Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Risk Analyst SME

$105k - $200k

Technomics

Job Description

Job Description

Technomics is a growing employee-owned, decision analytics company that specializes in cost and economic analysis to facilitate better decisions faster . We enable a wide range of clients across the Federal government, from senior level policy makers to program managers, to choose smartly, buy effectively and operate efficiently. We deliver practical, credible and defensible results offering actionable insights by applying data-driven and analytics-based approaches in combination with multidisciplinary talent, subject matter experts, and tangible and repeatable assets in the form of databases, models, approaches and techniques.

Analysts have the knowledge, skills, abilities and initiative to deliver timely, practical and innovative solutions to our clients as part of high-performing project teams typically composed of a mix of junior and mid-level analysts who will look to you for technical acumen and mentoring.

Our employee-owners pride themselves on their ability to apply deep analytical rigor and innovative thought that assist clients in understanding and solving a myriad of challenging resource planning and management problems.

This position may be located in Arlington, VA (Headquarters), Washington D.C., Pentagon, Springfield, VA., Chantilly, VA., Tysons Corner, VA.

Description:

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk identification.
The ideal candidate has deep experience with NIST SP 800-30, MITRE ATT&CK, and threat modeling approaches, and can translate technical risks into mission/business impacts. You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans, presenting findings, and traveling to client sites for mission assessments.
We are looking for someone who is agile, creative, and collaborative — able to apply lessons learned, enable data tagging and structured knowledge capture, and help shift the organization from reactive responses toward proactive risk management.

Clearance Required: Active DOE Q or higher (or ability to obtain)

Key Responsibilities:

  • Serve as a Subject Matter Expert (SME) in cyber risk assessment, analysis, and mitigation strategies for critical missions.
  • Conduct on-site and remote cyber risk assessments of enterprise systems, applications, and mission-critical infrastructures.
  • Apply NIST SP 800-30 risk assessment methodology, threat modeling techniques, and frameworks such as MITRE ATT&CK to evaluate vulnerabilities, threats, and risks.
  • Develop and present risk characterization reports, mitigation considerations, and recommendations to client leadership and system owners.
  • Create and manage task plans, assessment schedules, and execution strategies to ensure effective delivery of assessment activities.
  • Collaborate with multi-disciplinary teams of SMEs (cybersecurity, systems engineering, OT, supply chain, and mission assurance) to address enterprise risks.
  • Support the identification, analysis, and validation of complex security risks and associated vulnerabilities, including both technical and operational impacts.
  • Assist in the development of threat-informed mitigation strategies aligned with client enterprise assurance goals.
  • Implement data tagging and structured knowledge capture to enable proactive risk identification, trend analysis, and lessons-learned reuse.
  • Build analytic processes that leverage historical assessment data, external threat databases, and adversary TTPs to anticipate potential risks rather than solely reacting to identified vulnerabilities.
  • Provide expert consultation on risk acceptance, mitigation prioritization, and remediation planning to stakeholders.
  • Maintain awareness of emerging threats, vulnerabilities, adversary tactics, and best practices for defense in depth across the nuclear enterprise.

Required Qualifications:

  • 10+ years of experience in cybersecurity risk assessment, vulnerability analysis, or cyber mission assurance.
  • Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal standards.
  • Hands-on experience with threat modeling approaches and application of MITRE ATT&CK for risk evaluation.
  • Demonstrated ability to conduct complex cyber risk assessments and present findings to executive and technical audiences.
  • Proven ability to develop task plans, manage assessment milestones, and work independently or as part of a team.
  • Strong writing and briefing skills to produce risk reports, mitigation strategies, and decision support artifacts.

Preferred Qualifications:

  • Experience supporting national security organizations.
  • Familiarity with supply chain risk management (SCRM), insider threat analysis, or mission-critical system assurance.
  • Operational Technology (OT) and Systems Engineering (SE) experience in complex enterprise environments.
  • Knowledge of nuclear enterprise operations and mission dependencies.
  • Technical certifications such as Security+, CISSP, CISM, C-RMA, CAP, CEH, or OSCP.
  • Prior experience briefing and advising SES-level leadership or program executives.
  • Familiarity with tools supporting risk assessments and vulnerability analysis (e.g., Threat Modeling tools).

Work Environment:

  • Hybrid environment with headquarters-based work in D.C. and regular travel to client sites for on-site risk assessments.
  • Fast-paced, collaborative environment with cross-disciplinary SMEs (cybersecurity, engineering, OT, program management, and intelligence).
  • Requires agility, creativity, and strong interpersonal skills to interact effectively with diverse stakeholders across government, contractors, and mission partners.
  • Role demands adaptability to dynamic mission needs, shifting priorities, and classified environments.
  • Emphasis on teamwork, analytical rigor, and the ability to translate technical risks into mission/business impacts.

Salary range: $105,000- 200,000 USD

The salary range listed is one part of our total compensation package, which may also include bonuses, incentives and benefits. Individual compensation is determined based on qualifications such as relevant years of experience, education, certifications and geographic location

Technomics is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to protected status under applicable law, including disability and protected veteran status.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber Risk Analyst SME in Arlington, VA vacancy
  •  ...to operate smarter, faster, and more securely in dynamic environments.   JOB DESCRIPTION Iron EagleX is seeking a SME Cyber Network Analyst to join our fast-paced technical team. In this role, you will analyze, engineer, and troubleshoot complex network environments... 
    Suggested
    Contract work

    General Dynamics Information Technology

    Arlington, VA
    13 days ago
  • $70k - $115k

     ...databases, models, approaches and techniques. Analysts use problem-solving principles, processes...  ...VA. Description: We are seeking a Cyber Risk Data Engineer/Analyst . This role...  ...skills to document findings and support SME deliverables. Preferred Qualifications... 
    Suggested
    Internship
    Shift work

    Technomics

    Arlington, VA
    2 days ago
  • NTT DATA seeks a Cybersecurity and Risk Analyst to join the VAPT team, identifying and mitigating cybersecurity risks across enterprise systems, networks, and applications. You will perform vulnerability assessments, risk evaluations, and threat simulations aligned with... 
    Suggested

    NTT DATA North America

    Arlington, VA
    4 days ago
  • $109k - $124.4k

    Senior Associate, Cyber Governance & Risk - Cyber Exceptions Analyst Security is essential to what we do at Capital One, from protecting customer data to the associate experience. As a Cyber Exceptions Analyst within the Governance and Risk division, you see security as... 
    Suggested
    Full time
    Part time
    H1b
    Local area

    Capital One National Association

    Mc Lean, VA
    3 days ago
  •  ...Cyber Incident Response Analyst This Department of War enterprise data and analytics program delivers mission-critical capabilities that enable...  ...Leidos Digital Modernization sector is seeking an experienced SME Cyber Incident Response Analyst to support the delivery,... 
    Suggested

    Leidos

    Alexandria, VA
    18 hours ago
  • $112k - $179k

    ResponsibilitiesPeraton is currently hiring Sr Industrial Control System Cyber Threat Intelligence Analyst for its Federal Strategic Cyber programs.Location: On-site...  ...hunting engagements.Serve as subject matter expert (SME) for ICS Security activities.Identify potential open-... 
    Contract work
    Currently hiring
    Shift work

    Peraton Corporation

    Arlington, VA
    1 day ago
  • $83k - $166k

    Washington, DCAdministrative and Logistics Support /Full Time On-Site /On-siteInformation Systems Security Manager (ISSM) - SME Work Location: Washington, DC Employment Type: Full-Time, Expert-Level Department: Administrative and Logistics Support CGS is seeking a skilled... 
    Full time

    CONTACT GOVERNMENT SERVICES

    Washington DC
    3 days ago
  • OverviewAbacus Technology is seeking a Cyber Security Engineering SME to provide security and test and evaluation support for the RDT&E Engineering...  ...Management Plans, Information Support Plans, PPPs, Security Risk Analyses, Security Vulnerability and Countermeasure... 
    Full time

