Risk Manager
$155k - $165kCustomer Value Partners, Inc
Overview CVP is seeking an Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program. The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency's CIO and CISO in cybersecurity tasks such as information security policy development and implementation; security compliance monitoring; security audit management; risk assessment; system authorization; security reporting; and other information security-related tasks. Responsibilities
Salary Band: $155-165k (Depending on experience) This position is contingent upon program award. We are proactively recruiting qualified candidates in advance of contract award. About CVP CVP is an award-winning healthcare and next-gen technology and consulting services firm solving critical problems for healthcare, national security, and public sector clients. We help organizations achieve lasting transformation. CVP is an Equal Opportunity Employer dedicated to actively recruiting individuals and providing advancement opportunities based on merit and legitimate job qualifications. We ensure that all associates receive equal opportunities based on their personal qualifications and job requirements. CVP strictly prohibits any form of discrimination or harassment. At CVP, we cultivate a work environment that encourages fairness, teamwork, and respect among all associated. We are committed to maintaining a workplace where everyone can grow both personally and professionally.
- Identify, evaluate, and develop strategies for handling risks to reduce information security and privacy risk across the agency.
- Provide recommendations, guidance, planning, and implementation support for agency risk management activities and tools, and provide support as needed to enhance the agency's Information Security Program related to governance, optimizations, automation, and supporting tools.
- Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for Information Systems and Organizations and SP 800-39, Managing Information Security Risk (as revised).
- Conducting an enterprise risk assessment and developing an agency Information Security Risk Assessment Report that addresses all findings from the assessment
- Developing an agency Privacy and Security Roadmap that recommends privacy and information security capabilities based on risks identified in the agency's Information Security Risk Assessment Report
- Developing an agency Information Security Risk Management Plan that addresses how the agency will implement and perform risk management activities regarding risk tolerance, risk assessment, risk response, risk monitoring, and risk capabilities
- Providing risk management guidance to the agency offices for A&A activities as required, ensuring continuous risk monitoring of information security control implementation effectiveness and required information security compliance requirements
- Support the Information Security and Assurance Office (ISAO) in implementing and overseeing the organization's information security risk management and security assessment and authorization (A&A) activities.
- Advise the agency on how best to tailor the revised A&A process to handle non-traditional technologies including, but not limited to, cloud, mobile, and Internet of Things.
- Provide the agency recommendations on how it can continuously monitor and assess the security posture of agency information systems over time and alert agency decision makers when an information system presents an increased risk or eminent threat to agency data and/or operations.
- Develop guidance, templates, other tools, and advice to the program offices to support their risk management and ATO activities.
- Provide risk management and information security continuous monitoring program implementation recommendations to program offices
- Track and review Plans of Actions and Milestones (POA&Ms) agency-wide to identify areas of risk as a result of unimplemented POA&Ms, a buildup of risk-based decisions, or other cross-cutting issues observed as a result of its risk management support.
- Track the A&A status for all divisions and programs that have information systems to validate they meet the requirements to protect the agency's data and operations.
- Develop the required artifacts to complete security accreditation packages for OCIO information systems and perform any required assessments, as requested. The Contractor shall provide oversight and advisory support to agency program office personnel for completion of information system A&A packages, as requested.
- Follow NIST Federal Information Processing Standards (FIPS) and Special Publications (SPs) to include, but not limited to, FIPS 199 and 200, SP 800-39, SP 800-37, SP 800-137, SP 800-60, SP 800-53, SP 800-53A, SP 800-34, SP 800-30, and SP 800-18. The Contractor shall comply with all agency IT security and Privacy policies and standards including, and the agency Privacy Impact Assessment (PIA) requirements and associated templates.
- Minimum of six years' experience in cybersecurity. 10+ years' experience is preferred.
- Minimum of six years' experience leading and delivering in FISMA-based and FedRAMP Assessment and Authorization (A&A) programs for comparably sized federal agencies and programs. Seven plus years' experience is preferred.
- Shall have at least one of the following industry-recognized certifications:
- Certified Information System Security Professional (CISSP)
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- Familiarity with Information Technology Infrastructure Library (ITIL) Foundation Compliance (GRC) tool, continuous monitoring, and vulnerability management tools or services. Note: NIH currently uses CSAM.
- Demonstrated experience managing cybersecurity teams including personnel, workload, priorities, scheduling, and risks.
