Cyber Risk Analyst SME

Technomics, Inc.

Arlington (VA)

On-site

USD 100,000 - 130,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

A decision analytics company in Arlington is looking for a Cyber Risk Analyst to conduct assessments and develop mitigation strategies. The ideal candidate should have over 10 years of experience in cybersecurity, particularly with NIST SP 800-30 and MITRE ATT&CK frameworks. This position requires strong skills in risk evaluation, collaboration with multi-disciplinary teams, and the ability to communicate effectively with stakeholders. The role offers an opportunity to make significant impacts within various critical missions.

Qualifications

  • 10+ years of experience in cybersecurity risk assessment.
  • Deep knowledge of NIST SP 800-30 and RMF.
  • Demonstrated ability to present findings to executives.

Responsibilities

  • Serve as a Subject Matter Expert in cyber risk assessment.
  • Conduct on-site and remote cyber risk assessments.
  • Develop and present risk characterization reports.

Skills

Cybersecurity risk assessment
Vulnerability analysis
Risk communication
Agility
Collaboration

Education

10+ years of experience in cybersecurity

Tools

MITRE ATT&CK
NIST SP 800-30

Job description

Current job opportunities are posted here as they become available.

Technomics is a growing employee-owned, decision analytics company that specializes in cost and economic analysis to facilitate better decisions faster. We enable a wide range of clients across the Federal government, from senior level policy makers to program managers, to choose smartly, buy effectively and operate efficiently. We deliver practical, credible and defensible results offering actionable insights by applying data-driven and analytics-based approaches in combination with multidisciplinary talent, subject matter experts, and tangible and repeatable assets in the form of databases, models, approaches and techniques.

Senior Analystshave the knowledge, skills, abilities and initiative to deliver timely, practical and innovative solutions to our clients as part of high-performing project teams typically composed of a mix of junior and mid-level analysts who will look to you for technical acumen and mentoring.

Our employee-owners pride themselves on their ability to apply deep analytical rigor and innovative thought that assist clients in understanding and solving a myriad of challenging resource planning and management problems.

This position is located in Arlington, VA.

Description:

We are seeking a Cyber Risk Analyst (SME-level). This role involves conducting on-site and remote cyber risk assessments, developing mitigation strategies, and enabling proactive enterprise risk identification.
The ideal candidate has deep experience with NIST SP 800-30, MITRE ATT&CK, and threat modeling approaches, and can translate technical risks into mission/business impacts. You will work alongside cybersecurity, OT, and systems engineering SMEs, creating task plans, presenting findings, and traveling to client sites for mission assessments.
We are looking for someone who is agile, creative, and collaborative — able to apply lessons learned, enable data tagging and structured knowledge capture, and help shift the organization from reactive responses toward proactive risk management.

Clearance Required: Active DOE Q or higher (or ability to obtain)

