To support the Department of Veterans Affairs Cybersecurity Operations and Services Enterprise program, the remote Cybersecurity Supply Chain Risk Analyst will assess cybersecurity supply-chain risks, document security requirements and findings, and coordinate with various stakeholders on third-party risk decisions. Key responsibilities Assess cybersecurity supply-chain risks associated with vendors, products, services, software, and third-party dependencies Document supply-chain security requirements, risk findings, mitigations, and acceptance decisions Coordinate with acquisition, engineering, security, legal, and program stakeholders on third-party risk decisions Required qualifications Bachelor's degree in cybersecurity, information systems, supply-chain management, business, engineering, or a related field, or equivalent relevant experience Five or more years of experience in cybersecurity, third-party risk, supply-chain risk, GRC, security assessment, or related fields Experience conducting vendor or product security assessments and documenting risks, controls, and remediation actions Working knowledge of cybersecurity supply-chain risk management practices, NIST guidance, and third-party security controls Strong risk-analysis, documentation, stakeholder-engagement, and judgment skills
Cybersecurity Supply Chain Analyst in workfromhome at Unknown Company
This position is listed as full time and able to be worked remotely.