- Proven experience bringing innovative approaches to help reduce the FISMA workload and time to authorization/reauthorization through such methods as boundary consolidation, common control identification and re-use, automation, assessment readiness reviews, and digital transformation.
- PMP Certification
- CISSP Certification
- Experience with Security Assessment Tools (Tenable Nessus, DBProtect, Wireshark, WebInspect)
- NIH/HHS experience
- Rockville, MD (Hybrid)
Salary Band: $155-165k (Depending on experience) This position is contingent upon program award. We are proactively recruiting qualified candidates in advance of contract award. About CVP CVP is an award-winning healthcare and next-gen technology and consulting services firm solving critical problems for healthcare, national security, and public sector clients. We help organizations achieve lasting transformation. CVP is an Equal Opportunity Employer dedicated to actively recruiting individuals and providing advancement opportunities based on merit and legitimate job qualifications. We ensure that all associates receive equal opportunities based on their personal qualifications and job requirements. CVP strictly prohibits any form of discrimination or harassment. At CVP, we cultivate a work environment that encourages fairness, teamwork, and respect among all associated. We are committed to maintaining a workplace where everyone can grow both personally and professionally.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Risk Manager in Rockville, MD vacancy
$155k - $165k
...Cybersecurity Risk Manager CVP is seeking a Cybersecurity Risk Manager for a large government agency enterprise-level cybersecurity program. The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency's CIO and CISO in cybersecurity...SuggestedContract workFor contractorsWork at office$90k - $120k
As a Healthcare Financial/Actuarial Manager you will be a key member of the Financial Actuarial & Analytics (FAA) Community of Expertise. You will substantially contribute to a wide variety of complex analyses and projects involving the design, financing, and measurement...SuggestedTemporary workWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hours- ...financial/actuarial engagements for a portfolio of small clients or manages FAA resources on more complex clients and/or deliverables... ...retirement/employment concepts Guides teams on cost avoidance, risk and funding strategies and deliverables based on client need Provides...SuggestedFull timeTemporary workWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hours
$151.9k - $173.4k
...Risk Manager Capital One's Enterprise Risk Management (ERM) Team has responsibility for helping the overall organization identify, manage, and mitigate key risks that may keep the company from achieving its strategic objectives. The Corporate Policy Office (CPO) is...SuggestedFull timePart timeWork at officeLocal area- ...Enterprise Risk (Financial) Hybrid | Tysons, VA (4 Days In-Office Per Week) Cherry Bekaert Recruiting & Staffing is partnered... ...and critical infrastructure resilience on a search for a Program Manager - Enterprise Risk . This role supports a high-visibility...SuggestedWork at officeShift work
$90k - $120k
...Healthcare Financial/Actuarial Manager ~202605971 ~Potomac, Maryland, United States ~Arlington, Virginia, United States ~Cockeysville, Maryland, United States ~Glen Allen, Virginia, United States ~Full time View favourites Description As a Healthcare...Full timeTemporary workWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hours$153k - $229k
...agile environment? Do you have strong experience in operational risk and controls, model risk, and reporting, along with analytical and... ..., and customer-focused, apply for the Operational Risk Senior Manager to help lead SFA Risk Management.Our Impact:As part of Freddie Mac...Local area$177.7k - $202.8k
...Senior Risk Manager At Capital One, we dare to dream, disrupt, and deliver a better way. We bring ingenuity, simplicity, and humanity to an industry ripe for change. As a senior leader in Enterprise Risk Management (ERM), you will join a critical second-line-of-defense...Full timePart timeWork at officeLocal area- TPRM Risk Manager Capital One is seeking an experienced and self-motivated Manager to join our Third Party Risk Management team, within the second line of defence. The TPRM team is a dedicated group of professionals whose mission is to provide value-add, independent stewardship...
