Leidos is seeking a Senior Supply Chain Risk Management Threat Intelligence Lead Analyst to provide ... Conduct proactive threat analysis of foreign suppliers, third-party software developers, and ...
Leidos is seeking a Senior Supply Chain Risk Management Threat Intelligence Lead Analyst to provide ... Conduct proactive threat analysis of foreign suppliers, third-party software developers, and ...
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
Manager - ServiceNow
Baltimore, MD · On-site +1
... Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions, change control, and ...
Manager - ServiceNow
Baltimore, MD · On-site +1
... Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions, change control, and ...
Third-party or C2C candidates will not be considered Description: Client is looking for a Strategic Procurement Analyst to facilitate the Third-Party Risk Management and Contracting processes. The ...
Quick apply
Third-party or C2C candidates will not be considered Description: Client is looking for a Strategic Procurement Analyst to facilitate the Third-Party Risk Management and Contracting processes. The ...
Third-party or C2C candidates will not be considered Description: Client is looking for a Strategic Procurement Analyst to facilitate the Third-Party Risk Management and Contracting processes. The ...
Quick apply
Third-party or C2C candidates will not be considered Description: Client is looking for a Strategic Procurement Analyst to facilitate the Third-Party Risk Management and Contracting processes. The ...
... third-party risk management (TPRM), Cyber Supply Chain Risk Management (C-SCRM), technical risk ... assessments, IT auditing, cybersecurity risk management, or infrastructure defense in a federal or ...
... third-party risk management (TPRM), Cyber Supply Chain Risk Management (C-SCRM), technical risk ... assessments, IT auditing, cybersecurity risk management, or infrastructure defense in a federal or ...
Responsibilities include planning, implementation, and monitoring of compliance and risk management requirements across internal and third-party processes. In this high-visibility role, the Sr. ...
Responsibilities include planning, implementation, and monitoring of compliance and risk management requirements across internal and third-party processes. In this high-visibility role, the Sr. ...
... topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk ... management, with a focus on cyber risk quantification, or an equal amount of time as product ...
... topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk ... management, with a focus on cyber risk quantification, or an equal amount of time as product ...
The Senior Analyst will respond to inquiries on the security controls policy, processes, and procedures implemented for managed systems and applications, as well as support Third Party Risk ...
The Senior Analyst will respond to inquiries on the security controls policy, processes, and procedures implemented for managed systems and applications, as well as support Third Party Risk ...
Procurement Manager
Washington, DC · On-site
$130K - $160K/yr
Contribute to and help refine third-party risk management frameworks, standards, and practices. * Monitor vendor performance against cost, service, and delivery expectations, and partner with TPRM to ...
Quick apply
Procurement Manager
Washington, DC · On-site
$130K - $160K/yr
Contribute to and help refine third-party risk management frameworks, standards, and practices. * Monitor vendor performance against cost, service, and delivery expectations, and partner with TPRM to ...
Cybersecurity & Privacy Technology Manager
Baltimore, MD · On-site
$152K - $172K/yr
Management of the USM's Vulnerability and Threat Management Program: * Monitors relevant ... Third-party risk/security reviews (vendor assessments, security/privacy requirements) * Security ...
Cybersecurity & Privacy Technology Manager
Baltimore, MD · On-site
$152K - $172K/yr
Management of the USM's Vulnerability and Threat Management Program: * Monitors relevant ... Third-party risk/security reviews (vendor assessments, security/privacy requirements) * Security ...
Drive product related policy management, issue management, change management, risk assessment, third-party risk management, and training. * Build standards for the product team, such as documentation ...
Drive product related policy management, issue management, change management, risk assessment, third-party risk management, and training. * Build standards for the product team, such as documentation ...
Be Seen First
Credit Manager
Baltimore, MD · On-site
$80K - $120K/yr
Analyze financial statements, cash flow, and credit risk for commercial customers. * Manage a portfolio of accounts and make credit recommendations based on financial data and third-party reporting.
Quick apply
Be Seen First
Credit Manager
Baltimore, MD · On-site
$80K - $120K/yr
Analyze financial statements, cash flow, and credit risk for commercial customers. * Manage a portfolio of accounts and make credit recommendations based on financial data and third-party reporting.
Guide business and support units through the Third-Party Risk Management Program in conjunction with the Third-Party Risk Management team to ensure selected vendors are properly risk-tiered, vetted ...
Guide business and support units through the Third-Party Risk Management Program in conjunction with the Third-Party Risk Management team to ensure selected vendors are properly risk-tiered, vetted ...
Guide business and support units through the Third-Party Risk Management Program in conjunction with the Third-Party Risk Management team to ensure selected vendors are properly risk-tiered, vetted ...
Guide business and support units through the Third-Party Risk Management Program in conjunction with the Third-Party Risk Management team to ensure selected vendors are properly risk-tiered, vetted ...
Senior Manager, Travel and Event Security
Washington, DC · On-site
$145K - $160K/yr
Coordinate, train, and support high-performing third-party security vendors, ensuring defined ... Risk Assessments & Briefings: Conduct pre-event site walkthroughs and collaborate with marketing ...
Senior Manager, Travel and Event Security
Washington, DC · On-site
$145K - $160K/yr
Coordinate, train, and support high-performing third-party security vendors, ensuring defined ... Risk Assessments & Briefings: Conduct pre-event site walkthroughs and collaborate with marketing ...
Data, Privacy & Cybersecurity Associate Attorney
Washington, DC · On-site
$235K - $310K/yr
Counsel clients on cybersecurity governance, third-party risk management, and information security compliance. * Analyze federal, state, and industry-specific cybersecurity and privacy regulations ...
Quick apply
Data, Privacy & Cybersecurity Associate Attorney
Washington, DC · On-site
$235K - $310K/yr
Counsel clients on cybersecurity governance, third-party risk management, and information security compliance. * Analyze federal, state, and industry-specific cybersecurity and privacy regulations ...
Title: Director, Risk Management We are KBR When you become part of our KBR team, your ... and third-party administrators to mitigate financial exposure and drive favorable outcomes.
Title: Director, Risk Management We are KBR When you become part of our KBR team, your ... and third-party administrators to mitigate financial exposure and drive favorable outcomes.
Third Party Risk Manager information
See Hanover, MD salary details
$51.2K - $62K
4% of jobs
$62K - $72.7K
6% of jobs
$72.7K - $83.4K
11% of jobs
$87.4K is the 25th percentile. Wages below this are outliers.
$83.4K - $94.1K
11% of jobs
The median wage is $102.6K / yr.
$94.1K - $104.8K
23% of jobs
$104.8K - $115.6K
13% of jobs
$122.6K is the 75th percentile. Wages above this are outliers.
$115.6K - $126.3K
12% of jobs
$126.3K - $137K
8% of jobs
$137K - $147.7K
6% of jobs
$147.7K - $158.4K
4% of jobs
$158.4K - $169.1K
2% of jobs
$51.2K
$111K
$169.1K
How much do third party risk manager jobs pay per year?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.
What are the key skills and qualifications needed to thrive as a third party risk manager?
What is a third party risk manager?
How does a third party risk manager typically collaborate with other departments to manage vendor risks?

Full-time
Posted 8 days ago
Leidos rating
8.3
Based on 151 frontline employees who took The Breakroom Quiz
77th of 485 rated business services
Job description
Leidos is seeking a Senior Supply Chain Risk Management Threat Intelligence Lead Analyst to provide advanced, high-level technical and analytical support to the FAA's Counterintelligence (CI) Supply Chain Risk Management (SCRM) program. The program is responsible for identifying, assessing, and mitigating foreign intelligence, nation-state, and cybersecurity threats to the FAA's supply chain, critical infrastructure, and enterprise networks. Embedded as a senior leader within a 4-person team, this position focuses on threat landscapes, adversarial intent, and geopolitical vulnerability modeling. Providing independent, authoritative all-source intelligence analysis, the senior analyst designs analytic methodologies using Open Source Intelligence (OSINT) and corporate registries to uncover hidden Foreign Ownership, Control, or Influence (FOCI), technology transfer risks, and strategic threat trends targeting the aviation industrial base. This role oversees the evaluation of physical, technical, and personnel vulnerabilities, including sophisticated hardware/firmware threats and insider risks, to produce exquisite intelligence briefings that guide FAA executive leadership and empower the broader SCRM framework.
