SCRM/Emerging Technology Security Analyst

K2United, LLC.

Washington (District of Columbia)

On-site

USD 120,000 - 170,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

K2United, LLC seeks a cybersecurity risk professional to support SCRM programs and AI security reviews across federal-facing technology. You will analyze third-party and tech risks, maintain SCRM records, and provide risk mitigation recommendations for software, systems, and services that use AI or emerging capabilities.

The role requires four-plus years in cybersecurity risk or vendor risk, a bachelor's in a related field, and strong written analysis skills.

Qualifications

  • Bachelor's degree or equivalent in cybersecurity or IT.
  • 4+ years in cybersecurity risk, third-party or vendor risk.
  • Experience with third-party risk assessments and risk analyses.
  • Familiarity with OMB M-21-30, M-22-18, M-23-16 and NIST SP 800-218.
  • Strong written communication and deliverables.

Responsibilities

  • Support the operation and enhancement of the client's SCRM activities, including documentation support, stakeholder coordination, and maintenance of SCRM records.
  • Analyze third-party and technology-related security risks and prepare risk mitigation recommendations.
  • Identify gaps in current SCRM practices and recommend improvements to process, monitoring, governance, and reporting.
  • Support evaluation of the security posture of third-party technologies and evolving cyber risks.
  • Support AI security-related compliance, vulnerability, and risk activities for software, systems, services, and tools incorporating AI-enabled functions or emerging technologies.
  • Perform security review support and risk analysis; develop recommendations for secure implementation and governance considerations.
  • Coordinate with stakeholders on the security implications of emerging technical capabilities.
  • Support secure adoption assessments for modernization, automation, and analytics opportunities.
  • Apply OMB M-21-30, M-22-18, and M-23-16; NIST software supply chain security guidance; NIST SP 800-218 (Secure Software Development Framework); and the NIST AI Risk Management Framework and Playbook.

Skills

SCRM knowledge
Vendor risk analysis
Security compliance analysis
Federal policy familiarity
Written communication

Education

Bachelor's degree in cybersecurity or IT

Tools

SBOM generation

Job description

Description

K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.

Our four core values define how we show up every day:

  • Respect Others - We lead with respect, building trust and connection.
  • Internally Driven - We are relentlessly compelled to accomplish our objectives.
  • Collaborative Innovation - We create by listening, sharing, and working together.
  • Client Success - We hold our clients' mission as our own.

We believe in people who are accountable, curious, and motivated to make an impact that matters.

Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.

Position Summary

Support the client's Supply Chain Risk Management (SCRM) program and the security review of AI-enabled and emerging technologies. This position analyzes third-party and technology-related security risk, maintains SCRM records and documentation, identifies gaps in current SCRM practice, and provides risk analysis and secure-implementation recommendations for software, systems, and services that incorporate AI or other emerging capabilities affecting enterprise risk.

Key Responsibilities
  • Support the operation and enhancement of the client's SCRM activities, including documentation support, stakeholder coordination, and maintenance of SCRM records.
  • Analyze third-party and technology-related security risks and prepare risk mitigation recommendations.
  • Identify gaps in current SCRM practices and recommend improvements to process, monitoring, governance, and reporting.
  • Support evaluation of the security posture of third-party technologies and evolving cyber risks.
  • Support AI security-related compliance, vulnerability, and risk activities for software, systems, services, and tools incorporating AI-enabled functions or emerging technologies.
  • Perform security review support and risk analysis; develop recommendations for secure implementation and governance considerations.
  • Coordinate with stakeholders on the security implications of emerging technical capabilities.
  • Support secure adoption assessments for modernization, automation, and analytics opportunities.
  • Apply OMB M-21-30, M-22-18, and M-23-16; NIST software supply chain security guidance; NIST SP 800-218 (Secure Software Development Framework); and the NIST AI Risk Management Framework and Playbook.
  • Maintain currency with emerging NIST publications on AI topics and translate them into practical review criteria.
  • Support compliance with the client's Secure and Trustworthy Artificial Intelligence Policy, including the written-approval workflow, required disclosures covering training data sources, learning cutoff dates and model limitations, human-oversight requirements, output review controls, and AI activity logging.
Requirements
  • Bachelor's degree in cybersecurity, information technology, risk management, or a related field. Equivalent experience considered in lieu of degree.
  • Four or more years in cybersecurity risk, third-party or vendor risk, or security compliance analysis.
  • Demonstrated experience performing third-party or supply chain security risk assessments and producing written risk analyses and mitigation recommendations.
  • Working knowledge of federal software supply chain policy - OMB M-21-30, M-22-18, and M-23-16 - and NIST SP 800-218.
  • Familiarity with the NIST AI Risk Management Framework and the security and governance considerations specific to AI-enabled systems.
  • Strong written analysis skills. This position produces recurring written deliverables reviewed by the OCISO.
Preferred Qualifications
  • SBOM generation, ingestion, and analysis experience.
  • Experience with FedRAMP package review and third-party SaaS security assessment.
  • Experience developing AI governance intake and review workflows, including model documentation and disclosure review.
  • Familiarity with the FCC Covered List and covered equipment and services screening obligations.

Applicants must be willing to take a drug test and submit to a credit and background investigation as part of the selection process.

The U.S. government restricts access by Foreign Nationals to certain types of technology and technical data. Consequently, this posting is intended only for U.S. citizens.

K2United, LLC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or protected Veteran status.

This job description is not an exhaustive list of job responsibilities. K2United management reserves the right to change or alter this job description at any time without notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SCRM/Emerging Technology Security Analyst
SCRM/Emerging Technology Security Analyst

K2Share LLC • Washington

On-site
USD 120,000 - 170,000
SCRM & AI Security Risk Analyst
SCRM & AI Security Risk Analyst

K2United, LLC. • Washington

On-site
USD 120,000 - 170,000
SCRM & AI Security Analyst
SCRM & AI Security Analyst

K2Share LLC • Washington

On-site
USD 120,000 - 170,000
Security Operations AI Engineer, Contract
Security Operations AI Engineer, Contract

Talanto • Northern (KY)

Hybrid
USD 120,000 - 150,000
Security Control Assessor/Representatives
Security Control Assessor/Representatives

Dark Wolf Solutions, LLC • Arlington (VA)

Hybrid
USD 135,000 - 150,000
Hybrid/remote opportunities
EEO/AA employer
AI-Assisted Cyber Analysis Specialist
AI-Assisted Cyber Analysis Specialist

Jobgether • United States

On-site
USD 90,000 - 190,000
Healthcare and wellness benefits
Financial and retirement benefits
Continuing education
Security Engineer - Governance Risk Compliance
Security Engineer - Governance Risk Compliance

Xai • New York (NY)

On-site
USD 100,000 - 228,000
Equity
Comprehensive medical, vision, and dental coverage
401(k) retirement plan
+2
AI Security Engineer - Mid
AI Security Engineer - Mid

Koniag Government Services • Washington

Hybrid
USD 120,000 - 170,000
Medical insurance
Dental insurance
Vision insurance
+7
Senior Cyber Defense & AI Security Engineer
Senior Cyber Defense & AI Security Engineer

Broadview Federal Credit Union • City of Albany (NY)

On-site
USD 106,194 - 138,052
Cyber Security Analyst II
Cyber Security Analyst II

Scientific Research Corporation • San Diego (CA)

On-site
USD 84,000 - 140,000
Medical, dental, and vision plans
401(k) with company match
Paid time off & holidays
+1