×
Register Here to Apply for Jobs or Post Jobs. X

Senior Risk & Compliance Analyst; C-SCRM Lead

Job in Newport News, Virginia, 23601, USA
Listing for: Connected Logistics
Full Time position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 115000 - 125000 USD Yearly USD 115000.00 125000.00 YEAR
Job Description & How to Apply Below
Position: Senior Risk & Compliance Analyst (C-SCRM Lead)

Description

Contingent Upon Contract Award

Remote with occasional on-site support

Connected Logistics is seeking a Senior Risk & Compliance Analyst (C-SCRM Lead) to support the Cybersecurity Architecture and Engineering Services supporting the Department of Veterans Affairs (VA) Office of Information Security (OIS) Cybersecurity Operations Systems Engineering (COSE) program.

The Senior Risk & Compliance Analyst (C-SCRM Lead) serves as the lead subject matter expert for cybersecurity risk management, compliance, and Cybersecurity Supply Chain Risk Management (C-SCRM). This position provides expertise in conducting IT security risk assessments, threat and vulnerability analysis, and security control assessments to identify and evaluate risks to organizational systems, platforms, applications, data, and supporting technology supply chains.

The Senior Risk & Compliance Analyst assesses the potential exposure of proprietary, sensitive, and mission-critical information resulting from weaknesses in technology platforms, security controls, access procedures, system configurations, third-party products and services, or other forms of access to organizational systems and data. The role leads C-SCRM activities and supports the identification, documentation, prioritization, mitigation, and continuous monitoring of cybersecurity and supply chain risks throughout the system and acquisition lifecycle.

Key Responsibilities
  • Lead cybersecurity risk management, compliance, and C-SCRM activities across systems, applications, infrastructure, cloud environments, products, services, and supporting technology supply chains.
  • Conduct comprehensive IT security risk assessments and threat analyses to identify vulnerabilities, control weaknesses, threat exposure, and potential impacts to organizational systems and data.
  • Lead and coordinate Cybersecurity Supply Chain Risk Management (C-SCRM) assessments of technology products, software, hardware, services, suppliers, vendors, and other third-party dependencies.
  • Identify and evaluate supply chain cybersecurity risks associated with product provenance, supplier dependencies, software components, third-party services, and technology acquisition.
  • Conduct and oversee security control assessments to determine the effectiveness of implemented security safeguards and identify gaps requiring remediation or risk treatment.
  • Evaluate risks associated with unauthorized access, excessive privileges, insecure access procedures, platform vulnerabilities, system configurations, data protection weaknesses, and third-party access.
  • Develop and maintain cybersecurity and C-SCRM risk registers, documenting identified risks, likelihood, impact, risk severity, mitigating controls, responsible parties, and remediation status.
  • Perform risk analysis and develop actionable risk mitigation and remediation recommendations based on identified threats, vulnerabilities, control deficiencies, and organizational risk tolerance.
  • Track identified security deficiencies and remediation activities through closure, including supporting the development and management of Plans of Action and Milestones (POA&Ms) where applicable.
  • Support implementation and execution of organizational Risk Management Framework (RMF) processes, including security assessment, authorization, continuous monitoring, and ongoing risk management activities.
  • Assess compliance with applicable organizational cybersecurity policies, security requirements, contractual obligations, and established security control frameworks.
  • Review system security documentation, assessment results, vulnerability findings, control evidence, architecture artifacts, and supporting documentation to determine cybersecurity risk and compliance posture.
  • Collaborate with cybersecurity, engineering, architecture, acquisition, program management, and operational stakeholders to integrate security and supply chain risk considerations into technical and business decisions.
  • Provide risk-based recommendations to program and cybersecurity leadership, clearly communicating technical risks, business impacts, mitigation alternatives, residual risk, and recommended courses of action.
  • Support continuous monitoring of cybersecurity and supply chain risks, including changes to systems, suppliers, technologies, threat conditions, vulnerabilities, and operational environments.
  • Develop and maintain risk assessment reports, compliance documentation, C-SCRM artifacts, executive risk summaries, metrics, dashboards, and other…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary