Third-Party & Supply Chain Risk Analyst
True Anomaly · Denver, CO or Long Beach, CA or Washington, DC
- Senior
- Full-time
- $105,000 – $150,000
- Posted 2026-09-24
- Confirmed live on 25 September 2026
Job description
Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.
OUR MISSION
True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.
OUR VALUES
• Be the offset. We create asymmetric advantages with creativity and ingenuity.
• What would it take? We challenge assumptions to deliver ambitious results.
• It’s the people. Our team is our competitive advantage and we are better together.
Your Mission
We are seeking a driven and detail-oriented Third-Party & Supply Chain Risk Analyst to own the day-to-day execution of our Third-Party Vendor Risk Management (TPVRM) and Cyber Supply Chain Risk Management (C-SCRM) programs, with a secondary line of effort supporting the broader Enterprise Risk Management (ERM) function. Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role assessing suppliers and subcontractors, tracing risk through our hardware and software supply chains, tracking remediation, and building the data foundation that powers executive-level decisions about who we buy from and depend on.
This role is ideal for a mid-career risk professional who is fluent in frameworks such as NIST RMF, NIST SP 800-161 (C-SCRM), and CMMC, is developing practical experience with risk quantification methodologies like FAIR and OCTAVE, and is eager to grow within a fast-paced aerospace and defense environment where the supply chain spans spacecraft hardware, payloads, and mission software. You will work closely with procurement, supply chain, engineering, security, legal, and compliance teams to identify, document, and track risk across our full population of vendors, suppliers, and the components they deliver.
Responsibilities
Third-Party Vendor Risk Management
• Own and execute the vendor risk assessment lifecycle end to end — intake, tiering, onboarding due diligence, and periodic reassessment — including security questionnaire administration, documentation review, and risk scoring.
• Maintain the vendor risk inventory and lifecycle tracking records, ensuring every vendor and subcontractor is appropriately tiered by criticality and data/access exposure, and is reassessed on schedule.
• Continuously monitor third-party risk signals — cybersecurity advisories, breach disclosures, financial-health and adverse-media indicators, regulatory and debarment actions (e.g., SAM.gov exclusions), and contractual compliance status — escalating material changes to the Senior Enterprise Risk Manager.
• Assess vendor cybersecurity posture against contractual and regulatory requirements, including flow-down of DFARS 252.204-7012, NIST SP 800-171, and CMMC obligations to subcontractors handling Controlled Unclassified Information (CUI).
• Partner with contracts, procurement, and legal teams to translate assessment findings into recommended risk mitigation language, flow-down clauses, and remediation commitments before award and at renewal.
• Track vendor remediation items to closure, maintaining risk acceptance records where residual risk is formally accepted by an accountable owner.
Supply Chain Risk Management (C-SCRM)
• Build and maintain the program that traces risk through both the hardware and software supply chains — extending beyond first-tier vendors to the components, subcomponents, and sub-tier suppliers that go into spacecraft, payloads, and mission systems.
• Establish and maintain supplier and component inventories, including support for Hardware Bill of Materials (HBOM) and Software Bill of Materials (SBOM) practices, to enable provenance, traceability, and rapid impact analysis when a supplier or part is compromised, discontinued, or flagged.
• Align the C-SCRM program with NIST SP 800-161 Rev. 1, applicable CMMC supply chain requirements, and DFARS clauses, documenting supply chain risk controls and their coverage across critical suppliers.
• Support sub-tier and single-/sole-source dependency analysis, surfacing concentration risk and resilience gaps for critical components and escalating to program and supply chain leadership.
Enterprise Risk Management
• Support the design, execution, and continuous improvement of the enterprise risk management program under the direction of the Senior Enterprise Risk Manager, ensuring third-party and supply chain risks roll up into the enterprise risk picture.
• Support the application of FAIR methodology to help quantify third-party and supply chain risks in financial terms and contribute to risk prioritization analyses for leadership.
• Maintain and update the enterprise risk register, ensuring accuracy of risk ratings, ownership assignments, remediation status, and residual risk tracking for supplier- and vendor-originated risks.
• Build and maintai
Prepare for the interview
Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.
More at True Anomaly
- Senior Designer, Events · Long Beach, CA
- Senior COMSEC Manager · Denver, CO
- Senior Program Manager, IT Governance and Compliance · Denver, CO or Long Beach, CA or Washington, DC
- Compliance Engineer III · Denver, CO or Long Beach, CA or Washington, DC
- Senior Electrical Engineer, FPGA Development · Long Beach, CA
- Senior Accountant · Denver, CO
- Cost Accounting Manager · Denver, CO
- Fixed Asset Accountant · Denver, CO