×
Register Here to Apply for Jobs or Post Jobs. X

Supply Chain Risk Management Specialist

Job in San Diego, San Diego County, California, 92189, USA
Listing for: Leidos
Full Time position
Listed on 2026-08-04
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 92300 - 166850 USD Yearly USD 92300.00 166850.00 YEAR
Job Description & How to Apply Below

Description

Leidos is seeking a Supply Chain Risk Management Analyst to provide technical and analytical support to the Federal Aviation Administration's (FAA) Counterintelligence (CI) Supply Chain Risk Management (SCRM) program. The program is responsible for identifying, assessing, and mitigating foreign intelligence, nation-state, and cybersecurity threats to the FAA’s supply chain, critical infrastructure, and enterprise networks. Embedded within a 3-person team, this position focuses on enterprise risk assessments and procurement execution support.

Providing risk analysis aligned with the FAA Acquisition Management System (AMS) framework, the analyst evaluates the actual security posture of software suppliers, cloud providers, Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) environments. This role translates threat data into technical risk scoring, conducts criticality analysis, and drafts custom contract security language to protect and mitigate threats against FAA supply chain.

Primary

Responsibilities
  • Conduct enterprise-level vendor risk assessments and technical security reviews for software suppliers, cloud providers (SaaS/PaaS/IaaS), AI tools, telecommunications, and OT/ICS (Operational Technology/Industrial Control Systems).
  • Conduct technical and non-technical risk scoring to compile comprehensive Vendor Risk Reports that map systemic vulnerabilities.
  • Provide specialized SCRM subject matter expertise throughout the procurement lifecycle, including early-stage acquisition planning and source selections.
  • Author Acquisition Security Reviews and evaluation matrices that integrate directly into the FAA Acquisition Management System (AMS) pipeline.
  • Draft specific contract security language, technical security requirements, and risk acceptance recommendations to mitigate identified supply chain risks prior to contract award.
  • Translate highly technical and complex risk assessment data into clear, Executive Decision Packages for a non-technical audience to enable FAA senior leadership to make rapid, fully informed decisions.
  • Contribute to the development and maintenance of FAA SCRM policies, governance documentation, and standard operating procedures (SOPs).
  • Formulate performance metrics and program reports for executive leadership.
  • Maintain critical operational and collaborative relationships with external stakeholders, including the FAA Chief Information Officer (CIO), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Homeland Security (DHS), and the broader Intelligence Community (IC).
  • Coordinate and facilitate SCRM training and awareness campaigns for acquisition personnel and program offices.
Basic Qualifications

Citizenship: U.S. Citizenship required

Clearance: Active Top Secret/SCI clearance is required

Education: Bachelor’s degree in Supply Chain Risk Management, Intelligence Studies, National Security, Logistics, Data Science, Cybersecurity, Information Technology, Computer Science/Engineering, or a related discipline. (Equivalent professional experience or specialized training may be substituted).

Experience: 8+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or OSINT) or professional experience in third-party risk management (TPRM), Cyber Supply Chain Risk Management (C-SCRM), technical risk assessments, cybersecurity risk management, or infrastructure defense.

Framework Knowledge: Strong working knowledge of federal cybersecurity and risk management frameworks, specifically NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) and NIST SP 800-53.

Technical

Skills:

Hands-on experience evaluating the security posture, software supply chains, and configurations of at least three of the following technology profiles:

  • Cloud infrastructure and service providers (SaaS, PaaS, IaaS)
  • Commercial software packages and open-source dependencies
  • Artificial Intelligence (AI) platforms or Machine Learning tools
  • Telecommunications hardware or infrastructure frameworks
  • Operational Technology (OT) or Industrial Control…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary