Software Analyst supports the mission of the National Information Assurance Partnership by conducting in-depth software assurance and Software Bill of Materials (SBOM) analysis for commercial technologies seeking evaluation, authorization, or deployment within National Security Systems (NSS) and other sensitive U.S. Government environments.This role focuses heavily on software supply chain transparency, software provenance, open-source software (OSS) risk analysis, vulnerability identification, and vendor cybersecurity practices. The analyst evaluates software components, dependencies, development practices, and third-party supplier risks to identify potential threats to the confidentiality, integrity, and availability of government systems.The position requires strong technical analysis, cybersecurity knowledge, and the ability to assess software ecosystems from both a security and supply chain perspective.Key ResponsibilitiesConduct Software Bill of Materials (SBOM) analysis on commercial software products, platforms, and applications undergoing evaluation or review.Analyze software dependencies, transitive dependencies, and third-party libraries to identify supply chain risks and hidden software exposure.Review and validate SBOM formats and standards including:SPDXCycloneDXSWID tagsAssess software provenance, code lineage, package integrity, and software component authenticity.Identify known vulnerabilities and software weaknesses through:CVE analysisKEV reviewVulnerability databasesThreat intelligence sourcesEvaluate risks associated with:Open-source software (OSS)Foreign-developed software componentsUnsupported or end-of-life dependenciesUnmaintained librariesSoftware obfuscation or lack of transparencyPerform secure software supply chain assessments aligned with:NIST SSDFExecutive Order 14028Federal software assurance guidanceNIAP protection profile requirementsConduct due diligence research on software vendors, developers, maintainers, and software ecosystems.Analyze vendor secure development practices including:Secure coding methodologiesBuild pipeline securityCI/CD protectionsDependency managementPatch managementCode signingReview software development and deployment architectures for potential supply chain attack vectors.Support Common Criteria evaluations and software assurance activities through technical risk analysis and supply chain assessments.Produce technical reports, analytical findings, risk summaries, and executive-level briefings related to software supply chain security.Collaborate with government, industry, evaluation labs, and cybersecurity stakeholders to improve software assurance practices and SBOM utilization.Monitor emerging software supply chain threats, malware campaigns, dependency compromise incidents, and malicious package activity. Preferred Education & Certifications(U) Fourteen (14) years experience as a SE in programs and contracts of similar scope, type and complexity is required. Bachelor's degree in System Engineering, Computer Science, Information Systems, Engineering Science, Engineering Management, or related discipline from an accredited college or university is required. Five (5) years of additional SE experience may be substituted for a bachelor's degree.Preferred certifications may include:CISSPCSSLPSecurity+GIAC certificationsCertified SCRM ProfessionalCloud security certificationsApplication security certificationsPublished Required SkillsExperience in software supply chain security, cybersecurity analysis, application security, or SCRM.Strong understanding of:Software Bills of Materials (SBOMs)Open-source software ecosystemsSoftware composition analysis (SCA)Vulnerability managementSecure software developmentFamiliarity with:Common CriteriaNIAP evaluation conceptsNIST cybersecurity guidanceFederal software security initiativesKnowledge of software package managers and ecosystems such as:npmPyPIMavenNuGetGitHub repositoriesAbility to analyze complex software dependency structures and identify risk indicators.Experience writing technical analytical reports and communicating findings to technical and non-technical audiences.LCAT Domain Experience Needed:IA and cybersecurity architectures, concepts, principles, use cases, and standards;DoD, IC, and other federal government (e.g., NIST) policy, directives, and instructions relevant to IA and cybersecurity strategic planning and direction.Published Desired SkillsExperience with SBOM and software analysis tools such as:Dependency-TrackSyftGrypeBlack DuckSnykSonatype NexusMend.ioAnchoreFamiliarity with:Static Application Security Testing (SAST)Dynamic Application Security Testing (DAST)Malware analysisReverse engineeringCode signing validationUnderstanding of:Supply chain attacksDependency confusionTyposquattingBuild system compromiseMalicious open-source package activityExperience evaluating software vendor security maturity and secure development lifecycle practices.Knowledge of cloud-native software architectures and container security.TS/SCI with polygraph is required.
Job Posted by ApplicantPro