Supply Chain Risk Management Senior Analyst

Leidos LLC

Washington (District of Columbia)

On-site

USD 116,000 - 210,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Leidos is seeking a Senior-Level Supply Chain Risk Management Analyst to support the FAA CI SCRM program. You will lead complex enterprise risk assessments, provide high-level analytical support, and translate technical risk data into executive-ready reports for rapid decision-making.

You will evaluate security postures of software supply chains, cloud services, AI tools, and OT/ICS environments, drafting security language for contracts and guiding procurement through AMS processes.

Qualifications

  • U.S. Citizenship required.
  • Active Top Secret/SCI clearance required.
  • 12+ years in intelligence analysis or senior-level risk management.
  • Strong working knowledge of NIST SP 800-161 and NIST SP 800-53.
  • Experience evaluating security posture of software supply chains and related tech.
  • Ability to translate vulnerabilities into clear executive summaries.

Responsibilities

  • Lead FAA CI SCRM product quality and mentoring across the team.
  • Oversee enterprise vendor risk assessments and SBOM triage for critical vendors.
  • Develop risk scoring methodologies and executive-ready Vendor Risk Reports.
  • Draft contract security language and security requirements for FAA AMS alignment.
  • Create executive dashboards and risk communications for non-technical audiences.

Skills

TS/SCI clearance
NIST SP 800-161
NIST SP 800-53
SBOMs & vendor risk
Contract security language
Executive summaries

Education

Bachelor’s or Master’s degree (technical)

Tools

Cloud providers (SaaS/PaaS/IaaS)
AI platforms/tools
OT/ICS environments
SBOM review

Job description

Leidos is seeking a Senior-Level Supply Chain Risk Management Analyst to provide advanced technical and analytical support to the FAA’s Counterintelligence (CI) Supply Chain Risk Management (SCRM) program. The program is responsible for identifying, assessing, and mitigating foreign intelligence, nation-state, and cybersecurity threats to the FAA’s supply chain, critical infrastructure, and enterprise networks. Embedded as a senior leader within a 3-person team, this position focuses on complex enterprise risk assessments and procurement execution support. Providing high-level, independent analytical support aligned with the FAA Acquisition Management System (AMS) framework, the senior analyst evaluates the actual security posture of software suppliers, cloud providers, Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) environments. This role translates threat data into technical risk scoring, conducts complex criticality analyses, and drafts custom contract security language to protect and mitigate advanced threats against the FAA supply chain.

Primary Responsibilities

Team lead ensuring strict quality control, mentoring, and analytical integrity across all FAA CI SCRM products. Lead the execution of complex, enterprise-level vendor risk assessments and oversee the analytical triage of Software Bills of Materials (SBOMs) for critical air traffic management software, cloud providers (SaaS/PaaS/IaaS), Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) frameworks. Conduct and oversee technical and non-technical risk scoring methodologies to compile comprehensive Vendor Risk Reports that map systemic vulnerabilities and cascading supply chain risks. Provide authoritative SCRM analytical expertise throughout the procurement lifecycle, guiding early-stage acquisition planning and complex source selections. Author definitive Acquisition Security Reviews and evaluation matrices that support and align with the FAA AMS pipeline. Formulate and draft specific contract security language, technical security requirements, and risk acceptance recommendations to legally bind vendors and mitigate identified supply chain risks prior to contract award. Translate highly technical, complex risk assessment data into clear, sophisticated Executive Decision Packages and dashboards tailored for a non-technical audience to enable FAA senior leadership to make rapid, fully informed decisions. Lead the development, refinement, and maintenance of FAA SCRM policies, governance documentation, and standard operating procedures (SOPs). Formulate strategic performance metrics and high-level program reports to track enterprise SCRM compliance for executive leadership. Maintain critical operational and collaborative relationships with external stakeholders, including the FAA Chief Information Officer (CIO), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Homeland Security (DHS), and the broader Intelligence Community (IC). Create, coordinate, and facilitate comprehensive SCRM training and awareness campaigns for acquisition personnel and program offices agency wide.

