Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cybersecurity Risk Analyst image - Rise Careers
Job details

Cybersecurity Risk Analyst

Amentum seeks a Cybersecurity Risk Analyst.

Amentum is a global leader in advanced engineering and innovative technology solutions, trusted by the United States and its allies to address their most significant and complex challenges in science, security and sustainability. Headquartered in Virginia, we have more than 53,000 employees in approximately 80 countries across all 7 continents.

The Cybersecurity Risk Analyst role is a remote-telework position that supports our governance, risk, information assurance. and compliance (R&C) arm of the cybersecurity team.  This role supports Amentum’s data protection requirements through the assessment of controls and working with teams through the mitigation process. Qualified candidates will need a versatile skill set that emphasizes regulatory comprehension, technology, effective collaboration, critical thinking, analytical prowess, risk management, and strong communications skills. US Citizenship is required to apply. This is a remote-telework role.

Essential Responsibilities:

  • Develop Assessment and Authorization (A&A) packages for various systems.
  • Oversee cybersecurity change management and end user support for compliance and risk.
  • Craft, validate, and document necessary cybersecurity information such as System Security Plan (SSP), Privacy Impact Assessment (PIA), Configuration Management Plan (CMP), Plan of Action and Milestones (POA&M), and Standard Operating Procedures (SOP) as necessary.
  • Perform cyber assessments and audits as directed.
  • Lead discussions with various teams, both internal and external, around data compliance and risk efforts.
  • Provide expertise to system administrators, engineers, and Information System Security Manager (ISSM) to create or update system/site policies, procedures, and process guides.
  • Consult with and brief executive management on compliance and risk matters.
  • Create, maintain, and provide metrics and status reports to cybersecurity leadership.
  • Travel up to 25%.
  • Perform all other position related duties as assigned or requested.

Knowledge, Skills, and Abilities:

  • Demonstrated experience in technology assessments, handling multiple assignments and finding mutually acceptable solutions to security problems, preferably within the defense or government contracting industry
  • Demonstrated experience recommending and devising cybersecurity controls to mitigate risk
  • Demonstrated experience in policy research and applying it to developing policies and procedures related to cybersecurity technology
  • Knowledge of DFARS and NIST publications and their relevancy to compliance and risk.
  • Demonstrable strong written and verbal communications.

Minimum Qualifications:

  • Must be a U.S. Citizen
  • Bachelor’s degree in IT, Cybersecurity, or a related field. Two years in related field can be substituted for each year of the four years of college.
  • Minimum of five (5) years of experience in performing cybersecurity assessments to include three years of hands-on experience in IT risk management or three years of cybersecurity in Federal Government environments
  • Certification of one of the following:
  • CompTIA Network+, Security+ certified or equivalent
  • CISSP
  • Microsoft Azure Security Engineer Associate certified or equivalent
  • Experience with common cybersecurity tools and platforms such as Nessus, Microsoft GCCH / O365, Microsoft Azure Gov, Microsoft Defender, Fireeye products, email protection platforms, and Palo Alto products.
  • Ability to read, understand, and document network infrastructure in logical diagrams, data flow diagrams, security boundaries.

       

Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, religion, color, sex, gender, national origin, age, United States military veteran’s status, ancestry, sexual orientation, gender identity, marital status, family structure, medical condition including genetic characteristics or information, veteran status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal EEO laws and supplemental language at EEO including Disability/Protected Veterans and Labor Laws Posters.

Average salary estimate

$100000 / YEARLY (est.)
min
max
$80000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cybersecurity Risk Analyst, PAE

Amentum is excited to announce an opening for a Cybersecurity Risk Analyst! As a globally recognized leader in advanced engineering and innovative technology solutions, Amentum is dedicated to partnering with the United States and its allies to tackle pressing challenges in science, security, and sustainability. In this fascinating remote-telework position, you'll be a vital part of our cybersecurity team, specifically within the governance, risk, and compliance (R&C) sector. Your primary focus will be on ensuring our data protection parameters are met by assessing controls and collaborating with various teams throughout the mitigation process. We are looking for individuals who possess a versatile skill set, excelling in regulatory comprehension, effective collaboration, critical thinking, and risk management skills. In this role, you’ll take the reins on crafting key cybersecurity documents, lead cybersecurity assessments, and liaise with colleagues on compliance initiatives. Amentum values strong communicators who can articulate complex information clearly, so be prepared to consult with executive management on risk matters. The ideal candidate will have solid experience in cybersecurity assessments and regulations, particularly within the defense or government sectors. If you're a U.S. Citizen and have a passion for protecting critical information, then we’d love to hear from you and help advance your career at Amentum!

