ASM Research, An Accenture Federal Services Company logo

Cyber Risk Management Lead

ASM Research, An Accenture Federal Services Company

Ashburn, VAJob$170–190K/yrSeen todaySeen in employer's feed today

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$170–190K/yr
Location
Ashburn, VA
Work Authorization
US work authorization required

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

CompTIA Security+ISC2 CISSPISACA CISMISACA CRISCGIAC GCEDCompTIA CEHBachelor's degree

Job overview

Leads the identification, communication, and distribution of cybersecurity risks and actionable mitigations across the Agency IT environment, reviewing change requests, prioritizing vulnerability remediation, and developing risk assessment reports and recommendations in alignment with NIST and MITRE ATT&CK frameworks.

Skills & qualifications

RequiredNice to have

Skills

MITRE ATT&CKRisk AssessmentsNIST SP 800-37 RMFNIST Cybersecurity FrameworkNIST SP 800-53 Security ControlsManaging POA&MsVulnerability Scan ReviewEnterprise Logging System Audit ReviewOS/Application/Database Security Baseline ReviewSecurity Impact AnalysisSecurity Policy WritingZero Trust Architecture Understanding

Qualifications

Bachelor’s Degree in Information Assurance or Related FieldCompTIA Security+ISC2 CISSPISACA CISMISACA CRISCGIAC GCEDCompTIA CEHUS Citizenship Required7+ Years Professional Experience

Full job description

Leads the identification, communication, and distribution of cybersecurity risks and actionable mitigations/remediations at the tactical and strategic levels across the Agency IT environment, working closely with the VAT, SOC, CTI, SCAs, ISSMs, ISSOs, and system owners.

  • reviews change requests, prioritizes vulnerability remediation, and identifies common security-gap patterns using frameworks such as MITRE ATT&CK.

  • develops Risk Assessment Reports (RARs) and Cyber Risk Recommendation Memos (CRRMs) and supports Component Cyber Acquisition Risk Management (C-CARM) through the Acquisition Lifecycle Framework.

  • Identify tactical risks by working with operational teams (VAT, SOC, CTI) to build a full picture of tactical cyber risk; review and recommend approval/denial of tactical change requests.

  • Support prioritization of vulnerability remediation and identification of common security-gap patterns using frameworks such as MITRE ATT&CK.

  • Identify strategic risks by working with SCAs, ISSMs, ISSOs, and system owners; support Component Cyber Acquisition Risk Management (C-CARM) through templates/guidance tied to Acquisition Decision Events.

  • Develop and review Risk Assessment Reports (RARs) and Cyber Risk Recommendation Memos (CRRMs).

  • Conduct Risk Assessments gathering data on incidents, vulnerabilities, POA&Ms, KEVs, loss-magnitude metrics, threat actors, and TTPs.

  • Support development of an organizational risk tolerance level and information system risk profiles aligned to the NIST Cybersecurity Framework.

  • Maintain a near-real-time holistic risk management dashboard and CSD risk register for senior management visibility.

  • Provide briefings to senior management on the Agency's cyber risk posture; support Cybersecurity Supply Chain Risk Management (C-SCRM) documentation.

Minimum Qualifications

  • Bachelor’s Degree in Information Assurance, Computer Science, or related field.

  • Minimum 7 years of professional experience in information assurance, cybersecurity, risk management, or compliance; or, with a bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, 5 years of such experience

  • One of the following: CompTIA Security+; ISC2 CISSP; ISACA CISM; ISACA CRISC; GIAC GCED; CompTIA CEH

  • Candidates must be US citizens (no dual citizens) with the ability to pass a federal background investigation in order to gain access to sensitive information.

Other Job Specific Skills

  • Demonstrated knowledge/experience with: Risk Assessments; NIST SP 800-37 RMF; NIST Cybersecurity Framework; NIST SP 800-53 security controls; managing POA&Ms; reviewing vulnerability scan results; using the Enterprise Logging System for audit-log review; reviewing OS/application/database security baseline configuration; performing security impact analysis on change requests; writing security policy; and understanding of M-22-09 / Zero Trust Architecture pillars

Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.

Physical Requirements

The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

$170k - $189,500

EEO Requirements

It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.

All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.