Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Risk Analyst SME

Technomics

Technomics is a growing employee-owned, decision analytics company that specializes in cost and economic analysis to facilitate better decisions faster. We enable a wide range of clients across the Federal government, from senior level policy makers to program managers, to choose smartly, buy effectively and operate efficiently. We deliver practical, credible and defensible results offering actionable insights by applying data-driven and analytics-based approaches in combination with multidisciplinary talent, subject matter experts, and tangible and repeatable assets in the form of databases, models, approaches and techniques.

Senior Analystshave the knowledge, skills, abilities and initiative to deliver timely, practical and innovative solutions to our clients as part of high-performing project teams typically composed of a mix of junior and mid-level analysts who will look to you for technical acumen and mentoring.

Our employee-owners pride themselves on their ability to apply deep analytical rigor and innovative thought that assist clients in understanding and solving a myriad of challenging resource planning and management problems.

This position is located in Arlington, VA.

Description:

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk identification.
The ideal candidate has deep experience with NIST SP 800-30, MITRE ATT&CK, and threat modeling approaches, and can translate technical risks into mission/business impacts. You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans, presenting findings, and traveling to client sites for mission assessments.
We are looking for someone who is agile, creative, and collaborative - able to apply lessons learned, enable data tagging and structured knowledge capture, and help shift the organization from reactive responses toward proactive risk management.

Clearance Required: Active DOE Q or higher (or ability to obtain)

Key Responsibilities:
  • Serve as a Subject Matter Expert (SME) in cyber risk assessment, analysis, and mitigation strategies for critical missions.
  • Conduct on-site and remote cyber risk assessments of enterprise systems, applications, and mission-critical infrastructures.
  • Apply NIST SP 800-30 risk assessment methodology, threat modeling techniques, and frameworks such as MITRE ATT&CK to evaluate vulnerabilities, threats, and risks.
  • Develop and present risk characterization reports, mitigation considerations, and recommendations to client leadership and system owners.
  • Create and manage task plans, assessment schedules, and execution strategies to ensure effective delivery of assessment activities.
  • Collaborate with multi-disciplinary teams of SMEs (cybersecurity, systems engineering, OT, supply chain, and mission assurance) to address enterprise risks.
  • Support the identification, analysis, and validation of complex security risks and associated vulnerabilities, including both technical and operational impacts.
  • Assist in the development of threat-informed mitigation strategies aligned with client enterprise assurance goals.
  • Implement data tagging and structured knowledge capture to enable proactive risk identification, trend analysis, and lessons-learned reuse.
  • Build analytic processes that leverage historical assessment data, external threat databases, and adversary TTPs to anticipate potential risks rather than solely reacting to identified vulnerabilities.
  • Provide expert consultation on risk acceptance, mitigation prioritization, and remediation planning to stakeholders.
  • Maintain awareness of emerging threats, vulnerabilities, adversary tactics, and best practices for defense in depth across the nuclear enterprise.
Required Qualifications:
  • 10+ years of experience in cybersecurity risk assessment, vulnerability analysis, or cyber mission assurance.
  • Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal standards.
  • Hands-on experience with threat modeling approaches and application of MITRE ATT&CK for risk evaluation.
  • Demonstrated ability to conduct complex cyber risk assessments and present findings to executive and technical audiences.
  • Proven ability to develop task plans, manage assessment milestones, and work independently or as part of a team.
  • Strong writing and briefing skills to produce risk reports, mitigation strategies, and decision support artifacts.
Preferred Qualifications:
  • Experience supporting national security organizations.
  • Familiarity with supply chain risk management (SCRM), insider threat analysis, or mission-critical system assurance.
  • Operational Technology (OT) and Systems Engineering (SE) experience in complex enterprise environments.
  • Knowledge of nuclear enterprise operations and mission dependencies.
  • Technical certifications such as Security+, CISSP, CISM, C-RMA, CAP, CEH, or OSCP.
  • Prior experience briefing and advising SES-level leadership or program executives.
  • Familiarity with tools supporting risk assessments and vulnerability analysis (e.g., Threat Modeling tools).
Work Environment:
  • Hybrid environment with headquarters-based work in D.C. and regular travel to client sites for on-site risk assessments.
  • Fast-paced, collaborative environment with cross-disciplinary SMEs (cybersecurity, engineering, OT, program management, and intelligence).
  • Requires agility, creativity, and strong interpersonal skills to interact effectively with diverse stakeholders across government, contractors, and mission partners.
  • Role demands adaptability to dynamic mission needs, shifting priorities, and classified environments.
  • Emphasis on teamwork, analytical rigor, and the ability to translate technical risks into mission/business impacts.

