Senior Cybersecurity SME

Arlington, VA

Who we are and why you should join us:

As a consultant at Partner Forces, you will serve as a trusted advisor to our clients’ day in and day out. You will have the opportunity to collaborate with your colleagues, our partners, and our clients to ideate, initiate and complete tasks, projects, and initiatives. You will work on mission-oriented projects, where you will bring forward actionable insights, solve complex problems, and thrive on delivering meaningful solutions.

Partner Forces is grounded in our core values of integrity, excellence, positivity, candor, determination, and teamwork. Our culture is a reflection of this, ensuring that we:

  • Apply solution-oriented thinking to challenges and opportunities.
  • Thrive by remaining agile and embracing change.
  • Work to create an environment where everyone feels welcome and valued as teammates and contributors.
  • Bring out the best in others by applying sound judgment and exuding principled genuineness.
  • Embrace a continuous learning and growth mindset.
  • Encourage an open dialogue even when it is hard.
  • Continuously promoting teamwork and collaboration to achieve the best outcomes for our clients and teams.

As an employee at Partner Forces, you’ll join a team of consultants who share a passion for prioritizing collaboration, crafting solutions to mitigate risk, protecting critical infrastructure and helping our national security and industry partner tackle their most pressing challenges. At Partner Forces, we take our employees’ well-being and growth as seriously as we do our mission. You will be challenged every day, but we know that business and individual growth go hand-in-hand, so we offer a wide array of benefits that support the well-being and personal and professional development of our employees.

What we are looking for:

The Senior Cyber Analyst Subject Matter Expert (SME) will support the Cybersecurity and Infrastructure Security Agency (CISA) in designing and enhancing an improved incident response system. The ideal candidate will have deep expertise in cybersecurity, threat intelligence, and incident response, with a proven ability to develop and document repeatable SOPs and working instructions. This role plays a critical part in enabling CISA’s cybersecurity reporting and response initiatives, ensuring seamless coordination across the agency.

What you will do as a Senior Cyber Analyst SME:

  • Incident Analysis & Enrichment
    • Analyze, enrich, and triage cybersecurity incident reports to add contextual detail.
    • Identify and assess changing patterns, trends, technologies, Tactics, Techniques, and Procedures (TTPs).
    • Correlate reported incidents to known threat campaigns, adversary groups, and vulnerabilities (e.g., zero-day exploits).
  • Operational & Strategic Support
    • Assist in cyber analysis operations, ensuring adherence to CISA’s standard operating procedures, quality control standards, and best practices.
    • Support federal employees in analyzing operational environments, identifying new threat activities, and providing key recommendations to leadership and the larger CISA analytic community.
    • Collaborate with teams to ensure cohesive incident response and situational awareness.
  • Process & SOP Development
    • Develop and maintain comprehensive Standard Operating Procedures (SOPs) and Working Instructions (WIs) for incident handling and cybersecurity reporting.
    • Establish repeatable and effective processes for rapid threat identification, classification, and escalation.
    • Conduct regular reviews and audits of existing SOPs and WIs to ensure alignment with evolving threats and organizational priorities.
  • Threat Intelligence Integration
    • Integrate diverse threat intelligence sources (open-source, commercial, and classified) to enrich incident reports and vulnerability assessments.
    • Leverage frameworks like MITRE ATT&CK and the NIST Cybersecurity Framework (CSF) to map threat behaviors and strengthen detection and response capabilities.
    • Provide operationally relevant analysis of CIRCIA reporting for alignment to CISA priorities.
  • Communication & Coordination
    • Prepare and deliver briefings, reports, and presentations to senior leadership and stakeholders on emerging threats, significant incidents, and recommended mitigation strategies.
    • Foster a collaborative environment by sharing relevant threat intelligence and best practices across organizational lines.
    • Support outreach efforts to federal, state, local, and private-sector partners to enhance overall cybersecurity posture.
  • Tool & Technology Expertise
    • Identify and recommend enhancements to the incident response tool stack, including SIEM (e.g., Splunk, QRadar), Endpoint Detection and Response (EDR) solutions, Threat Intelligence Platforms (TIP) (e.g., MISP, ThreatConnect), and vulnerability management tools (e.g., Tenable Nessus, Qualys).
    • Continuously evaluate cutting-edge cybersecurity technologies and make recommendations for implementation to bolster CISA’s incident response capabilities.

Qualifications:

  • US Citizen (the nature of our contract requires employees be US citizens).
  • Top Secret clearance required.
  • At least 10 years of experience; 5-7 yeas of hands-on cybersecurity experience focused on threat analysis, threat intelligence, incident detection and incident response. 
  • Demonstrated success in investigating complex cybersecurity incidents and designing solutions for large-scale environments.
  • Bachelor’s degree preferred.
  • Strong analytical and problem-solving skills with the ability to conduct in-depth research and analysis.
  • Excellent communication skills, both written and verbal, for reporting and stakeholder engagement.
  • Proficiency in using cybersecurity frameworks and tools for forensic analysis.
  • Experience in developing and documenting effective cybersecurity processes and procedures.
  • Familiarity with emerging technologies and trends in cybersecurity.
  • Strong understanding of network security principles and intrusion detection methodologies.
  • Ability to identify and mitigate cybersecurity threats and vulnerabilities effectively.
  • Hybrid / In-person at Arlington and Washington, DC locations

Preferred Qualifications:

  • Relevant certifications such as CISM, CEH, or GIAC.
  • Experience with Mitre ATT&CK and other analytic frameworks.
  • Experience in the energy sector or other critical infrastructure industries.

At Partner Forces, we consider many factors when making compensation decisions, reflecting the unique skills and experiences each candidate brings, as well as organizational and contractual needs. An estimate of the salary range for this role is included here. We believe that salary is just one component of your total compensation package. Our goal is to support your growth and reward your contributions in a meaningful way. We look forward to exploring this further with you during the interview process.

Annual Salary Range

$165,000 - $180,000 USD

The Company

Partner Forces, LLC is a management consulting firm specializing in helping homeland security partners tackle their most pressing and complex challenges. We provide holistic, integrated solutions across the homeland and national security enterprise, offering expertise in program development and analysis, stakeholder engagement, strategic planning, technology implementation, security and preparedness assessment, and business process improvement.

Partner Forces is an equal opportunity employer. We do not discriminate based on race, color, religion, sex, national origin, disability, protected veteran status, or any other characteristic protected by applicable law. We are committed to fostering a workplace where all employees feel valued and respected. If you are unable to submit your application because of incompatible assistive technology or a disability, please contact us at recruiting@partnerforces.com. 

 

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...

Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Partner Forces’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.