Supply Chain Risk Management Specialist

Leidos LLC

United States

Remote

USD 92,000 - 167,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Leidos is seeking a Supply Chain Risk Management Analyst to support FAA's CI SCRM program, focusing on enterprise risk assessments of software, cloud, AI tools, and OT/ICS. You will translate threat data into technical risk scores and contribute to procurement execution with secure contract language.

Embedded in a small team, you will advise on acquisition planning, develop SOPs, and prepare executive summaries for FAA leadership while coordinating with agencies such as CISA, FBI, DHS, and the

Qualifications

  • Bachelor’s degree in a relevant field; equivalent professional experience may be substituted.
  • 8+ years of professional experience as an Intelligence Analyst or in third-party risk management / C-SCRM / cybersecurity risk management.
  • Knowledge of NIST SP 800-161 and NIST SP 800-53.

Responsibilities

  • Conduct enterprise-level vendor risk assessments and technical security reviews for software, cloud, AI tools, IT/OT/ICS.
  • Perform risk scoring to compile Vendor Risk Reports and map systemic vulnerabilities.
  • Provide SCRM SME guidance throughout the procurement lifecycle, including planning and source selections.
  • Draft Acquisition Security Reviews and evaluation matrices integrated into the FAA AMS pipeline.
  • Draft contract security language, technical security requirements, and risk acceptance recommendations.
  • Translate complex risk data into executive summaries for FAA senior leadership and coordinate with external agencies.

Skills

Vendor risk assessments
Risk scoring
Executive reporting
Acquisition planning
Contract security language
Stakeholder collaboration
Threat analysis

Education

Bachelor’s degree

Job description

Leidos is seeking a Supply Chain Risk Management Analyst to provide technical and analytical support to the Federal Aviation Administration's (FAA) Counterintelligence (CI) Supply Chain Risk Management (SCRM) program. The program is responsible for identifying, assessing, and mitigating foreign intelligence, nation-state, and cybersecurity threats to the FAA’s supply chain, critical infrastructure, and enterprise networks. Embedded within a 3-person team, this position focuses on enterprise risk assessments and procurement execution support. Providing risk analysis aligned with the FAA Acquisition Management System (AMS) framework, the analyst evaluates the actual security posture of software suppliers, cloud providers, Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) environments. This role translates threat data into technical risk scoring, conducts criticality analysis, and drafts custom contract security language to protect and mitigate threats against FAA supply chain.

Primary Responsibilities

Conduct enterprise-level vendor risk assessments and technical security reviews for software suppliers, cloud providers (SaaS/PaaS/IaaS), AI tools, telecommunications, and OT/ICS (Operational Technology/Industrial Control Systems). Conduct technical and non-technical risk scoring to compile comprehensive Vendor Risk Reports that map systemic vulnerabilities. Provide specialized SCRM subject matter expertise throughout the procurement lifecycle, including early-stage acquisition planning and source selections. Author Acquisition Security Reviews and evaluation matrices that integrate directly into the FAA Acquisition Management System (AMS) pipeline. Draft specific contract security language, technical security requirements, and risk acceptance recommendations to mitigate identified supply chain risks prior to contract award. Translate highly technical and complex risk assessment data into clear, Executive Decision Packages for a non-technical audience to enable FAA senior leadership to make rapid, fully informed decisions. Contribute to the development and maintenance of FAA SCRM policies, governance documentation, and standard operating procedures (SOPs). Formulate performance metrics and program reports for executive leadership. Maintain critical operational and collaborative relationships with external stakeholders, including the FAA Chief Information Officer (CIO), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Homeland Security (DHS), and the broader Intelligence Community (IC). Coordinate and facilitate SCRM training and awareness campaigns for acquisition personnel and program offices.

