Jobedly Post a Job

Cybersecurity and Risk Analyst

Gormat · Arlington, VA
Full-timeTechnologySenior$120,000–$135,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Cybersecurity Risk Analyst role

Cybersecurity Risk Analyst positions focus on delivering results in their domain. This page aggregates open Cybersecurity Risk Analyst roles and what employers typically expect.

**Clearance Requirement:** Active Secret or higher clearance required; must be eligible for a Top Secret clearance if requested **Background Investigation:** Must successfully complete a DEA background investigation Position Summary The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and Penetration Testing (VAPT) team, responsible for identifying, analyzing, and mitigating cybersecurity risks across enterprise systems, networks, and applications. This role focuses on evaluating vulnerabilities, integrating threat intelligence, and supporting compliance efforts to ensure confidentiality, integrity, and availability of organizational data and services. The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation activities in alignment with federal security frameworks such as NIST SP 800-53, FISMA, and ISO/IEC 27001. They provide actionable reporting to leadership, enabling risk-based decision-making, and collaborate with cross-functional teams to improve security posture, mitigate threats, and ensure adherence to federal directives and policies. The Cybersecurity and Risk Analyst defines system security requirements for IT systems and applications and conducts comprehensive risk assessments of management, operational, and technical security controls and control enhancements that are present or inherited by an IT system. The analyst determines the overall effectiveness of security controls based on criteria from applicable NIST frameworks (e.g., NIST SP 800-53) and relevant guidance such as NIST SP 800-30. This role supports the Risk Management Framework (RMF) Security Assessment and Authorization (SAA) process through validation of security configurations to ensure compliance with applicable cybersecurity policies, requirements, and directives. The analyst ensures compliance with Security Technical Implementation Guidance (STIG), security benchmarks, and organizational security requirements. The role utilizes automated and manual scanning tools and manual testing methodologies to identify system vulnerabilities, noncompliance, and mitigation strategies. Duties and Responsibilities ### Vulnerability Assessment & Risk Evaluation - Conduct vulnerability assessments across systems, applications, OT assets, and cloud environments using commercial and open-source tools. - Analyze, validate, and prioritize vulnerabilities based on severity, exploitability, and business impact. - Perform risk assessments on systems, applications, and ATO packages using frameworks such as NIST SP 800-30 and ISO 27005. - Maintain risk registers and communicate risk likelihood and impact to system owners and leadership. ### Threat Analysis & Simulation - Monitor and apply threat intelligence feeds to assess emerging threats and vulnerabilities. - Participate in red team operations, adversary emulation, and penetration testing exercises. - Correlate vulnerability threat data (e.g., CVEs, MITRE ATT&CK) to determine real-world exploitability. - Provide analysis of zero-day vulnerabilities, advanced attack techniques, and potential organizational impacts. ### Policy, Compliance & Governance Support - Ensure vulnerability management practices align with NIST SP 800-53, NIST SP 800-115, CIS Controls, and ISO 27001. - Support internal and external audits by mapping findings to compliance frameworks (FISMA, HIPAA, PCI-DSS). - Contribute to incident response readiness, business continuity, and disaster recovery planning. - Review and provide input on system change requests, patching compliance, and binding operational directives. ### Reporting & Documentation - Prepare detailed technical reports and executive summaries highlighting risks, vulnerabilities, and mitigations. - Document risk mitigation strategies, vulnerability management processes, and audit support artifacts. - Provide risk-related training and awareness to stakeholders, communicating technical risk in business terms. ### Coll…

Salary estimate

$120,000 – $135,000/yr
Provided by the employer.

Skills for this role

LeadershipSecurityPenetration Testing

Resume tips for Cybersecurity Risk Analyst applicants

Interview preparation

Prepare concrete STAR-format stories that show Cybersecurity Risk Analyst outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Cybersecurity Risk Analyst problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Gormat

Gormat is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles