Senior Risk & Compliance Analyst (C-SCRM Lead)

Connected Logistics

Springfield (VA)

Remote

USD 115,000 - 125,000

Full time

13 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) plan
Paid Time Off

Job summary

Connected Logistics seeks a Senior Risk & Compliance Analyst (C-SCRM Lead) to support the VA OIS COSE program, focusing on cybersecurity risk management and supply chain risk controls.

The role leads risk assessments, threat analyses, and C-SCRM efforts across systems and the supply chain, guiding remediation, monitoring, and documentation with federal program experience.

Qualifications

  • Bachelor's degree or equivalent in a technical field with 5+ years in cybersecurity/risk management.
  • Experience conducting IT security risk assessments, threat analyses, and control assessments.
  • Knowledge of RMF, NIST CSF, and supply chain risk management concepts.

Responsibilities

  • Lead cybersecurity risk management, compliance, and C-SCRM activities across systems, apps, infra, and cloud environments.
  • Conduct IT security risk assessments, threat analyses, and vulnerability evaluations.
  • Lead C-SCRM assessments of products, software, hardware, services, and third-party dependencies.
  • Identify and evaluate supply chain cybersecurity risks in procurement and development lifecycles.
  • Develop and maintain risk registers, POA&Ms, and remediation plans.
  • Support RMF processes: assessment, authorization, and continuous monitoring.
  • Communicate risk posture and remediation options to leadership and stakeholders.

Skills

IT risk assessments
C-SCRM
RMF
Threat analysis
Risk communication
Stakeholder coordination
Vulnerabilities
Security controls
Analytics

Education

Bachelor's degree in Cybersecurity/CS/IT/Engineering/IS/Risk Management
Associate's degree + 2 years experience

Job description

Description

Contingent Upon Contract Award

Remote with occasional on-site support

Connected Logistics is seeking a Senior Risk & Compliance Analyst (C-SCRM Lead) to support the Cybersecurity Architecture and Engineering Services supporting the Department of Veterans Affairs (VA) Office of Information Security (OIS) Cybersecurity Operations Systems Engineering (COSE) program.

The Senior Risk & Compliance Analyst (C-SCRM Lead) serves as the lead subject matter expert for cybersecurity risk management, compliance, and Cybersecurity Supply Chain Risk Management (C-SCRM). This position provides expertise in conducting IT security risk assessments, threat and vulnerability analysis, and security control assessments to identify and evaluate risks to organizational systems, platforms, applications, data, and supporting technology supply chains. The Senior Risk & Compliance Analyst assesses the potential exposure of proprietary, sensitive, and mission-critical information resulting from weaknesses in technology platforms, security controls, access procedures, system configurations, third-party products and services, or other forms of access to organizational systems and data. The role leads C-SCRM activities and supports the identification, documentation, prioritization, mitigation, and continuous monitoring of cybersecurity and supply chain risks throughout the system and acquisition lifecycle.

Key Responsibilities
  • Lead cybersecurity risk management, compliance, and C-SCRM activities across systems, applications, infrastructure, cloud environments, products, services, and supporting technology supply chains.
  • Conduct comprehensive IT security risk assessments and threat analyses to identify vulnerabilities, control weaknesses, threat exposure, and potential impacts to organizational systems and data.
  • Lead and coordinate Cybersecurity Supply Chain Risk Management (C-SCRM) assessments of technology products, software, hardware, services, suppliers, vendors, and other third-party dependencies.
  • Identify and evaluate supply chain cybersecurity risks associated with product provenance, supplier dependencies, software components, third-party services, and technology acquisition.
  • Conduct and oversee security control assessments to determine the effectiveness of implemented security safeguards and identify gaps requiring remediation or risk treatment.
  • Evaluate risks associated with unauthorized access, excessive privileges, insecure access procedures, platform vulnerabilities, system configurations, data protection weaknesses, and third-party access.
  • Develop and maintain cybersecurity and C-SCRM risk registers, documenting identified risks, likelihood, impact, risk severity, mitigating controls, responsible parties, and remediation status.
  • Perform risk analysis and develop actionable risk mitigation and remediation recommendations based on identified threats, vulnerabilities, control deficiencies, and organizational risk tolerance.
  • Track identified security deficiencies and remediation activities through closure, including supporting the development and management of Plans of Action and Milestones (POA&Ms) where applicable.
  • Support implementation and execution of organizational Risk Management Framework (RMF) processes, including security assessment, authorization, continuous monitoring, and ongoing risk management activities.
  • Assess compliance with applicable organizational cybersecurity policies, security requirements, contractual obligations, and established security control frameworks.
  • Review system security documentation, assessment results, vulnerability findings, control evidence, architecture artifacts, and supporting documentation to determine cybersecurity risk and compliance posture.
  • Collaborate with cybersecurity, engineering, architecture, acquisition, program management, and operational stakeholders to integrate security and supply chain risk considerations into technical and business decisions.
  • Provide risk-based recommendations to program and cybersecurity leadership, clearly communicating technical risks, business impacts, mitigation alternatives, residual risk, and recommended courses of action.
  • Support continuous monitoring of cybersecurity and supply chain risks, including changes to systems, suppliers, technologies, threat conditions, vulnerabilities, and operational environments.
  • Develop and maintain risk assessment reports, compliance documentation, C-SCRM artifacts, executive risk summaries, metrics, dashboards, and other supporting cybersecurity documentation.
  • Serve as a senior cybersecurity risk and C-SCRM advisor, providing technical guidance and subject matter expertise to project teams, system owners, security personnel, and organizational leadership.
Requirements
  • Public Trust: T4 or T5 (TS)
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Information Systems, Risk Management or a related technical discipline or an Associate's degree in the above discipline with an additional 2 years of experience.
  • Minimum of five (5) years of relevant professional experience in cybersecurity, information security, IT risk management, security compliance, security assessment, C-SCRM, or a related field.
  • Demonstrated experience conducting IT security risk assessments, threat analyses, and security control assessments.
  • Experience identifying and evaluating cybersecurity risks associated with system vulnerabilities, access controls, security procedures, technical platforms, applications, and organizational data.
  • Experience assessing risk and recommending appropriate security controls, mitigation strategies, remediation actions, and risk treatment approaches.
  • Knowledge of cybersecurity risk management concepts, assessment methodologies, security controls, vulnerability management, compliance, and continuous monitoring.
  • Ability to analyze technical and cybersecurity information and translate findings into understandable risk statements and actionable recommendations for technical and non-technical stakeholders.
  • Strong analytical, documentation, communication, and stakeholder coordination skills.
  • Ability to develop high-quality security assessment reports, risk documentation, compliance artifacts, and executive-level risk summaries.
Preferred Qualifications
  • Experience leading or supporting Cybersecurity Supply Chain Risk Management (C-SCRM) programs, assessments, or governance activities in a federal environment.
  • Working knowledge of NIST Risk Management Framework (RMF) principles and federal cybersecurity risk management practices.
  • Experience evaluating cybersecurity risks associated with third-party vendors, suppliers, software, hardware, cloud services, and externally provided technology services.
  • Experience supporting security authorization, continuous monitoring, security control assessment, vulnerability management, risk remediation, and POA&M processes.
  • Experience developing and maintaining enterprise or program-level cybersecurity and C-SCRM risk registers, risk scoring methodologies, mitigation plans, and reporting metrics.
  • Experience integrating cybersecurity risk considerations into system acquisition, engineering, architecture, DevSecOps, and lifecycle management processes.
  • Familiarity with federal cybersecurity and supply chain security standards, guidance, and control frameworks applicable to C-SCRM and IT risk management.
  • Experience communicating complex cybersecurity and supply chain risks to senior leadership and providing clear recommendations that support informed risk decisions.
  • Relevant cybersecurity, risk management, audit, or governance certifications are preferred, such as CISSP, CISM, CRISC, CAP/CGRC, or equivalent credentials.
Total Rewards Statement