Key Responsibilities:
  • Serve as a Subject Matter Expert (SME) in cyber risk assessment, analysis, and mitigation strategies for critical missions.
  • Conduct on-site and remote cyber risk assessments of enterprise systems, applications, and mission-critical infrastructures.
  • Apply NIST SP 800-30 risk assessment methodology, threat modeling techniques, and frameworks such as MITRE ATT&CK to evaluate vulnerabilities, threats, and risks.
  • Develop and present risk characterization reports, mitigation considerations, and recommendations to client leadership and system owners.
  • Create and manage task plans, assessment schedules, and execution strategies to ensure effective delivery of assessment activities.
  • Collaborate with multi-disciplinary teams of SMEs (cybersecurity, systems engineering, OT, supply chain, and mission assurance) to address enterprise risks.
  • Support the identification, analysis, and validation of complex security risks and associated vulnerabilities, including both technical and operational impacts.
  • Assist in the development of threat-informed mitigation strategies aligned with client enterprise assurance goals.
  • Implement data tagging and structured knowledge capture to enable proactive risk identification, trend analysis, and lessons-learned reuse.
  • Build analytic processes that leverage historical assessment data, external threat databases, and adversary TTPs to anticipate potential risks rather than solely reacting to identified vulnerabilities.
  • Provide expert consultation on risk acceptance, mitigation prioritization, and remediation planning to stakeholders.
  • Maintain awareness of emerging threats, vulnerabilities, adversary tactics, and best practices for defense in depth across the nuclear enterprise.
Required Qualifications:
  • 10+ years of experience in cybersecurity risk assessment, vulnerability analysis, or cyber mission assurance.
  • Deep knowledge of NIST SP 800-30, NIST Risk Management Framework (RMF), and related federal standards.
  • Hands-on experience with threat modeling approaches and application of MITRE ATT&CK for risk evaluation.
  • Demonstrated ability to conduct complex cyber risk assessments and present findings to executive and technical audiences.
  • Proven ability to develop task plans, manage assessment milestones, and work independently or as part of a team.
  • Strong writing and briefing skills to produce risk reports, mitigation strategies, and decision support artifacts.
Preferred Qualifications:
  • Experience supporting national security organizations.
  • Familiarity with supply chain risk management (SCRM), insider threat analysis, or mission-critical system assurance.
  • Operational Technology (OT) and Systems Engineering (SE) experience in complex enterprise environments.
  • Knowledge of nuclear enterprise operations and mission dependencies.
  • Technical certifications such as Security+, CISSP, CISM, C-RMA, CAP, CEH, or OSCP.
  • Prior experience briefing and advising SES-level leadership or program executives.
  • Familiarity with tools supporting risk assessments and vulnerability analysis (e.g., Threat Modeling tools).
  • Hybrid environment with headquarters-based work in D.C. and regular travel to client sites for on-site risk assessments.
  • Fast-paced, collaborative environment with cross-disciplinary SMEs (cybersecurity, engineering, OT, program management, and intelligence).
  • Requires agility, creativity, and strong interpersonal skills to interact effectively with diverse stakeholders across government, contractors, and mission partners.
  • Role demands adaptability to dynamic mission needs, shifting priorities, and classified environments.
  • Emphasis on teamwork, analytical rigor, and the ability to translate technical risks into mission/business impacts.

We are an Equal Opportunity Employer. As an Equal Opportunity Employer, we do not discriminate on the basis of race, color, religion, national origin, sex, age, marital status, disability or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Risk Data Engineer/Analyst
Cyber Risk Data Engineer/Analyst

Technomics, Inc. • Arlington (VA)

On-site
USD 70,000 - 90,000
Cyber Risk Data Engineer/Analyst
Cyber Risk Data Engineer/Analyst

Technomics, Inc. • Arlington (VA)

Hybrid
USD 70,000 - 115,000
Senior Cybersecurity Analyst/Engineer
Senior Cybersecurity Analyst/Engineer

Technomics, Inc. • Arlington (VA)

On-site
USD 100,000 - 130,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Technomics, Inc. • Arlington (VA)

On-site
USD 100,000 - 130,000
Cyber Risk Analyst (TS/SCI)
Cyber Risk Analyst (TS/SCI)

Beyond SOF • Reston (VA)

On-site
USD 95,000 - 140,000
Health insurance
Cybersecurity Analyst/Engineer
Cybersecurity Analyst/Engineer

Technomics, Inc. • Arlington (VA)

On-site
USD 85,000 - 110,000
Cybersecurity Subject Matter Expert (SME) – Bethesda, MD – Active TS/SCI Clearance with Polygra[...]
Cybersecurity Subject Matter Expert (SME) – Bethesda, MD – Active TS/SCI Clearance with Polygra[...]

Synertex LLC • Bethesda (MD)

On-site
USD 180,000 - 240,000
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering, Inc. • Fort Meade (MD)

On-site
USD 150,000 - 200,000
11 paid holidays
Minimum of 3 weeks PTO
Company sponsored group medical plan
+2
ME00629-System Vulnerability Analyst 4
ME00629-System Vulnerability Analyst 4

Momentum Engineering, Inc • Fort Meade (MD)

On-site
USD 150,000 - 200,000
11 paid holidays
Minimum of 3 weeks PTO
Company-sponsored medical plan
+2
Senior OT Cybersecurity Analyst
Senior OT Cybersecurity Analyst

Rmcinc • Norfolk (VA)

Hybrid
USD 100,000 - 130,000
Comprehensive health, vision, and dental insurance
Participation in Annual Bonus Program
Life insurance policy
+3