Primary Responsibilities:
The position of Supply Chain Risk Analyst will provide risk and opportunity planning, analysis and reporting to include:
· Vulnerability due diligence assessments, Cybersecurity Maturity Model Certification, PMO and source code analysis. To also develop policies and procedures that support customer office and align to risk management framework.
· This team will be responsible for developing the foundational policies and processes to stand up the Cyber Risk Management Team within Agency SOC.
· The position will lead the development of supplier threat and vulnerability assessments related to risk and support change management efforts across the corporation. In addition, individual may support category managers in developing risk assessments across various categories.
· May be required to draft and support all-source intelligence production in compliance with Tradecraft Standards
· Candidate will provide methods to properly communicate the risks applicable to Agency stakeholders and senior management.
· Candidate will create a holistic risk picture for the communications branch and will also provide briefings for senior management on the on the cyber risk posture of Agency.
· Attend and participate in meetings, conferences, and working groups in support of Agency.
· Conduct risk, vulnerability, criticality assessments to prioritize supply chain vendors and their potential impact on Agency’s mission.
· Candidate will assist the Government in conducting reviews and recommendations to aid the government in approving of risk acceptance memorandums, assist with the prioritization of POA&Ms, create risk profiles for all Agency information systems, identify common gaps in the information system compliance to focus holistic funding in support of remediating security findings for multiple systems.
Basic Qualifications:
· Clearance: All Agency SOC employees are required to successfully complete a Agency Background Investigation to support this program
· A Bachelor’s degree and 8 years of applicable experience is required, or a High School diploma + 9 years of applicable experience
· Professional writing, editing, and sourcing skills are mandatory in order to be successful in the position
· Ability to apply extensive knowledge of grammar, punctuation, and corporate writing standards in order to edit reports
· Ability to handle multiple tasks and adjust to changing priorities as needed
· Strong attention to details is required
· Past history developing policies and procedures for compliant procurement in an services environment
· Fundamental understanding of supplier quality management processes
· Strong understanding of Risk Management Framework (RMF)
· Strong understanding of NIST 800-161, NIST 800-30, NIST 800-37 or equivalent DoD policies/standards
Required Education/Experience
A Bachelor’s degree and 8 years of applicable experience is required, or a High School diploma + 9 years of applicable experience
Preferred Qualifications:
o Experience in cyber government, and/or federal law enforcement. Experience in Vulnerability scanning and analysis. Experience in financial, CSP and FISMA audits.
o Prior Agency Experience
Freqently Asked Questions
In Ashburn, VA, certifications like CISSP, CISM, or CRISC are highly regarded for Supply Chain Risk Analysts. These credentials validate expertise in cybersecurity and risk frameworks, aligning well with local government and federal agency requirements, boosting your profile in this competitive market.
Ashburn's proximity to federal agencies has increased demand for Supply Chain Risk Analysts, especially those skilled in cybersecurity and risk management frameworks. The region's growing tech and defense sectors further intensify hiring, making it a promising location for professionals with these niche skills.
Mastering vulnerability assessments, familiarity with NIST standards, and analytical skills for interpreting supply chain threats are crucial. Proficiency in synthesizing risk metrics into actionable intelligence distinguishes an effective Supply Chain Risk Analyst in complex environments.
Progression typically involves deepening expertise in cyber risk and vendor threat analysis, transitioning into managerial roles, or specializing in compliance audits like FISMA. Expanding knowledge in policy development and risk communication also paves the way for leadership opportunities.
Base-One Inc emphasizes integration with agency SOC teams and all-source intelligence compliance, offering a unique blend of cybersecurity and supply chain risk responsibilities. The role’s strong focus on policy creation and senior management briefings sets it apart in the federal contracting landscape.
Base-One Inc provides access to cutting-edge vulnerability scanning tools and fosters collaboration within cyber risk management teams. Analysts receive continuous training on frameworks like NIST 800-161, enabling them to adapt strategies effectively against emerging supply chain risks.
Supply Chain Risk Analysts in Ashburn typically earn between $95,000 and $125,000 annually, reflecting the region’s high demand for cybersecurity-savvy professionals. Salaries can vary based on experience, certifications, and specific risk management expertise.
While Supply Chain Risk Analysts focus on assessing vulnerabilities, threat modeling, and compliance, Financial Analysts concentrate on cost analysis and budgeting within supply chains. The former’s role demands a cybersecurity lens, whereas the latter leans towards financial optimization.
Effectively translating complex technical risk data into clear, strategic insights is often challenging. Analysts must balance technical accuracy with business impact, ensuring leadership comprehends priorities without getting overwhelmed by jargon.
Due to the sensitive nature of government-linked supply chain risk work in Ashburn, remote opportunities are limited. However, some hybrid arrangements exist, contingent on security clearances and agency policies.
Popular Searches for Supply Chain Risk Analyst