Cyber Supply Chain Risk Management (C-SCRM) Analyst
$89k - $100kFortress Information Security, LLC
Position: Cyber Supply Chain Risk Management (C-SCRM) Analyst Location: District of Columbia, Maryland, and Virginia - Hybrid, DC Job Id: 688 # of Openings: 1 Location: Hybrid, DC area Compensation: $89,000 - $100,000 Employment Type: Full-Time Travel Requirements: Up to 15% Clearance Requirement: Active Secret Clearance at time of hire Fortress is building a pipeline of qualified candidates for an upcoming Cyber Supply Chain Risk Management (C-SCRM) Analyst opening. While this role is not immediately open, we expect to fill it soon and want to connect with strong candidates now so we can move quickly when it does. Thank you for your understanding! What you can expect as the Cyber Supply Chain Risk Management (C-SCRM) Analyst at Fortress The Cyber Supply Chain Risk Management (C-SCRM) Analyst supports Fortress's Government Delivery team by identifying, analyzing, and communicating cyber supply chain risks for U.S. Navy programs. This role serves as the analytical engine behind risk discovery - reviewing submitted data, evaluating supply chain risk indicators, interpreting platform findings, and translating raw information into meaningful program and mission impact. Working closely with Management Analysts, Technical Project Managers, Delivery leaders, and technical subject matter experts, the analyst supports risk analysis, reporting, and customer delivery at scale. The role offers the opportunity to develop deep expertise in the Fortress C-SCRM Platform, Fortress deliverables, and relevant Navy systems and data, making it an ideal position for someone looking to grow as a trusted subject matter expert in federal cyber supply chain risk. This is a high-impact role directly tied to customer retention, program quality, and Fortress's continued growth across Navy accounts. Responsibilities Include: Analyze cyber supply chain risk data to identify supplier, product, software, hardware, ownership, control, influence, dependency, and vulnerability risks that may impact U.S. Navy programs. Review submitted data, including hardware and software bills of materials, for completeness, accuracy, consistency, and indicators of high supply chain risk. Evaluate findings within the Fortress C-SCRM Platform and identify risk patterns, anomalies, or areas requiring additional review or escalation. Translate raw threat and supply chain data, including indicators such as Foreign Ownership, Control, or Influence (FOCI), compromised software libraries, supplier exposure, product vulnerabilities, or bill of materials concerns, into clear risk narratives and potential mission impacts. Develop subject matter expertise in the Fortress C-SCRM Platform, Fortress products, Navy systems, customer data, and program deliverables to support accurate analysis and consistent delivery outcomes. Identify, document, and communicate high-risk supply chain findings so internal stakeholders and customer-facing team members understand the risk, impact, and recommended next steps. Partner with Management Analysts, Technical Project Managers, and technical subject matter experts to support program-level reporting, risk briefings, deliverable development, and customer milestones. Serve as a subject matter expert during customer discussions when needed, including answering questions about risk findings, data interpretation, platform outputs, or deliverable content. Document risk findings, assumptions, data limitations, and recommended areas for further review in a clear, defensible, and repeatable manner. Support the development and refinement of analytical processes, templates, quality checks, and reporting inputs that improve consistency, efficiency, and confidence in C-SCRM deliverables. Use Excel to review, organize, analyze, validate, and summarize supply chain, supplier, platform, bill of materials, or risk data. Use PowerPoint to support clear communication of risk findings, trends, impacts, and recommendations in customer-ready or internal briefing materials. Apply intermediate AI proficiency to improve research, analysis, summarization, pattern recognition, and workflow efficiency while following Fortress, customer, and security requirements for responsible AI use. Maintain awareness of cyber supply chain risk concepts, threat intelligence, supplier risk indicators, software risk, hardware risk, and federal cybersecurity requirements relevant to government and defense customers. Protect sensitive customer, supplier, product, and program information in accordance with applicable security, contractual, clearance, and customer requirements. Travel up to 15% for potential customer site visits, in-person meetings, or program-related engagements. Minimum Qualifications: 2-4 years of experience in cyber supply chain risk management, cybersecurity analysis, threat