Senior Cybersecurity Risk Analyst
Our client is a global engineering, construction, and professional services company providing solutions in defense, energy, environmental management, and infrastructure. They offer services including maintenance, logistics, sustainability, and project management to government and commercial clients.
About the role
The Senior Cybersecurity Risk Analyst is a remote, senior individual contributor position within the Cybersecurity Governance, Risk, and Compliance (GR&C) team. This role owns the enterprise's cyber risk assessment work: evaluating activities and operational decisions across the enterprise and articulating the resulting cyber risk to business leadership against the enterprise's risk appetite. The work is assessment-heavy and focuses on identifying cyber risk that compliance-driven review alone does not surface, framing that risk in business terms to support informed risk management decisions.
The role acts as a twin to the Compliance function, ensuring cohesive cyber risk management across the enterprise regardless of framework requirements. The position requires technical expertise to recognize risk in networking, cloud, endpoint, and identity decisions, and the ability to communicate risk effectively to both technical teams and leadership.
This is a contract role based in McLean, VA (remote), with a duration of 2 months, open to extensions and potential temp-to-hire. Only U.S. Citizens are eligible.
Responsibilities
- Conduct cyber risk assessments of activities and operational decisions across the enterprise, identifying risk to the confidentiality, integrity, and availability of enterprise systems and data.
- Articulate cyber risk to business and technical leadership in clear, decision-ready terms, framed against the enterprise's risk appetite.
- Lead cyber risk reviews across various assessment types, including third-party cyber risk assessment, temporary risk acceptance review, and software risk review, while tracking enterprise artificial intelligence development as it relates to cyber risk.
- Work with the Compliance function to ensure mandatory control interpretations do not leave other cyber risk unaddressed and that risk treatment is coherent across frameworks.
- Evaluate the cyber risk implications of technology decisions, recognizing risk in networking, cloud, endpoint, and identity and access architectures that compliance-only review would not surface.
- Articulate when residual cyber risk exceeds the enterprise's appetite and specify the required risk reduction.
- Contribute a risk-posture perspective to enterprise scoping and architecture decisions, including the residual risk implications of carved-out certification environments and enclave boundaries.
- Improve the operational and procedural aspects of the Cyber GR&C function, including assessment methodology, intake, risk articulation standards, evidence handling, and consistency of risk judgments across the team.
- Maintain current knowledge of the cyber risk, threat, technology, and regulatory landscape, incorporating this into assessments and the team's collective capability.
- Travel up to 25 percent.
- Perform other position-related duties as assigned.
Requirements
- Must be a U.S. Citizen.
- U.S. Remote-Telework role; must reside within the United States to work remotely.
- Minimum of 8 years of hands-on cybersecurity experience, with demonstrated depth in evaluating real technology environments, not solely policy or audit administration.
- Demonstrated ability to recognize cyber risk in networking, cloud, and endpoint technologies, and in identity and access management, to assess the decisions of engineering and IT teams independently.
- Demonstrated experience in enterprise risk management and third-party or vendor cyber risk assessment.
- Ability to articulate cyber risk to business leadership in decision-ready terms.
- Current Security+ or an equivalent industry certification (certification establishes baseline; demonstrated hands-on capability is weighted more heavily).
- Working knowledge of NIST publications and their relevance to cyber risk and compliance.
- Strong written and verbal communication, including explaining technical risk to non-technical stakeholders.
- Self-starter able to operate autonomously on ambiguous problems with limited direction.
- Ability to travel up to 25 percent.
Preferred Qualifications
- Senior certifications such as CISSP or CySA+, and an identity and access credential such as Microsoft SC-300.
- Hands-on experience in a Microsoft Azure environment, including Microsoft 365; exposure to Azure Government (GCC High) is strongly preferred.
- Direct experience assessing identity and access architectures, including Entra ID, B2B and external identity, conditional access, and privileged access.
- Experience in U.S. Federal or Defense Industrial Base (DIB) environments, and familiarity with CMMC, NIST SP 800-171/172, DFARS, and international frameworks such as UK Cyber Essentials, Australian Essential Eight, UK GDPR, and EU NIS2.
- Familiarity with multi-framework risk management across standards such as ISO/IEC 27001 and crosswalk approaches for cohesive risk treatment.
- Experience improving GR&C operational processes, including assessment methodology, intake, and risk reporting.
- Bachelor's degree in a related field (not required; equivalent experience is fully acceptable).
Work Environment
Typical remote office environment with no unusual hazards. Occasional lifting up to 50 pounds, constant sitting while using a computer terminal, constant use of sight for reviewing documents, constant use of speech and hearing for communication, and constant mental alertness required. Ability to work under deadlines, plan, and organize effectively.
Pay
$70.00 - $76.92/hr. on W2.
Benefits
- Health Insurance: Medical, dental, and vision coverage.
- Retirement Plans: Participation in a company-sponsored retirement savings plan.
- Legal Service Plans: Access to attorneys for legal advice and representation.