.Track product security risks and mitigation actions, and communicate...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work$100k - $150k
...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location... ...Risk Analyst to support enterprise cybersecurity and cyber defense operations... ...NIST SP 800-53, continuous monitoring, vulnerability management, or SOC/SIEM operations....SuggestedContract work- ...Cooperation Agency (DSCA) Program, Analytical, Technical, and Enterprise (PATAE) contract seeks to support program management,... ...modeling & simulation) to inform design decisions and risk mitigation.· Integrate cybersecurity, information assurance, and interoperability...Contract workFor contractorsWork at officeWorldwide
- ...contingent upon contract award ***Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis... ..., maintaining scan operations, and helping improve enterprise visibility into security weaknesses and cyber risk.Responsibilities...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$110.18k - $183.63k
...forward‑thinking organization. Job Summary The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and Penetration Testing (VAPT) team... ..., and mitigating cybersecurity risks across enterprise systems, networks, and applications. This role...Temporary workWork at officeRemote workFlexible hours- ...background investigation Position Summary The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and Penetration Testing (VAPT) team... ..., and mitigating cybersecurity risks across enterprise systems, networks, and applications. This role...Shift work
$110.18k - $183.63k
...organization. We are currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington,... ...is a critical member of the Vulnerability Assessment and Penetration Testing... ...mitigating cybersecurity risks across enterprise systems, networks, and applications...Temporary workWork at officeRemote workFlexible hours$104k - $156k
...forms the operational backbone of the enterprise security function. Operating within a... ...of security controls aligned to vulnerabilities, risks, issues and/or events. Support purple... ...security domains (or) Master's Degree in Cybersecurity or relevant field. Hands-on experience...Remote work$99k - $225k
Compliance ISSO and Enterprise Cybersecurity Security ArchitectThe Opportunity: Enterprise Cybersecurity (ECS) Governance, Risk and Compliance (GRC) plays a pivotal role in safeguarding... ..., from identifying technical vulnerabilities to guiding engineering teams through...Full timeContract workPart timeWork at officeLocal areaRemote work$104.8k - $192.2k
...Government and Public Sector - Cybersecurity - Penetration Tester -... ...discovering the newest security vulnerabilities, attending and speaking at... ...systemic security weaknesses.Risk Identification and Escalation... ...experience supporting enterprise or large-scale environments....For contractorsSummer holidayWork at officeLocal areaFlexible hours$86.8k - $198k
Enterprise Security Architect, LeadThe Opportunity: Security must be architected, not bolted... ...procedures.In this role, you will apply risk modeling and secure design methodologies... ...will partner with engineering teams, cybersecurity SMEs, cloud or platform owners, and business...Full timeContract workPart timeWork at officeLocal areaRemote work- ...fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We're... ...are seeking a motivated analyst to support the development... ..., supervisory, and risk management... ...concentration, and emerging vulnerabilities.Designing and building...InternshipLocal area
$90k - $130k
...Penetration Tester to join our cybersecurity team in Arlington, VA... ...Advana.The WDP is an enterprise-wide, multi-domain... ...and exploiting vulnerabilities to validate and... ...exploit vulnerabilities.Risk Assessment & Reporting... ...CompTIA CyberSecurity Analyst (CySA+)Federal IT Security...Full timeWork at office$120k - $180k
...Job Title: AI Cyber Engineer (Enterprise Security & Autonomous... ...implementing and operating AI-driven cybersecurity capabilities to continuously... ..., prioritize, and remediate vulnerabilities across the enterprise IT... ...identify weaknesses.Intelligent Risk PrioritizationLeverage and...Shift work- ...Cyber Network Defense Analyst (CNDA) Our partner provides remote and onsite advanced... ...-based, network-based and cloud-based cybersecurity analysis capabilities. Team personnel provide... ...network resources Coordinate with enterprise-wide cyber defense staff to validate...Immediate startRemote work
$155.6k - $306.8k
...Help clients reduce cyber risk by leading forward deployed... ...operational improvement across enterprise environments. In this role,... ...and help clients translate vulnerability data into sustained risk-reduction... ...degree in Computer Science, Cybersecurity, Information Systems,...Local area- ...supporting a U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and... ...Resources (CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management techniques, critical thinking, and...
$132k - $178k
...Enterprise Risk Analyst Denver, CO or Long Beach, CA or Washington, DC or SF Bay Area Space is a warfighting domain. True Anomaly seeks... ...on schedule. Monitor vendor risk signals including cybersecurity advisories, regulatory actions, and contractual compliance...Permanent employmentContract workWork at office- Phase2 Technology in Arlington, Virginia is looking for an experienced information security risk specialist to mitigate complex cybersecurity threats. This role requires collaboration with stakeholders to assess cybersecurity postures, leveraging eMASS and RMF for effective...Remote job
$120k - $136k
...SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure... ...across the U.S. We provide innovative enterprise-wide solutions as well as targeted... ...is seeking a Senior Digital Forensics Analyst to support the Diplomatic Security...Contract workFor contractorsInterim roleLocal areaRemote work$104k - $166k
ResponsibilitiesPeraton is seeking an experienced Data Analyst/Cyber Analytics professional to support... ...role, you'll work with large-scale cybersecurity and operational datasets to uncover... ...integrator and transformative enterprise IT provider, we deliver trusted, highly...Contract workShift work$110k - $120k
...is looking for a Senior Computer System Analyst to support our Defense health... ...R, and AI-driven analytics to develop enterprise dashboards, perform predictive analysis... ...Intelligence.Advance knowledge of cloud, cybersecurity, and /or virtual resource practices in...Work experience placement$104k - $166k
...hire an experienced Incident Response Analyst (ICS/OT/SCADA) for its' Federal Strategic... ....In This Role, You Will: Respond to cybersecurity incidents across ICS, OT, and IT environments... ...integrator and transformative enterprise IT provider, we deliver trusted, highly...Contract workCurrently hiringShift work1 day per week$82.6k - $162.8k
...re looking for an opportunity to work at the intersection of cybersecurity, data, and artificial intelligence, Deloitte’s Cyber Defense... ...strengthen cyber defense while enabling innovation across the enterprise.Recruiting for this role ends on 12/31/2026.Work you'll doAs...Local areaVisa sponsorship$105.4k - $207.8k
...response (SOAR) deployments aligned with enterprise security policies and regulatory... ...with security operations center analysts and threat detection engineers to prioritize... ...members, and staying current on cybersecurity threats, vulnerabilities, and compliance trendsA successful...Local areaVisa sponsorship$82.6k - $162.8k
...into scalable engineering outcomes across enterprise and cloud environments. Recruiting for... ...and workflow enhancements that improve analyst efficiency and response... ...Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a...Local areaVisa sponsorship$104k - $166k
ResponsibilitiesPeraton is Cyber Threat Analyst - Global Threat Analysis (GTA) for its'... ...) to assess emerging threats.Provide cybersecurity briefings and consultations to diverse... ...capability integrator and transformative enterprise IT provider, we deliver trusted, highly...Full timeContract workOverseasShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Enterprise Cybersecurity Vulnerability Risk Analyst. Be the first to apply!
- cyber security consultant McLean, VA
- cyber security specialist McLean, VA
- risk analyst McLean, VA
- risk officer McLean, VA
- it risk analyst McLean, VA
- senior quantitative risk analyst McLean, VA
- third party risk analyst McLean, VA
- operational risk specialist McLean, VA
- risk consultant McLean, VA
- operational risk consultant McLean, VA