Primary Responsibilities:
- Act as lead analyst ensuring strict quality control, mentoring, and analytical integrity across all FAA CI SCRM products.
- Conduct proactive threat analysis of foreign suppliers, third-party software developers, and hardware manufacturers to identify nation-state activity and strategic threat trends targeting the FAA.
- Utilize OSINT and corporate registries to screen prospective FAA vendors and evaluate the supply chain for Foreign Ownership, Control, or Influence (FOCI) indicators, foreign partnerships, and technology transfer threats.
- Monitor specialized threat feeds, nation-state activities, and geopolitical shifts to identify, evaluate, and mitigate strategic supply chain risks to the FAA.
- Support the FAA Insider Risk Program by identifying and analyzing personnel concerns, anomalous vendor behaviors, and internal vulnerabilities.
- Evaluate threat vectors including malicious hardware or software modifications, supply chain transit interdiction, and counterfeit electronic components.
- Synthesize complex data to produce clear, actionable Supplier Threat Profiles, Country Risk Profiles, link-analysis diagrams, and timely threat alerts/advisories for FAA program managers, technical teams, and executive decision-makers.
- Translate highly complex counterintelligence findings, technical hardware/software vulnerabilities, and macroeconomic geopolitical risks into exquisite intelligence briefings, dashboards, and executive decision packages tailored specifically for senior FAA leadership.
- Formulate performance metrics and program reports for executive leadership.
- Maintain critical operational and collaborative relationships with external stakeholders, including the FAA Chief Information Officer (CIO), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Homeland Security (DHS), and the broader Intelligence Community (IC).
- Coordinate and facilitate SCRM training and awareness campaigns for acquisition personnel and program offices.
Basic Qualifications:
- Citizenship: U.S. Citizenship required.
- Clearance: Active Top Secret/SCI clearance is required.
- Education: Bachelor's or Master's degree in Supply Chain, Intelligence Studies, National Security, Logistics, Data Science, Cybersecurity, Information Technology, Computer Science, Computer Engineering, or a related technical discipline. (Equivalent professional experience or specialized military/federal training may be substituted).
- Experience: 12+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or Open-Source Intelligence) or senior-level experience in third-party risk management (TPRM), Cyber Supply Chain Risk Management (C-SCRM), technical risk assessments, IT auditing, cybersecurity risk management, or infrastructure defense in a federal or highly regulated commercial environment.
- Analytical Capability: Proven experience using corporate registries, commercial databases, and OSINT techniques to analyze corporate structures, trace components, and evaluate FOCI.
- Technical Skills: Proficiency with due diligence or corporate intelligence platforms (e.g., Sayari, Altana, Interos, Maltego) and/or data modeling.
- Communication Skills: Exceptional written and verbal communication skills, with a proven track record of translating complex intelligence and technical risk data into clear, concise executive briefs and formal written reports for non-technical stakeholders and delivering briefing materials to C-suite or flag-level leadership.
Preferred Qualifications:
- Completion of formal military or federal intelligence training courses focusing on threat network analysis or open-source collection.
- High proficiency with advanced OSINT search techniques, corporate filing retrieval systems, and international trade/shipping databases.
- Familiarity with the acquisition frameworks and an understanding of how supply chain intelligence feeds into federal procurement lifecycles.
- Prior experience supporting threat intelligence or counterintelligence infrastructure defense missions specifically for critical infrastructure or a federal agency.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.
Original Posting:July 31, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Sourced by ZipRecruiter
At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.
Industry
It services
Company size
10,000+ Employees
Headquarters location
Reston, VA, US