Analyze third-party and technology-related security risks and prepare risk mitigation recommendations. * Identify gaps in current SCRM practices and recommend improvements to process, monitoring ...
Analyze third-party and technology-related security risks and prepare risk mitigation recommendations. * Identify gaps in current SCRM practices and recommend improvements to process, monitoring ...
Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst #1809720
Washington, DC · On-site
$114K - $126K/yr
The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) and its information, communications, and operational ...
Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst #1809720
Washington, DC · On-site
$114K - $126K/yr
The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) and its information, communications, and operational ...
Lifecycle Acquisition Analyst (Execution & Analysis/SCRM) - Senior
Springfield, VA · On-site
$161K - $200K/yr
Developing a robust SCRM program in accordance with DoW and IC policies, ensuring SCRM ... Advanced ability to create, implement, and analyze key SCRM metrics, data collection methodologies ...
Lifecycle Acquisition Analyst (Execution & Analysis/SCRM) - Senior
Springfield, VA · On-site
$161K - $200K/yr
Developing a robust SCRM program in accordance with DoW and IC policies, ensuring SCRM ... Advanced ability to create, implement, and analyze key SCRM metrics, data collection methodologies ...
... chain risk management (SCRM) subject matter expertise addressing regulatory/compliance ... and data validation/analysis methodologies. • Developing SCRM strategies, tactics, and ...
... chain risk management (SCRM) subject matter expertise addressing regulatory/compliance ... and data validation/analysis methodologies. • Developing SCRM strategies, tactics, and ...
Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst #1809720
Washington, DC · Hybrid
$113K - $146K/yr
The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) and its information, communications, and operational ...
Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst #1809720
Washington, DC · Hybrid
$113K - $146K/yr
The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) and its information, communications, and operational ...
Lifecycle Acquisition Analyst (Execution & Analysis/ SCRM) - Senior
Springfield, VA · On-site
$91K - $121K/yr
Responsibilities • Developing a robust SCRM program in accordance with DoW and IC policies ... and data validation/analysis methodologies. • Developing SCRM strategies, tactics, and ...
Lifecycle Acquisition Analyst (Execution & Analysis/ SCRM) - Senior
Springfield, VA · On-site
$91K - $121K/yr
Responsibilities • Developing a robust SCRM program in accordance with DoW and IC policies ... and data validation/analysis methodologies. • Developing SCRM strategies, tactics, and ...
Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst with Security Clearance
Washington, DC · On-site
$113K - $146K/yr
The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) by managing cybersecurity risks associated with the Agency ...
Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst with Security Clearance
Washington, DC · On-site
$113K - $146K/yr
The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) by managing cybersecurity risks associated with the Agency ...
Lifecycle Acquisition Analyst (Execution & Analysis/SCRM) - Senior (TMZ)
Springfield, VA · On-site
$91K - $121K/yr
... scrm strategies , senior management reviews , SMR , supply chain management , supply chain risk managment , TASPO Lifecycle Acquisition Analyst - Senior (JMTK & DCGS) Lifecycle Acquisition Analyst ...
Lifecycle Acquisition Analyst (Execution & Analysis/SCRM) - Senior (TMZ)
Springfield, VA · On-site
$91K - $121K/yr
... scrm strategies , senior management reviews , SMR , supply chain management , supply chain risk managment , TASPO Lifecycle Acquisition Analyst - Senior (JMTK & DCGS) Lifecycle Acquisition Analyst ...
The Supply Chain Risk Management (SCRM) Analyst will be responsible for the accurate assessment and analysis of suppliers in support of defense programs. This position entails a focused commitment to ...
The Supply Chain Risk Management (SCRM) Analyst will be responsible for the accurate assessment and analysis of suppliers in support of defense programs. This position entails a focused commitment to ...
Lifecycle Acquisition Analyst (Execution & Analysis/SCRM) - Se with Security Clearance
Burke, VA · On-site
$161K - $200K/yr
Developing a robust SCRM program in accordance with DoW and IC policies, ensuring SCRM ... Advanced ability to create, implement, and analyze key SCRM metrics, data collection methodologies ...
New
Lifecycle Acquisition Analyst (Execution & Analysis/SCRM) - Se with Security Clearance
Burke, VA · On-site
$161K - $200K/yr
Developing a robust SCRM program in accordance with DoW and IC policies, ensuring SCRM ... Advanced ability to create, implement, and analyze key SCRM metrics, data collection methodologies ...
New
Lifecycle Acquisition Analyst (Execution & Analysis/SCRM) - Se with Security Clearance
Springfield, VA · On-site
$161K - $200K/yr
Duties may include: • Developing a robust SCRM program in accordance with DoW and IC policies ... and data validation/analysis methodologies. • Developing SCRM strategies, tactics, and ...
