Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Dunhill Professional Search

Cyber Risk Management Lead

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
97
out of 100
Average of individual scores

Were these scores useful?

Job Description

Job Requirements Ashburn, VA Public Trust Polygraph Unspecified Career Level not specified $170,000 - $189,500 Job Description Cyber Risk Management Lead On site in Ashburn, VA - Monday through Friday, 8:30am to 5:00pm The Cyber Risk Management Lead leads the identification, communication and distribution of cybersecurity risks and actionable mitigations at both the tactical and strategic levels across a large federal IT environment. The Lead works closely with vulnerability assessment, security operations and cyber threat intelligence teams, Security Control Assessors, ISSMs, ISSOs and system owners to build a complete picture of cyber risk and to brief senior management on the organization's cyber risk posture.
Responsibilities:
Identify tactical risks by working with vulnerability assessment, security operations and cyber threat intelligence teams; review and recommend approval or denial of tactical change requests. Support prioritization of vulnerability remediation and identify common security-gap patterns using frameworks such as
MITRE ATT&CK.
Identify strategic risks by working with Security Control Assessors, ISSMs, ISSOs and system owners; support cyber acquisition risk management through templates and guidance tied to acquisition decision events. Develop and review Risk Assessment Reports (RARs) and Cyber Risk Recommendation Memos. Conduct risk assessments, gathering data on incidents, vulnerabilities, POA&Ms, Known Exploited Vulnerabilities, loss-magnitude metrics, threat actors and TTPs. Support development of an organizational risk tolerance level and information system risk profiles aligned to the NIST Cybersecurity Framework. Maintain a near-real-time risk management dashboard and cybersecurity risk register for senior management visibility. Brief senior management on cyber risk posture and support Cybersecurity Supply Chain Risk Management (C-SCRM) documentation.
Requirements:
Bachelor's degree in Information Assurance, Computer Science or a related field. At least 7 years of professional experience in information assurance, cybersecurity, risk management or compliance; or, with a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity or a related field, at least 5 years of such experience.
One of the following certifications:
CompTIA Security+, ISC2 CISSP, ISACA
CISM, ISACA CRISC, GIAC
GCED or CEH. Demonstrated experience with risk assessments, NIST
SP 800-37
RMF, the NIST Cybersecurity Framework and
NIST SP 800-53
security controls. Experience managing POA&Ms, reviewing vulnerability scan results, reviewing audit logs in an enterprise logging system, and reviewing OS, application and database security baseline configurations. Experience performing security impact analysis on change requests and writing security policy. Understanding of OMB M-22-09 and the Zero Trust Architecture pillars. US Citizenship (no dual citizenship) and the ability to pass a federal background investigation in order to be granted access to sensitive information.
Compensation:
$170,000 - $189,500 per year #cjpost group id: 10238000 Apply now