eTeam Inc. logo

Sr. Cybersecurity Risk Analyst

eTeam Inc.
  • Virginia, VA
  • $74.51–$76.92 Per Hour
  • Quick Apply
16 days ago
eTeam Inc.

Job Description

Job Title: Senior Cybersecurity Risk Analyst
Location: ClientLean, VA - Remote
Duration: 2 months
Shift: 8:00 AM 5:00 PM EST (Some flexibility)

Description:

  • Self-Starter
  • Strong written communication is critical
  • MS Office Proficiency Excel Reports, Charts, etc.
  • Service Now experience.
  • Government experience is a plus.
  • This opportunity is open to extensions and a possibility of temp-to-hire

Purpose and Scope

The Senior Cybersecurity Risk Analyst is a remote, senior individual contributor position within the Cybersecurity Governance, Risk, and Compliance (GR&C) team. This role owns the enterprise's cyber risk assessment work: evaluating activities and operational decisions across the enterprise and articulating the resulting cyber risk to business leadership against the enterprise's risk appetite.

The work is assessment heavy. The Senior Cybersecurity Risk Analyst examines technology and operational decisions for cyber risk that compliance-driven review alone does not surface, then frames that risk in business terms so GR&C and leaders can make informed accept, mitigate, or remediate decisions. The role is a twin to the Compliance function: where Compliance concentrates on the administrative work of demonstrating conformance to mandatory controls, this role works alongside it to drive cohesive cyber risk management across the enterprise regardless of which framework imposes a given requirement.

Consistent with the GR&C charter, the role helps protect Amentum against internal and external cyber threats and helps set, improve, and make recommendations on the enterprise security program based on industry best practices, regulations, policies, standards, and guidelines. GR&C surfaces and advises on risk so that business and operational owners can make informed decisions. This person must be technical enough to recognize risk in networking, cloud, endpoint, and identity decisions made by engineering and IT, and credible enough that their risk judgments carry weight with those teams and with leadership. The role acts on behalf of the entire enterprise rather than any single team, contract, or project, and brings attention to risk without hindering the business.

Essential Responsibilities

  1. Conduct cyber risk assessments of activities and operational decisions across the enterprise, identifying risk to the confidentiality, integrity, and availability of enterprise systems and data.
  2. Articulate cyber risk to business and technical leadership in clear, decision-ready terms, framed against the enterprise's risk appetite.
  3. Take lead on cyber risk reviews across a range of assessment types, such as third-party cyber risk assessment, temporary risk acceptance review, and software risk review, and track enterprise artificial intelligence development as it relates to cyber risk.
  4. Work with the Compliance function to ensure that mandatory control interpretations do not leave other cyber risk unaddressed, and that risk treatment is coherent across frameworks.
  5. Evaluate the cyber risk implications of technology decisions, recognizing risk in networking, cloud, endpoint, and identity and access architectures that compliance-only review would not surface.
  6. Articulate when residual cyber risk exceeds the enterprise's appetite and specify the risk reduction required.
  7. Contribute a risk-posture perspective to enterprise scoping and architecture decisions, including the residual risk implications of carved-out certification environments and enclave boundaries.
  8. Improve the operational and procedural aspects of the Cyber GR&C function: assessment methodology, intake, risk articulation standards, evidence handling, and the consistency of risk judgments across the team.
  9. Maintain current knowledge of the cyber risk, threat, technology, and regulatory landscape, and bring that currency into assessments and into the team's collective capability.
  10. Travel up to 25 percent. Perform other position-related duties as assigned.

Minimum Requirements

  • U.S. Remote-Telework role; must reside within the United States to work remotely.
  • Minimum of 8 years of hands-on cybersecurity experience, with demonstrated depth in evaluating real technology environments, not solely policy or audit administration.
  • Demonstrated ability to recognize cyber risk in networking, cloud, and endpoint technologies, and in identity and access management, well enough to assess the decisions of engineering and IT teams independently.
  • Demonstrated experience in enterprise risk management and in third-party or vendor cyber risk assessment.
  • Ability to articulate cyber risk to business leadership in decision-ready terms.
  • Current Security+ or an equivalent industry certification. (Certification establishes the baseline; demonstrated hands-on capability is weighted more heavily than credentials.)
  • Working knowledge of NIST publications and their relevance to cyber risk and compliance.
  • Strong written and verbal communication, including the ability to explain technical risk to non-technical stakeholders.
  • Self-starter able to operate autonomously on ambiguous problems with limited direction.
  • Ability to travel up to 25 percent.

Preferred and Differentiating Qualifications

The following raise the ceiling for this role. Hands-on depth in the areas below is valued above the number of certifications or degrees held.

  • Senior certifications such as CISSP or CySA+, and an identity and access credential such as Microsoft SC-300.
  • Hands-on experience in a Microsoft Azure environment, including Microsoft 365; exposure to Azure Government (GCC High) is strongly preferred.
  • Direct experience assessing identity and access architectures, including Entra ID, B2B and external identity, conditional access, and privileged access.
  • Experience in U.S. Federal or Defense Industrial Base (DIB) environments, and familiarity from a risk perspective with CMClient, NIST SP 800-171/172, and DFARS, and with international frameworks such as UK Cyber Essentials, Australian Essential Eight, UK GDPR, and EU NIS2.
  • Familiarity with multi-framework risk management across standards such as ISO/IEC 27001 and with crosswalk approaches that achieve cohesive risk treatment across frameworks.
  • Experience improving GR&C operational processes: assessment methodology, intake, and risk reporting.
  • Bachelor's degree in a related field. A degree is not required and does not substitute for demonstrated hands-on capability; equivalent experience is fully acceptable.

Numbers & Facts

LocationVirginia, VA
IndustryOther/Not Classified
Salary$74.51–$76.92 Per Hour
Company Size100 to 499 employees
Year Founded1998
Websitewww.eteaminc.com
Want to know if you’re a fit?
Upload your resume and let our AI show you.

Skills

  • Artificial Intelligence (AI)unmatched
  • Best Practicesunmatched
  • Business Operationsunmatched
  • Business-to-Business (B2B)unmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Computingunmatched
  • Code Reviewsunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Defense Federal Acquisition Regulations Supplement (DFARS)unmatched
  • Enterprise Architectureunmatched
  • Enterprise Protectionunmatched
  • GNU C Compilerunmatched
  • Governmentunmatched
  • ISO (International Organization for Standardization)unmatched
  • Identity Data Managementunmatched
  • Information Technology & Information Systemsunmatched
  • International Electro-Technical Commission (IEC)unmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Microsoft Access Databaseunmatched
  • Microsoft Excelunmatched
  • Microsoft Officeunmatched
  • Microsoft Product Familyunmatched
  • Microsoft Windows Azureunmatched
  • NIS (Network Information Service)unmatched
  • Operational Auditunmatched
  • Operational Improvementunmatched
  • Operations Processesunmatched
  • Policy Developmentunmatched
  • Presentation/Verbal Skillsunmatched
  • Procedure Developmentunmatched
  • Publicationsunmatched
  • Regulationsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Risk Management Framework (RMF)unmatched
  • Security Attacksunmatched
  • ServiceNowunmatched
  • Software Engineeringunmatched
  • Technical Leadershipunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Willing to Travelunmatched
  • Work From Homeunmatched
  • Writing Skillsunmatched

About Company

Looking for a great job? Join eTeam. We’re looking for talented staffing professionals to join our staff. We also provide contract assignments and full-time jobs at Fortune 2000 Companies. We’ve been named one of the best companies to work for by Staffing Industry Analysts and New Jersey Business.

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder