SCRM & AI Security Risk Analyst

K2United, LLC.

Washington (District of Columbia)

On-site

USD 120,000 - 170,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

K2United, LLC seeks a cybersecurity risk professional to support SCRM programs and AI security reviews across federal-facing technology. You will analyze third-party and tech risks, maintain SCRM records, and provide risk mitigation recommendations for software, systems, and services that use AI or emerging capabilities.

The role requires four-plus years in cybersecurity risk or vendor risk, a bachelor's in a related field, and strong written analysis skills.

Qualifications

  • Bachelor's degree or equivalent in cybersecurity or IT.
  • 4+ years in cybersecurity risk, third-party or vendor risk.
  • Experience with third-party risk assessments and risk analyses.
  • Familiarity with OMB M-21-30, M-22-18, M-23-16 and NIST SP 800-218.
  • Strong written communication and deliverables.

Responsibilities

  • Support the operation and enhancement of the client's SCRM activities, including documentation support, stakeholder coordination, and maintenance of SCRM records.
  • Analyze third-party and technology-related security risks and prepare risk mitigation recommendations.
  • Identify gaps in current SCRM practices and recommend improvements to process, monitoring, governance, and reporting.
  • Support evaluation of the security posture of third-party technologies and evolving cyber risks.
  • Support AI security-related compliance, vulnerability, and risk activities for software, systems, services, and tools incorporating AI-enabled functions or emerging technologies.
  • Perform security review support and risk analysis; develop recommendations for secure implementation and governance considerations.
  • Coordinate with stakeholders on the security implications of emerging technical capabilities.
  • Support secure adoption assessments for modernization, automation, and analytics opportunities.
  • Apply OMB M-21-30, M-22-18, and M-23-16; NIST software supply chain security guidance; NIST SP 800-218 (Secure Software Development Framework); and the NIST AI Risk Management Framework and Playbook.

Skills

SCRM knowledge
Vendor risk analysis
Security compliance analysis
Federal policy familiarity
Written communication

Education

Bachelor's degree in cybersecurity or IT

Tools

SBOM generation

Job description

K2United, LLC seeks a cybersecurity risk professional to support SCRM programs and AI security reviews across federal-facing technology. You will analyze third-party and tech risks, maintain SCRM records, and provide risk mitigation recommendations for software, systems, and services that use AI or emerging capabilities.

The role requires four-plus years in cybersecurity risk or vendor risk, a bachelor's in a related field, and strong written analysis skills.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SCRM & AI Security Analyst
SCRM & AI Security Analyst

K2Share LLC • Washington

On-site
USD 120,000 - 170,000
SCRM/Emerging Technology Security Analyst
SCRM/Emerging Technology Security Analyst

K2Share LLC • Washington

On-site
USD 120,000 - 170,000
SCRM/Emerging Technology Security Analyst
SCRM/Emerging Technology Security Analyst

K2United, LLC. • Washington

On-site
USD 120,000 - 170,000
C-SCRM Cybersecurity Expert | Federal Risk Leader
C-SCRM Cybersecurity Expert | Federal Risk Leader

Socket.dev • Washington

On-site
USD 150,000 - 175,000
401(k) with employer match
Paid time off & holidays
Parental leave
+1
Senior C-SCRM Specialist - Cybersecurity & Supply Chain
Senior C-SCRM Specialist - Cybersecurity & Supply Chain

Akira Technologies Inc. • Washington

On-site
USD 150,000 - 175,000
Senior AI Risk Analyst
Senior AI Risk Analyst

10xTalents • Malvern

Hybrid
USD 100,000 - 130,000
Lead Cybersecurity Supply Chain Risk Manager (C-SCRM SME)
Lead Cybersecurity Supply Chain Risk Manager (C-SCRM SME)

ADP, Inc. • Washington

On-site
USD 150,000 - 175,000
Health insurance
401(k) with employer match
Paid time off
+1
GRC Vendor Risk Analyst: AI Governance & Security
GRC Vendor Risk Analyst: AI Governance & Security

Community Bank, N.A. • City of Oneonta (NY)

On-site
USD 60,000 - 90,000
AI Risk & Tech Governance Senior Associate
AI Risk & Tech Governance Senior Associate

RSM US LLP • Chicago (IL)

On-site
USD 78,000 - 147,000
Federal AI Security Analyst - Risk & Compliance
Federal AI Security Analyst - Risk & Compliance

Accenture Federal Services • Arlington (VA)

On-site
USD 83,000 - 185,000