Frequently Asked Questions (FAQs) for Cybersecurity Risk Analyst Role at PAE
What are the key responsibilities of a Cybersecurity Risk Analyst at Amentum?

As a Cybersecurity Risk Analyst at Amentum, key responsibilities include developing Assessment and Authorization packages, overseeing cybersecurity change management, producing vital cybersecurity documentation like System Security Plans, conducting cyber assessments, and leading discussions around data compliance. You'll also assist system administrators and brief executive management on risk matters, ensuring that cybersecurity policies are well-crafted and in compliance with required regulations.

Join Rise to see the full answer
What qualifications do I need to apply for the Cybersecurity Risk Analyst position at Amentum?

To apply for the Cybersecurity Risk Analyst position at Amentum, you must be a U.S. Citizen with a Bachelor’s degree in IT, Cybersecurity, or a related field. You'll also need at least five years of experience in performing cybersecurity assessments, including three years in IT risk management. Additional certifications such as CompTIA Security+, CISSP, or equivalent are required, alongside familiarity with tools like Nessus and Microsoft Azure.

Join Rise to see the full answer
What skills are important for success as a Cybersecurity Risk Analyst at Amentum?

Success as a Cybersecurity Risk Analyst at Amentum hinges on several key skills, including regulatory comprehension, strong analytical and communication skills, and a solid understanding of risk management practices. Experience with cybersecurity assessments and the ability to translate technical details for broader audiences, including executive management, is crucial for this role.

Join Rise to see the full answer
Is remote work an option for the Cybersecurity Risk Analyst position at Amentum?

Yes! The Cybersecurity Risk Analyst role at Amentum is fully remote-telework, allowing you the flexibility to excel in your position from anywhere within the U.S. You'll be connected with teams and stakeholders through collaborative tools while enjoying the benefits of a remote workplace.

Join Rise to see the full answer
How can I advance my career as a Cybersecurity Risk Analyst at Amentum?

Advancing your career as a Cybersecurity Risk Analyst at Amentum can be achieved through continuous professional development, obtaining additional relevant certifications, and actively participating in cross-functional projects. Engaging with colleagues, expanding your skill set in emerging technologies, and showcasing your contributions to cybersecurity compliance and risk mitigation can help position you for future leadership opportunities.

Join Rise to see the full answer
Common Interview Questions for Cybersecurity Risk Analyst
Can you explain the process of developing an Assessment and Authorization package?

In developing an Assessment and Authorization package, it’s essential to understand the system's security requirements and operational environment. You'll begin by documenting the system’s architecture, identifying the security controls in place, and conducting a thorough assessment to ensure compliance with regulations. It's important to describe how controls mitigate risks and detail any remaining vulnerabilities. Presenting this information clearly will be crucial during the submission and review process.

Join Rise to see the full answer
How do you stay updated with changes in cybersecurity regulations?

Staying updated with cybersecurity regulations requires a proactive approach. I regularly follow industry news, join professional organizations, participate in webinars, and engage with cybersecurity forums. I also review newsletters from trusted sources such as NIST and DFARS. Continuous learning helps me ensure that my knowledge is current and that I can effectively advise on compliance matters.

Join Rise to see the full answer
What tools and platforms are you familiar with in cybersecurity?

I'm experienced with a range of cybersecurity tools including Nessus for vulnerability scanning, Microsoft Defender for endpoint security, and Palo Alto firewalls for network protection. Additionally, I have proficiency with Microsoft Azure services, which are critical for compliance and security assessments in cloud environments. Discussing specific use cases in past projects can demonstrate my hands-on experience with these platforms during the interview.

Join Rise to see the full answer
How do you approach risk management in cybersecurity?

My approach to risk management in cybersecurity involves a systematic assessment of potential vulnerabilities, evaluating the impact and likelihood of threats, and developing a prioritized action plan for mitigation. Collaboration with technical teams is crucial for implementing security controls effectively, and continuous monitoring of the system ensures that new threats are addressed promptly.

Join Rise to see the full answer
How do you document cybersecurity processes and procedures?

Documentation of cybersecurity processes and procedures involves creating clear, concise, and accessible materials that outline each step in detail. I typically start with a template for consistency, ensuring that I include objectives, the scope of the procedure, roles involved, and any references to compliance standards. Regular reviews and updates keep the documentation relevant and useful for training new team members.

