SME SCRM Policy & Compliance Analyst

Leidos Holdings Inc

Gaithersburg, MD

JOB DETAILS
SKILLS
Access Control, Artificial Intelligence (AI), Auditing, CISA - Certified Information Systems Auditor, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Communication Skills, CompTIA Security+, Configuration Management, Continuous Improvement, Contract Management, Contract Review, Data Analysis, Data Recovery, Defense Federal Acquisition Regulations Supplement (DFARS), Documentation, Emerging Technology, External Audit, Federal Contracts, Government, Government Contracts, Information Technology & Information Systems, Internet Security, Legal, Maintain Compliance, Operational Strategy, Organizational Skills, Policy Analysis, Procurement Management, Product Planning, Purchasing/Procurement, Regulatory Compliance, Risk, Risk Management, Section 508, Security Clearance, Security Compliance, Sensitive Compartmented Information (SCI), Standard Operating Procedures (SOP), Supply Chain, Supply Chain Management, Support Documentation, Top Secret Clearance, Traceability, U.S. National Institute of Standards and Technology (NIST), United States Department of Defense (DoD)
LOCATION
Gaithersburg, MD
POSTED
30+ days ago

In this role, you will work alongside government partners, engineers, and other industry teammates to translate operational and strategic requirements into scalable, production-ready solutions. You will contribute directly to product planning, execution, and continuous improvement-helping ensure capabilities are delivered efficiently, aligned to mission priorities, and positioned for sustained success. This position offers the opportunity to work on a high-visibility, enterprise program at the intersection of data, analytics, and emerging AI technologies. Ideal candidates are motivated by mission impact, comfortable operating in complex stakeholder environments, and interested in building deep domain expertise while delivering capabilities with real-world national security outcomes. Primary Responsibilities: Develop, maintain, and govern Supply Chain Risk Management (SCRM) policies, Standard Operating Procedures (SOPs), templates, and documentation to ensure consistent enterprise-wide implementation. Ensure program compliance with federal and DoD requirements including DFARS 252.204-7012, EO 14028, and NIST SP 800-171. Maintain and update risk registers, traceability matrices, and compliance documentation to support audits, assessments, and contract reviews. Coordinate with contracting, cybersecurity, and acquisition teams to ensure supply-chain requirements are integrated into procurement actions and adhered to throughout the vendor lifecycle. Support the Government in performing all auditing and audit reporting to external independent public auditors in support of an annual SOC1 audit, including preparation of the SOC1 Report. Prepare and update various compliance and security documents such as Access Control, Audit and Accountability Plan, Backup and Recovery, Change and Configuration Management Plan, and others as needed. Basic Qualifications: Top Secret with SCI eligibility security clearance Bachelors degree in a related field such as Information Technology, Cybersecurity, Supply Chain Management, or a related discipline. Minimum of 12 years of experience in cyber supply chain risk management, cybersecurity compliance, or a related field. Knowledge of federal and DoD requirements including DFARS 252.204-7012, DoDI 5200.44, EO 14028, and NIST SP 800-161. Experience with developing and maintaining SCRM policies, SOPs, and compliance documentation. Strong understanding of audit processes and experience in supporting audits and assessments. Excellent communication and coordination skills to work with contracting, cybersecurity, and acquisition teams. Certifications in Cybersecurity like Security plus, CISM Preferred Qualifications: Active TS/SCI Masters degree in Information Technology, Cybersecurity, Supply Chain Management, or a related discipline. Certifications such as CISSP, CISM, or CISA. Experience with SOC1 audits and preparing SOC1 Reports. Familiarity with Section 508 compliance requirements for Information and Communication Technology (ICT) products. Experience in managing travel and purchasing processes in a multi-tenant stakeholder environment. * Previous experience working with federal or DoD contracts and understanding of the procurement lifecycle. If youre looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. Were not hiring followers. Were recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. Were already at step 30 - and moving faster than anyone else dares. Original Posting: For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About the Company

L

Leidos Holdings Inc

SAIC is a premier Fortune 500® technology integrator driving our nation's digital transformation. Our robust portfolio of offerings across the defense, space, civilian, and intelligence markets includes secure high-end solutions in engineering, IT modernization, and mission solutions. Using our expertise and understanding of existing and emerging technologies, we integrate the best components from our own portfolio and our partner ecosystem to deliver innovative, effective, and efficient solutions that are critical to achieving our customers' missions. We are a team of 26,000 strong driven by mission, united purpose, and inspired by opportunity. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.1 billion. For more information, visit saic.com.
COMPANY SIZE
10,000 employees or more
INDUSTRY
Computer/IT Services
FOUNDED
2013
WEBSITE
https://jobs.saic.com/