Cybersecurity Risk Management Analyst positions focus on delivering results in their domain. This page aggregates open Cybersecurity Risk Management Analyst roles and what employers typically expect.
Cybersecurity Risk Management Analyst The Cybersecurity Risk Management Analyst provides advanced Governance, Risk, and Compliance (GRC) support for federal information systems in accordance with the Federal Information Security Modernization Act (FISMA) and the NIST Risk Management Framework (RMF). This role is responsible for managing Assessment & Authorization (A&A) activities, supporting external service authorizations, conducting cybersecurity risk assessments, and maintaining continuous monitoring efforts to ensure compliance with federal cybersecurity requirements. The position requires strong analytical, documentation, and stakeholder engagement skills while working collaboratively with federal system owners, Information System Security Officers (ISSOs), Cloud Service Providers, and executive leadership to maintain secure and compliant federal systems. **Cybersecurity Risk Management Analyst** The Cybersecurity Risk Management Analyst provides advanced Governance, Risk, and Compliance (GRC) support for federal information systems in accordance with the Federal Information Security Modernization Act (FISMA) and the NIST Risk Management Framework (RMF). This role is responsible for managing Assessment & Authorization (A&A) activities, supporting external service authorizations, conducting cybersecurity risk assessments, and maintaining continuous monitoring efforts to ensure compliance with federal cybersecurity requirements. The position requires strong analytical, documentation, and stakeholder engagement skills while working collaboratively with federal system owners, Information System Security Officers (ISSOs), Cloud Service Providers, and executive leadership to maintain secure and compliant federal systems. **Compensation & Benefits** Estimated Starting Salary Range Cybersecurity Risk Management Analyst- $140,000 – $150,000 Pay commensurate with experience. Full-time benefits include Medical, Dental, Vision, 401(k), paid time off, and other company-sponsored benefits as provided. Benefits are subject to change with or without notice.Cybersecurity Risk Management Analyst **Assessment & Authorization (A&A)** - Manage the full lifecycle of Risk Management Framework (RMF) activities in accordance with NIST Special Publication 800-37. - Develop, review, and maintain security authorization documentation including: - System Security Plans (SSPs) - Security Assessment Plans (SAPs) - Security Assessment Reports (SARs) - Plans of Action and Milestones (POA&Ms) - Review and evaluate FedRAMP authorization packages and package updates supporting cloud service authorization decisions. - Monitor Authorization to Operate (ATO) packages within the FedRAMP Secure Repository. - Coordinate with system owners, ISSOs, Cloud Service Providers, and security stakeholders regarding system changes and authorization activities. - Validate implementation of NIST SP 800-53 Rev. 5 security controls, including inherited and agency-implemented controls. - Conduct cybersecurity risk assessments utilizing NIST SP 800-30 methodologies. - Provide risk analysis and recommendations to Authorizing Officials and senior leadership. - Support continuous monitoring by reviewing vulnerability scans, managing POA&Ms, and coordinating remediation activities. **Governance, Risk & Compliance (GRC)** - Peer review cybersecurity policies, standards, procedures, and implementation guidance. - Perform regulatory and policy analysis to ensure alignment with federal cybersecurity requirements. - Conduct compliance gap analyses and recommend remediation strategies. - Assist in developing security control overlays, baseline updates, and control tailoring guidance. - Provide cybersecurity governance subject matter expertise. - Support enterprise reporting, cybersecurity metrics, and compliance dashboards utilizing ServiceNow. **Compliance & Oversight Support** - Support FISMA reporting activities. - Prepare documentation for internal and external audits and oversight re…