42 security risk analyst jobs at 33 companies in White Oak, MD
3w
Save
Mark Applied
Hide
3w
Physical Security & Risk Analyst
Mechanicsburg or Owings Mills
$105k-$125k/yrHybridFull Time
Gannett Fleming: Infrastructure engineering, design, and construction management firm.
10+ YOEBachelor's degree and 10+ years in physical security, infrastructure protection, risk assessment, resilience, emergency management, or related fields; strong analytical, communication, and project management skills required.
Microsoft Office, Microsoft Word, Microsoft Excel, Microsoft PowerPoint, Microsoft Outlook
Warner Bros. DiscoveryNASDAQ: WBD: Global media and entertainment creating iconic content.
3+ YOEBS/BA required, 3+ years information security experience with at least 1 year in third‑party risk management; knowledge of network, access control and encryption; strong communication and analytical skills.
D&G Support Services: Woman-owned federal contractor providing integrated logistics, supply-chain, data analytics, and program support to defense and homeland-security agencies.
5+ YOEBachelor's degree and 5–7 years in risk or intelligence analysis, national security, or a related field. Requires strong research, analytical, writing, communication, and collaboration skills.
Virtru: Private data security platform providing encryption and access controls for enterprises and government agencies.
5+ YOE5+ years in information security/GRC or IT audit, deep knowledge of CMMC/NIST/FedRAMP/SOC2/PCI, cloud and GRC tool experience, strong communication and risk assessment skills.
Sony Group CorporationTokyo Stock Exchange: 6758: Public Japanese entertainment-and-technology conglomerate serving consumers, creators, and businesses through games, music, pictures, electronics, and sensors.
2+ YOERequires statistics and data analysis expertise, SQL and Python or R, data modeling, information security knowledge, and typically 2 years of relevant experience. Bachelor's degree preferred.
SQL, Python, R, Git, GitHub, GitLab, Microsoft Power BI, Tableau, Looker, Domo, CMDB, SIEM
Board of Governors of the Federal Reserve System: U.S. government central banking agency that sets monetary policy, supervises financial institutions, and oversees Federal Reserve System.
6+ YOESenior information security analyst with 6+ years of experience, bachelor's degree or equivalent, strong risk management, governance, and compliance knowledge.
Baltimore Orioles: Privately owned Major League Baseball club based in Baltimore serving baseball fans.
2+ YOEBachelor’s in cybersecurity or IT; 2–5+ years in cybersecurity; strong analytical skills; knowledge of risk, resilience, and security tooling; on-site role.
A3 Technology, Inc.: Private professional-services contractor providing system engineering, IT, aviation, and financial-management support to federal agencies.
2+ YOEExperience in security analysis, risk assessment, or related analytical role; strong security principles, controls, and vulnerability management; ability to communicate findings clearly; strong written/verbal communication; ability to work independently and collaboratively.
El Segundo or Los Angeles or Washington or San Francisco or San Diego or Seattle or London
$120k-$150k/yrHybridFull Time
CHAOS Industries: Redefining modern defense with a multi-product portfolio.
5+ YOEBachelor's degree or equivalent experience, 5+ years of GRC or compliance experience, DoD or military experience, audit support, risk assessment, GRC tooling, and knowledge of major security frameworks.
AmazonNASDAQ: AMZN: Multinational technology focused on e-commerce and cloud computing.
4+ YOEBachelor's degree or equivalent and 4+ years in compliance, audit, risk, governance, or related work. Requires IT security, AWS or cloud computing, process documentation, and cross-functional coordination experience.
K2Share: A mission-driven organization providing cyber risk management, IT solutions, and workforce readiness education.
4+ YOEBachelor's degree or equivalent experience, 4+ years in cybersecurity, third-party/vendor risk, or compliance analysis, and experience producing security risk assessments and mitigation recommendations.
NIST SP 800-218, NIST AI Risk Management Framework and Playbook
Sancorp Consulting: Service-disabled veteran-owned federal contractor providing cybersecurity, intelligence, AI/ML, and professional services to government agencies.
5+ YOETS/SCI and U.S. citizenship required. Bachelor's in security-related discipline plus 5+ years (or 10 years experience). Experience in physical access control, credential/identity management, risk methodologies, security engineering, and government databases; intermediate Microsoft Office skills.
Microsoft Office, Microsoft Word, Microsoft Access, Microsoft Excel, Microsoft PowerPoint, DOD365, SharePoint, Adobe Acrobat, MPICAM, ISMS, Modified Infrastructure Survey Tool (MIST), Interagency Security Committee - Compliance System (ISC-CS), Homeland Security Information Network (HSIN)
Xcelerate Solutions: Private defense and national security contractor delivering federal clients enterprise vetting, aviation security, cybersecurity, and digital solutions.
3+ YOERequires 3+ years in industrial security risk identification, data systems, NISPOM, metrics, and analysis; experience with FSO duties, risk mitigation strategies, and security instruction.
Bank of AmericaNYSE: BAC: Global financial services and banking institution.
5+ YOE5+ years of cloud security experience with AWS, Azure, or Google Cloud; CI/CD experience with Jenkins or GitLab CI/CD; strong risk analysis and communication skills; bachelor's degree preferred.
AWS, Azure, Google Cloud, Infrastructure as Code (IaC), Policy as Code (PaC), Jenkins, GitLab CI/CD, GitHub Copilot, Claude Code, Java, Python
Bank of AmericaNYSE: BAC: Global financial services and banking institution.
5+ YOERequires 5+ years of cloud security experience, AWS/Azure/Google Cloud expertise, CI/CD experience with Jenkins or GitLab CI/CD, and strong risk analysis and communication skills. Bachelor's degree preferred.
AWS, Azure, Google Cloud, Infrastructure as Code (IaC), Policy as Code (PaC), Jenkins, GitLab CI/CD, GitHub Copilot, Claude Code, Java, Python, CI/CD
Peraton: Provider of mission-critical national security technologies and services.
8+ YOE8+ years in security operations or vulnerability management; Bachelor in Cybersecurity/IT (or 4 years additional experience); hands-on vulnerability scanning, cloud compliance, ISVM, API scanning; Secret clearance and U.S. citizenship required.
Peraton: Provider of mission-critical national security technologies and services.
8+ YOEBachelor's in Cybersecurity/IT (or 4 years' extra experience), 8+ years in security operations/vulnerability management (reduced with advanced degrees), hands-on ISVM and API scanning experience, automation and compliance familiarity, U.S. citizenship.
SOS International: Technology and services integrator for government and defense missions.
3+ YOE3–5 years security experience performing vulnerability assessments and scanning across OS, databases, web apps and cloud; troubleshooting scan tools; automation and ISVM experience; Bachelor's degree; Secret clearance eligible.
Information System Vulnerability Management (ISVM)
AI Security Governance and Risk Analyst - TS/SCI and Polygraph
Bethesda, Maryland, United States
$187k-$252k/yrOnsiteFull Time
General Dynamics Information TechnologyNew York Stock Exchange: GD: Provider of enterprise IT services and defense solutions.
7+ YOERequires TS/SCI with polygraph, U.S. citizenship, bachelor's degree in a related discipline, and 7+ years of experience. Desirable credentials include CISSP, CISM, GSLC, or AI governance certifications.
NIST SP 800-53, NIST AI RMF, Risk Management Framework, Zero Trust