We believe in fairness and clarity throughout our hiring process. The anticipated salary range for this position is $115,000.00-$125,000.00 USD. This is a good-faith range based on factors such as your experience, geographic location, and any applicable contractual requirements, and may vary slightly.

Beyond salary, we provide a robust benefits package and encourage ongoing professional development, because your growth and well-being matter to us. We're excited to support you in building a rewarding career with us!

Connected Logistics respects the need for confidentiality for all applicants.

Connected Logistics has been named a 2026 WTOP Top Workplace in the medium sized business category. Our mission is clear: we deliver mission-focused IT, cybersecurity, logistics, and enterprise modernization support to federal agencies. When we invest in our people and create an environment where they feel valued and empowered, we deliver stronger outcomes for our clients and the missions we support.

Connected Logistics offers an excellent benefits package that includes health, dental, vision, life, and disability insurance, a great 401(k) package, and generous Paid Time Off.

EOE/Disability/Veterans

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Connected Logistics • Springfield (VA)

On-site
USD 120,000 - 130,000
Senior Tool Integration Engineer
Senior Tool Integration Engineer

Connected Logistics • Springfield (VA)

Remote
USD 150,000 - 160,000
DevSecOps Engineer- SR
DevSecOps Engineer- SR

Logc2 • United States

Remote
USD 110,000 - 120,000
Health insurance
401(k) benefits
Paid time off
+1
Senior Security Architect 1 (Architecture Reviews, Threat Modeling, Solution Architectures)
Senior Security Architect 1 (Architecture Reviews, Threat Modeling, Solution Architectures)

Connected Logistics • Springfield (VA)

Remote
USD 140,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+2
Senior Security Architect (Cloud, Zero Trust, Identity, Security Patterns))
Senior Security Architect (Cloud, Zero Trust, Identity, Security Patterns))

Connected Logistics • Springfield (VA)

Hybrid
USD 140,000 - 150,000
Health, dental, vision, life insurance
401(k) plan
Paid Time Off
Security Engineer (Security Automation Engineer)- Mid
Security Engineer (Security Automation Engineer)- Mid

Connected Logistics • Springfield (VA)

Hybrid
USD 100,000 - 110,000
Deputy Program Manager
Deputy Program Manager

Connected Logistics • Springfield (VA)

On-site
USD 165,000 - 175,000
Health insurance
Dental insurance
Vision insurance
+4
Risk and Compliance Analyst
Risk and Compliance Analyst

Triumph Enterprises, Inc • Washington, Northern (KY)

On-site
USD 110,000 - 150,000
Program Manager
Program Manager

Connected Logistics • Springfield (VA)

On-site
USD 180,000 - 190,000
Health, dental, vision, life insurance
401(k) plan
Paid Time Off
Compliance SME, Intermediate
Compliance SME, Intermediate

Logc2 • Huntsville (AL)

On-site
USD 140,000 - 150,000
Health, dental, vision insurance
401(k) plan with generous PTO