Supply Chain Risk Management Senior Analyst
Leidos
- Location
- Washington, DC
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 26 approvals (FY2023)
- Posted
- 17h ago
Skills
About this role
Leidos is seeking a Senior-Level Supply Chain Risk Management Analyst to provide advanced technical and analytical support to the FAA’s Counterintelligence (CI) Supply Chain Risk Management (SCRM) program. The program is responsible for identifying, assessing, and mitigating foreign intelligence, nation-state, and cybersecurity threats to the FAA’s supply chain, critical infrastructure, and enterprise networks. Embedded as a senior leader within a 3-person team, this position focuses on complex enterprise risk assessments and procurement execution support. Providing high-level, independent analytical support aligned with the FAA Acquisition Management System (AMS) framework, the senior analyst evaluates the actual security posture of software suppliers, cloud providers, Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) environments. This role translates threat data into technical risk scoring, conducts complex criticality analyses, and drafts custom contract security language to protect and mitigate advanced threats against the FAA supply chain.
Primary Responsibilities
Team lead ensuring strict quality control, mentoring, and analytical integrity across all FAA CI SCRM products. Lead the execution of complex, enterprise-level vendor risk assessments and oversee the analytical triage of Software Bills of Materials (SBOMs) for critical air traffic management software, cloud providers (SaaS/PaaS/IaaS), Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) frameworks. Conduct and oversee technical and non-technical risk scoring methodologies to compile comprehensive Vendor Risk Reports that map systemic vulnerabilities and cascading supply chain risks. Provide authoritative SCRM analytical expertise throughout the procurement lifecycle, guiding early-stage acquisition planning and complex source selections. Author definitive Acquisition Security Reviews and evaluation matrices that support and align with the FAA AMS pipeline. Formulate and draft specific contract security language, technical security requirements, and risk acceptance recommendations to legally bind vendors and mitigate identified supply chain risks prior to contract award. Translate highly technical, complex risk assessment data into clear, sophisticated Executive Decision Packages and dashboards tailored for a non-technical audience to enable FAA senior leadership to make rapid, fully informed decisions. Lead the development, refinement, and maintenance of FAA SCRM policies, governance documentation, and standard operating procedures (SOPs). Formulate strategic performance metrics and high-level program reports to track enterprise SCRM compliance for executive leadership. Maintain critical operational and collaborative relationships with external stakeholders, including the FAA Chief Information Officer (CIO), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Homeland Security (DHS), and the broader Intelligence Community (IC). Create, coordinate, and facilitate comprehensive SCRM training and awareness campaigns for acquisition personnel and program offices agency wide.
Basic Qualifications
Citizenship: U.S. Citizenship required. Clearance: Active Top Secret/SCI clearance is required.
Education
Bachelor’s or Master’s degree in Supply Chain, Intelligence Studies, National Security, Logistics, Data Science, Cybersecurity, Information Technology, Computer Science, Computer Engineering, or a related technical discipline. (Equivalent professional experience or specialized military/federal training may be substituted).
Experience
12+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or Open-Source Intelligence) or senior-level experience in third-party risk management (TPRM), Cyber Supply Chain Risk