Technomics is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to protected status under applicable law, including disability and protected veteran status.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Cyber Risk Analyst SME in Arlington, VA vacancy
  • $131.3k - $237.35k

     ...Digital Modernization sector is seeking an experienced SME Zero Trust Cyber Security Analyst to support the delivery, enhancement, and adoption of enterprise...  ...data and system behavior to identify anomalies, risks, and potential threats. Collaborate with... 
    Suggested
    Local area
    Immediate start

    Leidos

    Alexandria, VA
    4 days ago
  •  ...better-informed decisions using trusted data at scale. Leidos Digital Modernization sector is seeking an experienced SME Cyber Incident Response Analyst to support the delivery, enhancement, and adoption of enterprise data and analytics products used across multiple DoD... 
    Suggested

    Koitecc Solutions

    Alexandria, VA
    17 hours ago
  • A technology firm in Virginia is seeking an experienced SME Cyber Incident Response Analyst to join its team. This role involves monitoring and responding to cyber threats, leading incident response activities, and providing expert investigative support. Ideal candidates... 
    Suggested

    Via Logic LLC

    Alexandria, VA
    1 day ago
  •  ...Junior Cyber Risk Data Engineer/Analyst Technomics is a growing employee-owned, decision analytics company that specializes in cost and economic...  ...verbal communication skills to document findings and support SME deliverables. Preferred Qualifications:... 
    Suggested
    Internship
    Shift work

    Technomics

    Arlington, VA
    4 days ago
  •  ...Holdings, a Pequot Company, is seeking a Management Analyst to support the Cybersecurity and Infrastructure...  ...Programs. The role involves providing research and cyber-physical security analytic support to reduce risks posed by small unmanned aircraft systems. The ideal... 
    Suggested
    Contract work
    Work at office

    Command Holdings, a Pequot Company

    Arlington, VA
    17 hours ago
  • $95.7k - $144.9k

    Bank of America is looking for a Resolution Analyst in Washington, DC. The role is pivotal in managing cybersecurity risks, requiring strong analytical and problem-solving...  ...team committed to enhancing the organization's cyber defense capabilities. #J-18808-Ljbffr Bank of... 

    Bank of America

    Washington DC
    22 hours ago
  • Insight Global is seeking a Risk Assessment Analyst to work hybrid in Alexandria, VA. This role supports senior DoD leadership by conducting cyber risk assessments and developing executive-level materials. Candidates must have a Top Secret Security Clearance and 5+ years... 

    Insight Global

    Alexandria, VA
    4 days ago
  • Phase2 Technology in Alexandria, VA is hiring a Risk Assessment Analyst to assess cyber threats and develop mitigation plans for federal clients. You will utilize your 5+ years of experience, including knowledge of cybersecurity risk assessments, to collaborate with industry... 

    Phase2 Technology

    Alexandria, VA
    4 days ago
  •  ...analytical skills. Responsibilities include evaluating incident response readiness, conducting vulnerability analyses, and communicating risks effectively. This role requires a BA/BS or equivalent experience, with onsite work and limited offsite support. Join a team focused... 

    POTOMAC MANAGEMENT SOLUTIONS

    Washington DC
    3 days ago
  • TAD PGS, Inc. has an outstanding contract position for a Senior Cybersecurity Supply Chain Risk Management Analyst in the Washington, DC area. The role involves analyzing supply chain cybersecurity risks and provides support for procurement documentation related to high... 
    Contract work

    TAD PGS, Inc.

    Washington DC
    22 hours ago
  •  ...Job Description Job Description Industrial Security / Risk / Analyst SME IV – DOE (Hybrid) Location: Washington D.C. BluePath Labs is a fast-growing research and consulting company committed to solving complex problems for federal, state, and local government... 
    Work at office
    Local area
    Flexible hours

    BluePath Labs

    Washington DC
    27 days ago
  • Saic is seeking a Cybersecurity Compliance analyst in Arlington, VA. This role involves providing expertise in Risk Management Framework and managing cybersecurity compliance for the Joint Staff. Key responsibilities include tracking compliance, consolidating risk metrics... 

    Saic

    Arlington, VA
    22 hours ago
  •  ...defense contracting firm in Arlington, VA, is seeking an IT/Telecommunications Analyst to conduct cybersecurity research and analysis. The role involves independent research into technology risk areas, providing support to client cases, and managing information... 

    Systems Planning & Analysis

    Arlington, VA
    3 days ago
  •  ...and critical asset owners who experience cyber-attacks, providing immediate investigation...  ...They are seeking an Enterprise Architect SME to support this critical customer mission....  ...preferred) Experience and/or familiarity of the Risk Management Framework (RMF) and security... 
    Contract work
    Immediate start

    NewGen Technologies (Maryland)

    Arlington, VA
    2 days ago
  •  ...provides technically advanced full-spectrum cyber, data operations, systems integration and...  ...is seeking an Enterprise Architect SME to support this critical customer mission...  ...- Experience and/or familiarity of the Risk Management Framework (RMF) and security and... 
    Contract work
    Immediate start

    Nightwing

    Arlington, VA
    22 hours ago
  • $135k - $216k

     ...IT Audit Advisory Consultant/FISCAM SME We are seeking a highly skilled and experienced IT Audit Advisory Consultant/FISCAM SME to...  ...Monitor, track, and report on IT CAP statuses and third-party risk management (e.g., service providers) Develop risk-based approaches... 
    Contract work
    For contractors
    Shift work

    Peraton

    Washington DC
    3 days ago
  • Business Computers Management Consulting Group Llc is seeking an Enterprise Architect SME to support U.S. Government missions by providing incident response and cyber security solutions. The ideal candidate will have over 12 years of experience in systems engineering and... 