intelligence, supplier risk, risk analysis, federal consulting, government delivery, or a related field. Active Secret clearance required at time of hire. Experience analyzing technical, supplier, product, vendor, threat, bill of materials, or risk data and translating findings into clear business, operational, or mission impact. Understanding of cyber supply chain risk concepts, including supplier risk, software risk, hardware risk, third-party risk, ownership/control concerns, threat exposure, and vulnerability or compromise indicators. Ability to review data for accuracy, completeness, and risk significance while documenting findings clearly and objectively. Ability to learn specialized platforms, customer systems, product workflows, and data structures quickly and apply that knowledge to risk analysis and deliverable development. Proficiency with Microsoft Excel, including the ability to organize, filter, compare, review, and summarize data. Proficiency with Microsoft PowerPoint, including the ability to support clear, professional presentations and briefing materials. Strong written communication skills with the ability to summarize complex risk information for internal stakeholders, program teams, and occasional customer-facing discussions. Ability to serve as a subject matter expert on risk findings, platform outputs, and deliverable content when needed. Ability to work effectively in a hybrid environment in the Washington, DC area. Ability to collaborate with project managers, analysts, technical teams, and delivery leaders while operating with moderate independence. Intermediate proficiency using AI tools to support research, analysis, summarization, and productivity while applying sound judgment, validation, and responsible-use practices. Ability to travel up to 15% for customer on-site visits, in-person meetings, or program-related engagements. Ability to handle sensitive information and comply with applicable security, confidentiality, clearance, and customer requirements. Preferred Skills: Security+ certification or other related cybersecurity, risk management, supply chain risk, or information assurance certification. Experience supporting Department of Defense, Department of Navy, federal civilian, or defense industrial base customers. Experience with C-SCRM, SCRM, vendor risk management, third-party risk management, software supply chain risk, hardware supply chain risk, cyber threat intelligence, or product assurance. Familiarity with FOCI, SBOM, HBOM, supplier risk scoring, vulnerability data, compromised software libraries, or product assurance workflows. Experience reviewing bills of materials, supplier data, software component data, hardware component data, product data, or platform-generated risk findings. Experience using data analysis, case management, risk management, cybersecurity, or reporting platforms to evaluate and communicate risk. Familiarity with federal cybersecurity frameworks, standards, or guidance such as NIST, CMMC, FedRAMP, RMF, or DoD cybersecurity requirements. Experience producing written findings, risk summaries, briefing inputs, or analytical reports for government or regulated customers. Education: Bachelor's Degree or equivalent professional work experience required. Employee Benefits: Remote and Hybrid working environment Competitive pay structure Medical, dental, vision plans with employees covered up to 90% with highly progressive options for dependents and families Company paid life, short- and long-term disability insurance Employee Assistance Program 401(k) match Flexible Paid Time Off Parental Leave Employment Perks: We provide each employee with professional growth opportunities through succession planning, up-skilling, and certifications Tuition and certification reimbursement Employee Referral Programs Company Sponsored Events Fortress is proud to be an Equal Opportunity Employer. All employees and applicants will receive consideration for employment without regard to age, color, disability, gender, national origin, race, religion, sexual orientation, gender identity, protected veteran status, or any other classification protected by federal, state, or local law. Fortress Information Security takes part in the E-Verify process for all new hires. For positions located in the US, the following conditions apply. If you are made a conditional offer of employment, you will have to undergo a drug test. ADA Disclaimer: In developing this job description care was taken to include all competencies needed to successfully perform in this position. However, for Americans with Disabilities Act (ADA) purposes, the essential functions of the job may or may not have been described for purposes of ADA reasonable accommodation. All reasonable accommodation requests will be reviewed and evaluated on a case-by-case basis. Pay Range: $89,000 - $100,000 per hour #J-18808-Ljbffr Fortress Information Security, LLC