Basic Qualifications
  • Citizenship: U.S. Citizenship required
  • Clearance: Active Top Secret/SCI clearance is required
  • Education: Bachelor’s degree in Supply Chain Risk Management, Intelligence Studies, National Security, Logistics, Data Science, Cybersecurity, Information Technology, Computer Science/Engineering, or a related discipline. (Equivalent professional experience or specialized training may be substituted).
  • Experience: 8+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or OSINT) or professional experience in third-party risk management (TPRM), Cyber Supply Chain Risk Management (C-SCRM), technical risk assessments, cybersecurity risk management, or infrastructure defense.
  • Framework Knowledge: Strong working knowledge of federal cybersecurity and risk management frameworks, specifically NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) and NIST SP 800-53.
  • Technical Skills: Hands-on experience evaluating the security posture, software supply chains, and configurations of at least three of the following technology profiles: Cloud infrastructure and service providers (SaaS, PaaS, IaaS) Commercial software packages and open-source dependencies Artificial Intelligence (AI) platforms or Machine Learning tools Telecommunications hardware or infrastructure frameworks Operational Technology (OT) or Industrial Control Systems (ICS).
  • Communication Skills: Proven capability to translate complex technical vulnerabilities, software flaws, and architectural risks into clear, well-structured, non-technical written reports and executive summaries.
Preferred Qualifications
  • Completion of formal military or federal intelligence training courses focusing on threat network analysis or open-source collection.
  • Possession of one or more of the following industry-recognized certifications: Certified Information Systems Security Professional (CISSP) Certified in Risk and Information Systems Control (CRISC) Certified Information Systems Auditor (CISA) Specialized federal SCRM or Counterintelligence training certifications (e.g., CDSE, ODNI, or defense-sponsored SCRM courses).
  • Proficiency with advanced OSINT search techniques, corporate filing retrieval systems, or international trade/shipping databases.
  • Demonstrated experience reviewing federal procurement mechanisms, source selection processes, or drafting contract security language.
Remote Interview / Identification Notice

Please be advised that during the interview, you will be required to keep your camera on, and your interviewer will be taking your picture for identification purposes if an offer letter is extended to you. If you're looking for comfort, keep scrolling.

At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting

October 5, 2026

For U.S. Positions

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range

Pay Range: $92,300.00 - $166,850.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.

Securing Your Data

Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to spam.leidos@leidos.com.

Commitment and Diversity

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Supply Chain Risk Management Senior Analyst
Supply Chain Risk Management Senior Analyst

Leidos Inc • Washington

On-site
USD 116,350 - 210,325
Supply Chain Risk Management Senior Analyst
Supply Chain Risk Management Senior Analyst

Leidos LLC • Washington

On-site
USD 116,000 - 210,000
Supply Chain Risk Management Senior Analyst
Supply Chain Risk Management Senior Analyst

Leidos • Washington

On-site
USD 116,350 - 210,325
Supply Chain Risk Management Senior Analyst
Supply Chain Risk Management Senior Analyst

Koitecc Solutions • Washington

On-site
USD 116,000 - 210,000
Supply Chain Risk Management Senior Analyst
Supply Chain Risk Management Senior Analyst

Via Logic LLC • Washington

On-site
USD 116,000 - 210,000
DevSecOps Security Engineer
DevSecOps Security Engineer

Via Logic LLC • Egg Harbor Township (NJ)

On-site
USD 87,000 - 157,000
Staff Cyber Security Engineer
Staff Cyber Security Engineer

Via Logic LLC • Bethesda (MD)

On-site
USD 108,000 - 195,000
Paid Time Off
11 paid Holidays
401K with 6% company match
+4
Junior Security Engineer
Junior Security Engineer

Leidos Inc • Bethesda (MD)

On-site
USD 70,000 - 126,000
Staff Cyber Security Engineer
Staff Cyber Security Engineer

Koitecc Solutions • Bethesda (MD), Northern (KY)

Hybrid
USD 108,000 - 195,000
Paid Time Off
11 paid holidays
401K with company match
+5
SCA-R Validator
SCA-R Validator

Leidos LLC • Alexandria (VA)

On-site
USD 87,000 - 157,000
Per diem while travel