1

Supply Chain Risk Management Jobs (NOW HIRING)

Everforth ECS is seeking a Supply Chain Risk Management Lead to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...

Be Seen First

Long Term Contract position through 2026 + extension Position 1: Supply Chain Risk Management (SCRM) Analyst -- This role focuses on identifying, analyzing, and managing cybersecurity, compliance ...

New

Supply Chain Risk Analyst

Nashua, NH · On-site

$118.10K - $200.76K/yr

Develop and maintain supply chain risk management documentation and reports * Provide recommendations to improve supply chain resilience and risk management practices * Implementing and updating ...

New

next page

Showing results 1-20

Supply Chain Risk Management information

See salary details

$40.5K

$100.3K

$146K

How much do supply chain risk management jobs pay per year?

As of May 28, 2026, the average yearly pay for supply chain risk management in the United States is $100,315.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,000.00 and $120,000.00 per year, depending on experience, location, and employer.

What is a Supply Chain Risk Management job?

A Supply Chain Risk Management job involves identifying, assessing, and mitigating risks that could disrupt the supply chain. Professionals in this role analyze potential threats such as supplier failures, geopolitical issues, cybersecurity risks, and natural disasters. They develop contingency plans, implement risk mitigation strategies, and work with suppliers and internal teams to ensure business continuity. The goal is to minimize disruptions, optimize resilience, and protect the organization's operational and financial performance.

What are the key skills and qualifications needed to thrive in the Supply Chain Risk Management position, and why are they important?

To thrive in Supply Chain Risk Management, you need strong analytical skills, an understanding of logistics and risk assessment, and a relevant bachelor's degree (such as supply chain management, business, or engineering). Familiarity with ERP systems, risk analysis software, and certifications like Certified Supply Chain Professional (CSCP) or Certified in Risk and Information Systems Control (CRISC) are commonly required. Excellent problem-solving abilities, effective communication, and adaptability help you collaborate with various stakeholders and navigate changing circumstances. These skills are vital for proactively identifying, evaluating, and mitigating risks to ensure stable and resilient supply chain operations.

What are the most common challenges faced in a Supply Chain Risk Management role?

Supply Chain Risk Management professionals frequently deal with challenges such as disruptions from geopolitical events, natural disasters, supplier reliability issues, and fluctuating market conditions. Balancing cost efficiency with resilience, maintaining real-time visibility across complex networks, and coordinating responses among multiple internal and external partners are also key aspects of the job. You may need to anticipate and respond quickly to risks, requiring both analytical forecasting and decisive action under pressure. Overcoming these challenges involves continuous monitoring, adaptation of strategies, and effective cross-departmental collaboration, which can make the work dynamic and rewarding for those who enjoy problem-solving in fast-paced environments.
What cities are hiring for Supply Chain Risk Management jobs? Cities with the most Supply Chain Risk Management job openings:
What states have the most Supply Chain Risk Management jobs? States with the most job openings for Supply Chain Risk Management jobs include:
Infographic showing various Supply Chain Risk Management job openings in the United States as of May 2026, with employment types broken down into 100% Full Time. Highlights an 92% In-person, and 8% Hybrid job distribution, with an average salary of $100,315 per year, or $48.2 per hour.
Supply Chain Risk Management Lead

Supply Chain Risk Management Lead

ECS

Falls Church, VA • On-site

Full-time

Posted 22 days ago


Job description

Everforth ECS is seeking a Supply Chain Risk Management Lead to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. Please Note: This position is contingent upon contract award.
The War Data Platform (WDP) is a key initiative within the U.S. Department of War's (DoW) AI-First strategy introduced in early 2026. The WDP focuses on operational warfighting data and aims to accelerate the deployment of artificial intelligence (AI) on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, and supports collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts.
• The Supply Chain Risk Management (SCRM) Lead SME serves as the senior enterprise authority for software and vendor supply chain risk governance across the WDP Core Integration program, directing the full lifecycle of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements, and federal cybersecurity mandates. In this role, the specialist integrates automated supply chain risk tooling, Software Bill of Materials governance, vendor security assessment programs, and threat intelligence monitoring to reduce WDP exposure to supply chain-based attacks and sustain authoritative, audit-ready risk transparency for Authorizing Officials, program leadership, and Government oversight personnel.
• Leads enterprise Supply Chain Risk Management activities supporting Department of War information systems across unclassified and classified environments.
• Designs and executes supply chain risk governance frameworks addressing third-party vendors, commercial software, open-source components, and external service providers throughout the system lifecycle.
• Directs vendor security assessments evaluating cybersecurity posture, access controls, data handling practices, and compliance with federal and DoW requirements.
• Oversees software supply chain reviews including component provenance analysis, dependency mapping, and Software Bill of Materials validation to identify exposure to compromised or high-risk suppliers.
• Coordinates closely with contracting officers, acquisition teams, legal advisors, and system owners to integrate security requirements into procurement actions, vendor onboarding, and contract modifications.
• Maintains risk registers documenting third-party threats, mitigation strategies, residual risk, and acceptance decisions supporting Risk Management Framework activities.
• Provides advisory support to Authorizing Officials, Senior Information Security Officers, and program leadership on supply chain risk posture and emerging threat vectors.
• Monitors threat intelligence, Government advisories, and industry reporting related to supply chain compromise to inform proactive mitigation actions.
• Produces supply chain risk assessments, vendor security reports, and executive briefings supporting authorization decisions and continuous monitoring.
• Drives consistent risk transparency, lifecycle accountability, and mission resilience by reducing exposure to supply chain-based attacks and strengthening trust in system dependencies.
• Performs other duties as assigned.
• Current Secret security clearance with the ability to obtain and maintain a Top Secret (TS) security clearance with Sensitive Compartmented Information (SCI).
• 15 or more years of progressive experience in cybersecurity, with demonstrated specialization in Supply Chain Risk Management, vendor risk governance, or software assurance programs supporting large-scale federal or defense information systems.
• Active DoW/DoD IAM Level I baseline certification, satisfied by one of the following: CompTIA Security+ CE, ISC² CAP, ISC² SSCP, or GIAC GSLC.
• Demonstrated experience designing and operating enterprise SCRM governance frameworks that address third-party software components - including COTS, GOTS, and open-source AI technologies - through automated vulnerability detection and scanning, component provenance analysis, and transitive dependency mapping across the full system development lifecycle.
• Proven ability to create, maintain, and govern Software Bill of Materials documentation for complex software platforms, including management of SBOM artifacts across 150 or more systems with recurring authorization obligations and integration into automated ingest-time scanning pipelines.
• Experience coordinating SCRM activities with contracting officers, acquisition teams, legal advisors, and system owners to embed supply chain security requirements into procurement actions, vendor onboarding agreements, and contract modification packages in compliance with DFARS 252.204-7020, NIST SP 800-171, and applicable DoW acquisition policy.
• Demonstrated experience supporting Risk Management Framework authorization activities, including generation and maintenance of supply chain risk artifacts in eMASS or Xacta, management of Plan of Action and Milestone remediation activities, and preparation of Body of Evidence packages supporting formal Government risk adjudication and audit defense.
• Proven ability to develop and present supply chain risk assessments, vendor security evaluation reports, and executive briefings to Authorizing Officials, Senior Information Security Officers, and program leadership audiences in support of authorization decisions and continuous monitoring obligations.
• Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
• Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).