Senior Cybersecurity Risk Analyst

VARITEMcLean, VA
Remote

About The Position

VARITE is seeking a qualified Senior Cybersecurity Risk Analyst for a remote position. This role is a senior individual contributor within the Cybersecurity Governance, Risk, and Compliance (GR&C) team. The primary responsibility is to own the enterprise's cyber risk assessment work, evaluating activities and operational decisions to articulate resulting cyber risk to business leadership in relation to the enterprise's risk appetite. This role is assessment-heavy and focuses on examining technology and operational decisions for cyber risks that compliance-driven reviews might miss. The Senior Cybersecurity Risk Analyst frames these risks in business terms to enable informed decisions regarding risk acceptance, mitigation, or remediation. This role complements the Compliance function by ensuring cohesive cyber risk management across the enterprise, regardless of the framework imposing requirements. The role aims to protect against internal and external cyber threats and improve the enterprise security program based on industry best practices, regulations, policies, standards, and guidelines. The ideal candidate will be technical enough to identify risks in networking, cloud, endpoint, and identity decisions and credible enough to ensure their risk judgments are respected by engineering teams, IT, and leadership. The role represents the entire enterprise, not a single team, contract, or project, and aims to highlight risk without impeding business operations.

Requirements

  • Must be a U.S. Citizen.
  • U.S. Remote-Telework role; must reside within the United States to work remotely.
  • Minimum of 8 years of hands-on cybersecurity experience, with demonstrated depth in evaluating real technology environments, not solely policy or audit administration.
  • Demonstrated ability to recognize cyber risk in networking, cloud, and endpoint technologies, and in identity and access management, well enough to assess the decisions of engineering and IT teams independently.
  • Demonstrated experience in enterprise risk management and in third-party or vendor cyber risk assessment.
  • Ability to articulate cyber risk to business leadership in decision-ready terms.
  • Current Security+ or an equivalent industry certification.
  • Working knowledge of NIST publications and their relevance to cyber risk and compliance.
  • Strong written and verbal communication, including the ability to explain technical risk to non-technical stakeholders.
  • Self-starter able to operate autonomously on ambiguous problems with limited direction.
  • Ability to travel up to 25 percent.

Nice To Haves

  • Senior certifications such as CISSP or CySA+, and an identity and access credential such as Microsoft SC-300.
  • Hands-on experience in a Microsoft Azure environment, including Microsoft 365; exposure to Azure Government (GCC High) is strongly preferred.
  • Direct experience assessing identity and access architectures, including Entra ID, B2B and external identity, conditional access, and privileged access.
  • Experience in U.S. Federal or Defense Industrial Base (DIB) environments, and familiarity from a risk perspective with CMMC, NIST SP 800-171/172, and DFARS, and with international frameworks such as UK Cyber Essentials, Australian Essential Eight, UK GDPR, and EU NIS2.
  • Familiarity with multi-framework risk management across standards such as ISO/IEC 27001 and with crosswalk approaches that achieve cohesive risk treatment across frameworks.
  • Experience improving GR&C operational processes: assessment methodology, intake, and risk reporting.
  • Bachelor's degree in a related field. A degree is not required and does not substitute for demonstrated hands-on capability; equivalent experience is fully acceptable.

Responsibilities

  • Conduct cyber risk assessments of activities and operational decisions across the enterprise, identifying risk to the confidentiality, integrity, and availability of enterprise systems and data.
  • Articulate cyber risk to business and technical leadership in clear, decision-ready terms, framed against the enterprise's risk appetite.
  • Take lead on cyber risk reviews across a range of assessment types, such as third-party cyber risk assessment, temporary risk acceptance review, and software risk review, and track enterprise artificial intelligence development as it relates to cyber risk.
  • Work with the Compliance function to ensure that mandatory control interpretations do not leave other cyber risk unaddressed, and that risk treatment is coherent across frameworks.
  • Evaluate the cyber risk implications of technology decisions, recognizing risk in networking, cloud, endpoint, and identity and access architectures that compliance-only review would not surface.
  • Articulate when residual cyber risk exceeds the enterprise's appetite and specify the risk reduction required.
  • Contribute a risk-posture perspective to enterprise scoping and architecture decisions, including the residual risk implications of carved-out certification environments and enclave boundaries.
  • Improve the operational and procedural aspects of the Cyber GR&C function: assessment methodology, intake, risk articulation standards, evidence handling, and the consistency of risk judgments across the team.
  • Maintain current knowledge of the cyber risk, threat, technology, and regulatory landscape, and bring that currency into assessments and into the team's collective capability.
  • Travel up to 25 percent.
  • Perform other position-related duties as assigned.

Benefits

  • Health Insurance: Medical, dental, and vision coverage
  • Retirement Plans: Participation in a company-sponsored retirement savings plan.
  • Legal Service Plans: Offering access to attorneys for legal advice and representation.
  • Employee referral bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service