Supply Chain Security Analyst
Listed on 2026-08-29
-
Security
Cybersecurity
Overview
Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+ employees of Draper tackle important national challenges with a promise of delivering successful and usable solutions. From military defense and space exploration to biomedical engineering, lives often depend on the solutions we provide. Our multidisciplinary teams of engineers and scientists work in a collaborative environment that inspires the cross-fertilization of ideas necessary for true innovation.
For more information about Draper, visit
The Supply Chain Risk Management (SCRM) Analyst will be responsible the accurate assessment and analysis of DIB suppliers in support of defense programs. This position entails a focused commitment to critically assess companies in the defense industrial base and manage the implementation of Supply Chain Risk Management NIST 800-53 control family to mitigate risks in the supply chain. The candidate should have experience drafting documentation to support compliance and process.
This position will leverage existing supply chain risk technologies and stringent organizational protocols to ensure that analysis and processes are timely and processes in a manner that complies with program supply chain risk management policy requirements.
- Lead vulnerability identification activities by conducting advanced analysis of systems, programs and architectures to determine crucial components, high-risk areas, and potential impacts across defense program supply chains.
- Conduct independent assessments and validations of supplier security practices to ensure compliance with federal defense and organizational requirements; document findings and provide expert recommendations to leadership and customers.
- Compile, synthesize and present complex risk assessments to internal stakeholders, executive leadership, and external customers to support informed decision making.
- Monitor and document major changes affective supply chain risk, quality, resilience, and compliance, ensuring that risks are escalated and mitigated proactively.
- Evaluate enterprise and supplier-level risks within Draper’s SCRM programs, identifying systemic issues and recommending improvements to strengthen program maturity.
- Drive enhancements to the existing SCRM framework by incorporating stakeholder feedback, industry best practices and emerging regulatory requirements; lead implementation of approved updates.
- Perform rigorous quality checks of supplier reviews, ensuring data accuracy, completeness, and analytical integrity; investigate discrepancies and deliver corrective action guidance.
- Collaborate cross functionally with engineering, product development, operations and security teams to ensure SCRM processes, standards and operations align with enterprise policies and strategic goals.
- Analyst multi-source data to identify trends in supplier quality, product defects, or recurring vulnerabilities, and develop mitigation strategies to prevent future occurrences.
- Maintain readiness to perform additional responsibilities in support of evolving organizational needs.
- Deep familiarity with software supply chain risks and the broader defense industrial base
- Strong working knowledge of SCRM NIST 800-53 control family to mitigate risks in the supply chain, with experience drafting documentation to support compliance and process.
- Expert understanding of DFARS, FAR, TAA, and supply chain relevant compliance topics: NDAA 889, 1260H, nearshore/offshore guidance, country of origin risks and critical supply chain considerations.
- Ability to operate as an independent, action-oriented self-starter, prioritizing and managing multiple work streams in a fast-paced environment.
- Proven success working within cross functional teams, adapting to changing priorities and providing leadership within complex matrixed environments.
- Familiarity with Quality Standards ISO 9001:2015 and AS9100 with demonstrated ability to integrate quality principals into supply chain risk processes.
- Advances skills in process integration including building workflows, identifying gaps and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).