$151.9k - $173.4k
...Overview Vertical Risk Manager: Card Risk We enable our Card business to innovate and deliver exceptional products and services in a well-managed risk ecosystem while ensuring we keep our promises to customers. As a Vertical Risk Manager at Capital One you’ll...Full timePart timeLocal area$134.5k - $265.1k
Position Summary Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional...Local areaVisa sponsorship- ...Location: Falls Church, VA Employment Type: Full-Time, Permanent Job Overview: We are seeking a Risk and Governance Manager to oversee technology-related risk processes within Investments & Capital Markets. In this role, you will work closely...Permanent employmentFull time
$151.9k - $173.4k
...Risk Manager - Channels and Shared Services (Hybrid) As a Risk Manager in Capital One's Card Risk Team you will apply your risk management, project management and analytical skills to our highest profile risk initiatives. Risk Managers are at the front line of defense...Full timePart timeWork at officeLocal area$150k - $170k
...Investment Manager Salary Range $150,000.00 - $170,000.00 Salary The Investment Manager leads financial evaluation, structuring, and execution of renewable energy investments, including greenfield development, acquisitions, and partnership transactions. This role...Work at office$90k - $110k
...seeking a Senior Treasury Analyst based in North Bethesda, Maryland. This position is part of the team responsible for treasury management and accounts payable, and will primarily focus on supporting the Senior Manager with daily treasury and cash management functions...Temporary work$134.5k - $265.1k
Position Summary Cyber Security & Risk Strategy ManagerOur Deloitte Cyber team understands the unique challenges and opportunities... ...ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to...Local areaVisa sponsorship$110k
...has a small but mighty team and is adding this role to provide additional support to the treasury function. You’ll report to Senior Manager with strong leadership and development skills whose desire I to promote from within. Salary to $110K + up to $10% bonus and...Bank staff$100k - $140k
...Get a tailored resume highlighting what this role needs. Role summary The Portfolio Manager oversees job site operations, including client relations, planning, budgeting, and facility/equipment/employee management. This role ensures safe execution of preventative and corrective...Full timeTemporary work$151.9k - $173.4k
...Overview Risk Manager, Enterprise Payments Risk Management Do you want to be part of an organization that’s dedicated to helping Capital One identify, manage and effectively mitigate risk – for our customers, our communities and our associates? As part of Operational...Full timePart timeLocal area$180k - $270k
...purpose.Position Overview:Are you an analytical and forward-looking risk leader who wants to help strengthen the housing finance system?... ...for families and communities nationwide.The Portfolio Risk Management Director will lead a high-impact team responsible for...Local area- Capital One seeks a Senior Manager, GEA Risk Guide to lead independent risk analysis and governance across Global Enterprise Affairs. You will influence senior partners and implement risk management practices in a fast-paced environment. The ideal candidate has 5+ years...
- Capital One is seeking a Risk Manager for Payments Risk Integration, Strategy, and Modernization (PRISM). The role blends strategic oversight with hands-on innovation to modernize the payments risk landscape across ACH, Wires, Cards, and Real-Time Payments. The position...Work at office
$151.9k - $173.4k
...Overview Risk Manager - Payments Risk Integration, Strategy, and Modernization (PRISM) (Hybrid) The Enterprise Payments Risk Integration, Strategy, and Modernization team (PRISM) is seeking a dynamic Manager who will play a pivotal role in driving risk mitigation...Full timePart timeWork at officeLocal area3 days per week$153.48k - $230.22k
...adoption and scale, not just innovation - you'll have the platform (and sponsorship) to make it real. The Director, Data & AI Risk Management , leads and delivers enterprise risk management activities that help AstraZeneca identify, assess, govern, report, and reduce...Hourly payTemporary workWork at officeFlexible hours3 days per week- Capital One is seeking a Senior Risk Manager in McLean, VA to lead risk governance and advisory work across Global Enterprise Affairs. This role emphasizes independent analysis, stakeholder collaboration, and delivering innovative risk mitigation strategies. The ideal...
- Capital One is seeking a Business Manager for Risk Foundations (ERM) in McLean, VA. The role focuses on strategic leadership, analytics, and driving risk-informed decisions across enterprise risk management. You will collaborate with partners, develop business strategies...
- Capital One in McLean, VA seeks a Senior Risk Manager to lead risk initiatives in its Global Payment Network Risk Operations. You will apply project management, AML and sanctions knowledge, and strong collaboration with executives to design and implement innovative financial...
- Capital One is seeking a Business Manager for the International Risk Program in McLean, VA. This role combines strategic leadership with rigorous analytic risk management to oversee international activities, including non-US products, offshore partners, and regulatory...
$200.7k - $229.1k
...Overview Senior Manager, Risk Data Product Manager Product Management at Capital One is a booming, vibrant craft that requires reimagining the status quo, finding value creation opportunities, and driving innovative and sustainable customer experiences through technology...Full timePart timeLocal area$184k - $276k
...Overview:Freddie Mac is seeking a highly experienced Director, Title Risk Assessment and Automation Solutions to lead the development,... ...appropriate standards for clear and marketable title, risk management, consumer protection, and regulatory compliance.This role requires...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Risk Manager. Be the first to apply!


