Experience: 12+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or Open-Source Intelligence) or senior-level experience in third-party risk ...
Experience: 12+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or Open-Source Intelligence) or senior-level experience in third-party risk ...
Conduct proactive threat analysis of foreign suppliers, third-party software developers, and ... Support the FAA Insider Risk Program by identifying and analyzing personnel concerns, anomalous ...
Conduct proactive threat analysis of foreign suppliers, third-party software developers, and ... Support the FAA Insider Risk Program by identifying and analyzing personnel concerns, anomalous ...
Manage third-party and vendor security assessments, including contract and security control reviews * Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ...
Quick apply
Manage third-party and vendor security assessments, including contract and security control reviews * Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ...
Manage third-party and vendor security assessments, including contract and security control reviews * Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ...
Quick apply
Manage third-party and vendor security assessments, including contract and security control reviews * Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ...
Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment ... third-party tools Coordinate with cyber defense engineering and system teams to support tool ...
Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment ... third-party tools Coordinate with cyber defense engineering and system teams to support tool ...
... risk analysis, and software testing techniques Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected ...
... risk analysis, and software testing techniques Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected ...
This position analyzes third-party and technology-related security risk, maintains SCRM records and documentation, identifies gaps in current SCRM practice, and provides risk analysis and secure ...
This position analyzes third-party and technology-related security risk, maintains SCRM records and documentation, identifies gaps in current SCRM practice, and provides risk analysis and secure ...
This position analyzes third-party and technology-related security risk, maintains SCRM records and documentation, identifies gaps in current SCRM practice, and provides risk analysis and secure ...
This position analyzes third-party and technology-related security risk, maintains SCRM records and documentation, identifies gaps in current SCRM practice, and provides risk analysis and secure ...
Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment ... data into third-party tools • Coordinate with cyber defense engineering and system teams to ...
Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment ... data into third-party tools • Coordinate with cyber defense engineering and system teams to ...
The position also develops and maintains compliance metrics, dashboards and trend analyses to ... Support compliance-related third-party risk identification, assessment, and mitigation activities ...
The position also develops and maintains compliance metrics, dashboards and trend analyses to ... Support compliance-related third-party risk identification, assessment, and mitigation activities ...
Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment ... data into third-party tools · Coordinate with cyber defense engineering and system teams to ...
Quick apply
Overview SOSi is seeking a Risk and Vulnerability Analyst II to support vulnerability assessment ... data into third-party tools · Coordinate with cyber defense engineering and system teams to ...
The Senior Analyst will respond to inquiries on the security controls policy, processes, and procedures implemented for managed systems and applications, as well as support Third Party Risk ...
The Senior Analyst will respond to inquiries on the security controls policy, processes, and procedures implemented for managed systems and applications, as well as support Third Party Risk ...
Operational Risk Analyst -Security Governance & Risk Issues Management Location: Merrifield VA ... Experience in working with all levels of staff, management, stakeholders, and third parties
Operational Risk Analyst -Security Governance & Risk Issues Management Location: Merrifield VA ... Experience in working with all levels of staff, management, stakeholders, and third parties
GRC Lead / Cyber Risk Manager
$125K - $169K/yr
Evaluate vendor and third-party cybersecurity risks * Conduct security assessments and due ... NIST Risk Management Framework (RMF) * NIST SP 800-53 / 800-171 * Experience supporting audits ...
GRC Lead / Cyber Risk Manager
$125K - $169K/yr
Evaluate vendor and third-party cybersecurity risks * Conduct security assessments and due ... NIST Risk Management Framework (RMF) * NIST SP 800-53 / 800-171 * Experience supporting audits ...
GRC Lead / Cyber Risk Manager
Washington, DC · On-site
$125K - $169K/yr
... Third-Party Risk Management Evaluate vendor and third-party cybersecurity risks Conduct security assessments and due diligence reviews Ensure contractual security and compliance requirements are met ...
GRC Lead / Cyber Risk Manager
Washington, DC · On-site
$125K - $169K/yr
... Third-Party Risk Management Evaluate vendor and third-party cybersecurity risks Conduct security assessments and due diligence reviews Ensure contractual security and compliance requirements are met ...
Manager, Security Engineering, Secure Third Party Tools
Arlington, VA · On-site
$175.10 - $236.90/hr
... risk analysis, and software testing techniques Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected ...
Manager, Security Engineering, Secure Third Party Tools
Arlington, VA · On-site
$175.10 - $236.90/hr
... risk analysis, and software testing techniques Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected ...
Implementation Manager
Mclean, VA · On-site
... risk management, third-party risk management or due diligence * Consulting experience is a plus * Bachelor's Degree in a relevant field * Must be a US citizen * Have the ability to analyze ...
Implementation Manager
Mclean, VA · On-site
... risk management, third-party risk management or due diligence * Consulting experience is a plus * Bachelor's Degree in a relevant field * Must be a US citizen * Have the ability to analyze ...
Partner as appropriate with other Forrester analysts on broader risk topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk. * Research/write/create approximately ...
Partner as appropriate with other Forrester analysts on broader risk topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk. * Research/write/create approximately ...
Facilitate analysis, evaluation and scoring of vendor proposals against criteria established and ... Guide business and support units through the Third-Party Risk Management Program in conjunction ...
Facilitate analysis, evaluation and scoring of vendor proposals against criteria established and ... Guide business and support units through the Third-Party Risk Management Program in conjunction ...
Provide focused analysis on Top 25 SF Servicer performance, monitor CRR Servicing Risk Scores * Attend Seller/Servicer Forum and Third-Party Risk oversight meetings * Monitor Transfers of Servicing ...
Provide focused analysis on Top 25 SF Servicer performance, monitor CRR Servicing Risk Scores * Attend Seller/Servicer Forum and Third-Party Risk oversight meetings * Monitor Transfers of Servicing ...
Internship Third Party Risk Analyst information
What is the difference between Internship Third Party Risk Analyst vs Internship Vendor Risk Analyst?
| Aspect | Internship Third Party Risk Analyst | Internship Vendor Risk Analyst |
|---|---|---|
| Certifications | Relevant risk management or compliance certifications (e.g., CRISC, CISA) | Similar certifications in risk or vendor management |
| Work Environment | Financial institutions, corporations, or consulting firms focusing on third-party relationships | Organizations managing vendor relationships and supply chains |
| Industry Usage | Commonly used in banking, finance, and corporate sectors | Used across industries with significant vendor engagement |
Internship Third Party Risk Analysts and Internship Vendor Risk Analysts both focus on assessing and managing risks associated with external entities. The main difference lies in their scope: third-party risk analysts typically evaluate risks from all external partners, while vendor risk analysts specifically focus on vendors and supply chain risks. Both roles require similar skills and certifications, and are prevalent in industries with complex external relationships.
What are the most commonly searched types of Third Party Risk Analyst jobs in Washington?
The most popular types of Third Party Risk Analyst jobs in Washington are:

Leidos rating
8.3
Based on 152 frontline employees who took The Breakroom Quiz
79th of 492 rated business services
Job description
Leidos is seeking a Senior-Level Supply Chain Risk Management Analyst to provide advanced technical and analytical support to the FAA's Counterintelligence (CI) Supply Chain Risk Management (SCRM) program. The program is responsible for identifying, assessing, and mitigating foreign intelligence, nation-state, and cybersecurity threats to the FAA's supply chain, critical infrastructure, and enterprise networks. Embedded as a senior leader within a 3-person team, this position focuses on complex enterprise risk assessments and procurement execution support. Providing high-level, independent analytical support aligned with the FAA Acquisition Management System (AMS) framework, the senior analyst evaluates the actual security posture of software suppliers, cloud providers, Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) environments. This role translates threat data into technical risk scoring, conducts complex criticality analyses, and drafts custom contract security language to protect and mitigate advanced threats against the FAA supply chain.
Primary Responsibilities:
- Team lead ensuring strict quality control, mentoring, and analytical integrity across all FAA CI SCRM products.
- Lead the execution of complex, enterprise-level vendor risk assessments and oversee the analytical triage of Software Bills of Materials (SBOMs) for critical air traffic management software, cloud providers (SaaS/PaaS/IaaS), Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) frameworks.
- Conduct and oversee technical and non-technical risk scoring methodologies to compile comprehensive Vendor Risk Reports that map systemic vulnerabilities and cascading supply chain risks.
- Provide authoritative SCRM analytical expertise throughout the procurement lifecycle, guiding early-stage acquisition planning and complex source selections.
- Author definitive Acquisition Security Reviews and evaluation matrices that support and align with the FAA AMS pipeline.
- Formulate and draft specific contract security language, technical security requirements, and risk acceptance recommendations to legally bind vendors and mitigate identified supply chain risks prior to contract award.
- Translate highly technical, complex risk assessment data into clear, sophisticated Executive Decision Packages and dashboards tailored for a non-technical audience to enable FAA senior leadership to make rapid, fully informed decisions.
- Lead the development, refinement, and maintenance of FAA SCRM policies, governance documentation, and standard operating procedures (SOPs).
- Formulate strategic performance metrics and high-level program reports to track enterprise SCRM compliance for executive leadership.
- Maintain critical operational and collaborative relationships with external stakeholders, including the FAA Chief Information Officer (CIO), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Homeland Security (DHS), and the broader Intelligence Community (IC).
- Create, coordinate, and facilitate comprehensive SCRM training and awareness campaigns for acquisition personnel and program offices agency wide.
Basic Qualifications:
- Citizenship: U.S. Citizenship required.
- Clearance: Active Top Secret/SCI clearance is required.
- Education: Bachelor's or Master's degree in Supply Chain, Intelligence Studies, National Security, Logistics, Data Science, Cybersecurity, Information Technology, Computer Science, Computer Engineering, or a related technical discipline. (Equivalent professional experience or specialized military/federal training may be substituted).
- Experience: 12+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or Open-Source Intelligence) or senior-level experience in third-party risk management (TPRM), Cyber Supply Chain Risk Management (C-SCRM), technical risk assessments, IT auditing, cybersecurity risk management, or infrastructure defense in a federal or highly regulated commercial environment.
- Framework Knowledge: Strong working knowledge of federal cybersecurity and risk management frameworks, specifically NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) and NIST SP 800-53.
- Technical Skills: Demonstrated hands-on experience evaluating the security posture, software supply chains, and configurations of at least three of the following technology profiles:
- Cloud infrastructure and service providers (SaaS, PaaS, IaaS)
- Commercial software packages and open-source dependencies
- Artificial Intelligence (AI) platforms or Machine Learning tools
- Telecommunications hardware or infrastructure frameworks
- Operational Technology (OT) or Industrial Control Systems (ICS)
- Communication Skills: Proven capability to translate complex technical vulnerabilities, software flaws, and architectural risks into clear, well-structured, non-technical written reports and executive summaries.
Preferred Qualifications:
- Completion of formal military or federal intelligence training courses focusing on threat network analysis or open-source collection.
- Possession of one or more of the following industry-recognized certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Systems Auditor (CISA)
- Specialized federal SCRM or Counterintelligence training certifications (e.g., CDSE, ODNI, or defense-sponsored SCRM courses).
- Direct, demonstrable experience reviewing federal procurement mechanisms, source selection processes, or drafting legally binding contract security language specifically tailored to the FAA AMS framework.
- Ability to align supply chain threat assessments with the 5-step FAA Safety Risk Management (SRM) process (System Analysis, Hazard Identification, Risk Analysis, Risk Assessment, and Mitigation Control).
- Expert knowledge of Intelligence Community Directives (ICD 203) and Structured Analytic Techniques
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.
Original Posting:July 30, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Sourced by ZipRecruiter
At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.
Industry
It services
Company size
10,000+ Employees
Headquarters location
Reston, VA, US