Fortress Information Security logo
Fortress Information Security
Posted 34 days agoVerified live 2d ago

Cyber Supply Chain Risk Management (C-SCRM) Analyst

Brief overview

Remote
UndergradOr in progress
$89k–$100k/yrStated range
2+ yrsMinimum
4 H-1B approvalsDept. of Labor
2 green cardsCertified filings
Clearance requiredU.S. government
Cyber Supply Chain Risk Management (C-SCRM)Cybersecurity AnalysisThreat IntelligenceSupplier Risk ManagementRisk AnalysisBill of Materials Analysis (SBOM/HBOM)Microsoft ExcelMicrosoft PowerPointArtificial Intelligence for Research and AnalysisSecurity+ CertificationNIST Cybersecurity Frameworks

About the company

Fortress Information Security logo
Fortress Information Securityfortressinfosec.com

Fortress protects governments, critical infrastructure, supply chains, and digital assets from advanced cyber threats.

Visa sponsorship history

3 years sponsoring, last filed FY2025

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
4H-1B approved
100%approval rate
1new H-1B hires
2PERM certified
$105,341median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20231
20242
20251
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20231
20241
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20252
Top sponsored roles
Software EngineerDeveloper

Job description

Summary

Fortress Information Security is building a pipeline for a Cyber Supply Chain Risk Management Analyst to support its Government Delivery team. The role analyzes cyber supply chain risk data for U.S. Navy programs, develops risk narratives and reports, supports customer delivery, and collaborates with analysts, project managers, and technical subject matter experts.

Responsibilities

  • Analyze cyber supply chain risk data to identify supplier, product, software, hardware, ownership, control, influence, dependency, and vulnerability risks that may impact U.S. Navy programs
  • Review submitted data, including hardware and software bills of materials, for completeness, accuracy, consistency, and indicators of high supply chain risk
  • Evaluate findings within the Fortress C-SCRM Platform and identify risk patterns, anomalies, or areas requiring additional review or escalation
  • Translate raw threat and supply chain data, including indicators such as Foreign Ownership, Control, or Influence (FOCI), compromised software libraries, supplier exposure, product vulnerabilities, or bill of materials concerns, into clear risk narratives and potential mission impacts
  • Develop subject matter expertise in the Fortress C-SCRM Platform, Fortress products, Navy systems, customer data, and program deliverables to support accurate analysis and consistent delivery outcomes
  • Identify, document, and communicate high-risk supply chain findings so internal stakeholders and customer-facing team members understand the risk, impact, and recommended next steps
  • Partner with Management Analysts, Technical Project Managers, and technical subject matter experts to support program-level reporting, risk briefings, deliverable development, and customer milestones
  • Serve as a subject matter expert during customer discussions when needed, including answering questions about risk findings, data interpretation, platform outputs, or deliverable content
  • Document risk findings, assumptions, data limitations, and recommended areas for further review in a clear, defensible, and repeatable manner
  • Support the development and refinement of analytical processes, templates, quality checks, and reporting inputs that improve consistency, efficiency, and confidence in C-SCRM deliverables
  • Use Excel to review, organize, analyze, validate, and summarize supply chain, supplier, platform, bill of materials, or risk data
  • Use PowerPoint to support clear communication of risk findings, trends, impacts, and recommendations in customer-ready or internal briefing materials
  • Apply intermediate AI proficiency to improve research, analysis, summarization, pattern recognition, and workflow efficiency while following Fortress, customer, and security requirements for responsible AI use
  • Maintain awareness of cyber supply chain risk concepts, threat intelligence, supplier risk indicators, software risk, hardware risk, and federal cybersecurity requirements relevant to government and defense customers
  • Protect sensitive customer, supplier, product, and program information in accordance with applicable security, contractual, clearance, and customer requirements
  • Travel up to 15% for potential customer site visits, in-person meetings, or program-related engagements

