Cyber Risk Analyst SME
Technomics
Technomics is a growing employee-owned, decision analytics company that specializes in cost and economic analysis to facilitate better decisions faster. We enable a wide range of clients across the Federal government, from senior level policy makers to program managers, to choose smartly, buy effectively and operate efficiently. We deliver practical, credible and defensible results offering actionable insights by applying data-driven and analytics-based approaches in combination with multidisciplinary talent, subject matter experts, and tangible and repeatable assets in the form of databases, models, approaches and techniques.
Senior Analystshave the knowledge, skills, abilities and initiative to deliver timely, practical and innovative solutions to our clients as part of high-performing project teams typically composed of a mix of junior and mid-level analysts who will look to you for technical acumen and mentoring. Our employee-owners pride themselves on their ability to apply deep analytical rigor and innovative thought that assist clients in understanding and solving a myriad of challenging resource planning and management problems. This position is located in Arlington, VA. Description: We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk identification.The ideal candidate has deep experience with NIST SP 800-30, MITRE ATT&CK, and threat modeling approaches, and can translate technical risks into mission/business impacts. You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans, presenting findings, and traveling to client sites for mission assessments.
We are looking for someone who is agile, creative, and collaborative - able to apply lessons learned, enable data tagging and structured knowledge capture, and help shift the organization from reactive responses toward proactive risk management. Clearance Required: Active DOE Q or higher (or ability to obtain) Key Responsibilities:
- Serve as a Subject Matter Expert (SME) in cyber risk assessment, analysis, and mitigation strategies for critical missions.
- Conduct on-site and remote cyber risk assessments of enterprise systems, applications, and mission-critical infrastructures.
- Apply NIST SP 800-30 risk assessment methodology, threat modeling techniques, and frameworks such as MITRE ATT&CK to evaluate vulnerabilities, threats, and risks.
- Develop and present risk characterization reports, mitigation considerations, and recommendations to client leadership and system owners.
- Create and manage task plans, assessment schedules, and execution strategies to ensure effective delivery of assessment activities.
- Collaborate with multi-disciplinary teams of SMEs (cybersecurity, systems engineering, OT, supply chain, and mission assurance) to address enterprise risks.
- Support the identification, analysis, and validation of complex security risks and associated vulnerabilities, including both technical and operational impacts.
- Assist in the development of threat-informed mitigation strategies aligned with client enterprise assurance goals.
- Implement data tagging and structured knowledge capture to enable proactive risk identification, trend analysis, and lessons-learned reuse.
- Build analytic processes that leverage historical assessment data, external threat databases, and adversary TTPs to anticipate potential risks rather than solely reacting to identified vulnerabilities.
- Provide expert consultation on risk acceptance, mitigation prioritization, and remediation planning to stakeholders.
- Maintain awareness of emerging threats, vulnerabilities, adversary tactics, and best practices for defense in depth across the nuclear enterprise.
- 10+ years of experience in cybersecurity risk assessment, vulnerability analysis, or cyber mission assurance.
- Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal standards.
- Hands-on experience with threat modeling approaches and application of MITRE ATT&CK for risk evaluation.
- Demonstrated ability to conduct complex cyber risk assessments and present findings to executive and technical audiences.
- Proven ability to develop task plans, manage assessment milestones, and work independently or as part of a team.
- Strong writing and briefing skills to produce risk reports, mitigation strategies, and decision support artifacts.
- Experience supporting national security organizations.
- Familiarity with supply chain risk management (SCRM), insider threat analysis, or mission-critical system assurance.
- Operational Technology (OT) and Systems Engineering (SE) experience in complex enterprise environments.
- Knowledge of nuclear enterprise operations and mission dependencies.
- Technical certifications such as Security+, CISSP, CISM, C-RMA, CAP, CEH, or OSCP.
- Prior experience briefing and advising SES-level leadership or program executives.
- Familiarity with tools supporting risk assessments and vulnerability analysis (e.g., Threat Modeling tools).
- Hybrid environment with headquarters-based work in D.C. and regular travel to client sites for on-site risk assessments.
- Fast-paced, collaborative environment with cross-disciplinary SMEs (cybersecurity, engineering, OT, program management, and intelligence).
