Senior Risk & Compliance Analyst; C-SCRM Lead
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Description
Contingent Upon Contract Award
Remote with occasional on-site support
Connected Logistics is seeking a Senior Risk & Compliance Analyst (C-SCRM Lead) to support the Cybersecurity Architecture and Engineering Services supporting the Department of Veterans Affairs (VA) Office of Information Security (OIS) Cybersecurity Operations Systems Engineering (COSE) program.
The Senior Risk & Compliance Analyst (C-SCRM Lead) serves as the lead subject matter expert for cybersecurity risk management, compliance, and Cybersecurity Supply Chain Risk Management (C-SCRM). This position provides expertise in conducting IT security risk assessments, threat and vulnerability analysis, and security control assessments to identify and evaluate risks to organizational systems, platforms, applications, data, and supporting technology supply chains.
The Senior Risk & Compliance Analyst assesses the potential exposure of proprietary, sensitive, and mission-critical information resulting from weaknesses in technology platforms, security controls, access procedures, system configurations, third-party products and services, or other forms of access to organizational systems and data. The role leads C-SCRM activities and supports the identification, documentation, prioritization, mitigation, and continuous monitoring of cybersecurity and supply chain risks throughout the system and acquisition lifecycle.
- Lead cybersecurity risk management, compliance, and C-SCRM activities across systems, applications, infrastructure, cloud environments, products, services, and supporting technology supply chains.
- Conduct comprehensive IT security risk assessments and threat analyses to identify vulnerabilities, control weaknesses, threat exposure, and potential impacts to organizational systems and data.
- Lead and coordinate Cybersecurity Supply Chain Risk Management (C-SCRM) assessments of technology products, software, hardware, services, suppliers, vendors, and other third-party dependencies.
- Identify and evaluate supply chain cybersecurity risks associated with product provenance, supplier dependencies, software components, third-party services, and technology acquisition.
- Conduct and oversee security control assessments to determine the effectiveness of implemented security safeguards and identify gaps requiring remediation or risk treatment.
- Evaluate risks associated with unauthorized access, excessive privileges, insecure access procedures, platform vulnerabilities, system configurations, data protection weaknesses, and third-party access.
- Develop and maintain cybersecurity and C-SCRM risk registers, documenting identified risks, likelihood, impact, risk severity, mitigating controls, responsible parties, and remediation status.
- Perform risk analysis and develop actionable risk mitigation and remediation recommendations based on identified threats, vulnerabilities, control deficiencies, and organizational risk tolerance.
- Track identified security deficiencies and remediation activities through closure, including supporting the development and management of Plans of Action and Milestones (POA&Ms) where applicable.
- Support implementation and execution of organizational Risk Management Framework (RMF) processes, including security assessment, authorization, continuous monitoring, and ongoing risk management activities.
- Assess compliance with applicable organizational cybersecurity policies, security requirements, contractual obligations, and established security control frameworks.
- Review system security documentation, assessment results, vulnerability findings, control evidence, architecture artifacts, and supporting documentation to determine cybersecurity risk and compliance posture.
- Collaborate with cybersecurity, engineering, architecture, acquisition, program management, and operational stakeholders to integrate security and supply chain risk considerations into technical and business decisions.
- Provide risk-based recommendations to program and cybersecurity leadership, clearly communicating technical risks, business impacts, mitigation alternatives, residual risk, and recommended courses of action.
- Support continuous monitoring of cybersecurity and supply chain risks, including changes to systems, suppliers, technologies, threat conditions, vulnerabilities, and operational environments.
- Develop and maintain risk assessment reports, compliance documentation, C-SCRM artifacts, executive risk summaries, metrics, dashboards, and other…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).