Cyber Risk Management Analyst
Merrifield, VA
Full Time Entry-level / Junior Clearance required USD 35K - 83K *
phia, LLC
At phia, trust us to solve the complex challenges of our connected world through top-tier cyber intelligence & threat hunting. Contact us.phia is seeking a proactive and experienced Cyber Risk Management Analyst with a passion for protecting large enterprises from cyber threats and a desire to advance their career in a dynamic and challenging environment. This is a remote position to be preformed from within the United States. U.S Citizenship and the ability to obtain a Public Trust are required.
What You'll Do
- Drive the design, development, implementation, and continuous improvement of third-party cyber risk management strategies and practices across public and private sectors.
- Implement and adapt industry-standard cybersecurity frameworks (e.g., ISO 27001, NIST CSF, NIST 800-53, NIST 800-171, CIS 18, Zero Trust Principles, FedRAMP).
- Conduct supply chain risk assessments using recognized audit reports (e.g., SOC 2 Type II) and questionnaire responses.
- Collaborate with cross-functional leadership and stakeholders, particularly in supply chain management, to communicate third-party risk management strategies, activities, and identified risks.
- Utilize third-party risk assessment platforms (e.g., Process Unity GRX) and risk management platforms (e.g., Diligent RSAM).
- Review and make recommendations for policy and process updates, insuring alignment with organizational risk requirements.
- Lead and mentor diverse teams with varying levels of subject matter expertise.
- Prioritize and manage multiple concurrent projects to ensure timely completion.
- Produce high-quality technical documentation and reports.
- Engage in continuous learning to expand personal knowledge and upskill team members.
Required: Education + Experience
- 3+ years of experience in the security aspects of multiple platforms, operating systems, software, communications, and network protocols.
- Familiarity with third-party risk assessment platforms (e.g., Process Unity GRX) and risk management platforms (e.g., Diligent RSAM).
- Familiarity with cyber risk assessment and management frameworks, methodologies, and reporting. (e.g., SOC 2 Type II) and questionnaire responses.
- Strong understanding and practical experience in adapting and implementing industry-standard cybersecurity frameworks and standards (e.g., ISO 27001, NIST CSF, NIST 800-53, NIST 800-171, CIS 18, Zero Trust Principles, FedRAMP).
- Excellent communication skills to effectively engage with cross-functional leadership and stakeholders, particularly in supply chain management regarding third-party risk management strategies and activities.
- Experience in managing and instructing diverse teams with varying levels of subject matter expertise.
- Strong organizational skills to manage competing priorities and ensure timely completion of projects.
- Technical Writing Skills: Proficient in producing high-quality technical documentation and reports.
Security Clearance
- U.S. Citizenship required
- Ability to obtain Public Trust (or higher) government clearance
Preferred
- Bachelor’s degree in Computer Science, Information Technology or Information Security or other relevant disciplines.
- Public and Private Sector Experience
- Familiarity with CyberGRX (now Process Unity GRX) and Diligent RSAM
- Proximity to customer locations in the DMV (DC, MD, or VA) Metro area or Raleigh/Durham, NC is ideal.
Preferred Certifications
- CRISC - Certified in Risk and Information Systems Control
- CISSP- Certified Information Systems Security Professional
- CCSK- Certificate of Cloud Security Knowledge or CCSP
- CISA-Certified Information Systems Auditor certifications
- CISM- Certified Information Security Manager
Who You Are A proactive problem solver that appreciates the challenges of working in a fast-paced, dynamic environment.Intellectually curious with a genuine desire to learn and advance your career.An effective communicator, both verbally and in writing.Customer service-oriented and mission-focused.Critical thinker with excellent problem-solving skills If your experience and qualifications aren’t a match for this position, you will remain in our database for consideration for future opportunities that may be a better fit.
Who We Arephia, LLC is a Northern Virginia-based, small business established in 2011 with a focus on Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyber Architecture & Capability Analysis, Cyber Policy & Strategy, and Information Assurance/Security. we proudly support various agencies and offices within the Department of Defense (DoD), Federal government, and private/commercial entities.phia values work-life balance and offers the following benefits to full-time employees: Comprehensive medical insurance to include dental and visionShort Term & Long-Term Disability 401k Retirement Savings Plan with Company MatchTuition and Professional Development Assistance Flex Spending Accounts (FSA)
phia does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity, or any other reason prohibited by law in the provision of employment opportunities and benefits.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: CCSK CCSP CISA CISM CISSP Clearance Cloud Computer Science CRISC DoD FedRAMP Incident response ISO 27001 NIST NIST 800-53 Risk assessment Risk management Security Clearance SOC SOC 2 Strategy Zero Trust
Perks/benefits: 401(k) matching Career development Health care Insurance
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.