Hiring.Camp

Third-Party & Supply Chain Risk Analyst

Trueanomalyinc

·

Today

Salary
$105k – $150k
Location
Denver, CO or Long Beach, CA or Washington, DC · Denver, Colorado, United States · Los Angeles, California, United States · Washington, District of Columbia, United States
Department
Governance, Risk, & Compliance
Experience
5+ years
Visa
Not sponsored
Clearance
Required
Source
Greenhouse

Description

Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.

OUR MISSION

True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.

OUR VALUES

  • Be the offset. We create asymmetric advantages with creativity and ingenuity.
  • What would it take? We challenge assumptions to deliver ambitious results.
  • It’s the people. Our team is our competitive advantage and we are better together.

Your Mission

We are seeking a driven and detail-oriented Third-Party & Supply Chain Risk Analyst to own the day-to-day execution of our Third-Party Vendor Risk Management (TPVRM) and Cyber Supply Chain Risk Management (C-SCRM) programs, with a secondary line of effort supporting the broader Enterprise Risk Management (ERM) function. Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role assessing suppliers and subcontractors, tracing risk through our hardware and software supply chains, tracking remediation, and building the data foundation that powers executive-level decisions about who we buy from and depend on.

This role is ideal for a mid-career risk professional who is fluent in frameworks such as NIST RMF, NIST SP 800-161 (C-SCRM), and CMMC, is developing practical experience with risk quantification methodologies like FAIR and OCTAVE, and is eager to grow within a fast-paced aerospace and defense environment where the supply chain spans spacecraft hardware, payloads, and mission software. You will work closely with procurement, supply chain, engineering, security, legal, and compliance teams to identify, document, and track risk across our full population of vendors, suppliers, and the components they deliver.

Responsibilities

Third-Party Vendor Risk Management

  • Own and execute the vendor risk assessment lifecycle end to end — intake, tiering, onboarding due diligence, and periodic reassessment — including security questionnaire administration, documentation review, and risk scoring.
  • Maintain the vendor risk inventory and lifecycle tracking records, ensuring every vendor and subcontractor is appropriately tiered by criticality and data/access exposure, and is reassessed on schedule.
  • Continuously monitor third-party risk signals — cybersecurity advisories, breach disclosures, financial-health and adverse-media indicators, regulatory and debarment actions (e.g., SAM.gov exclusions), and contractual compliance status — escalating material changes to the Senior Enterprise Risk Manager.
  • Assess vendor cybersecurity posture against contractual and regulatory requirements, including flow-down of DFARS 252.204-7012, NIST SP 800-171, and CMMC obligations to subcontractors handling Controlled Unclassified Information (CUI).
  • Partner with contracts, procurement, and legal teams to translate assessment findings into recommended risk mitigation language, flow-down clauses, and remediation commitments before award and at renewal.
  • Track vendor remediation items to closure, maintaining risk acceptance records where residual risk is formally accepted by an accountable owner.

Supply Chain Risk Management (C-SCRM)

  • Build and maintain the program that traces risk through both the hardware and software supply chains — extending beyond first-tier vendors to the components, subcomponents, and sub-tier suppliers that go into spacecraft, payloads, and mission systems.
  • Establish and maintain supplier and component inventories, including support for Hardware Bill of Materials (HBOM) and Software Bill of Materials (SBOM) practices, to enable provenance, traceability, and rapid impact analysis when a supplier or part is compromised, discontinued, or flagged.
  • Align the C-SCRM program with NIST SP 800-161 Rev. 1, applicable CMMC supply chain requirements, and DFARS clauses, documenting supply chain risk controls and their coverage across critical suppliers.
  • Support sub-tier and single-/sole-source dependency analysis, surfacing concentration risk and resilience gaps for critical components and escalating to program and supply chain leadership.

Enterprise Risk Management

  • Support the design, execution, and continuous improvement of the enterprise risk management program under the direction of the Senior Enterprise Risk Manager, ensuring third-party and supply chain risks roll up into the enterprise risk picture.
  • Support the application of FAIR methodology to help quantify third-party and supply chain risks in financial terms and contribute to risk prioritization analyses for leadership.
  • Maintain and update the enterprise risk register, ensuring accuracy of risk ratings, ownership assignments, remediation status, and residual risk tracking for supplier- and vendor-originated risks.
  • Build and maintain program dashboards, KPI/KRI reports, and status tracking using tools such as Jira, Confluence, enterprise GRC platforms, and MS Project — with an emphasis on third-party and supply chain exposure metrics.
  • Assist with audit readiness activities including evidence collection, pre-assessment preparation, control documentation, and post-audit remediation tracking, including supply chain and vendor controls.
  • Contribute to the development and maintenance of risk policies, standards, and guidelines aligned to NIST SP 800-53 Rev. 5, NIST SP 800-171, NIST SP 800-161, RMF, and CMMC Level 3.

Cross-Functional Collaboration

  • Serve as a reliable day-to-day point of contact for third-party and supply chain risk inquiries from internal stakeholders across procurement, supply chain, engineering, security, operations, and legal teams.
  • Track program milestones, action items, and deliverables, proactively communicating status and flagging risks or dependencies to the Senior Enterprise Risk Manager.
  • Continuously improve vendor and supply chain risk workflows, questionnaire templates, tiering criteria, and reporting processes to support scalable and repeatable execution.
  • Support the preparation of materials for internal leadership briefings, external assessor interactions, and government partner reviews, including third-party and supply chain risk exposure summaries.

Qualifications

  • 5+ years of experience in third-party/vendor risk management, supply chain risk, enterprise risk management, GRC, cybersecurity risk, or a closely related discipline, with a substantial portion focused on third-party or supply chain risk.
  • Direct, hands-on experience executing third-party/vendor risk assessments, including questionnaire administration, documentation review, tiering, risk scoring, and remediation tracking.
  • Working knowledge of NIST SP 800-161 (C-SCRM), NIST SP 800-53, NIST SP 800-171, DoD RMF (IL5/IL6), and CMMC, with direct experience supporting assessments or audits under one or more of these frameworks.
  • Familiarity with supply chain risk concepts such as HBOM/SBOM, counterfeit-parts avoidance, provenance and traceability, sub-tier dependency and concentration risk, and prohibited-source screening (e.g., Section 889, FASCSA).
  • Familiarity with risk assessment methodologies including FAIR and/or OCTAVE, with a desire to deepen applied expertise in risk quantification.
  • Hands-on experience with program management and GRC documentation tools including Jira, Confluence (Atlassian suite), MS Project, enterprise GRC and/or third-party risk platforms, and MS Visio or Lucidchart.
  • Strong written and verbal communication skills, with the ability to clearly document findings and translate third-party and supply chain risk concepts for both technical and non-technical audiences.
  • Highly organized, self-directed, and comfortable managing multiple workstreams simultaneously in a fast-paced, regulated environment.
  • Active or ability to obtain SECRET, TS/SCI security clearance.
  • Must be a U.S. citizen, lawful permanent resident, or protected individual per ITAR requirements (8 U.S.C. 1324b(a)(3)).

Preferred Qualifications

  • Background in startup, aerospace, defense technology, or SaaS companies operating in regulated government markets, particularly with hardware and mission-software supply chains.
  • Industry certifications such as:
    • Certified Third Party Risk Professional (CTPRP)
    • Certified in Risk and Information Systems Control (CRISC)
    • Certified Information Systems Auditor (CISA)
    • Open FAIR Certification (The Open Group)
    • CompTIA Security+ or equivalent
    • Certified Professional in Supply Management (CPSM), SCPro, or similar supply chain certification
    • Certified ScrumMaster (CSM) or similar Agile certification
  • Experience with cloud environments, particularly Azure Government and/or AWS GovCloud.
  • Familiarity with POA&M management, SSP documentation, and audit evidence collection in DoD authorization contexts, including supplier and supply chain controls.
  • Working knowledge of ITAR, EAR, DFARS (including 252.204-7012, 252.204-7020, and 252.246-7007/7008), FOCI, and export control considerations as they relate to vendor and supply chain risk.
  • Experience assessing foreign ownership, control, or influence (FOCI) and country-of-origin risk for critical suppliers.
  • Familiarity with Agile/Scrum and hybrid project delivery models.

Compensation

  • Base Salary: Denver - $105,000 to $150,000, Long Beach - $115,000 to $160,000, Washington, DC - $115,000 to $160,000, SF Bay Area - $125,000 to $175,000
  • Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave

Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, location, and experience.

Additional Requirements

  • Work Location: This role will be onsite at one of our office locations: Centennial, CO, Long Beach, CA, or Washington, DC #LI-Onsite
  • Work Environment: Standard office setting, working at a desk or in a production factory environment
  • Physical Demands: May include frequent standing, sitting, walking, bending, and lifting or carrying items up to 20 lbs.

This position will be open until it is successfully filled.

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR), you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

We value diversity of experience, knowledge, backgrounds, and perspectives and harness these qualities to create extraordinary impact. True Anomaly is committed to equal employment opportunity regardless of sex, race, religion or belief, ethnic or national origin, disability, age, citizenship, marital, domestic or civil partnership status, sexual orientation, gender identity, pregnancy, maternity or related condition (including breastfeeding) or any other basis as protected by applicable law. If you have a disability or additional need that requires accommodation, please do not hesitate to let us know.

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us.

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us.

 

Skills

AWSAzureJiraConfluenceCybersecurityAgileScrumRisk ManagementComplianceProcurementProgram ManagementCompTIA