ECS

Supply Chain Risk Management Audit Analyst

ECS$75K — $95K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Current Secret security clearance.
  • Minimum 3 years of experience in supply chain risk management or related field, particularly in federal or defense environments.
  • Active IAM Level I certification (e.g., CompTIA Security+ CE, ISC² CAP, ISC² SSCP, GIAC GSLC).
  • Strong problem-solving and decision-making skills.
  • Excellent communication abilities, capable of engaging effectively with various stakeholders.

Responsibilities

  • Conduct detailed supply chain security reviews for DoW information systems.
  • Analyze third-party vendor security documentation for compliance with DoW and federal standards.
  • Review independent audit artifacts to assess security controls and safeguards.
  • Validate vendor responses to security assessments and identify risk conditions.
  • Collaborate with risk management leadership and other teams to document findings and remediation efforts.
  • Track vendor security deficiencies and monitor corrective actions.
  • Prepare documentation and reports for risk management activities and leadership briefings.

Benefits

  • Opportunity to work on a key initiative within the U.S. Department of War's AI strategy.
  • Engage in meaningful work that contributes to national defense and security.
  • Access to professional development opportunities within a defense contracting environment.
Full Job Description
Everforth ECS is seeking a Supply Chain Risk Management Audit Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. Please Note: This position is contingent upon contract award.

The War Data Platform (WDP) is a key initiative within the U.S. Department of War's (DoW) AI-First strategy introduced in early 2026. The WDP separates business and financial data from operational warfighting data, aiming to accelerate the deployment of artificial intelligence (AI) on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, and supports collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts.

The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit artifacts across classified and unclassified environments. This role directly strengthens WDP's mission assurance posture by evaluating vendor compliance, surfacing supply chain risk conditions, and maintaining audit-ready evidence packages that support RMF authorization decisions and government oversight requirements across the full WDP software and services portfolio.
• Performs detailed supply chain security review activities supporting DoW information systems across unclassified and classified environments.
• Conducts structured analysis of third-party vendor security documentation, evaluating cybersecurity controls, governance practices, and risk management approaches against DoW and federal requirements.
• Reviews independent audit artifacts including SOC reports, ISO certifications, penetration test summaries, and vendor attestations to assess adequacy of security safeguards and control implementation.
• Validates vendor responses to security questionnaires, due diligence requests, and contractual security clauses, identifying gaps, inconsistencies, and residual risk conditions.
• Coordinates with Supply Chain Risk Management leadership, contracting personnel, system owners, and cybersecurity teams to document findings and support remediation planning.
• Tracks vendor security deficiencies, corrective actions, and closure status within risk registers, assessment repositories, and continuous monitoring dashboards.
• Prepares assessment summaries, deficiency reports, and supporting documentation for Risk Management Framework activities, authorization decisions, and leadership briefings.
• Maintains organized evidence packages within SharePoint and approved document management systems to support audits and inspections.
• Monitors emerging supply chain threats, government advisories, and policy updates to inform assessment criteria and review focus areas.
• Contributes to improved third-party risk visibility, stronger vendor accountability, and sustained mission assurance while reinforcing program values of diligence, transparency, consistency, and disciplined risk oversight.
• Performs other duties as assigned.
• Current Secret security clearance.
• A minimum of 3 years of experience in supply chain risk management, third-party security assessment, cybersecurity compliance, or a closely related discipline within a federal, defense, or government contracting environment, with demonstrated ability to evaluate vendor security documentation and produce audit-ready assessment artifacts in support of RMF authorization activities.
• Active IAM Level I certification, satisfied by one of the following: CompTIA Security+ CE, ISC² CAP, ISC² SSCP, or GIAC GSLC.
• Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
• Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

More Aerospace & Defense Jobs

Find similar Supply Chain Risk Management Audit Analyst jobs: