Lead the execution of complex, enterprise-level vendor risk assessments and oversee the analytical triage of Software Bills of Materials (SBOMs) for critical air traffic management software, cloud ...
Lead the execution of complex, enterprise-level vendor risk assessments and oversee the analytical triage of Software Bills of Materials (SBOMs) for critical air traffic management software, cloud ...
The Risk Management Analyst supports the identification, assessment, and communication of discrete and overall program and project risk across cost, schedule, and performance dimensions within a ...
Quick apply
The Risk Management Analyst supports the identification, assessment, and communication of discrete and overall program and project risk across cost, schedule, and performance dimensions within a ...
The Risk Management Analyst supports the identification, assessment, and communication of discrete and overall program and project risk across cost, schedule, and performance dimensions within a ...
The Risk Management Analyst supports the identification, assessment, and communication of discrete and overall program and project risk across cost, schedule, and performance dimensions within a ...
Risk Management Analyst
Washington, DC · On-site +1
The Risk Management Analyst supports the identification, assessment, and communication of discrete and overall program and project risk across cost, schedule, and performance dimensions within a ...
Risk Management Analyst
Washington, DC · On-site +1
The Risk Management Analyst supports the identification, assessment, and communication of discrete and overall program and project risk across cost, schedule, and performance dimensions within a ...
Risk Management Analyst
Sterling, VA · On-site
$86K - $181K/yr
Risk Management Analyst Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph Employee Type: Regular Percentage of Travel Required: Up ...
Risk Management Analyst
Sterling, VA · On-site
$86K - $181K/yr
Risk Management Analyst Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph Employee Type: Regular Percentage of Travel Required: Up ...
Risk Management Analyst
Washington, DC · On-site
Strategic Insight, Ltd. is seeking a Risk Management Analyst to support our US Navy client. The job is on-site at the Navy Yard, supporting the Cruiser / Destroyer group in DPAE Modernization and ...
Quick apply
Risk Management Analyst
Washington, DC · On-site
Strategic Insight, Ltd. is seeking a Risk Management Analyst to support our US Navy client. The job is on-site at the Navy Yard, supporting the Cruiser / Destroyer group in DPAE Modernization and ...
We are seeking a Enterprise Risk Management Analyst to support the Department of State IT Governance Support Services Bureau of Consular Affairs. This position supports the decision-making framework ...
We are seeking a Enterprise Risk Management Analyst to support the Department of State IT Governance Support Services Bureau of Consular Affairs. This position supports the decision-making framework ...
We are seeking a Enterprise Risk Management Analyst to support the Department of State IT Governance Support Services Bureau of Consular Affairs. This position supports the decision-making framework ...
We are seeking a Enterprise Risk Management Analyst to support the Department of State IT Governance Support Services Bureau of Consular Affairs. This position supports the decision-making framework ...
Risk Manager
Mclean, VA · On-site
$55 - $60/hr
Perform risk tracking, trending, analysis, and executive reporting * Provide strategic thinking on next levels of maturity in Technology & Vendor Risk management * Act as a cross functional partner ...
Quick apply
Risk Manager
Mclean, VA · On-site
$55 - $60/hr
Perform risk tracking, trending, analysis, and executive reporting * Provide strategic thinking on next levels of maturity in Technology & Vendor Risk management * Act as a cross functional partner ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · On-site +1
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · On-site +1
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Vendor Security Manager
$58 - $72/hr
The ideal candidate brings expertise in cybersecurity, vendor risk management, compliance ... Excellent analytical, organizational, and documentation skills. * Strong verbal and written ...
Quick apply
Vendor Security Manager
$58 - $72/hr
The ideal candidate brings expertise in cybersecurity, vendor risk management, compliance ... Excellent analytical, organizational, and documentation skills. * Strong verbal and written ...
Vendor Security Manager
Washington, DC · On-site
$58 - $72/hr
The ideal candidate brings expertise in cybersecurity, vendor risk management, compliance ... Excellent analytical, organizational, and documentation skills. * Strong verbal and written ...
Quick apply
Vendor Security Manager
Washington, DC · On-site
$58 - $72/hr
The ideal candidate brings expertise in cybersecurity, vendor risk management, compliance ... Excellent analytical, organizational, and documentation skills. * Strong verbal and written ...
Junior Risk Management Analyst
Camp Springs, MD · On-site
$59K - $63K/yr
Lynch Consultants is seeking a Junior Risk Management Analyst with a solid understanding of risk management, internal controls, audit support, financial management, business process improvement who ...
Junior Risk Management Analyst
Camp Springs, MD · On-site
$59K - $63K/yr
Lynch Consultants is seeking a Junior Risk Management Analyst with a solid understanding of risk management, internal controls, audit support, financial management, business process improvement who ...
Lynch Consultants is seeking a Junior Risk Management Analyst with a solid understanding of risk management, internal controls, audit support, financial management, business process improvement who ...
Quick apply
Lynch Consultants is seeking a Junior Risk Management Analyst with a solid understanding of risk management, internal controls, audit support, financial management, business process improvement who ...
Configuration and Risk Management Analyst
$85K - $95K/yr
This position provides engineering and analytical support for configuration management activities while also supporting program risk management processes throughout the system life-cycle. The ideal ...
Configuration and Risk Management Analyst
$85K - $95K/yr
This position provides engineering and analytical support for configuration management activities while also supporting program risk management processes throughout the system life-cycle. The ideal ...
Vendor Security Manager
Washington, DC · On-site
$58 - $72/hr
Lead the organization's third-party risk management and vendor security program. * Manage and ... Excellent analytical, organizational, and documentation skills. * Strong verbal and written ...
Vendor Security Manager
Washington, DC · On-site
$58 - $72/hr
Lead the organization's third-party risk management and vendor security program. * Manage and ... Excellent analytical, organizational, and documentation skills. * Strong verbal and written ...
Configuration and Risk Management Analyst
$85K - $95K/yr
This position provides engineering and analytical support for configuration management activities while also supporting program risk management processes throughout the system life-cycle. The ideal ...
Configuration and Risk Management Analyst
$85K - $95K/yr
This position provides engineering and analytical support for configuration management activities while also supporting program risk management processes throughout the system life-cycle. The ideal ...
The Financial and Risk Management Analyst is a member of the CIF Secretariat Financial and Risk Management Team, reporting directly to the Head of Financial and Risk Management. Key responsibilities ...
The Financial and Risk Management Analyst is a member of the CIF Secretariat Financial and Risk Management Team, reporting directly to the Head of Financial and Risk Management. Key responsibilities ...
Vendor Risk Management Analyst information
See Washington, DC salary details
$41.3K - $51.8K
4% of jobs
$51.8K - $62.2K
13% of jobs
$69.8K is the 25th percentile. Wages below this are outliers.
$62.2K - $72.7K
11% of jobs
$72.7K - $83.1K
16% of jobs
The median wage is $85.8K / yr.
$83.1K - $93.6K
25% of jobs
$98.8K is the 75th percentile. Wages above this are outliers.
$93.6K - $104K
13% of jobs
$104K - $114.5K
8% of jobs
$114.5K - $124.9K
3% of jobs
$124.9K - $135.4K
1% of jobs
$135.4K - $145.8K
1% of jobs
$145.8K - $156.3K
5% of jobs
$41.3K
$93.2K
$156.3K
How much do vendor risk management analyst jobs pay per year?
What is a vendor risk management analyst?
What are the key skills and qualifications needed to thrive as a vendor risk management analyst, and why are they important?
How does a vendor risk management analyst typically interact with other departments within an organization?
What is the difference between Vendor Risk Management Analyst vs Procurement Analyst?
| Aspect | Vendor Risk Management Analyst | Procurement Analyst |
|---|---|---|
| Certifications | Certifications like CTPRP, CRISC, or vendor risk management courses | CPM, CPSM, or purchasing certifications |
| Work Environment | Focus on risk assessment, compliance, and vendor evaluations | Focus on sourcing, purchasing, and supplier negotiations |
| Industry Usage | Common in finance, healthcare, and technology sectors | Prevalent across manufacturing, retail, and corporate sectors |
The main difference is that a Vendor Risk Management Analyst specializes in assessing and mitigating risks associated with vendors, ensuring compliance and security. In contrast, a Procurement Analyst primarily handles sourcing and purchasing activities. Both roles require analytical skills and industry knowledge but focus on different aspects of vendor and supply chain management.

Leidos rating
8.3
Based on 151 frontline employees who took The Breakroom Quiz
75th of 481 rated business services
Job description
Leidos is seeking a Senior-Level Supply Chain Risk Management Analyst to provide advanced technical and analytical support to the FAA's Counterintelligence (CI) Supply Chain Risk Management (SCRM) program. The program is responsible for identifying, assessing, and mitigating foreign intelligence, nation-state, and cybersecurity threats to the FAA's supply chain, critical infrastructure, and enterprise networks. Embedded as a senior leader within a 3-person team, this position focuses on complex enterprise risk assessments and procurement execution support. Providing high-level, independent analytical support aligned with the FAA Acquisition Management System (AMS) framework, the senior analyst evaluates the actual security posture of software suppliers, cloud providers, Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) environments. This role translates threat data into technical risk scoring, conducts complex criticality analyses, and drafts custom contract security language to protect and mitigate advanced threats against the FAA supply chain.
Primary Responsibilities:
- Team lead ensuring strict quality control, mentoring, and analytical integrity across all FAA CI SCRM products.
- Lead the execution of complex, enterprise-level vendor risk assessments and oversee the analytical triage of Software Bills of Materials (SBOMs) for critical air traffic management software, cloud providers (SaaS/PaaS/IaaS), Artificial Intelligence (AI) tools, telecommunications, and Operational Technology / Industrial Control Systems (OT/ICS) frameworks.
- Conduct and oversee technical and non-technical risk scoring methodologies to compile comprehensive Vendor Risk Reports that map systemic vulnerabilities and cascading supply chain risks.
- Provide authoritative SCRM analytical expertise throughout the procurement lifecycle, guiding early-stage acquisition planning and complex source selections.
- Author definitive Acquisition Security Reviews and evaluation matrices that support and align with the FAA AMS pipeline.
- Formulate and draft specific contract security language, technical security requirements, and risk acceptance recommendations to legally bind vendors and mitigate identified supply chain risks prior to contract award.
- Translate highly technical, complex risk assessment data into clear, sophisticated Executive Decision Packages and dashboards tailored for a non-technical audience to enable FAA senior leadership to make rapid, fully informed decisions.
- Lead the development, refinement, and maintenance of FAA SCRM policies, governance documentation, and standard operating procedures (SOPs).
- Formulate strategic performance metrics and high-level program reports to track enterprise SCRM compliance for executive leadership.
- Maintain critical operational and collaborative relationships with external stakeholders, including the FAA Chief Information Officer (CIO), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Homeland Security (DHS), and the broader Intelligence Community (IC).
- Create, coordinate, and facilitate comprehensive SCRM training and awareness campaigns for acquisition personnel and program offices agency wide.
Basic Qualifications:
- Citizenship: U.S. Citizenship required.
- Clearance: Active Top Secret/SCI clearance is required.
- Education: Bachelor's or Master's degree in Supply Chain, Intelligence Studies, National Security, Logistics, Data Science, Cybersecurity, Information Technology, Computer Science, Computer Engineering, or a related technical discipline. (Equivalent professional experience or specialized military/federal training may be substituted).
- Experience: 12+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or Open-Source Intelligence) or senior-level experience in third-party risk management (TPRM), Cyber Supply Chain Risk Management (C-SCRM), technical risk assessments, IT auditing, cybersecurity risk management, or infrastructure defense in a federal or highly regulated commercial environment.
- Framework Knowledge: Strong working knowledge of federal cybersecurity and risk management frameworks, specifically NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) and NIST SP 800-53.
- Technical Skills: Demonstrated hands-on experience evaluating the security posture, software supply chains, and configurations of at least three of the following technology profiles:
- Cloud infrastructure and service providers (SaaS, PaaS, IaaS)
- Commercial software packages and open-source dependencies
- Artificial Intelligence (AI) platforms or Machine Learning tools
- Telecommunications hardware or infrastructure frameworks
- Operational Technology (OT) or Industrial Control Systems (ICS)
- Communication Skills: Proven capability to translate complex technical vulnerabilities, software flaws, and architectural risks into clear, well-structured, non-technical written reports and executive summaries.
Preferred Qualifications:
- Completion of formal military or federal intelligence training courses focusing on threat network analysis or open-source collection.
- Possession of one or more of the following industry-recognized certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Systems Auditor (CISA)
- Specialized federal SCRM or Counterintelligence training certifications (e.g., CDSE, ODNI, or defense-sponsored SCRM courses).
- Direct, demonstrable experience reviewing federal procurement mechanisms, source selection processes, or drafting legally binding contract security language specifically tailored to the FAA AMS framework.
- Ability to align supply chain threat assessments with the 5-step FAA Safety Risk Management (SRM) process (System Analysis, Hazard Identification, Risk Analysis, Risk Assessment, and Mitigation Control).
- Expert knowledge of Intelligence Community Directives (ICD 203) and Structured Analytic Techniques
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.
Original Posting:July 30, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Sourced by ZipRecruiter
At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.
Industry
It services
Company size
10,000+ Employees
Headquarters location
Reston, VA, US