Jobs › California › Washington, DC › Third-Party & Supply Chain Risk Analyst
Third-Party & Supply Chain Risk Analyst
True Anomaly is hiring for the job of Third-Party & Supply Chain Risk Analyst, Denver, CO, CA or Washington (On-site). This is a Risk job in the governance, risk, and compliance field. Review the full details below and apply directly with True Anomaly.
Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.
OUR MISSION
True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors, enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.
OUR VALUES
Be the offset. We create asymmetric advantages with creativity and ingenuity.
What would it take? We challenge assumptions to deliver ambitious results.
It’s the people. Our team is our competitive advantage and we are better together.
Your Mission
We are seeking a driven and detail-oriented Third-Party & Supply Chain Risk Analyst to own the day-to-day execution of our Third-Party Vendor Risk Management (TPVRM) and Cyber Supply Chain Risk Management (C-SCRM) programs, with a secondary line of effort supporting the broader Enterprise Risk Management (ERM) function. Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role assessing suppliers and subcontractors, tracing risk through our hardware and software supply chains, tracking remediation, and building the data foundation that powers executive-level decisions about who we buy from and depend on.
This role is ideal for a mid-career risk professional who is fluent in frameworks such as NIST RMF, NIST SP 800-161 (C-SCRM), and CMMC, is developing practical experience with risk quantification methodologies like FAIR and OCTAVE, and is eager to grow within a fast-paced aerospace and defense environment where the supply chain spans spacecraft hardware, payloads, and mission software. You will work closely with procurement, supply chain, engineering, security, legal, and compliance teams to identify, document, and track risk across our full population of vendors, suppliers, and the components they deliver.
Responsibilities
Third-Party Vendor Risk Management
Own and execute the vendor risk assessment lifecycle end to end, intake, tiering, onboarding due diligence, and periodic reassessment, including security questionnaire administration, documentation review, and risk scoring.
Maintain the vendor risk inventory and lifecycle tracking records, ensuring every vendor and subcontractor is appropriately tiered by criticality and data/access exposure, and is reassessed on schedule.
Continuously monitor third-party risk signals, cybersecurity advisories, breach disclosures, financial-health and adverse-media indicators, regulatory and debarment actions (e.g., SAM.gov exclusions), and contractual compliance status, escalating material changes to the Senior Enterprise Risk Manager.
Assess vendor cybersecurity posture against contractual and regulatory requirements, including flow-down of DFARS 252.204-7012, NIST SP 800-171, and CMMC obligations to subcontractors handling Controlled Unclassified Information (CUI).
Partner with contracts, procurement, and legal teams to translate assessment findings into recommended risk mitigation language, flow-down clauses, and remediation commitments before award and at renewal.
Track vendor remediation items to closure, maintaining risk acceptance records where residual risk is formally accepted by an accountable owner.
Supply Chain Risk Management (C-SCRM)
Build and maintain the program that traces risk through both the hardware and software supply chains, extending beyond first-tier vendors to the components, subcomponents, and sub-tier suppliers that go into spacecraft, payloads, and mission systems.
Establish and maintain supplier and component inventories, including support for Hardware Bill of Materials (HBOM) and Software Bill of Materials (SBOM) practices, to enable provenance, traceability, and rapid impact analysis when a supplier or part is compromised, discontinued, or flagged.
Align the C-SCRM program with NIST SP 800-161 Rev. 1, applicable CMMC supply chain requirements, and DFARS clauses, documenting supply chain risk controls and their coverage across critical suppliers.
Support sub-tier and single-/sole-source dependency analysis, surfacing concentration risk and resilience gaps for critical components and escalating to program and supply chain leadership.
Enterprise Risk Management
Support the design, execution, and continuous improvement of the enterprise risk management program under the direction of the Senior Enterprise Risk Manager, ensuring third-party and supply chain risks roll up into the enterprise risk picture.
Support the application of FAIR methodology to help quantify third-party and supply chain risks in financial terms and contribute to risk prioritization analyses for leadership.
Maintain and update the enterprise risk register, ensuring accuracy of risk ratings, ownership assignments, remediation status, and residual risk tracking for supplier- and vendor-originated risks.
Build and maintain program dashboards, KPI/KRI reports, and status tracking using tools such as Jira, Confluence, enterprise GRC platforms, and MS Project, with an emphasis on third-party and supply chain exposure metrics.
Assist with audit readiness activit
Location and market context
This job is based in Denver on-site. Local candidates benefit from being close to True Anomaly's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About risk management jobs
Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.
How to position yourself for this risk management job
Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how True Anomaly would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Head of Risk and Money Services · Gusto · Denver, CO
- Director, Information Security Governance, Risk, and Compliance (GRC) · PenFed Credit Union · McLean, VA
- Senior, Business Risk & AI Automation · Reddit, Inc. · Canada · Remote
- Senior Data Modeler, Fraud Risk Detection · Experian · United States
- Senior Risk Analyst – Data Science & Analytics · Experian · Mumbai, in
- Credit Risk Manager (F/H) · Younited · Paris
- Risk Manager · GE Vernova · 3 Locations
- IP Security & Risk Leader · GE Vernova · 3 Locations
More jobs at True Anomaly
- Senior Program Manager, IT Governance and Compliance · True Anomaly · Denver, CO, CA or Washington
More GRC jobs in Denver
- Retirement Compliance Specialist · Gusto · Denver, CO
- Fund Compliance, Associate Director · PINE Advisor Solutions · Denver, CO
- Auditor (Performance) · Office of the Inspector General · Denver, Colorado
- AML Investigator · Robinhood · Denver, CO
- Contractor Special/Program Security Officer (CPSO) · KBR · Colorado Springs, CO
- Cybersecurity AI Risk and Governance Director · Vantage Data Centers · Denver, CO · Remote
Hiring for Risk?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Third-Party & Supply Chain Risk Analyst in Denver, CO, CA or Washington open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.