Senior Risk & Compliance Analyst (C-SCRM Lead)
Fully Remote Springfield, VA
Description

Contingent Upon Contract Award

Remote with occasional on-site support


Connected Logistics is seeking a Senior Risk & Compliance Analyst (C-SCRM Lead) to support the Cybersecurity Architecture and Engineering Services supporting the Department of Veterans Affairs (VA) Office of Information Security (OIS) Cybersecurity Operations Systems Engineering (COSE) program.


The Senior Risk & Compliance Analyst (C-SCRM Lead) serves as  the lead subject matter expert for cybersecurity risk management, compliance, and Cybersecurity Supply Chain Risk Management (C-SCRM). This position provides expertise in conducting IT security risk assessments, threat and vulnerability analysis, and security control assessments to identify and evaluate risks to organizational systems, platforms, applications, data, and supporting technology supply chains. The Senior Risk & Compliance Analyst assesses the potential exposure of proprietary, sensitive, and mission-critical information resulting from weaknesses in technology platforms, security controls, access procedures, system configurations, third-party products and services, or other forms of access to organizational systems and data. The role leads C-SCRM activities and supports the identification, documentation, prioritization, mitigation, and continuous monitoring of cybersecurity and supply chain risks throughout the system and acquisition lifecycle. 


Key Responsibilities

  • Lead cybersecurity risk management, compliance, and C-SCRM activities across systems, applications, infrastructure, cloud environments, products, services, and supporting technology supply chains. 
  • Conduct comprehensive IT security risk assessments and threat analyses to identify vulnerabilities, control weaknesses, threat exposure, and potential impacts to organizational systems and data. 
  • Lead and coordinate Cybersecurity Supply Chain Risk Management (C-SCRM) assessments of technology products, software, hardware, services, suppliers, vendors, and other third-party dependencies. 
  • Identify and evaluate supply chain cybersecurity risks associated with product provenance, supplier dependencies, software components, third-party services, and technology acquisition. 
  • Conduct and oversee security control assessments to determine the effectiveness of implemented security safeguards and identify gaps requiring remediation or risk treatment. 
  • Evaluate risks associated with unauthorized access, excessive privileges, insecure access procedures, platform vulnerabilities, system configurations, data protection weaknesses, and third-party access. 
  • Develop and maintain cybersecurity and C-SCRM risk registers, documenting identified risks, likelihood, impact, risk severity, mitigating controls, responsible parties, and remediation status. 
  • Perform risk analysis and develop actionable risk mitigation and remediation recommendations based on identified threats, vulnerabilities, control deficiencies, and organizational risk tolerance. 
  • Track identified security deficiencies and remediation activities through closure, including supporting the development and management of Plans of Action and Milestones (POA&Ms) where applicable. 
  • Support implementation and execution of organizational Risk Management Framework (RMF) processes, including security assessment, authorization, continuous monitoring, and ongoing risk management activities. 
  • Assess compliance with applicable organizational cybersecurity policies, security requirements, contractual obligations, and established security control frameworks. 
  • Review system security documentation, assessment results, vulnerability findings, control evidence, architecture artifacts, and supporting documentation to determine cybersecurity risk and compliance posture. 
  • Collaborate with cybersecurity, engineering, architecture, acquisition, program management, and operational stakeholders to integrate security and supply chain risk considerations into technical and business decisions. 
  • Provide risk-based recommendations to program and cybersecurity leadership, clearly communicating technical risks, business impacts, mitigation alternatives, residual risk, and recommended courses of action. 
  • Support continuous monitoring of cybersecurity and supply chain risks, including changes to systems, suppliers, technologies, threat conditions, vulnerabilities, and operational environments. 
  • Develop and maintain risk assessment reports, compliance documentation, C-SCRM artifacts, executive risk summaries, metrics, dashboards, and other supporting cybersecurity documentation. 
  • Serve as a senior cybersecurity risk and C-SCRM advisor, providing technical guidance and subject matter expertise to project teams, system owners, security personnel, and organizational leadership.
Requirements
  • Public Trust: T4 or T5 (TS)
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Information Systems, Risk Management or a related technical discipline or an Associate's degree in the above discipline with an additional 2 years of experience.
  • Minimum of five (5) years of relevant professional experience in cybersecurity, information security, IT risk management, security compliance, security assessment, C-SCRM, or a related field. 
  • Demonstrated experience conducting IT security risk assessments, threat analyses, and security control assessments. 
  • Experience identifying and evaluating cybersecurity risks associated with system vulnerabilities, access controls, security procedures, technical platforms, applications, and organizational data. 
  • Experience assessing risk and recommending appropriate security controls, mitigation strategies, remediation actions, and risk treatment approaches. 
  • Knowledge of cybersecurity risk management concepts, assessment methodologies, security controls, vulnerability management, compliance, and continuous monitoring. 
  • Ability to analyze technical and cybersecurity information and translate findings into understandable risk statements and actionable recommendations for technical and non-technical stakeholders. 
  • Strong analytical, documentation, communication, and stakeholder coordination skills. 
  • Ability to develop high-quality security assessment reports, risk documentation, compliance artifacts, and executive-level risk summaries. 

Preferred Qualifications:

  • Experience leading or supporting Cybersecurity Supply Chain Risk Management (C-SCRM) programs, assessments, or governance activities in a federal environment. 
  • Working knowledge of NIST Risk Management Framework (RMF) principles and federal cybersecurity risk management practices. 
  • Experience evaluating cybersecurity risks associated with third-party vendors, suppliers, software, hardware, cloud services, and externally provided technology services. 
  • Experience supporting security authorization, continuous monitoring, security control assessment, vulnerability management, risk remediation, and POA&M processes. 
  • Experience developing and maintaining enterprise or program-level cybersecurity and C-SCRM risk registers, risk scoring methodologies, mitigation plans, and reporting metrics. 
  • Experience integrating cybersecurity risk considerations into system acquisition, engineering, architecture, DevSecOps, and lifecycle management processes. 
  • Familiarity with federal cybersecurity and supply chain security standards, guidance, and control frameworks applicable to C-SCRM and IT risk management. 
  • Experience communicating complex cybersecurity and supply chain risks to senior leadership and providing clear recommendations that support informed risk decisions. 
  • Relevant cybersecurity, risk management, audit, or governance certifications are preferred, such as CISSP, CISM, CRISC, CAP/CGRC, or equivalent credentials. 

Total Rewards Statement


We believe in fairness and clarity throughout our hiring process. The anticipated salary range for this position is $115,000.00-$125,000.00 USD. This is a good-faith range based on factors such as your experience, geographic location, and any applicable contractual requirements, and may vary slightly.


Beyond salary, we provide a robust benefits package and encourage ongoing professional development, because your growth and well-being matter to us. We’re excited to support you in building a rewarding career with us!


Connected Logistics respects the need for confidentiality for all applicants.


Connected Logistics has been named a 2026 WTOP Top Workplace in the medium sized business category. Our mission is clear: we deliver mission-focused IT, cybersecurity, logistics, and enterprise modernization support to federal agencies. When we invest in our people and create an environment where they feel valued and empowered, we deliver stronger outcomes for our clients and the missions we support.


Connected Logistics offers an excellent benefits package that includes health, dental, vision, life, and disability insurance, a great 401(k) package, and generous Paid Time Off.


EOE/Disability/Veterans