Job Overview
Job description
- Salary:
- USD 116,350 - 210,325 per year
- Location:
- Washington, DC
- Work arrangement:
- On-site
Role Summary
Description
Leidos is seeking a Senior-Level Supply Chain Risk Management Analyst to provide advanced technical and analytical support to the FAA's Counterintelligence (CI) Supply Chain Risk Management (SCRM) program. The program is responsible for identifying, assessing, and mitigating foreign intelligence, nation-state, and cybersecurity threats to the FAA's supply chain, critical infrastructure, and enterprise networks. Embedded as a senior leader within a 3-person team, this position focuses on complex enterprise risk assessments and procurement execution support. Providing high-level, independent analytical support aligned with the FAA Acquisition Management System (AMS) framework, the senior analyst evaluates the actual security posture of software suppliers, cloud providers, Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) environments. This role translates threat data into technical risk scoring, conducts complex criticality analyses, and drafts custom contract security language to protect and mitigate advanced threats against the FAA supply chain.
Responsibilities
- Team lead ensuring strict quality control, mentoring, and analytical integrity across all FAA CI SCRM products.
- Lead the execution of complex, enterprise-level vendor risk assessments and oversee the analytical triage of Software Bills of Materials (SBOMs) for critical air traffic management software, cloud providers (SaaS/PaaS/IaaS), Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) frameworks.
- Conduct and oversee technical and non-technical risk scoring methodologies to compile comprehensive Vendor Risk Reports that map systemic vulnerabilities and cascading supply chain risks.
- Provide authoritative SCRM analytical expertise throughout the procurement lifecycle, guiding early-stage acquisition planning and complex source selections.
- Author definitive Acquisition Security Reviews and evaluation matrices that support and align with the FAA AMS pipeline.
- Formulate and draft specific contract security language, technical security requirements, and risk acceptance recommendations to legally bind vendors and mitigate identified supply chain risks prior to contract award.
- Translate highly technical, complex risk assessment data into clear, sophisticated Executive Decision Packages and dashboards tailored for a non-technical audience to enable FAA senior leadership to make rapid, fully informed decisions.
- Lead the development, refinement, and maintenance of FAA SCRM policies, governance documentation, and standard operating procedures (SOPs).
- Formulate strategic performance metrics and high-level program reports to track enterprise SCRM compliance for executive leadership.
- Maintain critical operational and collaborative relationships with external stakeholders, including the FAA Chief Information Officer (CIO), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Homeland Security (DHS), and the broader Intelligence Community (IC).
- Create, coordinate, and facilitate comprehensive SCRM training and awareness campaigns for acquisition personnel and program offices agency wide.
Requirements
- Citizenship: U.S. Citizenship required.
- Clearance: Active Top Secret/SCI clearance is required.
- Education: Bachelor's or Master's degree in Supply Chain, Intelligence Studies, National Security, Logistics, Data Science, Cybersecurity, Information Technology, Computer Science, Computer Engineering, or a related technical discipline. (Equivalent professional experience or specialized military/federal training may be substituted).
- Experience: 12+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or Open-Source Intelligence) or senior-level experience in third-party risk management (TPRM), Cyber Supply Chain Risk Management (C-SCRM), technical risk assessments, IT auditing, cybersecurity risk management, or infrastructure defense in a federal or highly regulated commercial environment.
- Framework Knowledge: Strong working knowledge of federal cybersecurity and risk management frameworks, specifically NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) and NIST SP 800-53.
- Technical Skills: Demonstrated hands-on experience evaluating the security posture, software supply chains, and configurations of at least three of the following technology profiles:- Cloud infrastructure and service providers (SaaS, PaaS, IaaS)
- Commercial software packages and open-source dependencies
- Artificial Intelligence (AI) platforms or Machine Learning tools
- Telecommunications hardware or infrastructure frameworks
- Operational Technology (OT) or Industrial Control Systems (ICS)
- Communication Skills: Proven capability to translate complex technical vulnerabilities, software flaws, and architectural risks into clear, well-structured, non-technical written reports and executive summaries.
Preferred Qualifications
- Completion of formal military or federal intelligence training courses focusing on threat network analysis or open-source collection.
- Possession of one or more of the following industry-recognized certifications:- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Systems Auditor (CISA)
- Specialized federal SCRM or Counterintelligence training certifications (e.g., CDSE, ODNI, or defense-sponsored SCRM courses).
- Direct, demonstrable experience reviewing federal procurement mechanisms, source selection processes, or drafting legally binding contract security language specifically tailored to the FAA AMS framework.
- Ability to align supply chain threat assessments with the 5-step FAA Safety Risk Management (SRM) process (System Analysis, Hazard Identification, Risk Analysis, Risk Assessment, and Mitigation Control).
- Expert knowledge of Intelligence Community Directives (ICD 203) and Structured Analytic Techniques
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.
Pay Range $116,350.00 - $210,325.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.
Securing Your Data
Beware of fake employment opportunities using Leidos' name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system - never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com.
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
About the Company
Looking for an opportunity to make an impact?
At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business.
Your greatest work is ahead!
We are looking for a Substation Protection & Controls Engineer to join our team. As a Career Protection & Control Engineer, candidates will have the opportunity to design substation protection and control projects for electric utilities at voltages from 12kV up to 500kV. This is an exciting and growing field in the power systems industry and allows candidates to get exposure to how the power generation such as that of renewable energy ties into the electric system. Candidates will be expected to use knowledge of digital logic design, AC and DC circuits to design substation electrical projects.
HYBRID SCHEDULE: Candidates must live in Framingham, MA office's client servicing territory. MA, CT, NH, RI. (1 - 4 days in office.)
Successful candidates can look forward to a fast paced, diverse work environment and flexible work hours/work arrangements as well as managers who will encourage career development and growth including:
In this role, you can also expect to gain experience in the following:
- Role:
- Supply Chain Risk Management Senior Analyst
- Job Type:
- Senior Level | Management
Company profile
Leidos
leidos.comLeidos is a technology and science company that delivers solutions at the intersection of national security, health and critical infrastructure for government and commercial customers. Its work spans defense tech, AI, cyber, digital, space, health and energy, including advanced space, aerial, maritime and ground platforms for U.S. and allied forces. The company is organized around five growth engines under its NorthStar 2030 strategy and is headquartered in Reston, Virginia.
- Company Size
- 10,000 - 50,000 employees
- Headquarters
- Reston, Virginia, United States
- Founded
- 1969
- Founders
- John Robert Beyster
- Funding Stage
- Public
In the news
Leidos to Extend Support for US Army’s ARTEMIS Spy Plane Ops in Europe
The Defense Post ·