Quick Overview
Salary
$170k - $189.5k/yr
Seniority
Mid Senior
Work mode
On Site
Location
Ashburn, VA, United States
Posted
Yesterday
Zero Trust
Job Description
Cyber Risk Management Lead On site in Ashburn, VA - Monday through Friday, 8:30am to 5:00pm The Cyber Risk Management Lead leads the identification, communication and distribution of cybersecurity risks and actionable mitigations at both the tactical and strategic levels across a large federal IT environment. The Lead works closely with vulnerability assessment, security operations and cyber threat intelligence teams, Security Control Assessors, ISSMs, ISSOs and system owners to build a complete picture of cyber risk and to brief senior management on the organization's cyber risk posture.
Responsibilities
- Identify tactical risks by working with vulnerability assessment, security operations and cyber threat intelligence teams; review and recommend approval or denial of tactical change requests.
- Support prioritization of vulnerability remediation and identify common security-gap patterns using frameworks such as MITRE ATT&CK.
- Identify strategic risks by working with Security Control Assessors, ISSMs, ISSOs and system owners; support cyber acquisition risk management through templates and guidance tied to acquisition decision events.
- Develop and review Risk Assessment Reports (RARs) and Cyber Risk Recommendation Memos.
- Conduct risk assessments, gathering data on incidents, vulnerabilities, POA&Ms, Known Exploited Vulnerabilities, loss-magnitude metrics, threat actors and TTPs.
- Support development of an organizational risk tolerance level and information system risk profiles aligned to the NIST Cybersecurity Framework.
- Maintain a near-real-time risk management dashboard and cybersecurity risk register for senior management visibility.
- Brief senior management on cyber risk posture and support Cybersecurity Supply Chain Risk Management (C-SCRM) documentation.
Requirements
- Bachelor's degree in Information Assurance, Computer Science or a related field.
- At least 7 years of professional experience in information assurance, cybersecurity, risk management or compliance; or, with a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity or a related field, at least 5 years of such experience.
- One of the following certifications: CompTIA Security+, ISC2 CISSP, ISACA CISM, ISACA CRISC, GIAC GCED or CEH.
- Demonstrated experience with risk assessments, NIST SP 800-37 RMF, the NIST Cybersecurity Framework and NIST SP 800-53 security controls.
- Experience managing POA&Ms, reviewing vulnerability scan results, reviewing audit logs in an enterprise logging system, and reviewing OS, application and database security baseline configurations.
- Experience performing security impact analysis on change requests and writing security policy.
- Understanding of OMB M-22-09 and the Zero Trust Architecture pillars.
- US Citizenship (no dual citizenship) and the ability to pass a federal background investigation in order to be granted access to sensitive information.
Compensation: $170,000 - $189,500 per year #cjpost
Similar jobs
- MI
Senior Data Scientist - IntelliScript (Remote)
NewMilliman IntelliScript
Brookfield, WI🇺🇸$93.7k - $223.0k/yrRemote9 hours agoDockerSQLAWS+13Technology - SA
Operations Systems Engineer
SAIC
Chantilly, VA🇺🇸$160.0k - $200k/yrRemote3 days agoTechnology - BO
F-15 Mission Systems Integration Senior Manager with Security Clearance
NewBoeing
Berkeley, MO🇺🇸$170k - $230k/yrOn-site9 hours agoAgileTechnology - GG
Information Systems Security Officer (ISSO) II with Security Clearance
NewgTANGIBLE Corporation (gTC)
Suitland, MD🇺🇸HybridYesterdayTechnology - BO
Software Engineer - Developer (Experienced or Senior)
NewBoeing
Saint Louis, Missouri🇺🇸$126.7k - $171.3k/yrHybrid57 minutes agoMATLABAgileC+++2Technology - SA
Business Systems Analyst
NewSENKO Advanced Components
Hudson, Massachusetts🇺🇸Hybrid57 minutes agoFiberMicrosoft OfficeTechnology