Senior Cyber Risk Engineer | NIST CSF/RMF Lead

White Cap Supply Holdings, LLC.

United States

Hybrid

USD 110,000 - 170,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

White Cap Supply Holdings, LLC. is seeking a cybersecurity risk professional to implement and maintain risk frameworks (NIST CSF/RMF) and to assess security controls across the organization.

The role requires deep expertise in identifying gaps, leading risk mitigation, and communicating findings to senior IT leaders. Hybrid work arrangement and opportunities to influence security posture across critical infrastructure.

Qualifications

  • 5+ years of cybersecurity experience conducting risk assessments, identifying security gaps, and mitigation strategies.
  • Strong analytical and problem-solving skills, with the ability to communicate complex technical issues to senior IT leaders and non-technical stakeholders.
  • Experience with identity and access management (IAM), identity governance and administration (IGA), and Privileged Access Management (PAM).
  • Knowledge of access governance, least-privilege principles, privileged account lifecycle management, access reviews, RBAC, and security exception management.
  • Hands-on experience conducting information security assessments, SC1/SC2 control testing, remediation tracking.
  • In-depth knowledge of NIST CSF and RMF with ability to apply to organizational security practices.
  • Working knowledge of CIS Controls and CIS Benchmarks; experience documenting control gaps.
  • Experience administering risk and control self-assessments (RCSAs) and coordinating with risk/control owners.
  • Ability to collect, validate, reconcile, and analyze security data and develop key risk indicators.
  • Experience producing security dashboards and executive-level presentations for leadership reviews.
  • Certifications: CRISC, CGRC, CISSP or comparable.

Responsibilities

  • Conduct thorough and regular risk assessments to identify threats and vulnerabilities related to critical infrastructure.
  • Identify, track, and report on Cyber Key Risk Indicators.
  • Collaborate with cross-functional teams to integrate security measures into processes and systems.
  • Stay updated on emerging cyber threats and industry best practices; conduct threat intelligence monitoring.
  • Lead the implementation of comprehensive cyber risk management strategies and risk monitoring.
  • Perform annual assessments of operating system security baselines.

Skills

Cyber risk assessments
NIST CSF
RMF
Threat intelligence
Risk governance
IAM/IGA/PAM
Control testing
Executive communication
Security dashboards

Education

BS/BA in related field
MS/MA in related field

Job description

White Cap Supply Holdings, LLC. is seeking a cybersecurity risk professional to implement and maintain risk frameworks (NIST CSF/RMF) and to assess security controls across the organization.

The role requires deep expertise in identifying gaps, leading risk mitigation, and communicating findings to senior IT leaders. Hybrid work arrangement and opportunities to influence security posture across critical infrastructure.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Risk Engineer — NIST CSF/RMF
Senior Cyber Risk Engineer — NIST CSF/RMF

White Cap Supply Holdings, LLC. • Northern (KY)

Hybrid
USD 90,000 - 130,000
Senior Cyber Risk Management Engineer
Senior Cyber Risk Management Engineer

White Cap Supply Holdings, LLC. • Northern (KY)

Hybrid
USD 90,000 - 130,000
Senior Cyber Risk Management Engineer
Senior Cyber Risk Management Engineer

White Cap Supply Holdings, LLC. • United States

On-site
USD 110,000 - 170,000
RMF Cybersecurity Engineer | Risk & Authorization (Remote)
RMF Cybersecurity Engineer | Risk & Authorization (Remote)

Dark Wolf Solutions, LLC • Herndon (VA)

On-site
USD 120,000 - 150,000
Cybersecurity Integration Lead — RMF & NIST Expert
Cybersecurity Integration Lead — RMF & NIST Expert

LMI • Washington

Hybrid
USD 125,000 - 190,000
Travel 25-50%
TS/SCI clearance required
US citizenship required
Senior Cybersecurity Engineer — RMF, NIST & Cloud Security
Senior Cybersecurity Engineer — RMF, NIST & Cloud Security

9th Way Insignia • Northern (KY)

Hybrid
USD 98,000 - 125,000
Medical
Dental
Vision
+4
Cybersecurity Manager I: Lead Security Engineering & Risk
Cybersecurity Manager I: Lead Security Engineering & Risk

Sierra Nevada Corporation • Lone Tree (CO)

On-site
USD 125,000 - 172,000
Medical, dental, and vision plans
401(k) with 150% match up to 6%
3 weeks paid time off
Cyber Risk Analyst — NIST, SOC 2 & ISO Frameworks
Cyber Risk Analyst — NIST, SOC 2 & ISO Frameworks

SherlockTalent • Delray Beach (FL)

On-site
USD 60,000 - 100,000
Senior Federal Cybersecurity Controls SME (NIST RMF)
Senior Federal Cybersecurity Controls SME (NIST RMF)

Kaizen Lab Inc. • Charlotte (NC)

On-site
USD 120,000 - 180,000
Cybersecurity Risk & Compliance Manager (Hybrid/Remote)
Cybersecurity Risk & Compliance Manager (Hybrid/Remote)

Phase2 Technology • Middletown (RI)

Hybrid
USD 62,000 - 141,000