Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Enterprise Cybersecurity Vulnerability Risk Analyst

$99k - $225k

Booz Allen Hamilton

Enterprise Cybersecurity Vulnerability Risk AnalystThe Opportunity:Cyber threats are everywhere, and vulnerabilities can create risk quickly when findings are not reviewed, prioritized, tracked, and resolved through clear ownership. In all of this cyber noise, how can organizations make practical, risk-informed decisions about vulnerability remediation, deferrals, exceptions, and appeals? The answer is you — an information security risk specialist who can help turn complex vulnerability information into clear decisions and accountable action.As a Vulnerability Exception and Deferral Analyst on our Enterprise IT and Cyber Risk team, you’ll manage the operational lifecycle of vulnerability exceptions, deferrals, appeals, and related risk decisions. You’ll review technical and business justifications, validate mitigating controls, assess risk impact, and help determine whether requests align with enterprise standards, risk tolerance, and compliance expectations. You’ll partner with vulnerability management, cyber architecture and engineering, hosting, network services, business information security officers, technical risk officers, product owners, and system owners to support timely, consistent, and defensible remediation decisions.You’ll use ServiceNow and related workflow tools to track vulnerability risk decisions, maintain accurate records, identify aging or bottlenecked items, and generate reporting on exception trends, workflow metrics, remediation status, and recurring risk themes. You’ll help improve the consistency and maturity of the vulnerability exception and deferral program by strengthening intake criteria, decision documentation, escalation paths, and operational reporting. This is your opportunity to support a high-impact cyber risk process while broadening your skills in vulnerability management, cloud security, risk governance, and workflow automation.Work with us as we protect the enterprise by strengthening how vulnerability risk is evaluated, tracked, escalated, and remediated. Due to the nature of work performed within this facility, U.S. citizenship is required.Join us. The world can’t wait.You Have:5+ years of experience supporting cybersecurity operations, vulnerability management, security findings management, technology risk, cyber risk, or remediation trackingExperience managing the lifecycle of security findings or vulnerabilities, including intake, assignment, tracking, aging, reporting, escalation, remediation coordination, or closure validationExperience evaluating vulnerability deferrals, exceptions, appeals, risk acceptances, or remediation delays, including review of technical and business justificationsExperience assessing mitigating controls, service level agreement compliance, risk-based prioritization, or risk-based decisioning for vulnerability findingsExperience using workflow platforms such as ServiceNow to manage vulnerability response, risk management, ITSM, CMDB, issue tracking, or remediation workflowsKnowledge of vulnerability management concepts, cloud security findings, Cloud Security Posture Management, remediation workflows, and operational risk reportingAbility to translate technical vulnerability data into clear risk summaries, workflow metrics, exception trends, and status updates for technical teams and risk governance forumsAbility to coordinate across technical and business teams during fast-paced remediation decision cyclesHS diploma or GEDNice If You Have:Experience with ServiceNow Vulnerability Response, Integrated Risk Management, ITSM, CMDB, or workflow automationExperience supporting cloud security or CSPM findings in AWS, Azure, Google Cloud Platform, or hybrid cloud environmentsExperience facilitating cross-functional huddles with cyber architecture and engineering, vulnerability management, hosting, network, BISO, technical risk, product, or system owner teamsKnowledge of security controls and alignment to regulations or frameworks, including NIST SP 800-53, NIST SP 800-171, FedRAMP, CMMC, SOC 2, or similar frameworksKnowledge of incident-style escalation handling, including rapid evaluation of critical or urgent vulnerabilities and coordination with on-call personnelAbility to identify operational trends, data quality issues, workflow bottlenecks, and process maturity opportunitiesAbility to manage competing priorities, drive tasks to closure with minimal supervision, and operate effectively in a developing or evolving risk management environmentAbility to support priority incidents or urgent remediation decisions outside normal working hours if required.Bachelor’s degreeCertifications in cybersecurity, risk, cloud, vulnerability management, or ServiceNow, including CISSP, CGRC, CRISC, Security+, AWS, Azure, or specialized ServiceNow certificationsCompensationAt Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.Identity StatementAs part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.Candidate AI Usage PolicyAI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work ModelOur people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.Commitment to Non-DiscriminationAll qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.SummaryLocation: McLean, VAType: Full time

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Enterprise Cybersecurity Vulnerability Risk Analyst in McLean, VA vacancy
  • $99k - $225k

    Enterprise Cybersecurity AI Risk AnalystThe Opportunity: Cyber threats are everywhere, and the rapid evolution of artificial intelligence is changing...  ...risk into clear, manageable actions.As an AI Cyber Risk Analyst on our Enterprise IT and Cyber Risk team, you’ll support... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    3 days ago
  • $80k - $128k

