ManTech International

Acquisition Security Risk Analyst

ManTech International • $97K — $161K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 5+ years in System Security Engineering, Program Protection, or Supply Chain Risk Management (or 7+ years of experience without a degree).
  • Experience in authoring program protection guidance or enterprise security frameworks in defense acquisition.
  • In-depth knowledge of DoD acquisition policies (DoDI 5000 series).
  • Familiarity with federal supply chain standards (NIST SP 800 series).
  • Experience integrating Critical Program Information (CPI) and Counterintelligence (CI) into risk strategies.
  • Ability to design assessment rubrics for vendor security evaluations.

Responsibilities

  • Author an enterprise-grade Acquisition Security Risk Posture Guide integrating various risk domains.
  • Translate defense acquisition mandates into practical playbooks and operational risk frameworks.
  • Map Mission-Critical Functions and Components to support Criticality Analysis workflows.
  • Structure supplier risk tiers and governance into acquisition milestones.
  • Incorporate Anti-Tamper and hardware assurance measures to prevent exploitation.
  • Integrate CPI protection and supply chain threat feeds into acquisition decisions.
  • Align contractor compliance standards with product security and enterprise risk frameworks.

Benefits

  • Health Insurance
  • Life Insurance
  • Paid Time Off
  • Holiday Pay
  • Short-term and long-term Disability
  • Retirement and Savings
  • Learning and Development opportunities
  • Wellness programs
Full Job Description
MANTECH seeks a motivated, career and customer-oriented Acquisition Security Risk Analyst to support our USMC contract out of Quantico, VA.

The Acquisition Security Risk Analyst will serve as a strategic author and systems security architect capable of conceptualizing, structuring, and authoring an enterprise-grade Acquisition Security Risk Posture Guide to weave disparate risk domains into a cohesive operational framework across the acquisition lifecycle.

Job Responsibilities include but are not limited to:
  • Authoring an enterprise-grade Acquisition Security Risk Posture Guide that integrates Critical Program Information (CPI), Criticality Analysis, SCRM/C-SCRM, Counterintelligence, and System Security Engineering.
  • Translating complex defense acquisition mandates into practical playbooks, decision trees, and operational risk frameworks for Program Managers, Chief Engineers, and Security Officers.
  • Mapping Mission-Critical Functions (MCFs) and Mission-Critical Components (MCCs) down to hardware, firmware, and software to support robust Criticality Analysis workflows.
  • Structuring supplier risk tiers, provenance verification, and Software/Hardware Bill of Materials (SBOM/HBOM) governance into acquisition milestones.
  • Incorporating Anti-Tamper, microelectronics trust, and hardware assurance measures to safeguard against reverse engineering, counterfeit parts, and physical exploitation.
  • Integrating Critical Program Information (CPI) protection, horizontal protection workflows, and supply chain threat feeds into acquisition milestone decisions.
  • Aligning contractor network compliance standards, such as DFARS [redacted], NIST SP 800-171, and CMMC, with delivered product security and enterprise risk frameworks.


Mandatory Qualifications:
  • Bachelor's degree with at least 5 years of experience in System Security Engineering, Program Protection, or Supply Chain Risk Management. An additional 2 years of experience may be substituted in lieu of degree.
  • Demonstrated experience authoring program protection guidance, governance playbooks, or enterprise security frameworks within defense acquisition pathways.
  • Deep knowledge of DoD acquisition policies including DoDI 5000.83, DoDI 5200.44, DoDI 5200.39, and DoDI 5000.90.
  • Strong familiarity with federal supply chain standards, including NIST SP 800-161 Rev. 1, NIST SP 800-160 Vols. 1 & 2, and NIST SP 800-53 Rev. 5.
  • Experience integrating Critical Program Information (CPI) identification, Counterintelligence (CI) feeds, and foreign ownership/influence (FOCI) regulations into risk mitigation strategies.
  • Proven ability to design assessment rubrics and scoring models to evaluate vendor security postures and analyze risk data, (e.g SBOM/HBOM).


Preferred Qualifications:
  • Certified Information Systems Security Professional (CISSP), Certified Authorization Professional (CAP), or related DoD 8570/8140 IAM Level II/III certifications.
  • Hands-on experience working within the Adaptive Acquisition Framework (AAF) pathways and applying the DoD Risk, Issue, and Opportunity (RIO) Management Guide.
  • Familiarity with microelectronics trust requirements, NDAA Section 889 compliance, and Federal Acquisition Security Council (FASC) exclusion guidelines.
  • Self-starter with exceptional technical authoring skills and the ability to collaborate across multidisciplinary engineering and program management teams.


Security Clearance Required:
  • Must have a current / active DoW Top Secret / SCI


Physical Requirements:
  • Sedentary work


The projected compensation range for this position is $97,100.00-$161,900.00. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (For Remote Opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, MANTECH invests in its employees beyond just compensation. MANTECH's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections.

About ManTech International

ManTech International Corporation is an American defense contracting firm that was founded in 1968. The company provides cybersecurity, intelligence, and defense solutions to the United States Government. ManTech has over 9,000 employees and operates in 40 countries worldwide. The company's services include software development, systems engineering, and enterprise IT solutions. ManTech has been awarded numerous contracts by the U.S. Department of Defense and other government agencies.
Learn more about ManTech International
Size
9,800 employees
Market Cap
$3.7 billion
Industry
Net Income
$120.5 million
Founded
1968
5 Year Trend
+9.8%
Revenue
$2.5 billion
NASDAQ

Similar Jobs

More Jobs at ManTech International

  • ManTech International
    All-Source Intelligence Analyst
    $85K — $141K *
    Sterling, VA 20164 (Loudoun County)
    Aerospace & Defense
    In-Person
  • ManTech International
    Systems Administrator
    $80K — $95K *
    Eglin Afb, FL 32542 (Okaloosa County)
    Information Technology
    In-Person
  • ManTech International
    Deployable Programmer
    $95K — $115K *
    Chandler, AZ 85225 (Maricopa County)
    Telecommunications & Hardware
    In-Person
  • ManTech International
    Deployable Programmer
    $95K — $115K *
    Philadelphia, PA 19120 (Philadelphia County)
    Aerospace & Defense
    In-Person
  • ManTech International
    Configuration Manager
    $70K — $117K *
    Virginia Beach, VA 23464 (Virginia Beach City County)
    Aerospace & Defense
    In-Person

More Aerospace & Defense Jobs

Find similar Acquisition Security Risk Analyst jobs: