Sr. Cyber Supply Chain Risk Management Analyst

wiscenterprises· Lifecycle Acquisition
Apply Now ↗
📍 Springfield, VA, USFULL TIME

About this role

Overview

We are seeking a technically proficient Cyber Supply Chain Risk Management (C-SCRM) professional to support U.S. Government stakeholders. The C-SCRM Analyst is responsible for identifying, assessing, and mitigating risks associated with the distributed and interconnected nature of Information and Communications Technology and Operational Technology (ICT/OT) product and service supply chains throughout their entire lifecycle. This includes protecting against malicious functionality, counterfeit components, foreign influence, and vulnerabilities derived from poor manufacturing.

Responsibilities

  • Risk Assessments: Evaluate vendor and supplier security postures (third-party/fourth-party) using frameworks such as NIST SP 800-161.
  • Threat Analysis: Monitor, analyze, and report on supply chain threats (counterfeit, malicious insertion, Tampering).
  • Policy Governance & Compliance: Lead the development, formal documentation, and maintenance of organizational C-SCRM policies, Standard Operating Procedures (SOPs), and implementation plans; concurrently monitor and enforce policy compliance across the enterprise by conducting systematic audits and risk assessments to ensure alignment with federal mandates such as NIST SP 800-161, DFARS , FAR, and Executive Order requirements.
  • Acquisition Support: Integrate C-SCRM controls into procurement documents, RFPs, and contracts, working alongside acquisition teams.
  • Technical Evaluation: Perform Software Bill of Materials (SBOM) and Hardware Bill of Materials (HBOM) analysis to identify components and vulnerabilities.
  • Operationalization: Develop and maintain C-SCRM policies, procedures, and Standard Operating Procedures (SOPs).
  • Incident Response: Support incident response teams when compromised products are identified.
  • Reporting: Create and present risk briefing materials, dashboards, and metrics to senior leadership. 
  •  

Required Qualifications

  • Education & Experience: Bachelor’s degree in Computer Science, Information Systems, Cyber Security, or Supply Chain Management, plus 2-8+ years of experience in cyber risk or supply chain management.
  • Frameworks: In-depth knowledge of NIST SP 800-161r1-upd1, NIST Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations, and Risk Management Framework (RMF).
  • Technical Skills: Experience implementing NIST and/or DoD C-SCRM policies.  Familiarity with C-SCRM/Third-Party Risk Management tools such as Exiger and eMAS
  • Security clearance: TS/SCI with Poly 

Desired Qualifications

  • Certifications: CISSP, CISM, CRISC, or C-SCRM certification.
  • Task Management: Experience with DoD/IC/NGA task management system (e.g. CATMS, NCERTS)
  • Domain Expertise: DoW Cybersecurity Supply Chain Risk Management.
  • Communications: Strong written and verbal communication skills
  • Professional Standard: Ability to execute complex workflows under general direction.  Comfortable in an independent work environment.  Self-directed.

Frequently Asked Questions

Is the salary disclosed for the Sr. Cyber Supply Chain Risk Management Analyst position at wiscenterprises?
The salary for this Sr. Cyber Supply Chain Risk Management Analyst role at wiscenterprises is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Sr. Cyber Supply Chain Risk Management Analyst position at wiscenterprises located?
This Sr. Cyber Supply Chain Risk Management Analyst role at wiscenterprises is based in Springfield, VA, US. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Sr. Cyber Supply Chain Risk Management Analyst role at wiscenterprises full-time or part-time?
This is listed as a FULL TIME position. It is posted as a Sr. Cyber Supply Chain Risk Management Analyst role in the Lifecycle Acquisition department at wiscenterprises.
Which team or department does the Sr. Cyber Supply Chain Risk Management Analyst at wiscenterprises belong to?
This Sr. Cyber Supply Chain Risk Management Analyst position is part of the Lifecycle Acquisition department at wiscenterprises. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Sr. Cyber Supply Chain Risk Management Analyst position at wiscenterprises?
Click the "Apply Now" button on this page. You will be redirected to wiscenterprises's official application portal hosted on icims where you can submit your application directly.
When was the Sr. Cyber Supply Chain Risk Management Analyst job at wiscenterprises posted?
This Sr. Cyber Supply Chain Risk Management Analyst position at wiscenterprises was posted on Jun 12, 2024. Apply as soon as possible — early applications are often reviewed first.
Sr. Cyber Supply Chain Risk Management Analyst
wiscenterprises
Apply for this role ↗

You'll be redirected to wiscenterprises's official application page on icims.