21 information security risk analyst jobs at 18 companies in Frederick, MD
1mo
Save
Mark Applied
Hide
1mo
Senior Information Security Risk Analyst
Washington, District of Columbia, United States
$103k-$191k/yrHybridFull Time
Warner Bros. DiscoveryNasdaq: WBD: Produces and distributes multimedia entertainment content and news worldwide.
3+ YOEBS/BA required, 3+ years information security experience with at least 1 year in third‑party risk management; knowledge of network, access control and encryption; strong communication and analytical skills.
Federal Reserve Board of Governors: The central bank of the United States.
6+ YOESenior information security analyst with 6+ years of experience, bachelor's degree or equivalent, strong risk management, governance, and compliance knowledge.
Virtru: Private data security platform providing encryption and access controls for enterprises and government agencies.
5+ YOE5+ years in information security/GRC or IT audit, deep knowledge of CMMC/NIST/FedRAMP/SOC2/PCI, cloud and GRC tool experience, strong communication and risk assessment skills.
SonyNYSE: SONY: Sells consumer electronics, video games, and entertainment media.
2+ YOERequires statistics and data analysis expertise, SQL and Python or R, data modeling, information security knowledge, and typically 2 years of relevant experience. Bachelor's degree preferred.
SQL, Python, R, Git, GitHub, GitLab, Microsoft Power BI, Tableau, Looker, Domo, CMDB, SIEM
Baltimore Orioles: Professional Major League Baseball team and entertainment organization.
2+ YOEBachelor’s in cybersecurity or IT; 2–5+ years in cybersecurity; strong analytical skills; knowledge of risk, resilience, and security tooling; on-site role.
A3 Technology, Inc.: Private professional-services contractor providing system engineering, IT, aviation, and financial-management support to federal agencies.
2+ YOEExperience in security analysis, risk assessment, or related analytical role; strong security principles, controls, and vulnerability management; ability to communicate findings clearly; strong written/verbal communication; ability to work independently and collaboratively.
Peraton: Provider of mission-critical national security technologies and services.
8+ YOE8+ years in security operations or vulnerability management; Bachelor in Cybersecurity/IT (or 4 years additional experience); hands-on vulnerability scanning, cloud compliance, ISVM, API scanning; Secret clearance and U.S. citizenship required.
Peraton: Provider of mission-critical national security technologies and services.
8+ YOEBachelor's in Cybersecurity/IT (or 4 years' extra experience), 8+ years in security operations/vulnerability management (reduced with advanced degrees), hands-on ISVM and API scanning experience, automation and compliance familiarity, U.S. citizenship.
SOSi: Provides technology and mission solutions for national security.
3+ YOE3–5 years security experience performing vulnerability assessments and scanning across OS, databases, web apps and cloud; troubleshooting scan tools; automation and ISVM experience; Bachelor's degree; Secret clearance eligible.
Information System Vulnerability Management (ISVM)
5+ YOERequires 5+ years of information security analysis experience or equivalent experience, training, military experience, or education. Expertise in cyber risk, threat intelligence, social engineering, and cross-functional security initiatives preferred.
Network Designs, Inc.: Service-disabled veteran-owned federal IT contractor designing network, cybersecurity, applications, and resilient technology solutions for government customers.
8+ YOEU.S. citizen with active TS clearance and ability to obtain SCI and pass CI polygraph; Bachelor's in CS/IT/business; 8+ years cybersecurity/risk/supply chain experience; Network+ and Security+ preferred.
Venture Global LNGNYSE: VG: Develops and operates liquefied natural gas export facilities.
10+ YOEBachelor's degree or equivalent experience; 10+ years in cybersecurity, information security engineering, or security architecture; cloud, multi-cloud, risk assessment, security frameworks, IAM, cryptography, and DevSecOps expertise.
Concurrent Technologies Corporation (CTC): An independent nonprofit applied scientific research and development organization delivering full-lifecycle solutions to government and private-sector clients.
10+ YOEBachelor's degree or equivalent experience, 10+ years of progressive cybersecurity experience, federal and intelligence community program experience, governance, policy, risk, compliance, cloud and on-premises expertise.
NIST Cybersecurity Framework (CSF), NIST Special Publications (800 Series), Risk Management Framework (RMF), FISMA, CNSS, Intelligence Community Directives (ICDs), Zero Trust Architecture
GDITNYSE: GD: Delivers IT and mission services to government agencies.
6+ YOEActive TS/SCI with polygraph, 6+ years related experience, DoD 8570 IAT Level II cert (e.g., Security+ CE, CND, SSCP, GSEC, GICSP, CySA+, CCNA Security), bachelor’s or equivalent, 3+ years IC RMF A&A, 1+ year Xacta experience, NIST 800-53 knowledge.
General Dynamics Information TechnologyNYSE: GD: Provides mission-critical IT services to government and defense organizations.
6+ YOEActive TS/SCI with Polygraph, 6+ years related experience, 3+ years IC RMF A&A experience, bachelor’s in technical field or equivalent, DoD 8570 IAT Level II cert (e.g., Security+ CE) and 1+ year Xacta experience.
MaximusNYSE: MMS: Government services and health administration partner for public programs.
7+ YOERequires active Secret clearance, US citizenship, 7+ years in cybersecurity, and 4+ years managing POA&Ms, federal security frameworks, vulnerability and risk management. Daily onsite work and 24x7x365 on-call availability required.
NIST 800-53, Risk Management Framework (RMF), Federal Information Security Modernization Act (FISMA), antivirus software, vulnerability scanners, access control, endpoint protection, Public Key Infrastructure (PKI), Security Information and Event Management (SIEM), Data Loss Prevention (DLP)
GovCIO: Provider of IT modernization and digital transformation services.
9+ YOEHigh School +9 years (or equivalent) experience. DoD 8570 IAT Level II (Security+ CE, CySA+, CCNA Security), active Secret clearance, application/cloud security and CI/CD vulnerability remediation experience, DISA STIGs and NIST RMF knowledge, and proficiency with enterprise risk tools.
Jira, Azure DevOps, Tenable Security Center, ServiceNow, Kubernetes, Docker, AWS, Azure, DISA STIGs, NIST Risk Management Framework (RMF), OWASP Top 10, CI/CD
The Swift Group: Invisible by Design. Impossible to Ignore.
2+ YOEPerform vulnerability assessments and security analysis of systems, networks, hardware and software; recommend mitigations. Requires OS/network knowledge, risk analysis skills, and active TS/SCI with Polygraph and U.S. citizenship.