Why This Role Stands Out
Elevate your career as a Cyber Risk Management Analyst with a competitive salary and the opportunity to make a significant impact on national security in a remote-friendly environment. If you have a strong background in cybersecurity risk assessments and possess excellent analytical and communication skills, you'll thrive in this role, contributing to critical decision-making and continuous skill development. Apply today to join a reputable company and advance your expertise in a dynamic field.
Quick Overview
Job Description
Cyber Risk Management Analyst Summary: The Cyber Risk Management Analyst Mid conducts cyber risk analyses and supports the identification, documentation, communication, and tracking of tactical and strategic cybersecurity risks across the CBP environment. The role integrates operational, compliance, vulnerability, threat, and system information into practical risk recommendations and decision-support products.
Location
- Primary duty location: Government site in the Washington, DC metropolitan area, primarily Ashburn, VA.
- Telework may be approved, but should not be the expectation.
- Travel to CBP locations may be required based on assigned work; role-specific travel expectations are identified below
- Relevant cybersecurity, information assurance, risk management, compliance, or information systems risk assessment experience
- Experience with cyber risk assessments, NIST RMF, NIST Cybersecurity Framework, NIST SP 800-53 controls, POA&Ms, vulnerability findings, and security impact analysis
- Knowledge of cyber risk communication, risk registers, risk profiles, risk acceptance, Zero Trust concepts, and security policy or procedure development
- Security+ required; CISSP, CISM, CRISC, GCED, CEH, or comparable certification preferred
- Strong analytical writing, briefing, and stakeholder coordination skills
- U.S. citizenship and ability to obtain and maintain the required CBP background investigation
- Gather and analyze security incidents, vulnerabilities, POA&Ms, known exploited vulnerabilities, threat actors, tactics, techniques, procedures, and other risk data
- Develop or update risk assessments, risk profiles, risk registers, Risk Assessment Reports, Cyber Risk Recommendation Memos, dashboards, reports, and briefings
- Evaluate proposed technical changes and provide cyber risk and security impact recommendations
- Support prioritization of vulnerability remediation, POA&Ms, risk responses, and common security gaps across systems
- Coordinate with vulnerability assessment, SOC, CTI, ISSO, ISSM, SCA, system owner, and other stakeholders to build tactical and strategic views of cyber risk
- Support cybersecurity supply chain risk management documentation, acquisition risk activities, SOPs, playbooks, metrics, and historical trend reporting
- Communicate actionable risk and mitigation recommendations to technical stakeholders and leadership
Similar jobs
- TE
Information Systems Security Manager (ISSM)
NewTekSynap
Fort Belvoir, Virginia🇺🇸$130k - $150k/yrHybrid2 hours agoData EntryTechnology - FO
Cyber Security Analyst
NewFedEx Office
Memphis, TN🇺🇸$7.1k/moHybrid17 hours agoExpressMFAMachine Learning+11Technology - FO
Sr Cyber Security Analyst
FedEx Office
Memphis, TN🇺🇸$9.2k - $16.6k/yrOn-site1 week agoSAFeDockerExpress+15Technology - RA
Senior Principal Software Security Engineer
NewRaytheon
Austin, TX🇺🇸$132.4k - $251.6k/yrHybrid17 hours agoScrumAgileC+++3Technology - RA
Embedded Security Software Engineer II (Onsite)
NewRaytheon
Miami, FL🇺🇸$68.9k - $131.1k/yrHybrid17 hours agoScrumAgileC+++3Technology - SE
Security Watch Center Analyst
NewSecuritas
Los Angeles, CA🇺🇸Hybrid2 days agoSchedulingAdministrative - SE
Global Security Operations Center Threat Monitoring Specialist
NewSecuritas
San Jose, CA🇺🇸Hybrid2 days agoMicrosoft OfficeTechnology - ST
Security Technician
Securitas Technology
West Palm Beach, FL🇺🇸On-site2 months agoMicrosoft OfficeAdministrative - ST
Security Technician
Securitas Technology
Orlando, FL🇺🇸On-site2 months agoMicrosoft OfficeAdministrative - AU
Security Solutions Engineer II
NewAllied Universal
Fort Myers, FL🇺🇸Hybrid17 hours agoLoad BalancingVMwareTechnology - SA
Information Systems Security Officer
NewSAIC
Chantilly, VA🇺🇸$120k - $160k/yrRemote17 hours agoSAFeAWSEncryption+3Technology - RA
Software Security Lead - Principal Software Engineer - S3E
NewRaytheon
Los Angeles, CA🇺🇸$107.5k - $204.5k/yrHybrid17 hours agoScrumAgileC+++3Technology