Demo

Cybersecurity Risk Analyst

The George Washington University
Ashburn, VA Full Time
POSTED ON 12/12/2025 CLOSED ON 1/7/2026

What are the responsibilities and job description for the Cybersecurity Risk Analyst position at The George Washington University?

Posting Details

I. Job Overview

Job Description Summary:

George Washington University Information Technology ( GWIT ) is the chief provider of technology services and applications at The George Washington University (GW). GWIT partners with all key stakeholders across GW to equip students, faculty, and staff with the technology and tools necessary to achieve academic and research excellence. This position works within GWIT to assure the security and compliance of systems to assure their confidentiality, integrity, and availability while protecting regulated, non-regulated, and research data.

Education

This position works within GWIT Technology Cybersecurity Risk and Assurance team to develop and implement the GW IT risk management strategy to identify, reduce / remediate, or monitor risks through education, awareness, IT vendor and product risk assessments and risk remediation monitoring across on-premises, managed cloud, and SasS environments. The position works collaboratively with other risk analysts and security engineers to enhance threat and vulnerability management for operational, academic, and research systems and tools. The position will also support assurance and compliance efforts as they relate to regulated research data and other applicable regulations and university polices. The position ensures collaborative outcomes with university stakeholders, external vendors, and partners with internal and external stakeholders to improve processes, mitigate risks, and remediate vulnerabilities related to IT risk. This position directly contributes to the overall GW IT cybersecurity risk management program including:

  • Development and delivery of IT security awareness and skills programs to faculty, staff, and students
  • Collaboration with key institutional stakeholders to identify, manage and where appropriate accept / track IT risk
  • Developing and implementing policies, standards and procedures to ensure university- wide risk mitigation.
  • Performing third party, product, and service risk assessments coordinating information gathering and review, issue and risk identification, assessment outcome reporting, tracking risks and related remediation activities, generating and delivering reports for stakeholders
  • Supporting and coordinating with compliance focused units and programs.

Performs other related duties as assigned. The omission of specific duties does not preclude the supervisor from assigning duties that are logically related to the position.

Minimum Qualifications

Qualified candidates will hold a Bachelor’s degree in an appropriate area of specialization plus 2 years of relevant professional experience, or, a Master’s degree or higher in a relevant area of study. Degree must be conferred by the start date of the position. Degree requirements may be substituted with an equivalent combination of education, training and experience.

Preferred Qualifications

Additional Required Licenses/Certifications/Posting Specific Minimum Qualifications:

  • Working understanding and experience with information security risk management and controls, effective communication and well-developed organizational skills.
  • Demonstrated understanding of third-party IT security risk assessments, information security risk governance frameworks (i.e., NIST ) and recommended mitigation approaches.
  • Demonstrated knowledge about identifying information security risks and controls associated with IT operational processes, including user awareness and decision maker influence
  • Demonstrated ability to track, monitor, and report on IT risk and control issues
  • Ability to translate technical details and trends into management reports
  • Demonstrated knowledge and/or experience preferred in:
    • GRC tool application administration or a GRC tool user highly desired
    • Public, Private and On-premises Cloud security measures and assessments
    • Experience applying NIST CSF , NIST 800-53, NIST 800-171 controls, particularly in support of security standards and evaluation of vendor practices alignment with control frameworks
  • Strong verbal and written communications skills
  • Ability to work with and collaborate across teams
  • Intellectual agility and interpersonal flexibility
Relevant cybersecurity certifications desired in one or more of the following areas:

  • Third Party Cyber Risk Assessor ( TPCRA ) Certification
  • Certified Information Systems Security Professional ( CISSP )
  • Certified Information Systems Auditor ( CISA )
  • Certified Information Systems Manager ( CISM )
  • Certified in Risk and Information Systems Control ( CRISC )
  • CompTIA Advanced Security Practitioner ( CASP )

Hiring Range $62,486.82 - $96,666.64

GW Staff Approach to Pay

How is pay for new employees determined at GW?

Healthcare Benefits

GW offers a comprehensive benefit package that includes medical, dental, vision, life & disability insurance, time off & leave, retirement savings, tuition, well-being and various voluntary benefits. For program details and eligibility, please visit https://hr.gwu.edu/benefits-programs.

II. JOB DETAILS

Campus Location: Ashburn, Virginia

College/School/Department: GW IT

Family Information Technology

Sub-Family IT Risk and Compliance

Stream Individual Contributor

Level Level 2

Full-Time/Part-Time: Full-Time

Hours Per Week: 40

Work Schedule: Monday - Friday 9am-5pm

Will this job require the employee to work on site? Yes

Employee Onsite Status Hybrid

Telework: Yes

Required Background Check: Criminal History Screening, Education/Degree/Certifications Verification, Social Security Number Trace, and Sex Offender Registry Search

Special Instructions To Applicants

Employer will not sponsor for employment Visa status

Internal Applicants Only? No

Posting Number: S013954

Job Open Date: 12/12/2025

Job Close Date

If temporary, grant funded, Sponsored Project funded or limited term appointment, position funded until:

Background Screening Successful Completion of a Background Screening will be required as a condition of hire.

EEO Statement

The university is an Equal Employment Opportunity employer that does not unlawfully discriminate in any of its programs or activities on the basis of race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity or expression, or on any other basis prohibited by applicable law.

Salary : $62,487 - $96,667

Cybersecurity Risk Management Analyst
Evolver Federal -
Springfield, VA
Senior Cybersecurity Risk Management Analyst
Evolver Federal -
Springfield, VA
Senior Cybersecurity Risk Management Analyst
Evolver, LLC -
Springfield, VA

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cybersecurity Risk Analyst?

Sign up to receive alerts about other jobs on the Cybersecurity Risk Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$149,432 - $188,965
Income Estimation: 
$179,455 - $227,077
Income Estimation: 
$99,793 - $130,112
Income Estimation: 
$125,027 - $157,872
This job has expired.
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at The George Washington University

  • The George Washington University Washington, DC
  • Posting Details I. Job Overview Job Description Summary: The Division for Student Affairs cultivates an inclusive community that supports connection, growt... more
  • 5 Days Ago

  • The George Washington University Washington, DC
  • Posting Details I. Job Overview Job Description Summary: Human Resources Management and Development ( HRMD ) is made up of several departments that serve a... more
  • 6 Days Ago

  • The George Washington University Washington, DC
  • Posting Details I. Job Overview Job Description Summary: The George Washington University’s Division of University Advancement (UA) is seeking a strategic ... more
  • 6 Days Ago

  • The George Washington University Washington, DC
  • Posting Details I. Job Overview Job Description Summary: The Academic Commons is an academic success community within GW Libraries and Academic Innovation ... more
  • 6 Days Ago


Not the job you're looking for? Here are some other Cybersecurity Risk Analyst jobs in the Ashburn, VA area that may be a better fit.

  • Evolver, LLC Springfield, VA
  • Evolver Federal is seeking a Cybersecurity Risk Management Analyst to support its Federal client in Springfield, VA in managing all aspects of cybersecurit... more
  • 16 Days Ago

  • Software Productivity Strategists, Inc. Rockville, MD
  • The Cybersecurity Risk Analyst is responsible for supporting and advancing the organization’s Governance, Risk, and Compliance (GRC) functions. This role h... more
  • 25 Days Ago

AI Assistant is available now!

Feel free to start your new journey!