Cyber Supply Chain Risk Management (C-SCRM) Analyst

Fortressinfosec

Washington (District of Columbia)

Hybrid

USD 89,000 - 100,000

Full time

16 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Remote and Hybrid work environment
401(k) match
Medical, dental, vision plans

Job summary

Fortress Information Security is seeking a Cyber Supply Chain Risk Management (C-SCRM) Analyst for its Government Delivery team in the District of Columbia area. The role is hybrid, with on-site work at Pax River about two days per week and flexibility as needed.

Responsibilities include analyzing cyber supply chain risks, reviewing BOMs, and translating data into risk narratives for stakeholders. Travel up to 15% and an active Secret clearance are required.

Qualifications

  • 2–4 years in cyber supply chain risk management or related field.
  • Active Secret clearance required at time of hire.
  • Experience translating risk data into business or mission impact.

Responsibilities

  • Analyze cyber supply chain risk data to identify supplier, product, software, hardware, ownership, control, influence, dependency, and vulnerability risks.
  • Review data, BOMs, and indicators for completeness and risk.
  • Translate findings into clear risk narratives and recommended actions.
  • Support program-level reporting, briefings, and deliverables with PMs and SMEs.

Skills

Cybersecurity analysis
Risk analysis
Data interpretation
Active Secret Clearance

Education

Bachelor’s Degree or equivalent

Tools

Excel
PowerPoint

Job description

Open Positions at Fortress

Fortress is building a pipeline of qualified candidates for an upcoming Cyber Supply Chain Risk Management (C-SCRM) Analyst opening. While this role is not immediately open, we expect to fill it soon and want to connect with strong candidates now so we can move quickly when it does. Thank you for your understanding!

Position: Cyber Supply Chain Risk Management (C-SCRM) Analyst

Location: District of Columbia, Maryland, and Virginia - Hybrid, DC (Hybrid – Onsite at Pax River approximately 2 days per week (6x per month) with the ability to flex as needed)

Job Id: 688

# of Openings: 1

Compensation: $89,000 - $100,000

Employment Type: Full-Time

Travel Requirements: Up to 15%

Clearance Requirement: Active Secret Clearance at time of hire

The Cyber Supply Chain Risk Management (C-SCRM) Analyst supports Fortress's Government Delivery team by identifying, analyzing, and communicating cyber supply chain risks for U.S. Navy programs. This role serves as the analytical engine behind risk discovery - reviewing submitted data, evaluating supply chain risk indicators, interpreting platform findings, and translating raw information into meaningful program and mission impact. Working closely with Management Analysts, Technical Project Managers, Delivery leaders, and technical subject matter experts, the analyst supports risk analysis, reporting, and customer delivery at scale. The role offers the opportunity to develop deep expertise in the Fortress C-SCRM Platform, Fortress deliverables, and relevant Navy systems and data, making it an ideal position for someone looking to grow as a trusted subject matter expert in federal cyber supply chain risk. This is a high-impact role directly tied to customer retention, program quality, and Fortress's continued growth across Navy accounts.