Join Rise to see the full answer
Can you describe a situation where you led a cybersecurity assessment?

During a previous engagement, I led a comprehensive cybersecurity assessment of our network infrastructure. I gathered a cross-functional team to identify possible vulnerabilities, executed tests to assess compliance with our established baseline, and documented the findings in a detailed report. This experience honed my skills in stakeholder engagement and cemented a culture of collaboration in addressing cybersecurity challenges.

Join Rise to see the full answer
How do you ensure effective communication of complex security matters to non-technical stakeholders?

I tailor my communication style when discussing complex security matters with non-technical stakeholders by avoiding jargon and focusing on the implications and benefits of cybersecurity initiatives. By using analogies and real-world examples, I can explain technical concepts clearly, ensuring that everyone understands the importance and necessity of our cybersecurity measures.

Join Rise to see the full answer
What is your experience with leading discussions on compliance and risk efforts?

I've had significant experience leading discussions concerning compliance and risk management. I facilitate meetings with both technical teams and executive stakeholders to present the current risk landscape, discuss mitigation strategies, and answer any questions. My goal is to create a shared understanding so that we can collectively address compliance requirements and enhance our cybersecurity posture.

Join Rise to see the full answer
How do you prioritize your tasks when managing multiple cybersecurity projects?

When managing multiple cybersecurity projects, I prioritize tasks based on their urgency and impact on our overall security objectives. I utilize project management tools to track deadlines, milestones, and resources. Regular check-ins with team members ensure alignment on priorities, allowing us to adapt as necessary while maintaining focus on high-impact tasks.

Join Rise to see the full answer
What experience do you have in consulting with executive management on compliance issues?

I have a solid background in consulting with executive management regarding compliance issues. I believe it’s crucial to present data-driven insights and recommendations clearly and succinctly. In my previous role, I prepared executive briefs on compliance risks and mitigation strategies, which played a pivotal role in securing approval for new cybersecurity initiatives.

Join Rise to see the full answer
Similar Jobs
Posted 7 days ago
Photo of the Rise User
Aculocity, LLC Remote No location specified
Posted 12 days ago
Posted 16 hours ago
Photo of the Rise User
Posted 15 hours ago
Photo of the Rise User
Spaulding Ridge Hybrid Chicago, Denver, Houston
Posted 9 days ago
Photo of the Rise User
Posted 6 days ago
Altalink Remote No location specified
Posted 12 days ago
Photo of the Rise User
TEKsystems Hybrid Honolulu, Hawaii, United States
Posted 2 hours ago
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
March 31, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
C
Someone from OH, Warren just viewed Front End Developer (for AI Agent) at CyberCare
I
Someone from OH, Warren just viewed Senior Angular Lead at Integrators services a.s.
Photo of the Rise User
Someone from OH, Warren just viewed SSr. Front End Engineer (Angular.js) at NTD Software
Photo of the Rise User
Someone from OH, Warren just viewed Front-End Developer at Apex Logic
S
Someone from OH, Warren just viewed Angular Developer at Sparkland
Photo of the Rise User
64 people applied to Jr SOC Analyst at IBM
Photo of the Rise User
28 people applied to Security Analyst Jr at DEUNA
Photo of the Rise User
Someone from OH, New Albany just viewed Diversity, Equity & Inclusion Manager at Axios
Photo of the Rise User
Someone from OH, Cincinnati just viewed Customer Service Associate at 2K
Photo of the Rise User
Someone from OH, Marion just viewed Casting: '2' at Backstage
Photo of the Rise User
Someone from OH, Westerville just viewed Junior Videographer at HyperionDev
Photo of the Rise User
Someone from OH, Columbus just viewed Part-time driver | Columbus, OH at Uber
Photo of the Rise User
Someone from OH, Columbus just viewed Operations Manager, Overnight at hims & hers
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Court Security Officer, Juneau, AK at Walden Security
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Senior Director GMA Operations Excellence-Oncology at Johnson & Johnson
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Application Developer at Barbaricum
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Outside Sales Account Executive at Pursuit
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Analyst, Demand Planning at Petco
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Associate Director Statistical Programming at Sobi
Photo of the Rise User
Someone from OH, North Ridgeville just viewed PMG is hiring: SEM Lead in Dallas at PMG
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Enterprise Architect (Senior Level) at Platinum Technologies
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Portfolio Execution Lead at Cushman & Wakefield
M
Someone from OH, North Ridgeville just viewed Lead Success Specialist at Max Drive