Primary Responsibilities:
The position of Supply Chain Risk Analyst will provide risk and opportunity planning, analysis and reporting to include:
· Vulnerability due diligence assessments, Cybersecurity Maturity Model Certification, PMO and source code analysis. To also develop policies and procedures that support customer office and align to risk management framework.
· This team will be responsible for developing the foundational policies and processes to stand up the Cyber Risk Management Team within Agency SOC.
· The position will lead the development of supplier threat and vulnerability assessments related to risk and support change management efforts across the corporation. In addition, individual may support category managers in developing risk assessments across various categories.
· May be required to draft and support all-source intelligence production in compliance with Tradecraft Standards
· Candidate will provide methods to properly communicate the risks applicable to Agency stakeholders and senior management.
· Candidate will create a holistic risk picture for the communications branch and will also provide briefings for senior management on the on the cyber risk posture of Agency.
· Attend and participate in meetings, conferences, and working groups in support of Agency.
· Conduct risk, vulnerability, criticality assessments to prioritize supply chain vendors and their potential impact on Agency’s mission.
· Candidate will assist the Government in conducting reviews and recommendations to aid the government in approving of risk acceptance memorandums, assist with the prioritization of POA&Ms, create risk profiles for all Agency information systems, identify common gaps in the information system compliance to focus holistic funding in support of remediating security findings for multiple systems.
Basic Qualifications:
· Clearance: All Agency SOC employees are required to successfully complete a Agency Background Investigation to support this program
· A Bachelor’s degree and 8 years of applicable experience is required, or a High School diploma + 9 years of applicable experience
· Professional writing, editing, and sourcing skills are mandatory in order to be successful in the position
· Ability to apply extensive knowledge of grammar, punctuation, and corporate writing standards in order to edit reports
· Ability to handle multiple tasks and adjust to changing priorities as needed
· Strong attention to details is required
· Past history developing policies and procedures for compliant procurement in an services environment
· Fundamental understanding of supplier quality management processes
· Strong understanding of Risk Management Framework (RMF)
· Strong understanding of NIST 800-161, NIST 800-30, NIST 800-37 or equivalent DoD policies/standards
Required Education/Experience
A Bachelor’s degree and 8 years of applicable experience is required, or a High School diploma + 9 years of applicable experience
Preferred Qualifications:
o Experience in cyber government, and/or federal law enforcement. Experience in Vulnerability scanning and analysis. Experience in financial, CSP and FISMA audits.
o Prior Agency Experience
Freqently Asked Questions
Professionals in Chantilly benefit from certifications like Certified Supply Chain Professional (CSCP) and Certified Information Systems Security Professional (CISSP) due to the region's focus on cybersecurity and federal compliance. These credentials boost expertise in supply chain risk and improve competitiveness in the local job market.
Chantilly's proximity to federal agencies creates higher demand for supply chain risk analysts specializing in cybersecurity and government standards. Compared to other Virginia areas, competition is moderate, with a strong preference for candidates familiar with risk management frameworks and federal compliance.
Mastery in vulnerability assessments, familiarity with NIST standards, and strong policy development skills stand out. Employers look for candidates who can analyze supplier risks comprehensively and communicate findings effectively to senior management, critical for maintaining secure supply chains.
Progression may lead toward senior risk analyst roles, risk management leadership, or specialized cybersecurity positions. Expanding expertise in government compliance and intelligence production can open doors to advisory roles influencing corporate or agency-wide supply chain security.
Base-One Inc emphasizes integrating cyber risk management deeply within agency operations, focusing on vulnerability due diligence and intelligence compliance. This contrasts with general industry roles by blending supply chain risks with federal cybersecurity mandates, offering a unique analytical environment.
Daily tasks blend risk assessments of supply vendors, policy drafting aligned with federal frameworks, and briefing senior stakeholders on cyber vulnerabilities. Analysts also collaborate across teams to manage change initiatives, reflecting the company’s commitment to dynamic risk mitigation.
In Chantilly, salaries for supply chain risk analysts generally range between $90,000 and $120,000 annually, reflecting the area's federal market influence. Nationally, this positions Chantilly competitively, with higher pay due to specialized government-related risk management expertise.
A frequent misconception is that the role solely involves data collection, whereas it requires strategic policy development and intelligence synthesis. Analysts must actively shape risk frameworks, not just report vulnerabilities, highlighting the role’s strategic impact on organizational security.
Popular Searches for Supply Chain Risk Analyst