Cyber Risk Analyst SME
$105k - $200kTechnomics
Cyber Risk Analyst Technomics is a growing employee-owned, decision analytics company that specializes in cost and economic analysis to facilitate better decisions faster. We enable a wide range of clients across the Federal government, from senior level policy makers to program managers, to choose smartly, buy effectively and operate efficiently. We deliver practical, credible and defensible results offering actionable insights by applying data-driven and analytics-based approaches in combination with multidisciplinary talent, subject matter experts, and tangible and repeatable assets in the form of databases, models, approaches and techniques. Analysts have the knowledge, skills, abilities and initiative to deliver timely, practical and innovative solutions to our clients as part of high-performing project teams typically composed of a mix of junior and mid-level analysts who will look to you for technical acumen and mentoring. Our employee-owners pride themselves on their ability to apply deep analytical rigor and innovative thought that assist clients in understanding and solving a myriad of challenging resource planning and management problems. This position may be located in Arlington, VA (Headquarters), Washington D.C., Pentagon, Springfield, VA., Chantilly, VA., Tysons Corner, VA. Description: We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk identification. The ideal candidate has deep experience with NIST SP 800-30, MITRE ATT&CK, and threat modeling approaches, and can translate technical risks into mission/business impacts. You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans, presenting findings, and traveling to client sites for mission assessments. We are looking for someone who is agile, creative, and collaborative — able to apply lessons learned, enable data tagging and structured knowledge capture, and help shift the organization from reactive responses toward proactive risk management. Clearance Required: Active DOE Q or higher (or ability to obtain) Key Responsibilities: Serve as a Subject Matter Expert (SME) in cyber risk assessment, analysis, and mitigation strategies for critical missions. Conduct on-site and remote cyber risk assessments of enterprise systems, applications, and mission-critical infrastructures. Apply NIST SP 800-30 risk assessment methodology, threat modeling techniques, and frameworks such as MITRE ATT&CK to evaluate vulnerabilities, threats, and risks. Develop and present risk characterization reports, mitigation considerations, and recommendations to client leadership and system owners. Create and manage task plans, assessment schedules, and execution strategies to ensure effective delivery of assessment activities. Collaborate with multi-disciplinary teams of SMEs (cybersecurity, systems engineering, OT, supply chain, and mission assurance) to address enterprise risks. Support the identification, analysis, and validation of complex security risks and associated vulnerabilities, including both technical and operational impacts. Assist in the development of threat-informed mitigation strategies aligned with client enterprise assurance goals. Implement data tagging and structured knowledge capture to enable proactive risk identification, trend analysis, and lessons-learned reuse. Build analytic processes that leverage historical assessment data, external threat databases, and adversary TTPs to anticipate potential risks rather than solely reacting to identified vulnerabilities. Provide expert consultation on risk acceptance, mitigation prioritization, and remediation planning to stakeholders. Maintain awareness of emerging threats, vulnerabilities, adversary tactics, and best practices for defense in depth across the nuclear enterprise. Required Qualifications: 10+ years of experience in cybersecurity risk assessment, vulnerability analysis, or cyber mission assurance. Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal standards. Hands-on experience with threat modeling approaches and application of MITRE ATT&CK for risk evaluation. Demonstrated ability to conduct complex cyber risk assessments and present findings to executive and technical audiences. Proven ability to develop task plans, manage assessment milestones, and work independently or as part of a team. Strong writing and briefing skills to produce risk reports, mitigation strategies, and decision support artifacts. Preferred Qualifications: Experience supporting national security organizations. Familiarity with supply chain risk management (SCRM), insider threat analysis, or mission-critical system assurance. Operational Technology (OT) and Systems Engineering (SE) experience in complex enterprise environments. Knowledge of nuclear enterprise operations and mission dependencies. Technical certifications such as Security+, CISSP, CISM, C-RMA, CAP, CEH, or OSCP. Prior experience briefing and advising SES-level leadership or program executives. Familiarity with tools supporting risk assessments and vulnerability analysis (e.g., Threat Modeling tools). Work Environment: Hybrid environment with headquarters-based work in D.C. and regular travel to client sites for on-site risk assessments. Fast-paced, collaborative environment with cross-disciplinary SMEs (cybersecurity, engineering, OT, program