Cybersecurity Compliance and Risk Manager

Booz Allen Hamilton

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Newport, RI
Salary
$61,900–$141,000 / yr
Posted
25 days ago
Freshness
Confirmed live yesterday
Closes
Nov 15, 2026

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $168k
This role $101k
$46k most similar roles pay here $214k

This role pays less than 97% of similar roles. Most pay $141,850–$195,075 — the shaded band above. At the midpoint, this role pays about $101k versus about $168k for comparable roles.

Based on 239 similar postings.

Employer

About Booz Allen Hamilton

Booz Allen Hamilton is a management and technology consulting firm that provides analytics, digital, engineering, and cybersecurity solutions primarily to U.S. government agencies and commercial clients. Industry: Management & Technology Consulting

Booz Allen Hamilton currently has 802 open roles on FindRole.

Listed pay typically runs $86,800–$198,000 across 783 roles with salary data.

Most-posted roles

View all roles at Booz Allen Hamilton

At a glance

TL;DR · Cybersecurity Compliance and Risk Manager

The Cybersecurity Compliance and Risk Manager is a hybrid technical and compliance-focused role responsible for designing, implementing, and managing procedures to ensure database, software, and system-level security across client infrastructures. You will lead RMF execution, including security control attribution, documentation, assessment, and authorization while implementing and validating NIST SP 800-53 controls. Daily responsibilities include performing vulnerability assessments, maintaining continuous monitoring for risk visibility, managing enterprise POA&Ms to remediate findings, and mentoring junior team members. The role requires proficiency with DoW tools such as ACAS, VRAM, and eMASS, alongside experience applying STIGs and SRGs across network environments. Candidates must possess a Secret clearance and relevant certifications like Security+, CISM, or CISSP. This position addresses the critical challenge of safeguarding enterprise systems against evolving threats within complex technical environments.

What you'll do

  • Lead RMF execution including security control attribution, documentation, assessment, and authorization.
  • Implement and validate NIST SP 800-53 security controls across enterprise systems.
  • Perform vulnerability assessments and risk analysis using tools like ACAS, VRAM, and eMASS.
  • Apply and verify DoW STIGs and SRGs across software, database, and network environments.
  • Manage enterprise POA&Ms to track and remediate identified security findings.
  • Maintain continuous monitoring activities for system compliance and risk visibility.
  • Develop mitigation strategies and communicate technical risks to clients and SMEs.
  • Provide guidance and mentorship to cybersecurity team members.

What we're looking for

  • 3+ years of experience with DoD or Navy cybersecurity and Risk Management Framework (RMF).
  • 3+ years of experience with cyber vulnerability assessment, remediation, and mitigation tools including ACAS, eMASS, and VRAM.
  • 1+ years of experience working with DoD STIGs and SRGs.
  • Experience implementing, documenting, assessing, and monitoring NIST SP 800-53 security controls.
  • Secret clearance required.
  • High school diploma or GED.
  • DoD 8140 Certification such as Security+ CE, CISM, CISSP, or SecurityX Certification.
  • Experience as an NQV, ISSE, or with Xacta, ESS, Altiris, and ServiceNow (preferred); Bachelor's or Master's degree in a technical field (preferred).

More like this

Similar roles

Cybersecurity Engineer and Risk Analyst

Booz Allen Hamilton

San Diego, CA 23 days ago $99,000$225,000
RMF ACAS STIG eMASS DevSecOps Vulnerability Assessment Network Security Linux Windows Virtualization Intrusion Prevention Systems Firewalls Big Data Analytics Cybersecurity Policy Systems Development Lifecycle
4+ yrs exp

Cybersecurity Engineer and Risk Analyst

Booz Allen Hamilton

San Diego, CA 50 days ago $69,300$158,000
RMF ACAS STIGing eMASS DevSecOps Network Security System Administration Windows Linux Firewalls Intrusion Prevention Systems Big Data Analytics Configuration Management Data Flow Diagrams Boundary Diagrams Systems Development Lifecycle
3+ yrs exp

Cybersecurity Engineer and Risk Analyst

Booz Allen Hamilton

San Diego, CA 23 days ago $69,300$158,000
RMF eMASS ACAS STIG Evaluate-STIG Network Security Big Data Analytics Windows Linux Firewalls Intrusion Prevention Systems Cybersecurity Policy Systems Development Lifecycle Information Technology
4+ yrs exp

Cybersecurity Manager

Abbott

Lake Forest, IL +2 11 days ago $113,300$226,700
NIST ISO 27001 SOC2 HITRUST FedRAMP CISM SOX GDPR FDA OWASP CVSS MITRE ATT&CK Risk Management Audit Data Governance AI Governance Cybersecurity Strategy
10+ yrs exp

Senior Cybersecurity Compliance Lead Consultant

Blue Cross Blue Shield Association (BCBSA)

Chicago, IL 14 days ago $157,600$228,550
FedRAMP NIST Cybersecurity Framework ISO 27001 AI Generative AI Cloud Security Risk Management Project Management Change Management HIPAA/HITECH EU DPD Continuous Monitoring Audit Readiness
10+ yrs exp

Cyber Compliance Oversight Manager

3M

Maplewood, MN +1 3 days ago $164,612$201,193
ISO 27001 NIST CSF SOX PCI CMMC TISAX SWIFT CISSP CISA CISM Cybersecurity Compliance Monitoring Control Assessment Audit Project Management SLAs KPIs
5+ yrs exp