Responsibilities Include
  • Analyze cyber supply chain risk data to identify supplier, product, software, hardware, ownership, control, influence, dependency, and vulnerability risks that may impact U.S. Navy programs.
  • Review submitted data, including hardware and software bills of materials, for completeness, accuracy, consistency, and indicators of high supply chain risk.
  • Evaluate findings within the Fortress C-SCRM Platform and identify risk patterns, anomalies, or areas requiring additional review or escalation.
  • Translate raw threat and supply chain data, including indicators such as Foreign Ownership, Control, or Influence (FOCI), compromised software libraries, supplier exposure, product vulnerabilities, or bill of materials concerns, into clear risk narratives and potential mission impacts.
  • Develop subject matter expertise in the Fortress C-SCRM Platform, Fortress products, Navy systems, customer data, and program deliverables to support accurate analysis and consistent delivery outcomes.
  • Identify, document, and communicate high-risk supply chain findings so internal stakeholders and customer-fac​ing team members understand the risk, impact, and recommended next steps.
  • Partner with Management Analysts, Technical Project Managers, and technical subject matter experts to support program-level reporting, risk briefings, deliverable development, and customer milestones.
  • Serve as a subject matter expert during customer discussions when needed, including answering questions about risk findings, data interpretation, platform outputs, or deliverable content.
  • Document risk findings, assumptions, data limitations, and recommended areas for further review in a clear, defensible, and repeatable manner.
  • Support the development and refinement of analytical processes, templates, quality checks, and reporting inputs that improve consistency, efficiency, and confidence in C-SCRM deliverables.
  • Use Excel to review, organize, analyze, validate, and summarize supply chain, supplier, platform, bill of materials, or risk data.
  • Use PowerPoint to support clear communication of risk findings, trends, impacts, and recommendations in customer-ready or internal briefing materials.
  • Apply intermediate AI proficiency to improve research, analysis, summarization, pattern recognition, and workflow efficiency while following Fortress, customer, and security requirements for responsible AI use.
  • Maintain awareness of cyber supply chain risk concepts, threat intelligence, supplier risk indicators, software risk, hardware risk, and federal cybersecurity requirements relevant to government and defense customers.
  • Protect sensitive customer, supplier, product, and program information in accordance with applicable security, contractual, clearance, and customer requirements.
  • Travel up to 15% for potential customer site visits, in-person meetings, or program-related engagements.
Minimum Qualifications
  • 2–4 years of experience in cyber supply chain risk management, cybersecurity analysis, threat intelligence, supplier risk, risk analysis, federal consulting, government delivery, or a related field.
  • Active Secret clearance required at time of hire.
  • Experience analyzing technical, supplier, product, vendor, threat, bill of materials, or risk data and translating findings into clear business, operational, or mission impact.
  • Understanding of cyber supply chain risk concepts, including supplier risk, software risk, hardware risk, third‑party risk, ownership/control concerns, threat exposure, and vulnerability or compromise indicators.
  • Ability to review data for accuracy, completeness, and risk significance while documenting findings clearly and objectively.
  • Ability to learn specialized platforms, customer systems, product workflows, and data structures quickly and apply that knowledge to risk analysis and deliverable development.
  • Proficiency with Microsoft Excel, including the ability to organize, filter, compare, review, and summarize data.
  • Proficiency with Microsoft PowerPoint, including the ability to support clear, professional presentations and briefing materials.
  • Strong written communication skills with the ability to summarize complex risk information for internal stakeholders, program teams, and occasional customer‑facing discussions.
  • Ability to serve as a subject matter expert on risk findings, platform outputs, and deliverable content when needed.
  • Ability to work effectively in a hybrid environment in the Washington, DC area.
  • Ability to collaborate with project managers, analysts, technical teams, and delivery leaders while operating with moderate independence.
  • Intermediate proficiency using AI tools to support research, analysis, summarization, and productivity while applying sound judgment, validation, and responsible‑use practices.
  • Ability to travel up to 15% for customer on‑site visits, in-person meetings, or program‑related engagements.
  • Ability to handle sensitive information and comply with applicable security, confidentiality, clearance, and customer requirements.
Preferred Skills
  • Security+ certification or other related cybersecurity, risk management, supply chain risk, or information assurance certification.
  • Experience supporting Department of Defense, Department of Navy, federal civilian, or defense industrial base customers.
  • Experience with C-SCRM, SCRM, vendor risk management, third‑party risk management, software supply chain risk, hardware supply chain risk, cyber threat intelligence, or product assurance.
  • Familiarity with FOCI, SBOM, HBOM, supplier risk scoring, vulnerability data, compromised software libraries, or product assurance workflows.
  • Experience reviewing bills of materials, supplier data, software component data, hardware component data, product data, or platform‑generated risk findings.
  • Experience using data analysis, case management, risk management, cybersecurity, or reporting platforms to evaluate and communicate risk.
  • Familiarity with federal cybersecurity frameworks, standards, or guidance such as NIST, CMMC, FedRAMP, RMF, or DoD cybersecurity requirements.
  • Experience producing written findings, risk summaries, briefing inputs, or analytical reports for government or regulated customers.
Education
  • Bachelor’s Degree or equivalent professional work experience required.
Employee Benefits
  • Remote and Hybrid working environment
  • Competitive pay structure
  • Medical, dental, vision plans with employees covered up to 90% with highly progressive options for dependents and families
  • Company paid life, short- and long‑term disability insurance
  • Employee Assistance Program
  • 401(k) match
  • Flexible Paid Time Off
  • Parental Leave
Employment Perks
  • We provide each employee with professional growth opportunities through succession planning, up‑skilling, and certifications
  • Tuition and certification reimbursement
  • Employee Referral Programs
  • Company Sponsored Events

Fortress is proud to be an Equal Opportunity Employer. All employees and applicants will receive consideration for employment without regard to age, color, disability, gender, national origin, race, religion, sexual orientation, gender identity, protected veteran status, or any other classification protected by federal, state, or local law. Fortress Information Security takes part in the E‑Verify process for all new hires. For positions located in the US, the following conditions apply. If you are made a conditional offer of employment, you will have to undergo a drug test. ADA Disclaimer: In developing this job description care was taken to include all competencies needed to successfully perform in this position. However, for Americans with Disabilities Act (ADA) purposes, the essential functions of the job may or may not have been described for purposes of ADA reasonable accommodation. All reasonable accommodation requests will be reviewed and evaluated on a case-by-case basis.

Pay Range: $89,000 - $100,000 per hour

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Supply Chain Risk Management (C-SCRM) Analyst
Cyber Supply Chain Risk Management (C-SCRM) Analyst

Fortress Information Security, LLC • Maryland

Hybrid
USD 89,000 - 100,000
Remote and Hybrid working environment
Medical, dental, vision plans
401(k) match
+1
Cyber Supply Chain Risk Management (C-SCRM) Analyst
Cyber Supply Chain Risk Management (C-SCRM) Analyst

Fortress • Washington, Virginia (IL)

Hybrid
USD 89,000 - 100,000
Remote and Hybrid working environment
Medical, dental, vision plans
Data Quality Analyst
Data Quality Analyst

Fortressinfosec • Maryland

Hybrid
USD 89,000 - 128,000
Remote and Hybrid working environment
Competitive pay structure
Medical, dental, vision plans
Software and Data Quality Analyst
Software and Data Quality Analyst

Fortress Information Security, LLC • Maryland

Hybrid
USD 89,000 - 128,000
Remote and Hybrid working environment
Competitive pay structure
Medical, dental, vision plans
+3
Data Quality Analyst
Data Quality Analyst

Fortress • Virginia (MN), Washington

Hybrid
USD 89,000 - 128,000
Remote and hybrid working environment
Competitive pay structure
Medical, dental, and vision plans
+2
Configuration and Cybersecurity Specialist
Configuration and Cybersecurity Specialist

Fortress Information Security • Washington

Hybrid
USD 110,000 - 171,000
Remote and Hybrid working environment
Competitive pay structure
Medical, dental, vision coverage 90%+
+1
Configuration and Cybersecurity Specialist
Configuration and Cybersecurity Specialist

Fortress Information Security, LLC • Maryland

Hybrid
USD 110,000 - 171,000
Remote/hybrid options
Competitive pay
Medical/dental/vision
+3
Senior Technical Project Manager
Senior Technical Project Manager

Fortress Information Security, LLC • Town of Florida (NY)

Hybrid
USD 110,000 - 180,000
Competitive pay
Medical, dental, vision
401(k) match
+3
Principal Forward Deployed Engineer
Principal Forward Deployed Engineer

Fortress Information Security • Town of Florida (NY)

On-site
USD 172,000 - 250,000
Remote and Hybrid working environment
Competitive pay structure
401(k) match
+2
Principal Forward Deployed Engineer
Principal Forward Deployed Engineer

Fortress Information Security, LLC • Town of Florida (NY)

Hybrid
USD 172,000 - 250,000
Remote/Hybrid work options
Competitive pay
Health plans
+5