management, and intelligence). Requires agility, creativity, and strong interpersonal skills to interact effectively with diverse stakeholders across government, contractors, and mission partners. Role demands adaptability to dynamic mission needs, shifting priorities, and classified environments. Emphasis on teamwork, analytical rigor, and the ability to translate technical risks into mission/business impacts. Salary range: $105,000- 200,000 USD The salary range listed is one part of our total compensation package, which may also include bonuses, incentives and benefits. Individual compensation is determined based on qualifications such as relevant years of experience, education, certifications and geographic location Technomics is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to protected status under applicable law, including disability and protected veteran status. Technomics
- SME Cyber Network Analyst Iron EagleX is seeking a SME Cyber Network Analyst to join our fast-paced technical team. In this role, you will analyze, engineer, and troubleshoot complex network environments while supporting the integration and operationalization of advanced...SuggestedContract work
- NTT DATA seeks a Cybersecurity and Risk Analyst to join the VAPT team, identifying and mitigating cybersecurity risks across enterprise systems, networks, and applications. You will perform vulnerability assessments, risk evaluations, and threat simulations aligned with...Suggested
- Booz Allen Hamilton in McLean, VA is seeking an Information Security Risk Specialist to help clients identify cyber risks, evaluate policies, and craft mitigation plans for DoD systems in AWS, Azure, or hybrid environments. You will translate security concepts for stakeholders...Suggested
$109k - $124.4k
Senior Associate, Cyber Governance & Risk - Cyber Exceptions Analyst Security is essential to what we do at Capital One, from protecting customer data to the associate experience. As a Cyber Exceptions Analyst within the Governance and Risk division, you see security as...SuggestedFull timePart timeH1bLocal area- ...Cyber Incident Response Analyst This Department of War enterprise data and analytics program delivers mission-critical capabilities that enable... ...Leidos Digital Modernization sector is seeking an experienced SME Cyber Incident Response Analyst to support the delivery,...Suggested
$144.3k - $240.5k
...security-engineering products).Serving as SME across the security subdomains - cross-domain... ...(CDS), anti-tamper (AT), COMSEC, and cyber - and integrate them into the engineering... ...CDS definitionSupporting the future cyber risk assessment (tabletop through red/blue-team...Contract work$110.18k - $183.63k
...to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington, Virginia (US-VA), United States (US).Job Summary: The Cybersecurity and Risk Analyst is a...Full timeTemporary workWork at officeRemote workFlexible hours$112k - $179k
ResponsibilitiesPeraton is currently hiring Sr Industrial Control System Cyber Threat Intelligence Analyst for its Federal Strategic Cyber programs.Location: On-site... ...hunting engagements.Serve as subject matter expert (SME) for ICS Security activities.Identify potential open-...Contract workCurrently hiringShift work$100k - $150k
...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location: 50 miles of McLean, Virginia... ...Cybersecurity Risk Analyst to support enterprise cybersecurity and cyber defense operations in the Washington, D.C. metropolitan area....Contract work- ...Risk Analyst The Risk Analyst is responsible for providing guidance on tools to measure and manage risk, identify/mitigate threats, and... ...understanding of the intent, objectives, and activities of cyber threat actors and support the cyber defense program. Required...Work experience placement
- ...Encouraged to Apply. Job Description NDi is looking for an SME Software Asset Management Analyst that serves as the senior technical authority for... ...compliance posture. Validate compliance posture outputs, risk narratives, and liability estimates to support executive...For contractorsRemote work
- ...Description Job Description We are seeking a Subject Matter Expert (SME) Enterprise Architect to join our team supporting a large-scale... ...records. Evaluate proposed architectural deviations, document risks and impacts, and provide recommendations for approval. Serve...Flexible hours
$83k - $166k
Washington, DCAdministrative and Logistics Support /Full Time On-Site /On-siteInformation Systems Security Manager (ISSM) - SME Work Location: Washington, DC Employment Type: Full-Time, Expert-Level Department: Administrative and Logistics Support CGS is seeking a skilled...Full time- OverviewAbacus Technology is seeking a Cyber Security Engineering SME to provide security and test and evaluation support for the RDT&E Engineering... ...Management Plans, Information Support Plans, PPPs, Security Risk Analyses, Security Vulnerability and Countermeasure...Full time
- Invictus International Consulting, LLC. seeks a Senior Cybersecurity Risk & Exposure Analyst III to lead complex operational risk analyses for DoD systems from Alexandria, VA. You will correlate vulnerabilities, asset data, and controls to identify exposures with the greatest...
$110.18k - $183.63k
...with us. If you want to be part of an inclusive, adaptable, and forward‑thinking organization. Job Summary The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and Penetration Testing (VAPT) team, responsible for identifying, analyzing...Temporary workWork at officeRemote workFlexible hours- Kids for the Future is seeking a Business Management Analyst II to support CISA Sector Risk Management activities in Arlington, VA. The role focuses on governance, risk management, stakeholder engagement, and executive-level deliverables to strengthen cross-sector coordination...
$175k - $190k
...DescriptionEverforth ECS is seeking an Information System Security Engineer SME to work in our Washington, DC office. Please Note: This position... ...a strong background in security engineering, architecture, and risk management, with a focus on protecting sensitive information and...Contract workWork at office$99k - $225k
Risk Management Framework Cybersecurity Analyst The Opportunity: Are you looking for an opportunity to share your experience in Risk Management Framework (RMF) and cybersecurity to support our country and safeguard our nation? As a RMF Cybersecurity Analyst, you will...Full timeContract workPart timeLocal areaRemote work$161.9k - $199.26k
GovCIO is currently hiring for a SME Network Engineer with an active Secret clearance to provide classified and unclassified Tier 3 senior-level support for the design, implementation, and deployment of network-specific technologies across a government Enterprise environment...Currently hiringWorldwide$176k - $282k
...Systems Security Engineer - Subject Matter Expert (SME)/Cloud-based to support its Federal Strategic Cyber programs.Location: National Capital Region (NCR):In... ...Prepare step, ensuring roles, responsibilities, and risk management strategies are clearly defined and maintained...Contract workTemporary workFor contractorsWork at officeShift work$120k - $165k
...enforcement. Our mission is to empower analysts and decision-makers through data-... ...Praescient Analytics is seeking a Principal Cyber Systems Engineer, SME to provide high-level technical... ...mission-level integration. Adversarial Risk Assessment: Recommend and conduct assessments...Full timeWork at office- ...operations that steal billions from victims each year. As a Cyber Threat Intelligence Analyst , you'll lead infrastructure-driven investigative work:... ...end with minimal supervision, partnering with the Scams SME team and with data, engineering, and product to sharpen TRM...Worldwide
$104k - $166k
ResponsibilitiesPeraton is currently seeking a Senior Risk and Vulnerability Analyst.Location: Chandler, AZ or Washington DCRole and Responsibilities: The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by identifying, analyzing,...Contract workShift work- ...contingent upon contract award ***Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis... ...enterprise visibility into security weaknesses and cyber risk.Responsibilities· Perform vulnerability assessments and...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$140k - $160k
...DescriptionEverforth ECS is seeking a Mid Cyber Threat Intelligence (CTI) Analyst to join our team in Arlington, VA (... ...Mid Cyber Threat Intelligence (CTI) SME to support the organization's cyber... ..., and emerging cybersecurity risks.Analyze vulnerabilities and assess potential...$62k - $141k
...tools to capture and preserve evidence for security events. The analyst contributes to the development forensics playbooks and standard... ...state, local, or international law. Digital Forensics Analyst SME Serve as a key member of a 24x7x365 Security Operations Center and...Full timeContract workPart timeWork at officeLocal areaRemote work$135k - $216k
...experienced IT Audit Advisory Consultant/FISCAM SME to join our team. This position will... ...report on IT CAP statuses and third-party risk management (e.g., service providers)Develop... ...ID: 2026-165501Position Category: Cyber SecurityClearance: Top Secret/SCI w/PolyContract workFor contractorsShift work$122k - $253k
...Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence mission support services... ...of services. Nightwing is seeking an Cyber Network Forensic Analyst to support this critical customer mission. Responsibilities:...Contract workImmediate start$122k - $253k
...Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence mission support services... ...of services. Nightwing is seeking a Cyber Network Defense Analyst to support this critical customer mission. The CDNA uses information...Contract workImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Risk Analyst SME. Be the first to apply!
- cyber security analyst Arlington, VA
- remote cyber security analyst Arlington, VA
- information security consultant Arlington, VA
- risk consultant Arlington, VA
- risk analyst Arlington, VA
- operational risk specialist Arlington, VA
- operational risk consultant Arlington, VA
- risk officer Arlington, VA
- it risk analyst Arlington, VA
- cyber sales Arlington, VA


