Cybersecurity Risk Analyst

Kearney & CompanyAlexandria, VA
Hybrid

About The Position

Kearney & Company is seeking a skilled and vigilant Cybersecurity Risk Analyst to join our dynamic team. The Cybersecurity Risk Analyst is responsible for identifying, assessing, and monitoring risks across the organization. This role helps strengthen the company’s security posture by evaluating risk, identifying threats, analyzing vulnerabilities, supporting remediation efforts, and ensuring alignment with security standards, policies, and frameworks.

Requirements

  • Bachelor’s degree from an accredited university or equivalent professional experience from a relevant field.
  • Minimum 2.5 years experience in OSINT, cybersecurity, information security, risk management, auditing, or related fields.
  • Understanding of cyber threats, vulnerabilities, cloud security, identity and access management, OSINT, and security controls.
  • Familiarity with risk frameworks (e.g., NIST CSF, NIST 800‑53, ISO 27001, CIS).
  • Ability to interpret technical issues and translate them into business‑level risk impacts.
  • Excellent written and verbal communication skills.
  • Strong data visualization, analytical, and documentation skills.
  • Ability to obtain and maintain an U.S. security clearance (requires U.S. citizenship)

Nice To Haves

  • Cybersecurity or OSINT Certifications such as Security+, CySA+, CISA, GOSI, or C|OSINT

Responsibilities

  • Identify, assess, and document risks across systems, applications, vendors, and cloud environments.
  • Conduct risk assessments and security reviews, including threat analysis, vulnerability analysis, and control evaluations.
  • Monitor the evolving threat landscape and provide insights into emerging risks.
  • Collect, analyze, and operationalize Open-Source Intelligence (OSINT) to identify emerging threats, adversary activity, and external risk indicators.
  • Identify, assess, and investigate potential insider threat risks by analyzing user activity, behavioral indicators, and anomalous patterns across systems and data sources.
  • Collect, correlate, and document findings from logs, alerts, OSINT, and case files to support insider threat inquiries and escalation decisions.
  • Support the development and enhancement of risk governance processes, policies, and reporting.
  • Participate in incident response by evaluating risk impact and supporting post‑incident risk reduction activities.
  • Maintain risk registers and prepare reports and briefings for leadership, stakeholders, and governance committees.
  • Evaluate third‑party vendors for cybersecurity and data protection risks.
  • Assist in ensuring compliance with frameworks such as NIST, ISO 27001, CIS Controls, SOC 2, and internal security policies.
  • Contribute to security awareness efforts by communicating risk drivers, trends, and recommended best practices.
  • Monitor, organize, and ensure the integrity of digital case files within the case management platform.

Benefits

  • Medical, Dental, Vision, Life, AD&D, and Disability Insurance
  • 401(k) Retirement Plan and 529 Education Savings Plan
  • Flexible Spending & Health Savings Account
  • Accident, Critical Illness, Hospital Indemnity Insurances
  • Legal Insurance and Pet Insurance
  • Employee Assistance Program, fitness and wellness benefits, and other firm benefits.
  • Paid holidays, vacation, and sick time
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service