We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results

Information Security Risk Assessor

DMI (Digital Management, Inc.)
tuition assistance, 401(k)
United States, Maryland, Rockville
Jul 10, 2025

Information Security Risk Assessor


Job ID
2025-28097

Category
Information Assurance


Location

US-MD-Rockville



About DMI

DMI is a leading provider of digital services and technology solutions, headquartered in Tysons Corner, VA. With a focus on end-to-end managed IT services, including managed mobility, cloud, cybersecurity, network operations, and application development, DMI supports public sector agencies and commercial enterprises around the globe. Recognized as a Top Workplace, DMI is committed to delivering secure, efcient, and cost-effective solutions that drive measurable results. Learn more at www.dminc.com



About the Opportunity

DMI, LLC is seeking an Information Security Risk Analyst to join us.

Duties and Responsibilities:

The Analyst will support our client's Governance, Risk, and Compliance (GRC) efforts by performing detailed risk evaluations and compliance assessments. The analyst will work primarily within the client's ServiceNow GRC platform to review IT security policy exception requests, assess vulnerabilities, and support broader risk governance activities. Responsibilities include, but are not limited to, the following:

Cross-Functional Risk Support Responsibilities

    Collaborate with internal departments including IT, legal, compliance, audit, and business operations to identify, assess, and manage cybersecurity risks across the organization.
  • Support vulnerability assessments by interpreting technical findings, validating remediation efforts, and ensuring alignment with policy.
  • Participate in internal control evaluations to assess effectiveness and identify potential gaps based on relevant frameworks such as NIST 800-53 and ISO 27001.
  • Assist with the design, documentation, and implementation of risk treatment plans, ensuring appropriate mitigation strategies are in place and tracked through resolution.
  • Contribute to audit preparation activities, respond to information requests, and support remediation of audit findings as needed.
  • Use ServiceNow GRC functionality to support workflow management, risk tracking, and reporting.
  • Recommend improvements to exception request workflows, dashboards, and system configurations where appropriate.

Policy Exception Review Process

  • Review and assess policy exception requests submitted via the client's ServiceNow GRC platform.
  • Confirm the completeness, consistency, and accuracy of the information provided in the exception request form.
  • Conduct detailed risk assessments for each exception request, identifying relevant threats, vulnerabilities, likelihood of exploitation, and potential impacts.
  • Analyze the effect of granting exceptions on system security, regulatory compliance, and business continuity.
  • Develop formal approval or denial recommendations based on the risk assessment and alignment with County policy and risk tolerance.
  • Document all risk analysis, decisions, and recommendations in the ServiceNow GRC platform in accordance with County policy and audit standards.
  • Present findings and recommendations to the CISO and designated approvers.
  • Use ServiceNow GRC functionality to support workflow management, risk tracking, and reporting.
  • Recommend improvements to exception request workflows, dashboards, and system configurations where appropriate.


Qualifications

Education and Years of Experience:

  • Ideal candidate will have 4+ years of experience in a relevant field

Required and Desired Skills/Certifications:

  • Demonstrated hands-on experience with Governance, Risk, Compliance tools such as ServiceNow, Riskonnect, LogicManager, RSA Archer.
  • Strong understanding and application of cybersecurity risk management principles and control frameworks, including NIST SP 800-53, NIST RMF 800-37, ISO 27001, HIPAA Security Rule, PCI and FedRAMP.
  • Demonstrated ability to conduct structured risk assessments, to include the analysis of compensating controls, residual risk determination, application of quantitative risk models, and providing formal recommendation regarding the acceptance or denial of exception requests.
  • Demonstrated experience with the policy exception request process to include the intake/review of new exception requests to ensure completeness, accuracy, and consistency of the information provided, follow up with requestors to obtain missing or unclear information, performance of risk assessments, approval/denial recommendations and stakeholder communications regarding risk acceptance
  • Strong technical foundation with the ability to interpret network diagrams, threat models, vulnerability scan results, and compliance assessment reports.
  • Familiarity with risk qualification methodologies such as NIST, ISO 27005, Factor Analysis of Information Risk (FAIR).
  • Demonstrated ability to evaluate third-party System and Organization Controls (SOC) reports specifically SOC 1 Type II and SOC 2 Type II-for completeness, relevance, and control alignment.
  • Proven ability to contribute to third-party risk assessments, compliance audits, and the evaluation of internal security controls.
  • Proven track record in performing the duties of an Information Security Risk Analyst, including structured risk assessments and policy exception reviews.
  • Track record of supporting policy exception management processes and risk tolerance assessments in complex regulatory environments.

Desired Certifications:

  • CISSP (Certified Information Systems Security Professional)
  • CRISC (Certified in Risk and Information Systems Control)
  • GRCP (GRC Professional Certification)
  • CISA (Certified Information Systems Auditor)
  • CGRC (Certified in Governance, Risk, and Compliance)

Additional Requirements:

  • Successful completion of a Fingerprint background investigation.
  • The ideal candidate is a mid-level cybersecurity professional with a solid track record in:

    • risk analysis

    • policy exception review

    • control evaluation within a regulated environment.

    • possess hands-on experience with Governance, Risk, and Compliance (GRC) platforms-preferably ServiceNow-and are adept at navigating complex workflows related to policy deviations, risk acceptances, and control exceptions.

Min Citizenship Status Required: Must be eligible to work in the United State

Physical Requirements: No Physical requirement needed for this position.

Location: Rockville, MD, US



Working at DMI

DMI is a diverse, prosperous, and rewarding place to work. Our culture is shaped by five core values that guide how we work, grow, and succeed together:

  • Do What's Right - We lead with honesty and integrity.
  • Own the Outcome - We take responsibility and deliver.
  • Deliver for Our Customers - We are relentless about delivering value.
  • Think Bold, Act Smart - We innovate with purpose.
  • Win Together - We collaborate and celebrate our success.

These values aren't just ideals-they show up in how we support every part of your well-being:

  • Convenience/Concierge - Virtual health visits, commuter perks, pet insurance, and entertainment discounts that make life easier.
  • Development - Annual performance reviews, tuition assistance, and internal career growth opportunities to help you thrive.
  • Financial - Generous 401(k) matches, life and disability insurance, and financial wellness tools to support your future.
  • Recognition - Annual awards, service anniversaries, referral bonuses, and peer-to-peer shoutouts that spotlight your achievements.
  • Wellness - Healthcare coverage, wellness programs, flu shots, and biometric screenings to support your health.

DMI values employees for their talents and contributions, and we take pride in helping our customers achieve their goals. Because when we live our values, we all win together.

***************** No Agencies Please *****************

Applicants selected may be subject to a government security investigation and must meet eligibility requirements for access to classified information. US citizenship may be required for some positions.



Connect With Us!

Not ready to apply? Connect with us for general consideration.
Applied = 0

(web-8588dfb-vpc2p)