Cyber Supply Chain Risk Management (C-SCRM) Analyst
$89k - $100kFortress
Position: Cyber Supply Chain Risk Management (C-SCRM) Analyst Location: District of Columbia, Maryland, and Virginia - Hybrid, DC Job Id: 688 # of Openings: 1 Fortress is building a pipeline of qualified candidates for an upcoming Cyber Supply Chain Risk Management (C-SCRM) Analyst opening. While this role is not immediately open, we expect to fill it soon and want to connect with strong candidates now so we can move quickly when it does. Thank you for your understanding! Cyber Supply Chain Risk Management (C-SCRM) Analyst Location: Hybrid, DC area Compensation: $89,000 - $100,000 Employment Type: Full-Time Travel Requirements: Up to 15% Clearance Requirement: Active Secret Clearance at time of hire What you can expect as the Cyber Supply Chain Risk Management (C-SCRM) Analyst at Fortress... The Cyber Supply Chain Risk Management (C-SCRM) Analyst supports Fortress's Government Delivery team by identifying, analyzing, and communicating cyber supply chain risks for U.S. Navy programs. This role serves as the analytical engine behind risk discovery - reviewing submitted data, evaluating supply chain risk indicators, interpreting platform findings, and translating raw information into meaningful program and mission impact. Working closely with Management Analysts, Technical Project Managers, Delivery leaders, and technical subject matter experts, the analyst supports risk analysis, reporting, and customer delivery at scale. The role offers the opportunity to develop deep expertise in the Fortress C-SCRM Platform, Fortress deliverables, and relevant Navy systems and data, making it an ideal position for someone looking to grow as a trusted subject matter expert in federal cyber supply chain risk. This is a high-impact role directly tied to customer retention, program quality, and Fortress's continued growth across Navy accounts. Responsibilities Include: Analyze cyber supply chain risk data to identify supplier, product, software, hardware, ownership, control, influence, dependency, and vulnerability risks that may impact U.S. Navy programs. Review submitted data, including hardware and software bills of materials, for completeness, accuracy, consistency, and indicators of high supply chain risk. Evaluate findings within the Fortress C-SCRM Platform and identify risk patterns, anomalies, or areas requiring additional review or escalation. Translate raw threat and supply chain data, including indicators such as Foreign Ownership, Control, or Influence (FOCI), compromised software libraries, supplier exposure, product vulnerabilities, or bill of materials concerns, into clear risk narratives and potential mission impacts. Develop subject matter expertise in the Fortress C-SCRM Platform, Fortress products, Navy systems, customer data, and program deliverables to support accurate analysis and consistent delivery outcomes. Identify, document, and communicate high-risk supply chain findings so internal stakeholders and customer-facing team members understand the risk, impact, and recommended next steps. Partner with Management Analysts, Technical Project Managers, and technical subject matter experts to support program-level reporting, risk briefings, deliverable development, and customer milestones. Serve as a subject matter expert during customer discussions when needed, including answering questions about risk findings, data interpretation, platform outputs, or deliverable content. Document risk findings, assumptions, data limitations, and recommended areas for further review in a clear, defensible, and repeatable manner. Support the development and refinement of analytical processes, templates, quality checks, and reporting inputs that improve consistency, efficiency, and confidence in C-SCRM deliverables. Use Excel to review, organize, analyze, validate, and summarize supply chain, supplier, platform, bill of materials, or risk data. Use PowerPoint to support clear communication of risk findings, trends, impacts, and recommendations in customer-ready or internal briefing materials. Apply intermediate AI proficiency to improve research, analysis, summarization, pattern recognition, and workflow efficiency while following Fortress, customer, and security requirements for responsible AI use. Maintain awareness of cyber supply chain risk concepts, threat intelligence, supplier risk indicators, software risk, hardware risk, and federal cybersecurity requirements relevant to government and defense customers. Protect sensitive customer, supplier, product, and program information in accordance with applicable security, contractual, clearance, and customer requirements. Travel up to 15% for potential customer site visits, in-person meetings, or program-related engagements. Minimum Qualifications: 2–4 years of experience in cyber supply chain risk management, cybersecurity analysis, threat intelligence, supplier risk, risk analysis, federal consulting, government delivery, or a related field. Active Secret clearance required at time of hire. Experience analyzing technical, supplier, product, vendor, threat, bill of materials, or risk data and translating findings into clear business, operational, or mission impact. Understanding of cyber supply chain risk concepts, including supplier risk, software risk, hardware risk, third-party risk, ownership/control concerns, threat exposure, and vulnerability or compromise indicators. Ability to review data for accuracy, completeness, and risk significance while documenting findings clearly and objectively. Ability to learn specialized platforms, customer systems, product workflows, and data structures quickly and apply that knowledge to risk analysis and deliverable development. Proficiency with Microsoft Excel, including the ability to organize, filter, compare, review, and summarize data. Proficiency with Microsoft PowerPoint, including the ability to support clear, professional presentations and briefing materials. Strong written communication skills with the ability to summarize complex risk information for internal stakeholders, program teams, and occasional customer-facing discussions. Ability to serve as a subject matter expert on risk findings, platform outputs, and deliverable content when needed. Ability to work effectively in a hybrid environment in the Washington, DC area. Ability to collaborate with project managers, analysts, technical teams, and delivery leaders while operating with moderate independence. Intermediate proficiency using AI tools to support research, analysis, summarization, and productivity while applying sound judgment, validation, and responsible-use practices. Ability to travel up to 15% for customer on-site visits, in-person meetings, or program-related engagements. Ability to handle sensitive information and comply with applicable security, confidentiality, clearance, and customer requirements. Preferred Skills: Security+ certification or other related cybersecurity, risk management, supply chain risk, or information assurance certification. Experience supporting Department of Defense, Department of Navy, federal civilian, or defense industrial base customers. Experience with C-SCRM, SCRM, vendor risk management, third-party risk management, software supply chain risk, hardware supply chain risk, cyber threat intelligence, or product assurance. Familiarity with FOCI, SBOM, HBOM, supplier risk scoring, vulnerability data, compromised software libraries, or product assurance workflows. Experience reviewing bills of materials, supplier data, software component data, hardware component data, product data, or platform-generated risk findings. Experience using data analysis, case management, risk management, cybersecurity, or reporting platforms to evaluate and communicate risk. Familiarity with federal cybersecurity frameworks, standards, or guidance such as NIST, CMMC, FedRAMP, RMF, or DoD cybersecurity requirements. Experience producing written findings, risk summaries, briefing inputs, or analytical reports for government or regulated customers. Education: Bachelor’s Degree or equivalent professional work experience required. Employee Benefits: Remote and Hybrid working environment Competitive pay structure Medical, dental, vision plans with employees covered up to 90% with highly progressive options for dependents and families Company paid life, short- and long-term disability insurance Employee Assistance Program 401(k) match Flexible Paid Time Off We provide each employee with professional growth opportunities through succession planning, up-skilling, and certifications Tuition and certification reimbursement Employee Referral Programs Company Sponsored Events Fortress is proud to be an Equal Opportunity Employer. All employees and applicants will receive consideration for employment without regard to age, color, disability, gender, national origin, race, religion, sexual orientation, gender identity, protected veteran status, or any other classification protected by federal, state, or local law. Fortress Information Security takes part in the E-Verify process for all new hires. For positions located in the US, the following conditions apply. If you are made a conditional offer of employment, you will have to undergo a drug test. ADA Disclaimer: In developing this job description care was taken to include all competencies needed to successfully perform in this position. However, for Americans with Disabilities Act (ADA) purposes, the essential functions of the job may or may not have been described for purposes of ADA reasonable accommodation. All reasonable accommodation requests will be reviewed and evaluated on a case-by-case basis. #J-18808-Ljbffr Fortress
- Fortress is seeking a Cyber Supply Chain Risk Management (C-SCRM) Analyst to join its hybrid DC-area team. You will analyze risk data, review bills of materials, and translate findings into clear risk narratives for government programs, while supporting deliverables and...Cyber
- ...LLC is a Virginia-based service provider and subsidiary of AVIAN, focused on high-assurance cyber security and information solutions. The Information, Review and Release Analyst (IRRA) role emphasizes meticulous document review and redaction under EO 13526, FOIA, and the...Cyber
- Acclaim Technical Services, founded in 2000, is a leading cyber operations, intelligence solutions and operations, network infrastructure... ...We are hiring multiple Senior-Level Counterterrorism Watchlist Analysts to support a U.S. #J-18808-Ljbffr Acclaim Technical Services,...Cyber
$101.7k
Geo Owl LLC is seeking a senior analytic professional to support all-source intelligence across DCGS, AOC, targeting, cyber, space, and other ACC activities at the JBLE site in Virginia. The role requires a Master’s degree or a Bachelor’s with extensive experience and a...CyberFull time- ...supports a government CSSP contract, conducting end-to-end cyber incident management from initial detection through resolution. Day-to-day work... ...to take ownership of complex investigations, guide junior analysts, and contribute to training development. Those with a DoD...CyberContract work
$110k - $125k
...application process. Mid-Level Business Analyst Bluemont, VA, US 5 days ago Requisition... ...enterprise IT, including cloud services: cyber, software, advanced analytics, and AI. With... ...and support configuration/change management processes. Develop process flow diagrams...Cyber$115k - $135k
...accommodation or an alternative application process. Senior Business Analyst Bluemont, VA, US 5 days ago Requisition ID: 1477 Salary Range: $... ...and integration, enterprise IT, including cloud services: cyber, software, advanced analytics, and AI. With an intimate understanding...CyberWork experience placement$165k - $175k
All Source Analyst SME - Joint Base Langley-Eustis, VA Clearance: Active TS/SCI Position Description: The candidate will provide support... ...Air Operations Center (AOC) intelligence, targeting, analysis, cyber, space and other ACC intelligence activities. Responsibilities:...CyberContract work$80k - $100k
...Technical Services,founded in 2000, is a leading cyber operations, intelligence solutions and... ...Mid-Level Counterterrorism Watchlist Analysts to help support counterterrorism... ...experience in lieu of degree Ability to manage multiple sets of data Ability to apply operational...CyberContract workWork experience placementCurrently hiringShift work- ...AVIAN, represents a fusion of innovation, reliability, and top-tier cyber security and IT solutions. As a Virginia-based small business... .... Responsibilities As an Information, Review and Release Analyst (IRRA), the candidate will be expected to review and analyze select...CyberFlexible hours
$101.7k
...support for all-source intelligence including, but not limited to, DCGS, Air Operations Center (AOC) intelligence, targeting, analysis, cyber, space and other ACC intelligence activities. The contractor shall: Support ACC organizations with dedicated fusion and tradecraft...CyberTemporary workFor contractorsRemote workFlexible hours$180k - $230k
Program Manager - Air Force Special Programs Pentagon, VA Blue Sky Innovators is seeking... ...program success and maintain alignment. Risk Management: Identify program risks and develop... ...across advanced air, space, and cyber domains. You’ll work side-by-side with senior...CyberFull time$171k - $214k
...the ultimate mission to raise cyber resilience, so that every organization... ...of the Partner Development Manager (Federal) At Hack The Box (HTB)... ...from procurement officers to C‑level executives at major defense... ...defenses and reduce breach risk effectively. Rapidly growing its...CyberLong term contractTemporary workFor contractorsRemote workHome officeShift work- Level Up, LLC, a Virginia-based cybersecurity and IT solutions provider, seeks an Information, Review and Release Analyst (IRRA) to redact documents per EO 13526, FOIA and PA guidance. You will apply exemptions, train staff, and collaborate with client POCs to improve processes...
- ...team. The ideal candidate will be responsible for implementing, managing, and optimizing the Splunk platform to automate and... ...unsubscribe at any time. We work alongside clients to manage cyber risk and equip them with perspectives and programs to accelerate business...CyberWork experience placementLocal areaRemote workWork from home
- ...Summary BMA is seeking a Task Order Project Manager to support the DLA JETS Cybersecurity Assessment and Authorization Analyst (CS AAA) Support Services program. The position... ...of cybersecurity services supporting Risk Management Framework (RMF) implementation, system...Contract workFor contractorsLocal areaRemote work
$122k - $253k
...provides technically advanced full-spectrum cyber, data operations, systems integration and... ...the consolidated environment* Support risk assessments and develop risk mitigation countermeasures... ..., TLS encryption, and VPC firewall management**Desired Skills*** Prior experience...Cyber- ...Join J5 Consulting and Grow Your Cybersecurity Career At J5, we're a team of innovators protecting organizations from evolving cyber threats. Enjoy comprehensive benefits, including: ~100% employer-paid health coverage ~ a 6% 401(k) match ~ PTO ~ tuition...CyberLocal area
- Cyntel Technologies, LLC seeks an All Source Analyst SME to support Joint Base Langley-Eustis, VA. The role requires active TS/SCI clearance... ...intelligence including DCGS, AOC intelligence, targeting, cyber, space, and related ACC activities. The candidate will apply advanced...Cyber
$61.9k - $141k
...apply)job requisition id: R0246002Nuclear Analyst**The Opportunity:**As a nuclear analyst,... ...the safe, efficient, and compliant management of nuclear facilities, programs, and policies... ...nuclear operations to identify risks, inefficiencies, or opportunities for improvement...Full timeContract workPart timeWork at officeRemote work- Job Description: Orbis is seeking a M365 Support/Business Analyst to work on site at the Naval Weapons Station, Yorktown, VA, in support... ..., software requirements reviews and testing, database management, hardware support, help desk functions (Tier I) and other support...Contract work
$55 per hour
...Job Description Title Analyst Posting Start Date: 8/4/26 Requisition ID: 70568 ENGIE North... ...strong attention to detail, project management skills, and the ability to manage multiple... ...summarizing material findings, deficiencies, risks, and financing considerations....Hourly payFull timeContract workFixed term contractRemote workWork visaFlexible hours- ...Demonstrated Experience Demonstrated experience building and managing data pipelines Demonstrated experience with Python Demonstrated... ...re a team of innovators protecting organizations from evolving cyber threats. With 18+ years of success in government and commercial...CyberWork at officeLocal area
$20.88 - $26.01 per hour
Overview About M.C. Dean M.C. Dean is Building Intelligence. We design, build, operate, and maintain cyber-physical solutions for the nation’s most mission-critical facilities... ...Work and collaborate with Program Management personnel on matters of business and contractual...CyberContract work$100k - $200k
...will work with IC tools, collect and clean data, perform predictive and prescriptive analytics, and contribute to decision-making. Bachelor's degree and 3+ years in cyber/targeting required; salary range $100,000-$200,000. #J-18808-Ljbffr Acclaim Technical Services, Inc.Cyber- Overview About Level Up Level Up, LLC, a wholly-owned subsidiary of AVIAN, represents a fusion of innovation, reliability, and top-tier cyber security and IT solutions. As a Virginia-based small business with over 150 years of collective experience, we pride ourselves on...CyberFlexible hoursShift work
$61.4k - $102.52k
...requirements in the areas of Data Analytics and Software Development, Engineering, Targeting and Analysis, Operations, Training, and Cyber Operations. We maximize opportunities for success by building and maintaining trusted and reliable partnerships with our customers...CyberContract work- Optiv + ClearShark is seeking a seasoned Sr. Splunk Engineer to implement, manage, and optimize Splunk across security operations. You will develop custom playbooks, integrate with other security tools, and help automate workflows. In this role you will create reports...Cyber
$63k - $80k
...professionals ranges from skilled trades to project managers, engineers and software developers to... ...safeguard our seas, sky, land, space and cyber. HII's diverse workforce includes skilled... ...working to ensure a future where everyone c #J-18808-Ljbffr Huntington Ingalls...CyberFull timeFor contractorsApprenticeshipWork at officeRemote workRelocationShift work- ...Amyx is seeking to hire aBusiness/Financial Analyst for the Defense Threat Reduction Agency (... ...cost benefit analyses, and Earned Value Management System (EVMS) reporting analyses... ...attendance is essential. #J-18808-Ljbffr Anaesthesia Associates of Massachusetts, P.C.Contract workTemporary workFor contractorsFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Supply Chain Risk Management (C-SCRM) Analyst. Be the first to apply!

