Leidos

Senior SCRM Analyst

Leidos

full-time

Posted on:

Location Type: Office

Location: AlexandriaMarylandVirginiaUnited States

Visit company website

Explore more

AI Apply
Apply

Salary

💰 $107,900 - $195,050 per year

Job Level

About the role

  • Conducts comprehensive Cyber Supply Chain Risk Assessments on systems, products, and suppliers to identify vulnerabilities, foreign influence, and compliance gaps.
  • Monitors program adherence to all applicable supply-chain policies, federal regulations, Executive Orders, and Office of Management and Budget (OMB) memorandums.
  • Ensures continuous compliance with National Institute of Standards and Technology (NIST) guidelines and statutory requirements such as the National Defense Authorization Act (NDAA) Section 889 Parts A and B.
  • Supports risk findings and mitigation recommendations to safeguard the integrity, security, and reliability of the supply chain.
  • Provide subject matter expertise in DoD Supply Chain Risk Management (SCRM) to implement, expand, and mature an end-to-end SCRM program.
  • Support the development and continued refinement/updates of Mission Assurance policy.
  • Produce and present briefings of their findings, as well as meeting minutes, after action reports, trip reports, as necessary
  • Support SCRM Commercial Assessments of Networks, Network availability, and germane hardware to protect DoD's mission critical functions.
  • Capture specific information from the PMO and submitting that information as a Request for Information (RFI) to the appropriate entity to support SCRM Counterintelligence (CI) risk management analysis.
  • Gather requirements and develop SCRM RFIs.
  • Project manage SCRM Threat Analysis Center (TAC) RFI queue (informal inquiries, quick turn reports, formal SCRM TAC RFIs).
  • Support the implementation of SCRM processes and policies
  • Support periodic collection of SCRM internal process metrics in accordance with SCRM SOPs/CONOPS.
  • Support the implementation of the SCRM program strategy SCRM training, SCRM procedures, and other support related to supply chain risk management.
  • Conduct evaluations and prepare reports detailing any potential foreign influence or threats to DoD supply chains.
  • Risk assessment products shall be prepared in accordance with guidance from the Government Program lead, in accordance with SCRM Standard Operating Procedures (SOPs) and Concept of Operations (CONOPS).
  • Maintain active lines of communication with MA/SCRM Liaison at the Government.
  • Integrate with ConMon dashboard to ensure visibility of FOCI, SBOM and attestations.

Requirements

  • Active Top Secret (TS) clearance with SCI eligibility.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, Supply Chain Management, or related technical discipline and 8–12 years of relevant experience OR Master’s degree in a related field and 6–10 years of relevant experience.
  • Knowledge of DoD SCRM standards, including DoDI 5200.44, NIST 800-161, NIST 800-53A
  • Demonstrated ability to effectively communicate with and influence government customers
  • Developing SBOM and HBOM analysis, analyze end-to-end cyber supply chain risks
  • Proficient using GRC tools such as eMASS
  • Cybersecurity experience
  • Project Management fundamentals
  • Demonstrated experience with: In-depth analysis of C-SCRM, Zero Trust Capabilities, Infrastructures and Architecture.
  • 5+ years of team and/or operational leadership experience.
  • 7+ years of experience in USG cyber risk management, assessments and authorization (A&A), and using NIST Special Publications (SP) (e.g.: SP800-30, SP800-37, SP800-53, etc.)
  • 7+ years of experience in designing and engineering enterprise IT solutions within the USG using NIST SP (e.g.: SP800-60, SP800-64, SP800-80, SP800-122, SP800-137, SP800-146, SP800-160, SP800-204, SP800-207, SP800-213, etc.)
  • Certifications in Cybersecurity like Security plus, CISM
Benefits
  • Health and Wellness programs
  • Income Protection
  • Paid Leave
  • Retirement
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
Cyber Supply Chain Risk AssessmentRisk ManagementSBOM analysisCybersecurityProject ManagementC-SCRM analysisZero Trust CapabilitiesNIST 800-161NIST 800-53ANIST Special Publications
Soft Skills
Effective communicationInfluencing government customersTeam leadershipOperational leadership
Certifications
Top Secret clearanceSecurity PlusCISM