- Fortress Information Security, LLC is seeking a Cyber Supply Chain Risk Management (C-SCRM) Analyst to support the Government Delivery team. The role focuses on identifying, analyzing, and communicating cyber supply chain risks for U.S. Navy programs, acting as the analytical...Cyber
- Threat Analyst LOCATION Annapolis Junction, MD 20701 CLEARANCE TS/... ...role, you will monitor emerging risks, assess vulnerabilities, and... .... SIMILAR CAREER TITLES Cyber Threat Analyst, Intelligence... ...Systems, Security Studies, Risk Management, etc. ALTERNATE EXPERIENCE General...Cyber
$135k - $216k
...Intel/Operational Analys t to provide C4/Cyber Threat & Vulnerability Analysis to USPACOM... ...targeting priorities and SPOF exploitation risk Contextualize findings against known PACOM... ...and methodologies; familiarity with MRT-C frameworks and DCO concepts Familiarity with...CyberContract workShift work$137.1k - $152.3k
...a motivated and mission-driven Intrusion Analyst 3 to support critical government initiatives... ...Computer Scientists, Cryptologic Cyber Planners, Intrusion Analysts, Protocol Analysts... ...malware analysis and programming experience in C, C#, C++, Java, Perl, or Python is...CyberFull timeContract workLocal area$75.2k - $158.1k
Job Title: WTI Analyst - CITT Technical Analyst Job Category: Intelligence Time Type: Full... ...intelligence disciplines (e.g. TECHSIGINT, SIGINT/CYBER, MASINT) from all levels of classified... ...or 6 yrs. of experience. Experience with C-UAS and / or C-IED analysis and reporting....CyberFull timeLocal areaRemote workFlexible hours- ...the boundaries of offensive cyber operations? BigBear.ai is seeking... .... Proficiency in Assembly, C, C++, Java, Perl, and/or... ...disassemblers and debuggers. Project Management: Familiarity with Agile,... ...solutions for national security, supply chain management, and digital...Cyber
$182k - $233k
A cybersecurity firm in Maryland is seeking an experienced Exploitation Analyst to conduct deep target analysis and support the exploitation of digital networks. This role requires a Top Secret Clearance, relevant experience, and U.S. citizenship. The position offers a...Cyber- Peraton seeks an Operational Technology (OT) Criteria and Standards Analyst to establish the organizational foundation for IC/SCADA-focused cybersecurity assessments across the PACOM AOR. Location: Fort Meade, MD. You will develop OT-specific criteria aligned to DISA OT...Cyber
$7.5k
...Job Brief Exploitation, network, cyber Job Description RealmOne is FOCUSED on... ...opportunity supports a team of Exploitation Analysts, Digital Network Exploitation Analysts,... ...Headquartered in Columbia, MD., RealmOne supplies advanced cybersecurity, data science and...CyberContract workWork experience placementImmediate startFlexible hours$110k - $125k
Acclaim Technical Services, Inc. is looking for an All-Source Analyst (Production) in Annapolis, Maryland. This position requires an active... ...issues, provide analytic support for operations, and categorize cyber threats. A Master's degree in a related field is essential,...Cyber- Acclaim Technical Services is looking for an All-Source Analyst (Production) with an active TS/SCI clearance w/Poly for a contract expected... ..., providing all-source analytic support, and characterizing cyber threats. The ideal candidate will have a Master's degree or equivalent...CyberContract work
- ...experienced Senior J-9 HaC Incident Response Analyst to provide cybersecurity management support in a U.S. government DoD environment.... ...include monitoring, analyzing, and responding to cyber incidents, maintaining logs and chain of custody, and coordinating with CSSP and...Cyber
- Bytoa seeks Exploitation Analysts to support IC missions. You will apply expertise in adversary networks, network defenses, and cyber capabilities to develop exploitation plans and adjust as plans execute. Responsibilities include hypothesis formation, data-driven analysis...Cyber
- A leading technology provider is hiring an Exploitation Analyst in Maryland. Candidates must have an active security clearance at the TS/SCI polygraph level. The role demands expertise in cyber security and network engineering, where you will develop exploitation plans....CyberFlexible hours
- SIXGEN is seeking a Senior Malware Analyst to support USCYBERCOM operations from the Annapolis area. You will conduct deep malware analysis... ...to identify TTPs and inform defensive and offensive cyber missions. The role requires a Top Secret clearance with SCI eligibility...Cyber
- SIXGEN is seeking a Principal Targeting Analyst to build and lead a targeted collection capability for offensive cyber, red-team, and adversary-emulation missions. The role blends analyst- engineer duties, OSINT collection, and AI-driven automation to deliver mission-ready...Cyber
- Input Technology Solutions in Fort Meade, MD seeks a Senior Program Analyst to track DoD PPBE processes, draft and edit strategic documents, and apply performance metrics to programs and funding priorities. The role requires coordinating across DoD and IC partners, maintaining...Cyber
- A leading cyber operations company in Annapolis Junction, MD, is seeking an Operational Language Analyst - Spanish, Level 2. Responsibilities include translating and transcribing complex language materials, performing quality control, and processing foreign language materials...Cyber
- ...Target Analyst Reporter LOCATION Annapolis Junction, MD 20701 CLEARANCE TS/SCI CI Poly... ...Specialist, Geospatial Intelligence Analyst, Cyber Intelligence Analyst, All-Source Analyst... ...Strong organizational and time-management skills DESIRED SKILLS Familiarity with intelligence...CyberTemporary workFor contractorsImmediate startFlexible hours
$50k - $290k
...capabilities include Software Development, Engineering & IT, Data Science, Cyber Enablement, Logistics, and Training. Founded in 2019, Swift... ...around the globe. We are looking for an experienced Data Analyst to join our team in Annapolis Junction, MD....CyberContract workWork experience placement- ...subject matter expert in ensuring system security compliance and risk management throughout the program life cycle. This role involves driving... ...(IATT) and ATO efforts by coordinating with stakeholders, cyber teams, and Authorizing Officials (AO). Implement and validate...CyberFull timeInterim roleFlexible hours
- EverWatch invites applications for a Security Operations Center Analyst in the Annapolis Junction area to strengthen U.S. Cyber Command defenses. You will analyze logs, threat intelligence, and forensic data to identify advanced threats and respond to incidents with a deep...Cyber
$140k - $160k
A leading cyber operations firm located in Annapolis Junction, MD is seeking an Operational Language Analyst specialized in Turkish. The role focuses on processing voice and graphic language materials in support of SIGINT operations. Candidates should possess ILR Skill...Cyber$50k - $290k
...capabilities include Software Development, Engineering & IT, Data Science, Cyber Enablement, Logistics, and Training. Founded in 2019, Swift... ...country and around the globe. We are looking for a Forensic Analyst to join a growing team in Annapolis Junction, MD ....CyberContract workWork experience placement$125k - $145k
...Job Description Tensley Consulting is seeking a Target Analyst Reporter to support critical national security missions in the Fort... ...network exploitation, vulnerability analysis, network forensics, cyber operations, and intelligence community mission activities. The...Cyber$7.5k
...Scientists, Cryptanalytic Computer Scientists, Cryptologic Cyber Planners, Intrusion Analysts, Protocol Analysts, Signals Analysts and Reverse... ...challenges. Headquartered in Columbia, MD., RealmOne supplies advanced cybersecurity, data science and software engineering...CyberContract workWork experience placementImmediate startFlexible hours$50k - $290k
...capabilities include Software Development, Engineering & IT, Data Science, Cyber Enablement, Logistics, and Training. Founded in 2019, Swift... ...the country and around the globe. We are seeking a Target Analyst Reporter 2 (TAR) to support mission-focused intelligence...CyberContract workWork experience placement$128.04k - $173.23k
...Analytical Tools, Dashboard Management, Datasets, Data Visualization... ...Description: DATA VISUALIZATION ANALYST YOUR IMPACT... ...displays that communicate trends, risks, and performance outcomes, enabling... ...capabilities in AI, cloud, cyber and software development....CyberTemporary workWork at officeImmediate startRemote workWorldwideFlexible hours- Nyla Technology Solutions seeks a Cyber Data & Mobile Characterization Analyst in Annapolis Junction, MD. You will lead data-driven discovery, mobile app characterization, and advanced analytics to inform mission partners. Requirements include TS/SCI polygraph clearance...Cyber
- NetSage is seeking a Senior Exploitation Analyst Instructor to develop and deliver technical instruction for cyber training. You will create course materials, build scenarios, and craft exercises, demonstrations, and visual aids to teach and test concepts. The ideal candidate...Cyber
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Supply Chain Risk Management (C-SCRM) Analyst. Be the first to apply!
- risk officer Annapolis, MD
- risk analyst Annapolis, MD
- risk consultant Annapolis, MD
- it risk analyst Annapolis, MD
- senior data management analyst Annapolis, MD
- business analyst law firm Annapolis, MD
- senior business development analyst Annapolis, MD
- pega business analyst Annapolis, MD
- software asset management analyst Annapolis, MD
- knowledge management analyst Annapolis, MD