- Requires agility, creativity, and strong interpersonal skills to interact effectively with diverse stakeholders across government, contractors, and mission partners.
- Role demands adaptability to dynamic mission needs, shifting priorities, and classified environments.
- Emphasis on teamwork, analytical rigor, and the ability to translate technical risks into mission/business impacts.
Technomics is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to protected status under applicable law, including disability and protected veteran status.
$131.3k - $237.35k
...Digital Modernization sector is seeking an experienced SME Zero Trust Cyber Security Analyst to support the delivery, enhancement, and adoption of enterprise... ...data and system behavior to identify anomalies, risks, and potential threats. Collaborate with...SuggestedLocal areaImmediate start- ...better-informed decisions using trusted data at scale. Leidos Digital Modernization sector is seeking an experienced SME Cyber Incident Response Analyst to support the delivery, enhancement, and adoption of enterprise data and analytics products used across multiple DoD...Suggested
- A technology firm in Virginia is seeking an experienced SME Cyber Incident Response Analyst to join its team. This role involves monitoring and responding to cyber threats, leading incident response activities, and providing expert investigative support. Ideal candidates...Suggested
- ...Junior Cyber Risk Data Engineer/Analyst Technomics is a growing employee-owned, decision analytics company that specializes in cost and economic... ...verbal communication skills to document findings and support SME deliverables. Preferred Qualifications:...SuggestedInternshipShift work
- ...Holdings, a Pequot Company, is seeking a Management Analyst to support the Cybersecurity and Infrastructure... ...Programs. The role involves providing research and cyber-physical security analytic support to reduce risks posed by small unmanned aircraft systems. The ideal...SuggestedContract workWork at office
$95.7k - $144.9k
Bank of America is looking for a Resolution Analyst in Washington, DC. The role is pivotal in managing cybersecurity risks, requiring strong analytical and problem-solving... ...team committed to enhancing the organization's cyber defense capabilities. #J-18808-Ljbffr Bank of...- Insight Global is seeking a Risk Assessment Analyst to work hybrid in Alexandria, VA. This role supports senior DoD leadership by conducting cyber risk assessments and developing executive-level materials. Candidates must have a Top Secret Security Clearance and 5+ years...
- Phase2 Technology in Alexandria, VA is hiring a Risk Assessment Analyst to assess cyber threats and develop mitigation plans for federal clients. You will utilize your 5+ years of experience, including knowledge of cybersecurity risk assessments, to collaborate with industry...
- TAD PGS, Inc. has an outstanding contract position for a Senior Cybersecurity Supply Chain Risk Management Analyst in the Washington, DC area. The role involves analyzing supply chain cybersecurity risks and provides support for procurement documentation related to high...Contract work
- ...analytical skills. Responsibilities include evaluating incident response readiness, conducting vulnerability analyses, and communicating risks effectively. This role requires a BA/BS or equivalent experience, with onsite work and limited offsite support. Join a team focused...
- Saic is seeking a Cybersecurity Compliance analyst in Arlington, VA. This role involves providing expertise in Risk Management Framework and managing cybersecurity compliance for the Joint Staff. Key responsibilities include tracking compliance, consolidating risk metrics...
- ...defense contracting firm in Arlington, VA, is seeking an IT/Telecommunications Analyst to conduct cybersecurity research and analysis. The role involves independent research into technology risk areas, providing support to client cases, and managing information...
- ...Job Description Job Description Industrial Security / Risk / Analyst SME IV – DOE (Hybrid) Location: Washington D.C. BluePath Labs is a fast-growing research and consulting company committed to solving complex problems for federal, state, and local government...Work at officeLocal areaFlexible hours
- ...provides technically advanced full-spectrum cyber, data operations, systems integration and... ...is seeking an Enterprise Architect SME to support this critical customer mission... ...- Experience and/or familiarity of the Risk Management Framework (RMF) and security and...Contract workImmediate start
- ...and critical asset owners who experience cyber-attacks, providing immediate investigation... ...They are seeking an Enterprise Architect SME to support this critical customer mission.... ...preferred) Experience and/or familiarity of the Risk Management Framework (RMF) and security...Contract workImmediate start
$135k - $216k
...IT Audit Advisory Consultant/FISCAM SME We are seeking a highly skilled and experienced IT Audit Advisory Consultant/FISCAM SME to... ...Monitor, track, and report on IT CAP statuses and third-party risk management (e.g., service providers) Develop risk-based approaches...Contract workFor contractorsShift work- Business Computers Management Consulting Group Llc is seeking an Enterprise Architect SME to support U.S. Government missions by providing incident response and cyber security solutions. The ideal candidate will have over 12 years of experience in systems engineering and...
