Supply Chain Risk Management Specialist
WFA Digital Insight
Leidos’ Supply Chain Risk Management Specialist sits at the intersection of national security and procurement, directly supporting the FAA’s effort to shield its supply chain from foreign intelligence and cyber threats. Embedded in a three‑person team, the analyst tackles enterprise‑level vendor risk assessments, translating complex security postures of cloud providers, AI tools, and OT/ICS environments into actionable scores and contract language. The role demands fluency with the FAA Acquisition Management System and federal frameworks such as NIST SP 800‑161, plus the ability to brief senior FAA leaders in plain language. Candidates must bring eight years of intelligence or third‑party risk experience and an active Top‑Secret/SCI clearance, making this a highly specialized, mission‑critical position.
Job Description
Leidos is seeking a Supply Chain Risk Management Analyst to provide technical and analytical support to the Federal Aviation Administration's (FAA) Counterintelligence (CI) Supply Chain Risk Management (SCRM) program. The program is responsible for identifying, assessing, and mitigating foreign intelligence, nation-state, and cybersecurity threats to the FAA’s supply chain, critical infrastructure, and enterprise networks. Embedded within a 3-person team, this position focuses on enterprise risk assessments and procurement execution support. Providing risk analysis aligned with the FAA Acquisition Management System (AMS) framework, the analyst evaluates the actual security posture of software suppliers, cloud providers, Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) environments. This role translates threat data into technical risk scoring, conducts criticality analysis, and drafts custom contract security language to protect and mitigate threats against FAA supply chain. Primary
Responsibilities
Conduct enterprise-level vendor risk assessments and technical security reviews for software suppliers, cloud providers (SaaS/PaaS/IaaS), AI tools, telecommunications, and OT/ICS (Operational Technology/Industrial Control Systems). Conduct technical and non-technical risk scoring to compile comprehensive Vendor Risk Reports that map systemic vulnerabilities. Provide specialized SCRM subject matter expertise throughout the procurement lifecycle, including early-stage acquisition planning and source selections. Author Acquisition Security Reviews and evaluation matrices that integrate directly into the FAA Acquisition Management System (AMS) pipeline. Draft specific contract security language, technical security requirements, and risk acceptance recommendations to mitigate identified supply chain risks prior to contract award. Translate highly technical and complex risk assessment data into clear, Executive Decision Packages for a non-technical audience to enable FAA senior leadership to make rapid, fully informed decisions. Contribute to the development and maintenance of FAA SCRM policies, governance documentation, and standard operating procedures (SOPs). Formulate performance metrics and program reports for executive leadership. Maintain critical operational and collaborative relationships with external stakeholders, including the FAA Chief Information Officer (CIO), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Homeland Security (DHS), and the broader Intelligence Community (IC). Coordinate and facilitate SCRM training and awareness campaigns for acquisition personnel and program offices.Basic Qualifications
Citizenship: U.S. Citizenship required Clearance: Active Top Secret/SCI clearance is required Education: Bachelor’s degree in Supply Chain Risk Management, Intelligence Studies, National Security, Logistics, Data Science, Cybersecurity, Information Technology, Computer Science/Engineering, or a related discipline. (Equivalent professional experience or specialized training may be substituted). Experience: 8+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or OSINT) or professional experience in third-party risk management (TPRM), Cyber Supply Chain Risk Management (C-SCRM), technical risk assessments, cybersecurity risk management, or infrastructure defense. Framework Knowledge: Strong working knowledge of federal cybersecurity and risk management frameworks, specifically NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) and NIST SP 800-53. TechnicalSkills
Hands-on experience evaluating the security posture, software supply chains, and configurations of at least three of the following technology profiles: Cloud infrastructure and service providers (SaaS, PaaS, IaaS) Commercial software packages and open-source dependencies Artificial Intelligence (AI) platforms or Machine Learning tools Telecommunications hardware or infrastructure frameworks Operational Technology (OT) or Industrial Control Systems (ICS) CommunicationSkills
Proven capability to translate complex technical vulnerabilities, software flaws, and architectural risks into clear, well-structured, non-technical written reports and executive summaries.Preferred Qualifications
Completion of formal military or federal intelligence training courses focusing on threat network analysis or open-source collection. Possession of one or more of the following industry-recognized certifications: Certified Information Systems Security Professional (CISSP) Certified in Risk and Information Systems Control (CRISC) Certified Information Systems Auditor (CISA) Specialized federal SCRM or Counterintelligence training certifications (e.g., CDSE, ODNI, or defense-sponsored SCRM courses). Proficiency with advanced OSINT search techniques, corporate filing retrieval systems, or international trade/shipping databases. Demonstrated experience reviewing federal procurement mechanisms, source selection processes, or drafting contract security language. If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares. Original Posting: July 30, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: Pay Range $92,300.00 - $166,850.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.How to Stand Out
- Highlight any hands‑on experience with NIST SP 800‑161 or NIST SP 800‑53 in your resume and be ready to discuss specific assessments you performed.
- Prepare a concise case study that shows how you translated a technical risk score into actionable contract language for a senior audience.
- Ensure your Top‑Secret/SCI clearance status is up to date; mention clearance details early in the application.
- Familiarize yourself with the FAA Acquisition Management System workflow so you can speak confidently about integrating risk findings.
- Practice explaining complex security concepts in plain language, as interviewers will test your ability to brief non‑technical leaders.
- Include any relevant certifications (CISSP, CISA, etc.) even if not required; they can differentiate you.
- Watch for vague promises about salary; focus negotiations on the overall compensation package, remote stipend, and professional development funds.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.