Skills

  • • 2–4 years of experience in cyber supply chain risk management, cybersecurity analysis, threat intelligence, supplier risk, risk analysis, federal consulting, government delivery, or a related field
  • • Active Secret clearance required at time of hire
  • • Experience analyzing technical, supplier, product, vendor, threat, bill of materials, or risk data and translating findings into clear business, operational, or mission impact
  • • Understanding of cyber supply chain risk concepts, including supplier risk, software risk, hardware risk, third-party risk, ownership/control concerns, threat exposure, and vulnerability or compromise indicators
  • • Ability to review data for accuracy, completeness, and risk significance while documenting findings clearly and objectively
  • • Ability to learn specialized platforms, customer systems, product workflows, and data structures quickly and apply that knowledge to risk analysis and deliverable development
  • • Proficiency with Microsoft Excel, including the ability to organize, filter, compare, review, and summarize data
  • • Proficiency with Microsoft PowerPoint, including the ability to support clear, professional presentations and briefing materials
  • • Strong written communication skills with the ability to summarize complex risk information for internal stakeholders, program teams, and occasional customer-facing discussions
  • • Ability to serve as a subject matter expert on risk findings, platform outputs, and deliverable content when needed
  • • Ability to work effectively in a hybrid environment in the Washington, DC area
  • • Ability to collaborate with project managers, analysts, technical teams, and delivery leaders while operating with moderate independence
  • • Intermediate proficiency using AI tools to support research, analysis, summarization, and productivity while applying sound judgment, validation, and responsible-use practices
  • • Ability to travel up to 15% for customer on-site visits, in-person meetings, or program-related engagements
  • • Ability to handle sensitive information and comply with applicable security, confidentiality, clearance, and customer requirements
  • • Bachelor's Degree or equivalent professional work experience required
  • • Security+ certification or other related cybersecurity, risk management, supply chain risk, or information assurance certification
  • • Experience supporting Department of Defense, Department of Navy, federal civilian, or defense industrial base customers
  • • Experience with C-SCRM, SCRM, vendor risk management, third-party risk management, software supply chain risk, hardware supply chain risk, cyber threat intelligence, or product assurance
  • • Familiarity with FOCI, SBOM, HBOM, supplier risk scoring, vulnerability data, compromised software libraries, or product assurance workflows
  • • Experience reviewing bills of materials, supplier data, software component data, hardware component data, product data, or platform-generated risk findings
  • • Experience using data analysis, case management, risk management, cybersecurity, or reporting platforms to evaluate and communicate risk
  • • Familiarity with federal cybersecurity frameworks, standards, or guidance such as NIST, CMMC, FedRAMP, RMF, or DoD cybersecurity requirements
  • • Experience producing written findings, risk summaries, briefing inputs, or analytical reports for government or regulated customers

Qualifications

Must Haves

  • • 2–4 years of experience in cyber supply chain risk management, cybersecurity analysis, threat intelligence, supplier risk, risk analysis, federal consulting, government delivery, or a related field
  • • Active Secret clearance required at time of hire
  • • Experience analyzing technical, supplier, product, vendor, threat, bill of materials, or risk data and translating findings into clear business, operational, or mission impact
  • • Understanding of cyber supply chain risk concepts, including supplier risk, software risk, hardware risk, third-party risk, ownership/control concerns, threat exposure, and vulnerability or compromise indicators
  • • Ability to review data for accuracy, completeness, and risk significance while documenting findings clearly and objectively
  • • Ability to learn specialized platforms, customer systems, product workflows, and data structures quickly and apply that knowledge to risk analysis and deliverable development
  • • Proficiency with Microsoft Excel, including the ability to organize, filter, compare, review, and summarize data
  • • Proficiency with Microsoft PowerPoint, including the ability to support clear, professional presentations and briefing materials
  • • Strong written communication skills with the ability to summarize complex risk information for internal stakeholders, program teams, and occasional customer-facing discussions
  • • Ability to serve as a subject matter expert on risk findings, platform outputs, and deliverable content when needed
  • • Ability to work effectively in a hybrid environment in the Washington, DC area
  • • Ability to collaborate with project managers, analysts, technical teams, and delivery leaders while operating with moderate independence
  • • Intermediate proficiency using AI tools to support research, analysis, summarization, and productivity while applying sound judgment, validation, and responsible-use practices
  • • Ability to travel up to 15% for customer on-site visits, in-person meetings, or program-related engagements
  • • Ability to handle sensitive information and comply with applicable security, confidentiality, clearance, and customer requirements
  • • Bachelor's Degree or equivalent professional work experience required

Nice to Haves

  • • Security+ certification or other related cybersecurity, risk management, supply chain risk, or information assurance certification
  • • Experience supporting Department of Defense, Department of Navy, federal civilian, or defense industrial base customers
  • • Experience with C-SCRM, SCRM, vendor risk management, third-party risk management, software supply chain risk, hardware supply chain risk, cyber threat intelligence, or product assurance
  • • Familiarity with FOCI, SBOM, HBOM, supplier risk scoring, vulnerability data, compromised software libraries, or product assurance workflows
  • • Experience reviewing bills of materials, supplier data, software component data, hardware component data, product data, or platform-generated risk findings
  • • Experience using data analysis, case management, risk management, cybersecurity, or reporting platforms to evaluate and communicate risk
  • • Familiarity with federal cybersecurity frameworks, standards, or guidance such as NIST, CMMC, FedRAMP, RMF, or DoD cybersecurity requirements
  • • Experience producing written findings, risk summaries, briefing inputs, or analytical reports for government or regulated customers

Benefits

  • Remote and Hybrid working environment
  • Medical, dental, vision plans with employees covered up to 90% with highly progressive options for dependents and families
  • Company paid life, short- and long-term disability insurance
  • Employee Assistance Program
  • 401(k) match
  • Flexible Paid Time Off
  • Parental Leave
  • Professional growth opportunities through succession planning, up-skilling, and certifications
  • Tuition and certification reimbursement
  • Employee Referral Programs
  • Company Sponsored Events

More jobs like this