    Abacus Technology Corporation

    Washington DC
    2 days ago
  •  ...Description Job Description We are seeking a Subject Matter Expert (SME) Enterprise Architect to join our team supporting a large-scale...  ...records. Evaluate proposed architectural deviations, document risks and impacts, and provide recommendations for approval. Serve... 
    Flexible hours

    Ignite IT

    Washington DC
    12 days ago
  • $200k - $275k

     ...be applied in service to our country. About You You are a senior cyber infrastructure engineer, security platform engineer, or cyber...  ...Senior Cyber Infrastructure Engineer & Architect (Security Platforms SME) to support cybersecurity platform engineering, security... 
    For contractors
    Relocation package

    Virginia Tech Applied Research

    Arlington, VA
    18 hours ago
  • $100k - $150k

     ...Cybersecurity Risk Analyst Salary Range: $100,000 – $150,000 Clearance: TS/SCI + CI Poly Location: 50 miles of McLean, Virginia...  ...Cybersecurity Risk Analyst to support enterprise cybersecurity and cyber defense operations in the Washington, D.C. metropolitan area.... 
    Contract work

    OPS TECH ALLIANCE LLC

    McLean, VA
    3 days ago
  •  ...Risk Analyst The Risk Analyst is responsible for providing guidance on tools to measure and manage risk, identify/mitigate threats, and...  ...understanding of the intent, objectives, and activities of cyber threat actors and support the cyber defense program. Required... 
    Work experience placement

    Software Technology Inc

    Washington DC
    1 day ago
  •  ...provides technically advanced full-spectrum cyber, data operations, systems integration and...  ...is seeking an Enterprise Architect SME to support this critical customer mission*...  ...preferred)- Experience and/or familiarity of the Risk Management Framework (RMF) and security... 
    Contract work
    Immediate start

    Nightwing Group

    Arlington, VA
    3 days ago
  • Insight Global is seeking a Risk Assessment Analyst in a hybrid role, Alexandria, VA, to support senior DoD leadership in cybersecurity and DIB...  ...activities, and drive high-visibility initiatives to strengthen cyber posture while leveraging modern #J-18808-Ljbffr Insight... 

    Insight Global

    Alexandria, VA
    18 hours ago
  • $155k - $170k

     ...is seeking an experienced Information Systems Security Engineer SME to support a mission-critical federal cybersecurity programs in Washington...  ...expert supporting Security Assessment and Authorization, Risk Management Framework execution, cloud security, technical control... 
    Contract work

    ECS Federal

    Washington DC
    3 days ago
  • $175k - $190k

     ...DescriptionEverforth ECS is seeking an Information System Security Engineer SME to work in our Washington, DC office. Please Note: This position...  ...a strong background in security engineering, architecture, and risk management, with a focus on protecting sensitive information and... 
    Contract work
    Work at office

    ECS Federal

    Washington DC
    1 day ago
  • $161.9k - $199.26k

    GovCIO is currently hiring for a SME Network Engineer with an active Secret clearance to provide classified and unclassified Tier 3 senior-level support for the design, implementation, and deployment of network-specific technologies across a government Enterprise environment... 
    Currently hiring
    Worldwide

    Govcio

    Arlington, VA
    18 hours ago
  • $110.18k - $183.63k

     ...part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Cybersecurity and Risk Analyst to join our team in Arlington, Virginia (US-VA), United States (US). Job Summary: The Cybersecurity and Risk Analyst is a... 
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA, Inc.

    Arlington, VA
    a month ago
  • $176k - $282k

     ...Systems Security Engineer - Subject Matter Expert (SME)/Cloud-based to support its Federal Strategic Cyber programs.Location: National Capital Region (NCR):In...  ...Prepare step, ensuring roles, responsibilities, and risk management strategies are clearly defined and maintained... 
    Contract work
    Temporary work
    For contractors
    Work at office
    Shift work

    Peraton Corporation

    Washington DC
    3 days ago
  • Ops Tech Alliance seeks a Cybersecurity Risk Analyst to support enterprise cyber defense in the Washington, D.C. metro area. You will assess cybersecurity capabilities, identify operational risks and process gaps, support incident-response, and translate complex cyber... 

