MANTECH logo

Acquisition Security Risk Analyst

MANTECH
  • Quantico, VA
    1 day ago

    Job Description

    MANTECH seeks a motivated, career and customer-oriented Acquisition Security Risk Analyst to support our USMC contract out of Quantico, VA.


    The Acquisition Security Risk Analyst will serve as a strategic author and systems security architect capable of conceptualizing, structuring, and authoring an enterprise-grade Acquisition Security Risk Posture Guide to weave disparate risk domains into a cohesive operational framework across the acquisition lifecycle.


    Job Responsibilities include but are not limited to:

    • Authoring an enterprise-grade Acquisition Security Risk Posture Guide that integrates Critical Program Information (CPI), Criticality Analysis, SCRM/C-SCRM, Counterintelligence, and System Security Engineering.
    • Translating complex defense acquisition mandates into practical playbooks, decision trees, and operational risk frameworks for Program Managers, Chief Engineers, and Security Officers.
    • Mapping Mission-Critical Functions (MCFs) and Mission-Critical Components (MCCs) down to hardware, firmware, and software to support robust Criticality Analysis workflows.
    • Structuring supplier risk tiers, provenance verification, and Software/Hardware Bill of Materials (SBOM/HBOM) governance into acquisition milestones.
    • Incorporating Anti-Tamper, microelectronics trust, and hardware assurance measures to safeguard against reverse engineering, counterfeit parts, and physical exploitation.
    • Integrating Critical Program Information (CPI) protection, horizontal protection workflows, and supply chain threat feeds into acquisition milestone decisions.
    • Aligning contractor network compliance standards, such as DFARS 252.204-7012, NIST SP 800-171, and CMMC, with delivered product security and enterprise risk frameworks.

    Mandatory Qualifications:

    • Bachelor's degree with at least 5 years of experience in System Security Engineering, Program Protection, or Supply Chain Risk Management. An additional 2 years of experience may be substituted in lieu of degree. 
    • Demonstrated experience authoring program protection guidance, governance playbooks, or enterprise security frameworks within defense acquisition pathways.
    • Deep knowledge of DoD acquisition policies including DoDI 5000.83, DoDI 5200.44, DoDI 5200.39, and DoDI 5000.90.
    • Strong familiarity with federal supply chain standards, including NIST SP 800-161 Rev. 1, NIST SP 800-160 Vols. 1 & 2, and NIST SP 800-53 Rev. 5.
    • Experience integrating Critical Program Information (CPI) identification, Counterintelligence (CI) feeds, and foreign ownership/influence (FOCI) regulations into risk mitigation strategies.
    • Proven ability to design assessment rubrics and scoring models to evaluate vendor security postures and analyze risk data, (e.g SBOM/HBOM). 

    Preferred Qualifications:

    • Certified Information Systems Security Professional (CISSP), Certified Authorization Professional (CAP), or related DoD 8570/8140 IAM Level II/III certifications.
    • Hands-on experience working within the Adaptive Acquisition Framework (AAF) pathways and applying the DoD Risk, Issue, and Opportunity (RIO) Management Guide.
    • Familiarity with microelectronics trust requirements, NDAA Section 889 compliance, and Federal Acquisition Security Council (FASC) exclusion guidelines.
    • Self-starter with exceptional technical authoring skills and the ability to collaborate across multidisciplinary engineering and program management teams.

    Security Clearance Required:

    • Must have a current / active DoW Top Secret / SCI

    Physical Requirements:

    • Sedentary work

    Numbers & Facts

    LocationQuantico, VA

    Skills

    • Analysis Skillsunmatched
    • Bill of Materials (BOM)unmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Computer Firmwareunmatched
    • Computer Securityunmatched
    • Customer Acquisitionunmatched
    • Customer Relationsunmatched
    • Data Analysisunmatched
    • DoD Acquisitionsunmatched
    • DoD Directive 8140unmatched
    • DoD Directive 8570unmatched
    • Enterprise Protectionunmatched
    • IAM - Information Assurance Managementunmatched
    • Project/Program Managementunmatched
    • Regulationsunmatched
    • Reverse Engineeringunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Scorecardingunmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Clearanceunmatched
    • Security Complianceunmatched
    • Software Administrationunmatched
    • Strategic Planningunmatched
    • Supply Chainunmatched
    • Supply Chain Managementunmatched
    • System Architectureunmatched
    • Systems Engineeringunmatched
    • Team Playerunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Department of Defense (DoD)unmatched
    • United States Marine Corps (USMC)unmatched
    • Vendor/Supplier Evaluationunmatched
    • Workflow Analysisunmatched
    • Writing Skillsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder