CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

Cybersecurity Supply Chain Risk Analyst

9Thwayinsignia • United States - Remote

Job Description

<div class="content-intro"><p>9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to our government customers so they can achieve their missions. Our specialties include cybersecurity, cloud modernization, software development, data analytics, enterprise architecture, enterprise IT, analytics, process automation, and artificial intelligence. Learn more about 9th Way Insignia at <a href="https://9thwayinsignia.com/">https://9thwayinsignia.com/.</a></p> <p>Application password: Niner</p></div><h3>Project Introduction</h3> <p>The Department of Veterans Affairs Cybersecurity Operations and Services Enterprise (COSE) program delivers the enterprise cybersecurity operations, engineering, architecture, risk, and compliance support that safeguards VA systems, data, and mission delivery. The team helps strengthen the cyber resilience of the digital services relied on by Veterans, their families, and the VA workforce.</p> <p>9th Way Insignia is seeking a Cybersecurity Supply Chain Risk Analyst to support this program. This position is contingent upon contract award.</p> <h3>Professional Level</h3> <p>E3 – Engineer</p> <h3>Responsibilities</h3> <ul> <li>Assess cybersecurity supply-chain risks associated with vendors, products, services, software, and third-party dependencies.</li> <li>Document supply-chain security requirements, risk findings, mitigations, and acceptance decisions.</li> <li>Review supplier security evidence, software and hardware provenance information, vulnerability notices, and remediation plans.</li> <li>Coordinate with acquisition, engineering, security, legal, and program stakeholders on third-party risk decisions.</li> <li>Support continuous monitoring of supplier risks, emerging threats, and corrective-action status.</li> </ul> <h3>Requirements</h3> <ul> <li>Bachelor's degree in cybersecurity, information systems, supply-chain management, business, engineering, or a related field, or equivalent relevant experience.</li> <li>Five or more years of cybersecurity, third-party risk, supply-chain risk, GRC, security assessment, or related experience.</li> <li>Experience conducting vendor or product security assessments and documenting risks, controls, and remediation actions.</li> <li>Working knowledge of cybersecurity supply-chain risk management practices, NIST guidance, software supply-chain risks, and third-party security controls.</li> <li>Strong risk-analysis, documentation, stakeholder-engagement, and judgment skills.</li> </ul><div class="content-pay-transparency"><div class="pay-input"><div class="title">Salary Range</div><div class="pay-range"><span>$98,135</span><span class="divider">—</span><span>$125,000 USD</span></div></div></div><div class="content-conclusion"><p><em>9th Way Insignia’s range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.</em></p> <p><strong>Clearance/Background Investigation</strong><br>Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.</p> <p><strong>Benefits</strong><br>Eligible employees will have access to our comprehensive benefits package which includes Medic

Job Reference ID: CF-142775 • Posted on CloudFrame Job Scanner