Cybersecurity Supply Chain Risk Analyst
Core
Assess and mitigate cybersecurity supply-chain risks for vendors, products, software, and third-party dependencies to safeguard VA systems and data.
Role type
Cybersecurity Supply Chain Risk Analyst
Builds
Secure software and hardware supply chains for the Department of Veterans Affairs
Domain
Government cybersecurity / Supply chain risk management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Vendor security assessments, NIST guidance, third-party risk management, vulnerability analysis, remediation planning, stakeholder coordination, risk documentation
Preferred skills
Software supply-chain risk expertise, GRC frameworks, security architecture knowledge
Technologies
NIST frameworks, vulnerability management tools, security assessment platforms
Responsibilities
Assess cybersecurity supply-chain risks associated with vendors and third-party dependencies; Document security requirements, risk findings, and remediation plans; Review supplier security evidence and provenance information; Coordinate with acquisition, engineering, and legal stakeholders on risk decisions; Support continuous monitoring of supplier risks and emerging threats
Seniority
Mid-Senior level (5+ years experience)