Lifecycle Acquisition Analyst (Execution & Analysis/SCRM) - Se with Security Clearance
Springfield, VA · On-site
$161K - $200K/yr
Duties may include: • Developing a robust SCRM program in accordance with DoW and IC policies ... and data validation/analysis methodologies. • Developing SCRM strategies, tactics, and ...
Lifecycle Acquisition Analyst (Execution & Analysis/SCRM) - Seni with Security Clearance
Springfield, VA · On-site
$80K - $108K/yr
Developing a robust SCRM program in accordance with DoW and IC policies, ensuring SCRM ... Advanced ability to create, implement, and analyze key SCRM metrics, data collection methodologies ...
Lifecycle Acquisition Analyst (Execution & Analysis/SCRM) - Seni with Security Clearance
Springfield, VA · On-site
$80K - $108K/yr
Developing a robust SCRM program in accordance with DoW and IC policies, ensuring SCRM ... Advanced ability to create, implement, and analyze key SCRM metrics, data collection methodologies ...
Provide authoritative SCRM analytical expertise throughout the procurement lifecycle, guiding early-stage acquisition planning and complex source selections. * Author definitive Acquisition Security ...
Provide authoritative SCRM analytical expertise throughout the procurement lifecycle, guiding early-stage acquisition planning and complex source selections. * Author definitive Acquisition Security ...
Provide authoritative SCRM analytical expertise throughout the procurement lifecycle, guiding early-stage acquisition planning and complex source selections. * Author definitive Acquisition Security ...
Provide authoritative SCRM analytical expertise throughout the procurement lifecycle, guiding early-stage acquisition planning and complex source selections. * Author definitive Acquisition Security ...
System Engineer 2 (Vetting) with Security Clearance
Annapolis, MD · On-site
$190K - $220K/yr
The SCRM Analyst supports the mission of the National Security Agency Cybersecurity Collaboration Center by identifying, assessing, and mitigating supply chain risks impacting National Security ...
System Engineer 2 (Vetting) with Security Clearance
Annapolis, MD · On-site
$190K - $220K/yr
The SCRM Analyst supports the mission of the National Security Agency Cybersecurity Collaboration Center by identifying, assessing, and mitigating supply chain risks impacting National Security ...
Provide authoritative SCRM analytical expertise throughout the procurement lifecycle, guiding early-stage acquisition planning and complex source selections. * Author definitive Acquisition Security ...
Provide authoritative SCRM analytical expertise throughout the procurement lifecycle, guiding early-stage acquisition planning and complex source selections. * Author definitive Acquisition Security ...
Sr. CI Analyst SCRM (CI Specialist)
Riverdale Park, MD · On-site
$100K - $132K/yr
Job Title Sr. CI Analyst SCRM (CI Specialist) Location College Park, MD 20737 US (Primary) Category Intelligence Job Type Full-Time Career Level Staff Education High School / GED Travel Security ...
Sr. CI Analyst SCRM (CI Specialist)
Riverdale Park, MD · On-site
$100K - $132K/yr
Job Title Sr. CI Analyst SCRM (CI Specialist) Location College Park, MD 20737 US (Primary) Category Intelligence Job Type Full-Time Career Level Staff Education High School / GED Travel Security ...
Sr. CI Analyst SCRM (CI Specialist)
Fort George G Meade, MD · On-site
$100K - $132K/yr
Job Title Sr. CI Analyst SCRM (CI Specialist) Location Fort Meade, MD 20755 US (Primary) Category Intelligence Job Type Full-Time Career Level Staff Education High School / GED Travel Security ...
Sr. CI Analyst SCRM (CI Specialist)
Fort George G Meade, MD · On-site
$100K - $132K/yr
Job Title Sr. CI Analyst SCRM (CI Specialist) Location Fort Meade, MD 20755 US (Primary) Category Intelligence Job Type Full-Time Career Level Staff Education High School / GED Travel Security ...
Supply Chain Risk Management with Security Clearance
Fort George G Meade, MD · On-site
$87K - $107K/yr
Maintain active lines of communication with SCRM Threat Analysis Center (SCRM-TAC) located at the Russell-Knox Building at the Marine Corps Base Quantico, Virginia and other SCRM analytic functions ...
Supply Chain Risk Management with Security Clearance
Fort George G Meade, MD · On-site
$87K - $107K/yr
Maintain active lines of communication with SCRM Threat Analysis Center (SCRM-TAC) located at the Russell-Knox Building at the Marine Corps Base Quantico, Virginia and other SCRM analytic functions ...
System Engineer - Vetting
Annapolis Junction, MD · On-site
$190K - $220K/yr
The SCRM Analyst supports the mission of the National Security Agency Cybersecurity Collaboration Center by identifying, assessing, and mitigating supply chain risks impacting National Security ...
Quick apply
System Engineer - Vetting
Annapolis Junction, MD · On-site
$190K - $220K/yr
The SCRM Analyst supports the mission of the National Security Agency Cybersecurity Collaboration Center by identifying, assessing, and mitigating supply chain risks impacting National Security ...
Scrm Analyst information
See salary details
$31K - $40K
11% of jobs
$40K - $49K
9% of jobs
$52.1K is the 25th percentile. Wages below this are outliers.
$49K - $58K
15% of jobs
$58K - $67K
15% of jobs
The median wage is $67.3K / yr.
$67K - $76K
18% of jobs
$82.5K is the 75th percentile. Wages above this are outliers.
$76K - $85K
11% of jobs
$85K - $94K
7% of jobs
$94K - $103K
5% of jobs
$103K - $112K
4% of jobs
$112K - $121K
2% of jobs
$121K - $130K
3% of jobs
$31K
$73.3K
$130K
How much do scrm analyst jobs pay per year?
What states have the most Scrm Analyst jobs?
States with the most job openings for Scrm Analyst jobs include:
What are popular job titles related to Scrm Analyst jobs?
For Scrm Analyst jobs, the most frequently searched job titles are:

SCRM/Emerging Technology Security Analyst
Washington, DC
Full-time
Re-posted 8 days ago
Key responsibilities
Support the operation and enhancement of the client's Supply Chain Risk Management (SCRM) activities, including documentation support, stakeholder coordination, and maintenance of SCRM records.
Analyze third-party and technology-related security risks and prepare risk mitigation recommendations.
Support evaluation of the security posture of third-party technologies and emerging cyber risks.
Job description
Description
K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.
Our four core values define how we show up every day:
- Respect Others - We lead with respect, building trust and connection.
- Internally Driven - We are relentlessly compelled to accomplish our objectives.
- Collaborative Innovation - We create by listening, sharing, and working together.
- Client Success - We hold our clients' mission as our own.
We believe in people who are accountable, curious, and motivated to make an impact that matters.
Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.
Position Summary
Support the client's Supply Chain Risk Management (SCRM) program and the security review of AI-enabled and emerging technologies. This position analyzes third-party and technology-related security risk, maintains SCRM records and documentation, identifies gaps in current SCRM practice, and provides risk analysis and secure-implementation recommendations for software, systems, and services that incorporate AI or other emerging capabilities affecting enterprise risk.
Key Responsibilities
- Support the operation and enhancement of the client's SCRM activities, including documentation support, stakeholder coordination, and maintenance of SCRM records.
- Analyze third-party and technology-related security risks and prepare risk mitigation recommendations.
- Identify gaps in current SCRM practices and recommend improvements to process, monitoring, governance, and reporting.
- Support evaluation of the security posture of third-party technologies and evolving cyber risks.
- Support AI security-related compliance, vulnerability, and risk activities for software, systems, services, and tools incorporating AI-enabled functions or emerging technologies.
- Perform security review support and risk analysis; develop recommendations for secure implementation and governance considerations.
- Coordinate with stakeholders on the security implications of emerging technical capabilities.
- Support secure adoption assessments for modernization, automation, and analytics opportunities.
- Apply OMB M-21-30, M-22-18, and M-23-16; NIST software supply chain security guidance; NIST SP 800-218 (Secure Software Development Framework); and the NIST AI Risk Management Framework and Playbook.
- Maintain currency with emerging NIST publications on AI topics and translate them into practical review criteria.
- Support compliance with the client's Secure and Trustworthy Artificial Intelligence Policy, including the written-approval workflow, required disclosures covering training data sources, learning cutoff dates and model limitations, human-oversight requirements, output review controls, and AI activity logging.
Requirements
- Bachelor's degree in cybersecurity, information technology, risk management, or a related field. Equivalent experience considered in lieu of degree.
- Four or more years in cybersecurity risk, third-party or vendor risk, or security compliance analysis.
- Demonstrated experience performing third-party or supply chain security risk assessments and producing written risk analyses and mitigation recommendations.
- Working knowledge of federal software supply chain policy - OMB M-21-30, M-22-18, and M-23-16 - and NIST SP 800-218.
- Familiarity with the NIST AI Risk Management Framework and the security and governance considerations specific to AI-enabled systems.
- Strong written analysis skills. This position produces recurring written deliverables reviewed by the OCISO.
Preferred Qualifications
- SBOM generation, ingestion, and analysis experience.
- Experience with FedRAMP package review and third-party SaaS security assessment.
- Experience developing AI governance intake and review workflows, including model documentation and disclosure review.
- Familiarity with the FCC Covered List and covered equipment and services screening obligations.
Applicants must be willing to take a drug test and submit to a credit and background investigation as part of the selection process.
The U.S. government restricts access by Foreign Nationals to certain types of technology and technical data. Consequently, this posting is intended only for U.S. citizens.
K2United, LLC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or protected Veteran status.
This job description is not an exhaustive list of job responsibilities. K2United management reserves the right to change or alter this job description at any time without notice.
About K2Share
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
College Station, TX, US
Year founded
2000