×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity Risk Analyst

Job in Manassas, Prince William County, Virginia, 22110, USA
Listing for: ECLARO
Full Time position
Listed on 2026-07-06
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 92299 - 96432 USD Yearly USD 92299.00 96432.00 YEAR
Job Description & How to Apply Below

Overview

Job Number: 26-01087

ECLARO is looking for a Cybersecurity Risk Analyst for our client in Manassas, VA
. ECLARO’s client is a leading technology solutions provider, collaborating with customers to manage their needs and achieve success in their business goals.

Position Overview
  • Seeking a results-driven and analytically minded Cybersecurity Risk Analyst to serve a dual mission within the Cybersecurity team: owning Third-Party Risk Management (TPRM) operations and supporting the organization’s broader Cyber Governance & Risk.
  • The successful consultant will be the Subject Matter Expert (SME) for the TPRM program, currently administered through the SAFe platform, and will be equally responsible for insider threat monitoring, custom cybersecurity awareness training development, awareness metrics reporting, Disaster Recovery (DR) coordination, and executive-level risk reporting.
  • This role requires translating technical risk data into clear business intelligence, building Power BI dashboards and reports for leadership, and collaborating across IT, Operations, and Procurement.
  • The ideal consultant brings hands-on TPRM experience, strong data visualization skills, and a passion for building programs that protect members, infrastructure, and operational continuity.
Responsibilities
  • Other related duties may be assigned.
  • Third-Party Risk Management (TPRM) Operations
    • Evaluate new and prospective vendors through structured cybersecurity risk assessments to determine cyber clearance eligibility before contract execution or system access.
    • Serve as the primary SME and platform administrator for the TPRM solution (SAFe), maintaining data integrity, configuring risk workflows, and driving continuous platform optimization.
    • Maintain and update the enterprise vendor inventory, tracking risk tier classification, assessment status, contract dates, and lifecycle position for all third parties.
    • Execute structured vendor onboarding workflows, including security due diligence, contractual security requirements review, and formal risk acceptance documentation.
    • Monitor and triage automated vendor security alerts generated through SAFe; analyze alert severity and communicate actionable risk intelligence to stakeholders on time.
    • Manage vendor offboarding procedures, ensuring termination of data and system access, contractual closure, and record retention compliance.
    • Conduct periodic reassessments and ongoing monitoring of in-scope vendors according to risk tiering methodology and assessment calendar.
    • Develop and maintain Power BI dashboards and reports presenting vendor risk metrics, assessment completion rates, open risks, and trend analysis for leadership and risk committees.
  • Cyber Governance, Risk & Insider Threat
    • Support Insider Threat program by monitoring behavioral risk indicators, documenting escalation procedures, and maintaining governance records.
    • Assist in the preparation of cybersecurity governance artifacts, including risk registers, policy documents, control metrics, and compliance reports aligned to NIST CSF and applicable regulatory frameworks.
    • Generate periodic cyber risk reports for IT leadership, audit, and regulatory audiences, summarizing risk posture, open findings, control gaps, and remediation status.
    • Build and maintain Power BI dashboards to visualize governance and risk metrics, control effectiveness trends, and risk KPIs across the organization.
    • Participate in risk assessment activities and support internal control evaluations relevant to IT environments.
  • Cybersecurity Awareness Training & Metrics Reporting
    • Design and develop custom cybersecurity awareness training content tailored to the specific business operations and risk profiles of individual departments (e.g., Operations, Finance, Customer Engagement, Engineering).
    • Collaborate with department leads to schedule, deploy, and track training completion across the organization.
    • Administer phishing simulation campaigns; analyze results and produce actionable reports identifying at-risk user populations and trending behaviors.
    • Build and maintain Power BI dashboards tracking cybersecurity awareness KPIs, including training completion rates, phishing click-through rates, repeat offender trends, and department-level performance over time.
    • Prepare and present monthly and quarterly Cyber Awareness Reports for leadership, translating program metrics into clear risk narratives and recommended actions.
    • Stay current with evolving social engineering tactics and regulatory guidance to keep training content timely and impactful.
    • Evaluate training platform effectiveness and recommend enhancements.
  • Disaster Recovery (DR) Coordination & Reporting
    • Coordinate and facilitate Disaster Recovery testing exercises for core business applications in collaboration with IT Operations.
    • Develop DR test plans, scoping documents, timelines, and stakeholder communication plans.
    • Document test execution results, capture gaps or failures, and produce post-exercise reports for IT leadership and executives.
    • Track…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary