ECS

Supply Chain Risk Management Audit Analyst

ECS$80K — $110K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Minimum 3 years in supply chain risk management or related field
  • Current Secret security clearance
  • Active IAM Level I certification (e.g., CompTIA Security+ CE)
  • Proficient in evaluating vendor security documentation and audit artifacts
  • Strong problem-solving and decision-making skills
  • Excellent interpersonal and communication abilities

Responsibilities

  • Conduct detailed security reviews of supply chain processes for unclassified and classified environments
  • Analyze third-party vendor security documentation for compliance with DoW and federal standards
  • Review independent audit artifacts like SOC reports and ISO certifications
  • Validate vendor responses to security questionnaires and identify gaps
  • Coordinate with various stakeholders for documentation and remediation efforts
  • Track vendor security deficiencies and monitor progress
  • Prepare assessment summaries and reports for Risk Management processes

Benefits

  • Opportunities for professional development and growth
  • Supportive work environment focusing on mission assurance
  • Access to advanced resources in cybersecurity and risk management
  • Collaboration with high-level government and military stakeholders
  • Potential for impactful work within national defense initiatives
Full Job Description
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit artifacts across classified and unclassified environments. This role directly strengthens WDP's mission assurance posture by evaluating vendor compliance, surfacing supply chain risk conditions, and maintaining audit-ready evidence packages that support RMF authorization decisions and government oversight requirements across the full WDP software and services portfolio.
• Performs detailed supply chain security review activities supporting DoW information systems across unclassified and classified environments.
• Conducts structured analysis of third-party vendor security documentation, evaluating cybersecurity controls, governance practices, and risk management approaches against DoW and federal requirements.
• Reviews independent audit artifacts including SOC reports, ISO certifications, penetration test summaries, and vendor attestations to assess adequacy of security safeguards and control implementation.
• Validates vendor responses to security questionnaires, due diligence requests, and contractual security clauses, identifying gaps, inconsistencies, and residual risk conditions.
• Coordinates with Supply Chain Risk Management leadership, contracting personnel, system owners, and cybersecurity teams to document findings and support remediation planning.
• Tracks vendor security deficiencies, corrective actions, and closure status within risk registers, assessment repositories, and continuous monitoring dashboards.
• Prepares assessment summaries, deficiency reports, and supporting documentation for Risk Management Framework activities, authorization decisions, and leadership briefings.
• Maintains organized evidence packages within SharePoint and approved document management systems to support audits and inspections.
• Monitors emerging supply chain threats, government advisories, and policy updates to inform assessment criteria and review focus areas.
• Contributes to improved third-party risk visibility, stronger vendor accountability, and sustained mission assurance while reinforcing program values of diligence, transparency, consistency, and disciplined risk oversight.
• Performs other duties as assigned.
• Current Secret security clearance.
• A minimum of 3 years of experience in supply chain risk management, third-party security assessment, cybersecurity compliance, or a closely related discipline within a federal, defense, or government contracting environment, with demonstrated ability to evaluate vendor security documentation and produce audit-ready assessment artifacts in support of RMF authorization activities.
• Active IAM Level I certification, satisfied by one of the following: CompTIA Security+ CE, ISCB2 CAP, ISCB2 SSCP, or GIAC GSLC.
• Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
• Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

  • ECS
    Analytic Engineer
    $90K — $130K *
    Fairfax, VA 22031 (Fairfax County)
    Aerospace & Defense
    In-Person
  • ECS
    Analytic Engineer
    $90K — $130K *
    Falls Church, VA 22042 (Fairfax County)
    Aerospace & Defense
    In-Person
  • ECS
    Senior Governance Training Specialist
    $100K — $130K *
    Fairfax, VA 22031 (Fairfax County)
    Education, Government & Non-Profit
    In-Person
  • ECS
    Analytic Engineer
    $90K — $130K *
    Washington, DC 20310 (District Of Columbia County)
    Aerospace & Defense
    In-Person
  • ECS
    Senior Governance Training Specialist
    $100K — $130K *
    Falls Church, VA 22042 (Fairfax County)
    Education, Government & Non-Profit
    In-Person

More Aerospace & Defense Jobs

Find similar Supply Chain Risk Management Audit Analyst jobs: