See all jobs on Scoutfield
Search thousands of fresh jobs every day.
- Fresh listings
- Fast filters
- No subscription required

Senior Risk & Compliance Analyst – C-SCRM Lead
Connected Logistics. Lead cybersecurity risk management, compliance, and C-SCRM activities across systems, applications, infrastructure, cloud environments, products, services, and supporting technology supply chains .
Core Competencies
Role fitUse this summary to align your resume positioning with the role.
Demonstrates expertise in cybersecurity risk management, compliance, and C-SCRM activities, with a strong ability to conduct risk assessments, develop mitigation strategies, and communicate findings effectively to stakeholders. Proficient in managing security control assessments and maintaining risk registers while ensuring compliance with cybersecurity policies and frameworks.
ATS Keywords
Tailor your resumeTip: use these terms in your resume and cover letter to boost ATS matches.
Tech Stack
Tools & technologiesAbout the role
Key responsibilities & impact- Lead cybersecurity risk management, compliance, and C-SCRM activities across systems, applications, infrastructure, cloud environments, products, services, and supporting technology supply chains
- Conduct comprehensive IT security risk assessments and threat analyses to identify vulnerabilities, control weaknesses, threat exposure, and potential impacts
- Lead and coordinate C-SCRM assessments of technology products, software, hardware, services, suppliers, vendors, and third-party dependencies
- Identify and evaluate supply chain cybersecurity risks related to product provenance, supplier dependencies, software components, third-party services, and technology acquisition
- Conduct and oversee security control assessments to determine safeguard effectiveness and identify remediation or risk treatment gaps
- Evaluate risks associated with unauthorized access, excessive privileges, insecure access procedures, platform vulnerabilities, system configurations, data protection weaknesses, and third-party access
- Develop and maintain cybersecurity and C-SCRM risk registers
- Perform risk analysis and develop actionable mitigation and remediation recommendations
- Track security deficiencies and remediation activities through closure, including POA&M development and management
- Support RMF processes, including security assessment, authorization, continuous monitoring, and ongoing risk management
- Assess compliance with cybersecurity policies, security requirements, contractual obligations, and security control frameworks
- Review system security documentation, assessment results, vulnerability findings, control evidence, architecture artifacts, and supporting documentation
- Collaborate with cybersecurity, engineering, architecture, acquisition, program management, and operational stakeholders
- Provide risk-based recommendations to program and cybersecurity leadership
- Support continuous monitoring of cybersecurity and supply chain risks
- Develop and maintain risk assessment reports, compliance documentation, C-SCRM artifacts, executive risk summaries, metrics, dashboards, and supporting cybersecurity documentation
- Serve as a senior cybersecurity risk and C-SCRM advisor to project teams, system owners, security personnel, and organizational leadership
Requirements
What you’ll need- Public Trust: T4 or T5 (TS)
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Information Systems, Risk Management or a related technical discipline, or an Associate's degree in the above discipline with an additional 2 years of experience
- Minimum of five (5) years of relevant professional experience in cybersecurity, information security, IT risk management, security compliance, security assessment, C-SCRM, or a related field
- Demonstrated experience conducting IT security risk assessments, threat analyses, and security control assessments
- Experience identifying and evaluating cybersecurity risks associated with system vulnerabilities, access controls, security procedures, technical platforms, applications, and organizational data
- Experience assessing risk and recommending appropriate security controls, mitigation strategies, remediation actions, and risk treatment approaches
- Knowledge of cybersecurity risk management concepts, assessment methodologies, security controls, vulnerability management, compliance, and continuous monitoring
- Ability to analyze technical and cybersecurity information and translate findings into understandable risk statements and actionable recommendations for technical and non-technical stakeholders
- Strong analytical, documentation, communication, and stakeholder coordination skills
- Ability to develop high-quality security assessment reports, risk documentation, compliance artifacts, and executive-level risk summaries
- Preferred: Experience leading or supporting C-SCRM programs, assessments, or governance activities in a federal environment
- Preferred: Working knowledge of NIST Risk Management Framework (RMF) principles and federal cybersecurity risk management practices
- Preferred: Experience evaluating cybersecurity risks associated with third-party vendors, suppliers, software, hardware, cloud services, and externally provided technology services
- Preferred: Experience supporting security authorization, continuous monitoring, security control assessment, vulnerability management, risk remediation, and POA&M processes
- Preferred: Experience developing and maintaining enterprise or program-level cybersecurity and C-SCRM risk registers, risk scoring methodologies, mitigation plans, and reporting metrics
- Preferred: Experience integrating cybersecurity risk considerations into system acquisition, engineering, architecture, DevSecOps, and lifecycle management processes
- Preferred: Familiarity with federal cybersecurity and supply chain security standards, guidance, and control frameworks applicable to C-SCRM and IT risk management
- Preferred: Experience communicating complex cybersecurity and supply chain risks to senior leadership and providing clear recommendations that support informed risk decisions
- Preferred: Relevant cybersecurity, risk management, audit, or governance certifications such as CISSP, CISM, CRISC, CAP/CGRC, or equivalent credentials
Benefits
Comp & perks- Health insurance
- Dental insurance
- Vision insurance
- Life insurance
- Disability insurance
- 401(k) package
- Generous Paid Time Off
- Ongoing professional development
- Confidentiality for all applicants