    ResponsibilitiesPeraton is currently seeking a Risk and Vulnerability Analyst.Location: Chandler, AZ or...  ...and security risks across enterprise, cloud, and application environments...  ...QualificationsRequired: Bachelor’s degree in Cybersecurity, Information Technology, or related... 
    Suggested
    Contract work
    Shift work

    Peraton Corporation

    Washington DC
    3 days ago
  • $99k - $225k

    Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    2 days ago
  • $86.8k - $198k

    Enterprise Cybersecurity Product AnalystThe Opportunity:As an Enterprise Cybersecurity Product Analyst, you will support Booz Allen's Enterprise Cybersecurity (ECS) Product Security function...  ...expectations.Track product security risks and mitigation actions, and communicate... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    1 day ago
  • $100k - $150k

     ...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location...  ...Risk Analyst to support enterprise cybersecurity and cyber defense operations...  ...NIST SP 800-53, continuous monitoring, vulnerability management, or SOC/SIEM operations.... 
    Suggested
    Contract work

    OPS TECH ALLIANCE LLC

    McLean, VA
    2 days ago
  •  ...Cooperation Agency (DSCA) Program, Analytical, Technical, and Enterprise (PATAE) contract seeks to support program management,...  ...modeling & simulation) to inform design decisions and risk mitigation.· Integrate cybersecurity, information assurance, and interoperability... 
    Contract work
    For contractors
    Work at office
    Worldwide

    EGlobalTech

    Arlington, VA
    4 days ago
  •  ...contingent upon contract award ***Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis...  ..., maintaining scan operations, and helping improve enterprise visibility into security weaknesses and cyber risk.Responsibilities... 
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    3 days ago
  • $110.18k - $183.63k

     ...forward‑thinking organization. Job Summary The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and Penetration Testing (VAPT) team...  ..., and mitigating cybersecurity risks across enterprise systems, networks, and applications. This role... 
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA North America

    Arlington, VA
    3 days ago
  •  ...background investigation Position Summary The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and Penetration Testing (VAPT) team...  ..., and mitigating cybersecurity risks across enterprise systems, networks, and applications. This role... 
    Shift work

    Gormat

    Arlington, VA
    5 days ago
  • $110.18k - $183.63k

     ...organization. We are currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington,...  ...is a critical member of the Vulnerability Assessment and Penetration Testing...  ...mitigating cybersecurity risks across enterprise systems, networks, and applications... 
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA, Inc.

    Arlington, VA
    3 days ago
  • $104k - $156k

     ...forms the operational backbone of the enterprise security function. Operating within a...  ...of security controls aligned to vulnerabilities, risks, issues and/or events. Support purple...  ...security domains (or) Master's Degree in Cybersecurity or relevant field. Hands-on experience... 
    Remote work

    Relativity

    Washington DC
    11 hours ago
  • $99k - $225k

    Compliance ISSO and Enterprise Cybersecurity Security ArchitectThe Opportunity: Enterprise Cybersecurity (ECS) Governance, Risk and Compliance (GRC) plays a pivotal role in safeguarding...  ..., from identifying technical vulnerabilities to guiding engineering teams through... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    2 days ago
  • $104.8k - $192.2k

     ...Government and Public Sector - Cybersecurity - Penetration Tester -...  ...discovering the newest security vulnerabilities, attending and speaking at...  ...systemic security weaknesses.Risk Identification and Escalation...  ...experience supporting enterprise or large-scale environments.... 
    For contractors
    Summer holiday
    Work at office
    Local area
    Flexible hours

    EY (Ernst & Young)

    McLean, VA
    4 days ago
  • $86.8k - $198k

    Enterprise Security Architect, LeadThe Opportunity: Security must be architected, not bolted...  ...procedures.In this role, you will apply risk modeling and secure design methodologies...  ...will partner with engineering teams, cybersecurity SMEs, cloud or platform owners, and business... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    4 days ago
  •  ...fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We're...  ...are seeking a motivated analyst to support the development...  ..., supervisory, and risk management...  ...concentration, and emerging vulnerabilities.Designing and building... 
    Internship
    Local area

    Mitre

    McLean, VA
    3 days ago
  • $90k - $130k

     ...Penetration Tester to join our cybersecurity team in Arlington, VA...  ...Advana.The WDP is an enterprise-wide, multi-domain...  ...and exploiting vulnerabilities to validate and...  ...exploit vulnerabilities.Risk Assessment & Reporting...  ...CompTIA CyberSecurity Analyst (CySA+)Federal IT Security... 
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    1 day ago
  • $120k - $180k

     ...Job Title: AI Cyber Engineer (Enterprise Security & Autonomous...  ...implementing and operating AI-driven cybersecurity capabilities to continuously...  ..., prioritize, and remediate vulnerabilities across the enterprise IT...  ...identify weaknesses.Intelligent Risk PrioritizationLeverage and... 
    Shift work