    Business Computers Management Consulting Group Llc

    Arlington, VA
    22 hours ago
  •  ...Job Title Responsibilities Support annual information security program risk assessments. Facilitate/Support interviews and evidence gathering. Coordinate risk assessment activities with service provider. Coordinate and prepare documentation, internal... 
    Local area
    Remote work

    C.C. Pace Systems

    Washington DC
    22 hours ago
  •  ...Risk Analyst The Risk Analyst is responsible for providing guidance on tools to measure and manage risk, identify/mitigate threats, and...  ...understanding of the intent, objectives, and activities of cyber threat actors and support the cyber defense program. Required... 
    Work experience placement

    Software Technology Inc

    Washington DC
    2 days ago
  • Systems Analyst - TS required to apply; Washington DC; Junior to SME Washington, DC, USA 75000-155000 per year Competitive salary based on experience and qualifications Responsibilities Analyze science, engineering, business, and other data processing problems to implement... 

    Bow-Wave-LLC

    Washington DC
    2 days ago
  •  ...VMware vDefend Security Engineer (SME) Location: Onsite – Alexandria, VA (occasional travel to Springfield, VA) Clearance: Top Secret (TS) Required Type: Full-time / Onsite Federal Engagement Job Summary The VMware vDefend Security Engineer... 
    Full time
    Temporary work
    Immediate start

    PGTEK

    Alexandria, VA
    22 hours ago
  •  ...seeking a Cybersecurity Architect & Engineer SME who can create government solutions that...  ...withstand even the most complex of IT and Cyber threats. The SME will support a federal...  ...contain, minimize, and remediate associated risks. Provide system engineering and architectural... 
    Remote work

    Zermount, Inc.

    Arlington, VA
    22 hours ago
  • $131.3k - $237.35k

     ...Digital Modernization sector is seeking an experienced SME Cross Domain Implementation Analyst to support the delivery, enhancement, and adoption of enterprise...  ...III Preferred Qualifications: Experience with DoD Risk Management Framework (RMF) compliance. Familiarity with... 
    Local area
    Immediate start

    Leidos

    Alexandria, VA
    2 days ago
  • $83k - $166k

     ...Information Systems Security Manager (ISSM) - SME Work Location: Washington, DC Employment Type: Full-Time, Expert-Level Department: Administrative and Logistics Support CGS is seeking a skilled Information Systems Security Manager (... 
    Full time
    Flexible hours

    Contact Government Services, LLC

    Washington DC
    2 days ago
  • A defense technology contractor is seeking an SME III for Technology Capabilities in Washington, DC. You will serve as a senior technical authority, planning and executing advanced cyber engineering projects in a classified environment. The ideal candidate has over 15... 
    For contractors

    Core4ce

    Washington DC
    22 hours ago
  • $109k - $124.4k

    Senior Associate, Cyber Governance & Risk - Cyber Exceptions Analyst Security is essential to what we do at Capital One, from protecting customer data to the associate experience. As a Cyber Exceptions Analyst within the Governance and Risk division, you see security as... 
    Full time
    Part time
    H1b
    Local area

    Capital One National Association

    Mc Lean, VA
    4 days ago
  • Nucorevision, Inc is seeking a Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst in Washington, D.C. This role involves managing cybersecurity risks for a Federal Agency by ensuring the security and reliability of ICT/OT products across their lifecycle.... 
    Remote work
    3 days per week

    Nucorevision, Inc

    Washington DC
    3 days ago
  •  ...Subject Matter Expert (SME) - Cybersecurity & Risk Assessment Overview: The Subject Matter Expert (SME) provides advanced technical expertise to support assessment operations, with a focus on cybersecurity, risk analysis, and program integrity. This role is responsible... 

    Private Label Staff

    Washington DC
    3 days ago
  •  ...triage, threat analysis, and response to cyber incident reports. Experience with industrial...  ...Control System Cyber Threat Intelligence Analyst for its Federal Strategic Cyber programs....  ...engagements. Serve as subject matter expert (SME) for ICS Security activities. Identify... 
    Currently hiring

    Peraton

    Arlington, VA
    22 hours ago
  •  ...Job Description Job Description Information Systems Security Manager (ISSM) – SME    Work Location: Washington, DC  Employment Type: Full-Time, Expert-Level  Department: Administrative and Logistics Support  CGS is seeking a skilled Information Systems Security... 
    Full time
    Flexible hours

    Contact Government Services, LLC

    Washington DC
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Risk Analyst SME. Be the first to apply!