Haystack
← Back to Jobs
Technology
DP

Cyber Risk Management Lead with Security Clearance

Dunhill Professional SearchAshburn, VA🇺🇸United StatesPosted Oct 2, 2026

Quick Overview

Salary
$170k - $189.5k/yr
Seniority
Mid Senior
Work mode
On Site
Location
Ashburn, VA, United States
Posted
Yesterday
Zero Trust

Job Description

Cyber Risk Management Lead On site in Ashburn, VA - Monday through Friday, 8:30am to 5:00pm The Cyber Risk Management Lead leads the identification, communication and distribution of cybersecurity risks and actionable mitigations at both the tactical and strategic levels across a large federal IT environment. The Lead works closely with vulnerability assessment, security operations and cyber threat intelligence teams, Security Control Assessors, ISSMs, ISSOs and system owners to build a complete picture of cyber risk and to brief senior management on the organization's cyber risk posture.

Responsibilities

  • Identify tactical risks by working with vulnerability assessment, security operations and cyber threat intelligence teams; review and recommend approval or denial of tactical change requests.
  • Support prioritization of vulnerability remediation and identify common security-gap patterns using frameworks such as MITRE ATT&CK.
  • Identify strategic risks by working with Security Control Assessors, ISSMs, ISSOs and system owners; support cyber acquisition risk management through templates and guidance tied to acquisition decision events.
  • Develop and review Risk Assessment Reports (RARs) and Cyber Risk Recommendation Memos.
  • Conduct risk assessments, gathering data on incidents, vulnerabilities, POA&Ms, Known Exploited Vulnerabilities, loss-magnitude metrics, threat actors and TTPs.
  • Support development of an organizational risk tolerance level and information system risk profiles aligned to the NIST Cybersecurity Framework.
  • Maintain a near-real-time risk management dashboard and cybersecurity risk register for senior management visibility.
  • Brief senior management on cyber risk posture and support Cybersecurity Supply Chain Risk Management (C-SCRM) documentation.

Requirements

  • Bachelor's degree in Information Assurance, Computer Science or a related field.
  • At least 7 years of professional experience in information assurance, cybersecurity, risk management or compliance; or, with a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity or a related field, at least 5 years of such experience.
  • One of the following certifications: CompTIA Security+, ISC2 CISSP, ISACA CISM, ISACA CRISC, GIAC GCED or CEH.
  • Demonstrated experience with risk assessments, NIST SP 800-37 RMF, the NIST Cybersecurity Framework and NIST SP 800-53 security controls.
  • Experience managing POA&Ms, reviewing vulnerability scan results, reviewing audit logs in an enterprise logging system, and reviewing OS, application and database security baseline configurations.
  • Experience performing security impact analysis on change requests and writing security policy.
  • Understanding of OMB M-22-09 and the Zero Trust Architecture pillars.
  • US Citizenship (no dual citizenship) and the ability to pass a federal background investigation in order to be granted access to sensitive information.

Compensation: $170,000 - $189,500 per year #cjpost

Similar jobs