    Ampcus

    Washington DC
    2 days ago
  •  ...Cyber Network Defense Analyst (CNDA) Our partner provides remote and onsite advanced...  ...-based, network-based and cloud-based cybersecurity analysis capabilities. Team personnel provide...  ...network resources Coordinate with enterprise-wide cyber defense staff to validate... 
    Immediate start
    Remote work

    NewGen Technologies (Maryland)

    Arlington, VA
    3 days ago
  • $155.6k - $306.8k

     ...Help clients reduce cyber risk by leading forward deployed...  ...operational improvement across enterprise environments. In this role,...  ...and help clients translate vulnerability data into sustained risk-reduction...  ...degree in Computer Science, Cybersecurity, Information Systems,... 
    Local area

    Deloitte

    McLean, VA
    2 days ago
  •  ...supporting a U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and...  ...Resources (CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management techniques, critical thinking, and... 

    Node.Digital LLC

    Arlington, VA
    5 days ago
  • $132k - $178k

     ...Enterprise Risk Analyst Denver, CO or Long Beach, CA or Washington, DC or SF Bay Area Space is a warfighting domain. True Anomaly seeks...  ...on schedule. Monitor vendor risk signals including cybersecurity advisories, regulatory actions, and contractual compliance... 
    Permanent employment
    Contract work
    Work at office

    True Anomaly

    Washington DC
    1 day ago
  • Phase2 Technology in Arlington, Virginia is looking for an experienced information security risk specialist to mitigate complex cybersecurity threats. This role requires collaboration with stakeholders to assess cybersecurity postures, leveraging eMASS and RMF for effective... 
    Remote job

    Phase2 Technology

    Arlington, VA
    3 days ago
  • $120k - $136k

     ...SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure...  ...across the U.S. We provide innovative enterprise-wide solutions as well as targeted...  ...is seeking a Senior Digital Forensics Analyst to support the Diplomatic Security... 
    Contract work
    For contractors
    Interim role
    Local area
    Remote work

    SkyePoint Decisions

    Arlington, VA
    2 days ago
  • $104k - $166k

    ResponsibilitiesPeraton is seeking an experienced Data Analyst/Cyber Analytics professional to support...  ...role, you'll work with large-scale cybersecurity and operational datasets to uncover...  ...integrator and transformative enterprise IT provider, we deliver trusted, highly... 
    Contract work
    Shift work

    Peraton Corporation

    Arlington, VA
    3 days ago
  • $110k - $120k

     ...is looking for a Senior Computer System Analyst to support our Defense health...  ...R, and AI-driven analytics to develop enterprise dashboards, perform predictive analysis...  ...Intelligence.Advance knowledge of cloud, cybersecurity, and /or virtual resource practices in... 
    Work experience placement

    ECS Federal

    Falls Church, VA
    2 days ago
  • $104k - $166k

     ...hire an experienced Incident Response Analyst (ICS/OT/SCADA) for its' Federal Strategic...  ....In This Role, You Will: Respond to cybersecurity incidents across ICS, OT, and IT environments...  ...integrator and transformative enterprise IT provider, we deliver trusted, highly... 
    Contract work
    Currently hiring
    Shift work
    1 day per week

    Peraton Corporation

    Arlington, VA
    3 days ago
  • $82.6k - $162.8k

     ...re looking for an opportunity to work at the intersection of cybersecurity, data, and artificial intelligence, Deloitte’s Cyber Defense...  ...strengthen cyber defense while enabling innovation across the enterprise.Recruiting for this role ends on 12/31/2026.Work you'll doAs... 
    Local area
    Visa sponsorship

    Deloitte

    McLean, VA
    5 days ago
  • $105.4k - $207.8k

     ...response (SOAR) deployments aligned with enterprise security policies and regulatory...  ...with security operations center analysts and threat detection engineers to prioritize...  ...members, and staying current on cybersecurity threats, vulnerabilities, and compliance trendsA successful... 
    Local area
    Visa sponsorship

    Deloitte

    McLean, VA
    5 days ago
  • $82.6k - $162.8k

     ...into scalable engineering outcomes across enterprise and cloud environments. Recruiting for...  ...and workflow enhancements that improve analyst efficiency and response...  ...Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a... 
    Local area
    Visa sponsorship

    Deloitte

    McLean, VA
    5 days ago
  • $104k - $166k

    ResponsibilitiesPeraton is Cyber Threat Analyst - Global Threat Analysis (GTA) for its'...  ...) to assess emerging threats.Provide cybersecurity briefings and consultations to diverse...  ...capability integrator and transformative enterprise IT provider, we deliver trusted, highly... 
    Full time
    Contract work
    Overseas
    Shift work

    Peraton Corporation

    Arlington, VA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Enterprise Cybersecurity Vulnerability Risk Analyst. Be the first to apply!