Basic Qualifications
  • Citizenship: U.S. Citizenship required.
  • Clearance: Active Top Secret/SCI clearance is required.
  • Education: Bachelor’s or Master’s degree in Supply Chain, Intelligence Studies, National Security, Logistics, Data Science, Cybersecurity, Information Technology, Computer Science, Computer Engineering, or a related technical discipline. (Equivalent professional experience or specialized military/federal training may be substituted).
  • Experience: 12+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or Open-Source Intelligence) or senior-level experience in third-party risk management (TPRM), Cyber Supply Chain Risk Management (C‑SCRM), technical risk assessments, IT auditing, cybersecurity risk management, or infrastructure defense in a federal or highly regulated commercial environment.
  • Framework Knowledge: Strong working knowledge of federal cybersecurity and risk management frameworks, specifically NIST SP 800‑161 (Cybersecurity Supply Chain Risk Management Practices) and NIST SP 800‑53.
  • Technical Skills: Demonstrated hands‑on experience evaluating the security posture, software supply chains, and configurations of at least three of the following technology profiles: Cloud infrastructure and service providers (SaaS, PaaS, IaaS) Commercial software packages and open-source dependencies Artificial Intelligence (AI) platforms or Machine Learning tools Telecommunications hardware or infrastructure frameworks Operational Technology (OT) or Industrial Control Systems (ICS).
  • Communication Skills: Proven capability to translate complex technical vulnerabilities, software flaws, and architectural risks into clear, well‑structured, non‑technical written reports and executive summaries.
Preferred Qualifications
  • Completion of formal military or federal intelligence training courses focusing on threat network analysis or open‑source collection.
  • Possession of one or more of the following industry‑recognised certifications: Certified Information Systems Security Professional (CISSP) Certified in Risk and Information Systems Control (CRISC) Certified Information Systems Auditor (CISA) Specialised federal SCRM or Counterintelligence training certifications (e.g., CDSE, ODNI, or defence‑sponsored SCRM courses).
  • Direct, demonstrable experience reviewing federal procurement mechanisms, source selection processes, or drafting legally binding contract security language specifically tailored to the FAA AMS framework.
  • Ability to align supply chain threat assessments with the 5‑step FAA Safety Risk Management (SRM) process (System Analysis, Hazard Identification, Risk Analysis, Risk Assessment, and Mitigation Control).
  • Expert knowledge of Intelligence Community Directives (ICD 203) and Structured Analytic Techniques

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 — and moving faster than anyone else dares.

Pay Range

Pay Range $116,350.00 - $210,325.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programmes, Income Protection, Paid Leave and Retirement. More details are available here.

Commitment and Diversity

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Supply Chain Risk Management Senior Analyst
Supply Chain Risk Management Senior Analyst

Leidos Inc • Washington

On-site
USD 116,350 - 210,325
Supply Chain Risk Management Senior Analyst
Supply Chain Risk Management Senior Analyst

Via Logic LLC • Washington

On-site
USD 116,000 - 210,000
Supply Chain Risk Management Senior Analyst
Supply Chain Risk Management Senior Analyst

Leidos • Washington

On-site
USD 116,350 - 210,325
Supply Chain Risk Management Specialist
Supply Chain Risk Management Specialist

Leidos LLC • United States

Remote
USD 92,000 - 167,000
Principal Cyber Security Architect
Principal Cyber Security Architect

Leidos LLC • Gaithersburg (MD)

Hybrid
USD 131,000 - 237,000
DevSecOps Security Engineer
DevSecOps Security Engineer

Leidos LLC • Gaithersburg (MD)

Hybrid
USD 87,000 - 157,000
Health benefits
Paid leave
Retirement plan
Java Software Engineer - Scrum Master
Java Software Engineer - Scrum Master

Leidos LLC • Gaithersburg (MD)

Hybrid
USD 87,000 - 157,000
Health and Wellness programs
Income Protection
Paid Leave
+1
Security Authorization Lead
Security Authorization Lead

Via Logic LLC • Eagan (MN)

On-site
USD 108,000 - 195,000
Security Authorization Lead
Security Authorization Lead

Via Logic LLC • Egg Harbor Township (NJ)

On-site
USD 108,000 - 195,000
Senior Java Software Engineer / Scrum Master
Senior Java Software Engineer / Scrum Master

Leidos LLC • Gaithersburg (MD)

Hybrid
USD 108,000 - 195,000