
Cyber Risk Management Analyst Jr
ASM Research, An Accenture Federal Services Company
Ashburn, VAJob$88–99K/yrSeen todaySeen in employer's feed today
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Ashburn, VA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
The Cyber Risk Management Analyst supports identification, communication, and distribution of cybersecurity risks and actionable mitigations at both tactical and strategic levels within the agency’s information technology environment.
Skills & qualifications
Skills
Qualifications
Full job description
The Cyber Risk Management Analyst will support identification, communication, and distribution of cybersecurity risks and actionable mitigations or remediations at the tactical and strategic levels within the agency's information technology environment.
-
Assist the Government in identifying tactical risks through working with the operational teams such as the VAT, SOC, CTI, along with other applicable teams and data to create a full picture of the tactical cyber risks.
-
Assist the Government in conducting reviews and recommendations for approvals of tactical level change requests.
-
Assist the Government with the prioritization of vulnerability remediation.
-
Support the identification of common gaps in the information system security using methods such as the MITRE ATT&CK framework to focus recommendations to Government regarding holistic funding in support of remediating security gaps for multiple systems.
-
Support the identification of strategic risks through working with the Security Control Assessors (SCAs), Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), system owners, and other applicable teams to gather data for the creation of a full picture of the strategic cyber risks.
-
Support the Risk Assessment (RA) Initiative by conducting Risk Assessments for agency systems by gathering data on security incidents, vulnerabilities, Plan of Actions & Milestones (POA&Ms), Known Exploited Vulnerabilities (KEVs), Loss Magnitude Metrics, Threat Actors, and TTPs.
-
Assist the Government in developing and maintaining a risk tolerance level through working with senior management to formally establish the level of acceptable risk.
-
Assist the Government in developing information system risk profiles in alignment with the NIST Cybersecurity Framework.
-
Assist the Government in conducting reviews and recommendations to aid the Government in approving risk acceptance memoranda, assist with the prioritization of POA&Ms, create risk profiles for all information systems, and identify common gaps in the information system compliance to focus holistic funding in support of remediating security findings for multiple systems.
-
Assist the Government in creating a holistic picture of the cyber risks and effectively communicate the risks to the applicable stakeholders and senior management.
-
Assist the Government in providing briefings for senior management on the cyber risk posture of the agency.
-
Assist the Government in historical tracking and reporting of current trends on cybersecurity events and incidents, including but not limited to phishing, malware, and scanning / probing activity to develop probabilities for future occurrences.
-
Assist with creating and reviewing documentation and processes concerning Cybersecurity Supply Chain Risk Management (C-SCRM).
Minimum Qualifications
-
Bachelor’s Degree in Computer Science or a related field or equivalent experience.
-
Minimum 3 years of information security experience, to include experience related to cyber security risk management.
-
Candidates must be US citizens (no dual citizens) with the ability to pass a federal background investigation in order to be granted access to sensitive information.
Other Job Specific Skills
-
Strong understanding of IT cyber security tools, hardware/software security implementation, and communication protocols.
-
Familiarity with MITRE ATT&CK framework.
-
Strong written and verbal communication skills.
Compensation Ranges
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
Disclaimer
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
$88,200 - $99k
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Cyber Threat Analyst (I&W) with Splunk and AnalystPeraton · Arlington, VA · $104–166K/yrPosted 1w agoPosted 1w ago
Cyber Operations SMEPeraton · McLean, VA · $176–282K/yrPosted 2w agoPosted 2w ago
Lead Management & Program AnalystCustoms and Border Protection · Ashburn, VA · $144–187K/yrPosted 4 days agoPosted 4 days ago
Management and Program AnalystFederal Aviation Administration · Tutuila Island, American Samoa · $91–118K/yrPosted 4 days agoPosted 4 days ago
Management & Program AnalystFederal Aviation Administration · Tutuila Island, American Samoa · $76–99K/yrPosted 4 days agoPosted 4 days ago
You've read the whole posting — now see how you match it.