- ...Risk Analyst The Risk Analyst is responsible for providing guidance on tools to measure and manage risk, identify/mitigate threats, and... ...understanding of the intent, objectives, and activities of cyber threat actors and support the cyber defense program. Required...Work experience placement
- ...Job Title Responsibilities Support annual information security program risk assessments. Facilitate/Support interviews and evidence gathering. Coordinate risk assessment activities with service provider. Coordinate and prepare documentation, internal...Local areaRemote work
- Systems Analyst - TS required to apply; Washington DC; Junior to SME Washington, DC, USA 75000-155000 per year Competitive salary based on experience and qualifications Responsibilities Analyze science, engineering, business, and other data processing problems to implement...
- ...seeking a Cybersecurity Architect & Engineer SME who can create government solutions that... ...withstand even the most complex of IT and Cyber threats. The SME will support a federal... ...contain, minimize, and remediate associated risks. Provide system engineering and architectural...Remote work
$131.3k - $237.35k
...Digital Modernization sector is seeking an experienced SME Cross Domain Implementation Analyst to support the delivery, enhancement, and adoption of enterprise... ...III Preferred Qualifications: Experience with DoD Risk Management Framework (RMF) compliance. Familiarity with...Local areaImmediate start- ...VMware vDefend Security Engineer (SME) Location: Onsite – Alexandria, VA (occasional travel to Springfield, VA) Clearance: Top Secret (TS) Required Type: Full-time / Onsite Federal Engagement Job Summary The VMware vDefend Security Engineer...Full timeTemporary workImmediate start
$83k - $166k
...Information Systems Security Manager (ISSM) - SME Work Location: Washington, DC Employment Type: Full-Time, Expert-Level Department: Administrative and Logistics Support CGS is seeking a skilled Information Systems Security Manager (...Full timeFlexible hours- A defense technology contractor is seeking an SME III for Technology Capabilities in Washington, DC. You will serve as a senior technical authority, planning and executing advanced cyber engineering projects in a classified environment. The ideal candidate has over 15...For contractors
- Nucorevision, Inc is seeking a Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst in Washington, D.C. This role involves managing cybersecurity risks for a Federal Agency by ensuring the security and reliability of ICT/OT products across their lifecycle....Remote work3 days per week
$109k - $124.4k
Senior Associate, Cyber Governance & Risk - Cyber Exceptions Analyst Security is essential to what we do at Capital One, from protecting customer data to the associate experience. As a Cyber Exceptions Analyst within the Governance and Risk division, you see security as...Full timePart timeH1bLocal area- ...Subject Matter Expert (SME) - Cybersecurity & Risk Assessment Overview: The Subject Matter Expert (SME) provides advanced technical expertise to support assessment operations, with a focus on cybersecurity, risk analysis, and program integrity. This role is responsible...
- ...triage, threat analysis, and response to cyber incident reports. Experience with industrial... ...Control System Cyber Threat Intelligence Analyst for its Federal Strategic Cyber programs.... ...engagements. Serve as subject matter expert (SME) for ICS Security activities. Identify...Currently hiring
$131.3k - $237.35k
...Modernization sector is seeking an experienced SME Cybersecurity Engineer to support the... ...organization’s cybersecurity posture, Risk Management Framework (RMF) activities,... ...certification appropriate for Advanced Cyber Defense Analyst roles (e.g., GCFA or GCIA ),...Local areaImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Risk Analyst SME. Be the first to apply!
- information security consultant Arlington, VA
- remote cyber security analyst Arlington, VA
- cyber security analyst Arlington, VA
- operational risk consultant Arlington, VA
- it risk analyst Arlington, VA
- operational risk specialist Arlington, VA
- risk analyst Arlington, VA
- senior quantitative risk analyst Arlington, VA
- risk officer Arlington, VA
- risk consultant Arlington, VA


