> Markdown version of [/jobs/ext/2061076-cyber-security-risk-management-analyst](https://www.wearedevelopers.com/jobs/ext/2061076-cyber-security-risk-management-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security & Risk Management Analyst - **Company:** nTech Workforce - **Location:** Reston, VA, United States (Remote available) - **Experience:** Experienced - **Contract:** Temporary contract - **Skills:** Amazon Web Services, Microsoft Azure, Cyber Security, Information Systems, Information Leak Prevention, Intrusion Detection Systems, PCI Data Security Standards, Software Vulnerability Management, Data Processing, Cloud Platform System, Information Technology, Multiplatform, Servicenow, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 14, 2026 - **Apply:** https://www.dice.com/job-detail/334f5dde-e00d-4805-a6f5-71579f079ed8 ## About the Role * Candidate must reside in DMV area., * Bachelor s degree in Cybersecurity, Computer Science, Information Technology, or similar and 3+ years of experience in cybersecurity and risk management to include in the healthcare and/or health insurance industry. * Significant understanding of NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), and NIST 800-53. * Knowledgeable of Information Security Risk Management methodologies including FAIR quantitative model. * Knowledgeable of PCI DSS compliance. * Highly skilled performing risk assessments. * Experience using Governance, Risk, and Compliance (eGRC) tools. * Highly skilled in technical writing and documentation with proven ability to translate technical requirements to the business. * Excellent presentation and verbal communication skills. * Ability to understand, develop, and socialize security policies, standards, and procedures. * Ability to effectively lead/complete tasks with a minimal level of supervision. Preferred Skills & Experience * Possess CRISC, CISSP, or similar certification(s). * Experience using an eGRC tool such as Hyperproof, Archer, or ServiceNow. * Knowledgeable of SOC 2 and/or HITRUST compliance. * Proficiency with security controls for cloud environments (Azure and AWS) including FedRAMP requirements. * Familiarity with security tools such as wireless and network scanning applications, vulnerability assessment applications and concepts, IDS/IPS, Data Loss Prevention, and other appropriate security related tools and capabilities. * Experience working in a large, complex, multi-platform environment. * Familiarity with HIPAA Security Rule and compliance requirements. ## Description * Location: Remote (Reston, VA; regular remote flexibility with occasional monthly/quarterly on-site visits and mandatory on-site final interview), * Support the Cybersecurity Risk Management program providing support and guidance to a team of technically diverse cybersecurity specialists personnel while further supporting collaboration across the various risk related teams in the organization. * Support continuous monitoring efforts by partnering with TPRM, Procurement, Legal, and key business stakeholders. * Support the assessment of cybersecurity controls, identify gaps, assist in development of mitigation strategies, and manage them to closure. * Collaborate with internal and external teams to assess, monitor, and manage risks. * Work with business teams to conduct thorough assessments to identify potential risks to the organization. This includes evaluating their security practices, data handling procedures, and regulatory compliance (e.g., HIPAA, PCI, GDPR, etc.) * Represent Cybersecurity from a Risk Management perspective and execute security risk management leadership through the design and implementation of cybersecurity controls to maintain the confidentiality, integrity and availability of information systems and data. * Prepare detailed risk assessment reports, clearly articulating findings and recommendations and maintain a comprehensive repository of all risk assessments and associated documentation. * Conduct risk analyses to ensure consistency in the detailed risk assessment lifecycle inclusive of identification, socialization, mitigation, and closure. * Design, implement, and integrate security solutions to address enterprise risks and exposures. * Develop and maintain Information Security Risk Metrics supported by KPIs and KRIs to support the analytics team. * Test and report on new technologies to address security concerns and work closely with the vulnerability management team on the identified risks. * Support compliance/risk management efforts in support of NIST, FedRAMP, and HIPAA to include but not limited to: external assessment readiness/support, self-assessments, risk assessments, Plans-Of-Action-and-Milestone (POA&M) management, continuous monitoring. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [The Dark Corners of Kotlin Multiplatform](https://www.wearedevelopers.com/videos/100143-the-dark-corners-of-kotlin-multiplatform) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)