    OPS TECH ALLIANCE LLC

    Mc Lean, VA
    18 hours ago
  • $110.18k - $183.63k

     ...with us. If you want to be part of an inclusive, adaptable, and forward‑thinking organization. Job Summary The Cybersecurity and Risk Analyst is a critical member of the Vulnerability Assessment and Penetration Testing (VAPT) team, responsible for identifying, analyzing... 
    Temporary work
    Work at office
    Remote work
    Flexible hours

    NTT DATA North America

    Arlington, VA
    4 days ago
  • $144.9k - $265.8k

     ...landscape, organizations face increasingly complex cybersecurity risks and regulatory pressures. Identity—both human and non-human—is at...  ...core of every enterprise. As a Digital Identity & Authentication SME, you will help clients enhance user experience, reduce risk, and... 
    Work experience placement
    Summer holiday
    Flexible hours

    EY

    McLean, VA
    3 days ago
  • $120k - $165k

     ...enforcement. Our mission is to empower analysts and decision-makers through data-...  ...Praescient Analytics is seeking a Principal Cyber Systems Engineer, SME to provide high-level technical...  ...mission-level integration. Adversarial Risk Assessment: Recommend and conduct assessments... 
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    18 hours ago
  • $140k - $160k

     ...DescriptionEverforth ECS is seeking a Mid Cyber Threat Intelligence (CTI) Analyst to join our team in Arlington, VA (...  ...Mid Cyber Threat Intelligence (CTI) SME to support the organization's cyber...  ..., and emerging cybersecurity risks.Analyze vulnerabilities and assess potential... 

    ECS Federal

    Arlington, VA
    1 day ago
  • $104k - $166k

    ResponsibilitiesPeraton is currently seeking a Senior Risk and Vulnerability Analyst.Location: Chandler, AZ or Washington DCRole and Responsibilities: The Senior Risk and Vulnerability Analyst supports a 24x7 Security Operations Center (SOC) by identifying, analyzing,... 
    Contract work
    Shift work

    Peraton Corporation

    Washington DC
    4 days ago
  • $160k - $180k

     ...DescriptionEverforth ECS is seeking a Senior Cyber Threat Intelligence (CTI) Analyst to join our team in Arlington, VA (...  ...(CTI) Subject Matter Expert (SME) to lead threat intelligence...  ...proactively identify and mitigate cyber risks.Key ResponsibilitiesThreat Intelligence... 

    ECS Federal

    Arlington, VA
    1 day ago
  •  ...contingent upon contract award ***Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment and risk analysis...  ...enterprise visibility into security weaknesses and cyber risk.Responsibilities· Perform vulnerability assessments and... 
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    4 days ago
  • $161.9k - $199.26k

     ...Secret Hybrid schedule IT Infrastructure & Network Engineering & Operations Overview GovCIO is currently hiring for a SME Network Engineer with an active Secret clearance to provide classified and unclassified Tier 3 senior-level support for the design, implementation... 
    Full time
    Currently hiring
    Worldwide
    Flexible hours

    GovCIO

    Arlington, VA
    4 days ago
  • $135k - $216k

     ...experienced IT Audit Advisory Consultant/FISCAM SME to join our team. This position will...  ...report on IT CAP statuses and third-party risk management (e.g., service providers)Develop...  ...ID: 2026-165501Position Category: Cyber SecurityClearance: Top Secret/SCI w/Poly
    Contract work
    For contractors
    Shift work

    Peraton Corporation

    Herndon, VA
    3 days ago
  • Tuvli is seeking a Network Engineer SME for a government client in Alexandria, VA. This role focuses on stable operation, performance, and security of enterprise networks including LAN, WAN, and VPNs, with Juniper devices and firewall policies. Responsibilities include... 

    NANA Regional Corp

    Alexandria, VA
    18 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Risk Analyst SME. Be the first to apply!