Third-Party & Supply Chain Risk Analyst
$105k - $175kTrue Anomaly
Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.
OUR MISSION
True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.
OUR VALUES
- Be the offset. We create asymmetric advantages with creativity and ingenuity.
- What would it take? We challenge assumptions to deliver ambitious results.
- It’s the people. Our team is our competitive advantage and we are better together.
Your Mission
We are seeking a driven and detail-oriented Third-Party & Supply Chain Risk Analyst to own the day-to-day execution of our Third-Party Vendor Risk Management (TPVRM) and Cyber Supply Chain Risk Management (C-SCRM) programs, with a secondary line of effort supporting the broader Enterprise Risk Management (ERM) function. Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role assessing suppliers and subcontractors, tracing risk through our hardware and software supply chains, tracking remediation, and building the data foundation that powers executive-level decisions about who we buy from and depend on.
This role is ideal for a mid-career risk professional who is fluent in frameworks such as NIST RMF, NIST SP 800-161 (C-SCRM), and CMMC, is developing practical experience with risk quantification methodologies like FAIR and OCTAVE, and is eager to grow within a fast-paced aerospace and defense environment where the supply chain spans spacecraft hardware, payloads, and mission software. You will work closely with procurement, supply chain, engineering, security, legal, and compliance teams to identify, document, and track risk across our full population of vendors, suppliers, and the components they deliver.
Responsibilities
Third-Party Vendor Risk Management
- Own and execute the vendor risk assessment lifecycle end to end — intake, tiering, onboarding due diligence, and periodic reassessment — including security questionnaire administration, documentation review, and risk scoring.
- Maintain the vendor risk inventory and lifecycle tracking records, ensuring every vendor and subcontractor is appropriately tiered by criticality and data/access exposure, and is reassessed on schedule.
- Continuously monitor third-party risk signals — cybersecurity advisories, breach disclosures, financial-health and adverse-media indicators, regulatory and debarment actions (e.g., SAM.gov exclusions), and contractual compliance status — escalating material changes to the Senior Enterprise Risk Manager.
- Assess vendor cybersecurity posture against contractual and regulatory requirements, including flow-down of DFARS View phone number on aiapply.co, NIST SP 800-171, and CMMC obligations to subcontractors handling Controlled Unclassified Information (CUI).
- Partner with contracts, procurement, and legal teams to translate assessment findings into recommended risk mitigation language, flow-down clauses, and remediation commitments before award and at renewal.
- Track vendor remediation items to closure, maintaining risk acceptance records where residual risk is formally accepted by an accountable owner.
Supply Chain Risk Management (C-SCRM)
- Build and maintain the program that traces risk through both the hardware and software supply chains — extending beyond first-tier vendors to the components, subcomponents, and sub-tier suppliers that go into spacecraft, payloads, and mission systems.
- Establish and maintain supplier and component inventories, including support for Hardware Bill of Materials (HBOM) and Software Bill of Materials (SBOM) practices, to enable provenance, traceability, and rapid impact analysis when a supplier or part is compromised, discontinued, or flagged.
- Align the C-SCRM program with NIST SP 800-161 Rev. 1, applicable CMMC supply chain requirements, and DFARS clauses, documenting supply chain risk controls and their coverage across critical suppliers.
- Support sub-tier and single-/sole-source dependency analysis, surfacing concentration risk and resilience gaps for critical components and escalating to program and supply chain leadership.
Enterprise Risk Management
- Support the design, execution, and continuous improvement of the enterprise risk management program under the direction of the Senior Enterprise Risk Manager, ensuring third-party and supply chain risks roll up into the enterprise risk picture.
- Support the application of FAIR methodology to help quantify third-party and supply chain risks in financial terms and contribute to risk prioritization analyses for leadership.
- Maintain and update the enterprise risk register, ensuring accuracy of risk ratings, ownership assignments, remediation status, and residual risk tracking for supplier- and vendor-originated risks.
- Build and maintain program dashboards, KPI/KRI reports, and status tracking using tools such as Jira, Confluence, enterprise GRC platforms, and MS Project — with an emphasis on third-party and supply chain exposure metrics.
- Assist with audit readiness activities including evidence collection, pre-assessment preparation, control documentation, and post-audit remediation tracking, including supply chain and vendor controls.
- Contribute to the development and maintenance of risk policies, standards, and guidelines aligned to NIST SP 800-53 Rev. 5, NIST SP 800-171, NIST SP 800-161, RMF, and CMMC Level 3.
Cross-Functional Collaboration
- Serve as a reliable day-to-day point of contact for third-party and supply chain risk inquiries from internal stakeholders across procurement, supply chain, engineering, security, operations, and legal teams.
- Track program milestones, action items, and deliverables, proactively communicating status and flagging risks or dependencies to the Senior Enterprise Risk Manager.
- Continuously improve vendor and supply chain risk workflows, questionnaire templates, tiering criteria, and reporting processes to support scalable and repeatable execution.
- Support the preparation of materials for internal leadership briefings, external assessor interactions, and government partner reviews, including third-party and supply chain risk exposure summaries.
Qualifications
- 5+ years of experience in third-party/vendor risk management, supply chain risk, enterprise risk management, GRC, cybersecurity risk, or a closely related discipline, with a substantial portion focused on third-party or supply chain risk.
- Direct, hands-on experience executing third-party/vendor risk assessments, including questionnaire administration, documentation review, tiering, risk scoring, and remediation tracking.
- Working knowledge of NIST SP 800-161 (C-SCRM), NIST SP 800-53, NIST SP 800-171, DoD RMF (IL5/IL6), and CMMC, with direct experience supporting assessments or audits under one or more of these frameworks.
- Familiarity with supply chain risk concepts such as HBOM/SBOM, counterfeit-parts avoidance, provenance and traceability, sub-tier dependency and concentration risk, and prohibited-source screening (e.g., Section 889, FASCSA).
- Familiarity with risk assessment methodologies including FAIR and/or OCTAVE, with a desire to deepen applied expertise in risk quantification.
- Hands-on experience with program management and GRC documentation tools including Jira, Confluence (Atlassian suite), MS Project, enterprise GRC and/or third-party risk platforms, and MS Visio or Lucidchart.
- Strong written and verbal communication skills, with the ability to clearly document findings and translate third-party and supply chain risk concepts for both technical and non-technical audiences.
- Highly organized, self-directed, and comfortable managing multiple workstreams simultaneously in a fast-paced, regulated environment.
- Active or ability to obtain SECRET, TS/SCI security clearance.
- Must be a U.S. citizen, lawful permanent resident, or protected individual per ITAR requirements (8 U.S.C. 1324b(a)(3)).
Preferred Qualifications
- Background in startup, aerospace, defense technology, or SaaS companies operating in regulated government markets, particularly with hardware and mission-software supply chains.
- Industry certifications such as:
- Certified Third Party Risk Professional (CTPRP)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Systems Auditor (CISA)
- Open FAIR Certification (The Open Group)
- CompTIA Security+ or equivalent
- Certified Professional in Supply Management (CPSM), SCPro, or similar supply chain certification
- Certified ScrumMaster (CSM) or similar Agile certification
- Experience with cloud environments, particularly Azure Government and/or AWS GovCloud.
- Familiarity with POA&M management, SSP documentation, and audit evidence collection in DoD authorization contexts, including supplier and supply chain controls.
- Working knowledge of ITAR, EAR, DFARS (including View phone number on aiapply.co, View phone number on aiapply.co, and 252.246-7007/7008), FOCI, and export control considerations as they relate to vendor and supply chain risk.
- Experience assessing foreign ownership, control, or influence (FOCI) and country-of-origin risk for critical suppliers.
- Familiarity with Agile/Scrum and hybrid project delivery models.
Compensation
- Base Salary: Denver - $105,000 to $150,000, Long Beach - $115,000 to $160,000, Washington, DC - $115,000 to $160,000, SF Bay Area - $125,000 to $175,000
- Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave
Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, location, and experience.
Additional Requirements
- Work Location: This role will be onsite at one of our office locations: Centennial, CO, Long Beach, CA, or Washington, DC #LI-Onsite
- Work Environment: Standard office setting, working at a desk or in a production factory environment
- Physical Demands: May include frequent standing, sitting, walking, bending, and lifting or carrying items up to 20 lbs.
This position will be open until it is successfully filled.
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR), you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.
We value diversity of experience, knowledge, backgrounds, and perspectives and harness these qualities to create extraordinary impact. True Anomaly is committed to equal employment opportunity regardless of sex, race, religion or belief, ethnic or national origin, disability, age, citizenship, marital, domestic or civil partnership status, sexual orientation, gender identity, pregnancy, maternity or related condition (including breastfeeding) or any other basis as protected by applicable law. If you have a disability or additional need that requires accommodation, please do not hesitate to let us know.
