Cybersecurity Supply Chain Risk Analyst
Project Introduction
The Department of Veterans Affairs Cybersecurity Operations and Services Enterprise (COSE) program delivers the enterprise cybersecurity operations, engineering, architecture, risk, and compliance support that safeguards VA systems, data, and mission delivery. The team helps strengthen the cyber resilience of the digital services relied on by Veterans, their families, and the VA workforce.
9th Way Insignia is seeking a Cybersecurity Supply Chain Risk Analyst to support this program. This position is contingent upon contract award.
Professional Level
E3 – Engineer
Responsibilities
Assess cybersecurity supply-chain risks associated with vendors, products, services, software, and third-party dependencies.
Document supply-chain security requirements, risk findings, mitigations, and acceptance decisions.
Review supplier security evidence, software and hardware provenance information, vulnerability notices, and remediation plans.
Coordinate with acquisition, engineering, security, legal, and program stakeholders on third-party risk decisions.
Support continuous monitoring of supplier risks, emerging threats, and corrective-action status.
Requirements
Bachelor's degree in cybersecurity, information systems, supply-chain management, business, engineering, or a related field, or equivalent relevant experience.
Five or more years of cybersecurity, third-party risk, supply-chain risk, GRC, security assessment, or related experience.
Experience conducting vendor or product security assessments and documenting risks, controls, and remediation actions.
Working knowledge of cybersecurity supply-chain risk management practices, NIST guidance, software supply-chain risks, and third-party security controls.
Strong risk-analysis, documentation, stakeholder-engagement, and judgment skills.
Salary Range
$98,135—$125,000 USD