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.
True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us.
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.
True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us.
$101.1k - $115.4k
Senior Business Analyst - Third Party Risk Management (TPRM) Capital One is seeking a highly motivated, strategic and analytically adept Senior Business Analyst to join our Third Party Risk Management (TPRM) team. Sitting within the Operational Risk Management (ORM) second...SuggestedFull timePart timeLocal area- Capital One is seeking a Senior Business Analyst for Third Party Risk Management (TPRM) in McLean, VA. You will lead data reporting efforts, leverage SQL, and collaborate with multiple risk and business teams to drive proactive risk insights. This role sits within the...Suggested
- Capital One is seeking a Senior Business Analyst for Third Party Risk Management (TPRM) in McLean, VA. You will manage data reporting and analytics to inform risk decisions, collaborating with cross-functional teams across the enterprise. Responsibilities include building...Suggested
- Quantum Sky seeks a forward-thinking SCRM Analyst to support a Federal government client... ...on securing the government’s technology supply chain with detailed analysis, reporting, and collaboration... ...extensive experience in supply chain risk management, cybersecurity policies, and...Suggested
- Quantum Sky is searching for a forward-thinking and self-motivated Supply Chain Risk Management (SCRM) Analyst to support one of our law enforcement customers in Washington, DC. You will be responsible for helping Federal customers solve one of the most critical challenges...SuggestedWork experience placement
$110k - $130k
...Grounded in Understanding, and Focused on Impact . POSITION OVERVIEW The Senior Consultant will support Department-wide Supply Chain Risk Management (SCRM) across logistics and supply chain equities, including acquisition, sourcing, transportation, distribution,...Temporary workFlexible hours$116.35k - $210.33k
Leidos is seeking a Senior-Level Supply Chain Risk Management Analyst to provide advanced technical and analytical support to the FAA’s Counterintelligence... ...-Source Intelligence) or senior-level experience in third-party risk management (TPRM), Cyber Supply Chain Risk...Full timeContract workWork at office- ...contract role Clearance: Active Top Secret Qualifications: - Provides analytical support to manage the increasing risk of supply chain compromise related to cybersecurity, whether intentional or unintentional. - Identifies, assesses, and mitigates the risks...Long term contractPermanent employmentFull time
- ...growth, and winning ideas. Military Veterans Encouraged to Apply. Job Description: The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) and its information, communications, and...For contractorsWork at office
- ...and analyzes credit scoring metrics and risk ratings and quickly identifies material credit... ..., including recommendations from junior Analysts, and makes recommendations on... ...Regularly updates system comments to keep all parties informed of the status of all credit applications...Contract work
- ...MANTECH seeks a motivated, career and customer-oriented Supply Chain Risk Management (SCRM) Analyst/All Source Analyst to join our team in Springfield, VA . Responsibilities include but are not limited to: Conduct daily research to gather, assimilate, evaluate...Work at officeWorldwide
- R&D Security and Supply Chain Risk Advisor Advanced Resource Technologies is currently recruiting for a R&D Security and Supply Chain Risk Advisor to support the ARPA-H. This position is full-time, exempt. Start date is immediate upon selection and public trust clearance...Full timeWork at officeImmediate start
$110k - $120k
...Assurance & Critical Infrastructure Protection Analyst provides onsite support to the Joint... ...identify, assess, manage, and monitor risks to critical defense assets and missions.... ...(ABS) will not pay a fee to any third-party agency without a valid ABS Master Service...Work at officeRemote workMonday to FridayFlexible hours- ...Impact Assessments (PIAs), Privacy Threshold Analyses (PTAs), Third-Party Website and Application Privacy Assessments (TPWAs), and Privacy... ...stakeholders to help identify privacy requirements, assess privacy risks, and maintain required privacy documentation. Key...
- Senior Analyst, Cybersecurity GRC, Washington, DC The Senior Analyst, Cybersecurity GRC will administer the completion of compliance... ...for managed systems and applications, as well as support Third Party Risk Management (TPRM) and Governance and Risk functions in conducting...Work experience placement
$155k - $180k
Defense Supply Chain Risk Policy Consultant (Managing Consultant) You understand the power of great service experience and its ability to inspire customer behavior. You have a keen understanding of what it takes to deliver exceptional services, both in front of the house...Full timeTemporary workWork at officeFlexible hours- ...organizational priorities, financial objectives, risk requirements, and long-term strategy.... ...and mitigating procurement and third-party risks, including supplier concentration,... ...Education ~ Bachelor’s degree in business, supply chain management, procurement, economics,...Contract workWork experience placementWork at officeFlexible hours
$166.9k - $278.1k
...challenges faced by the banking industry. The opportunity Our Risk Technology Consulting practice helps clients modernize systems,... ...Compliance Management, Audit Management, Regulatory Change Management), Third-party Risk Management (TPRM), Business Continuity Management (BCM),...- ...Supply Chain Business Analyst The Supply Chain Business Analyst will work as an integral team member of a global serialization program, reporting to the Serialization Business Process Owner. The resource will be responsible for executing the business analysis needs...Contract workFlexible hours
$6,685 - $9,045 per month
...Quality Control Group! What you'll be doing... The Business Analyst is a solution-oriented professional who acts as a critical... ..... Northwest Administrators, Inc. is an industry leader in third-party administration of employee benefits. We administer one of the...Local area3 days per week$115k - $125k
...Job Description Description: NOTE: This opportunity is full-time employment position only (no 1099 or C2C engagements, or third parties or staffing agencies, please). The candidate MUST be a U.S. Citizen, local to the DMV area (Arlington, VA), and available to be...Full timeLocal areaRemote work$86.8k - $198k
Position, Navigation, & Timing Supply Chain Analyst, SeniorThe Opportunity:Are you looking for an opportunity to combine your technical skills with big picture thinking to make an impact in cybersecurity and critical infrastructure? You understand your customer’s environment...Full timeContract workPart timeWork at officeLocal areaRemote work- ACT1 Federal is seeking a qualified F-35 Supply Chain Management Analyst to support the Joint Program Office in Introduction to Service processes. The... ...include sustainment site activation planning, risk mitigation, and coordination with JPO, contractors and warfighters...For contractorsWork at officeDay shift
- ...Summary:Leads the application of best standards and practices in Supply Chain and Logistics, enforces compliance of relevant guidelines, and... ...-functionally to solve business problems; escalates issues or risks as appropriate; communicates progress and information....Contract workImmediate start
$70k - $90k
...We are seeking a Supply Chain Analyst to optimize logistics and inventory processes. Key Responsibilities Data Analysis: Analyze supply chain performance. Process Improvement: Identify efficiency opportunities. Reporting: Prepare operational reports. Qualifications...Full time$63.44k - $95.16k
...company to Ahold Delhaize USA, providing supply chain services that support the delivery of... ...Communicates with vendors and Inventory Analysts on any PO#'s that did not transmit or... ...with vendors, transportation providers, & third party consultants Experience with the...Full timeWork experience placementWork at officeRemote workFlexible hours- ...management through improved use of existing SAP tools and bar coding. Evaluates effective use of SAP data and systems related to supply chain. Improves use of SAP capabilities and tools. May assist in providing education regarding supply chain functions and processes...
- LMI is seeking a Senior Supply Chain and Food Modernization Analyst to support HQDA G-4 operations, including portfolio management, strategic planning, and executive decision support. The role focuses on delivering actionable insights, performance metrics, and cross-agency...
$142.6k - $261.5k
...the remediation and mitigation of process risk. You will assist engagement teams... ...with client technology professionals or third‑party strategic alliances to provide implementation... ...managing and supervising a team of business analysts and technology analysts through all...Work experience placementSummer holidayFlexible hours- Position Title: F-35 Supply Chain Management Analyst Location: Arlington, VA Category: Funded Schedule (FT/PT): FT Travel Required: Minimal Shift... ...level meetings to discuss SCM concerns and assist in risk-mitigation development and strategies Knowledge of F-35 sustainment...Temporary workFor contractorsWork at officeLocal areaRemote workFlexible hoursShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Third-Party & Supply Chain Risk Analyst. Be the first to apply!
- supply chain consultant Washington DC
- distribution analyst Washington DC
- logistics consultant Washington DC
- supply chain analyst Washington DC
- risk consultant Washington DC
- risk analyst Washington DC
- operational risk specialist Washington DC
- operational risk consultant Washington DC
- senior quantitative risk analyst Washington DC
- risk officer Washington DC


