Why This Role Stands Out
Leverage your technical and cybersecurity expertise in a hybrid role supporting national security initiatives, where you'll gain invaluable experience in software supply chain transparency and risk analysis. This position offers significant growth potential for driven professionals passionate about safeguarding critical government systems. Apply now to contribute to vital national security efforts and advance your career.
Quick Overview
Job Description
Software Analyst supports the mission of the National Information Assurance Partnership by conducting in-depth software assurance and Software Bill of Materials (SBOM) analysis for commercial technologies seeking evaluation, authorization, or deployment within National Security Systems (NSS) and other sensitive U.S. Government environments. This role focuses heavily on software supply chain transparency, software provenance, open-source software (OSS) risk analysis, vulnerability identification, and vendor cybersecurity practices.
The analyst evaluates software components, dependencies, development practices, and third-party supplier risks to identify potential threats to the confidentiality, integrity, and availability of government systems. The position requires strong technical analysis, cybersecurity knowledge, and the ability to assess software ecosystems from both a security and supply chain perspective.
Key Responsibilities
- Conduct Software Bill of Materials (SBOM) analysis on commercial software products, platforms, and applications undergoing evaluation or review.
- Analyze software dependencies, transitive dependencies, and third-party libraries to identify supply chain risks and hidden software exposure.
- Review and validate SBOM formats and standards including:
- SPDX
- CycloneDX
- SWID tags
- Assess software provenance, code lineage, package integrity, and software component authenticity.
- Identify known vulnerabilities and software weaknesses through:
- CVE analysis
- KEV review
- Vulnerability databases
- Threat intelligence sources
- Evaluate risks associated with:
- Open-source software (OSS)
- Foreign-developed software components
- Unsupported or end-of-life dependencies
- Unmaintained libraries
- Software obfuscation or lack of transparency
- Perform secure software supply chain assessments aligned with:
- NIST SSDF
- Executive Order 14028
- Federal software assurance guidance
- NIAP protection profile requirements
- Conduct due diligence research on software vendors, developers, maintainers, and software ecosystems.
- Analyze vendor secure development practices including:
- Secure coding methodologies
- Build pipeline security
- CI/CD protections
- Dependency management
- Patch management
- Code signing
- Review software development and deployment architectures for potential supply chain attack vectors.
- Support Common Criteria evaluations and software assurance activities through technical risk analysis and supply chain assessments.
- Produce technical reports, analytical findings, risk summaries, and executive-level briefings related to software supply chain security.
- Collaborate with government, industry, evaluation labs, and cybersecurity stakeholders to improve software assurance practices and SBOM utilization.
- Monitor emerging software supply chain threats, malware campaigns, dependency compromise incidents, and malicious package activity. Preferred Education & Certifications
- (U) Fourteen (14) years experience as a SE in programs and contracts of similar scope, type and complexity is required. Bachelor's degree in System Engineering, Computer Science, Information Systems, Engineering Science, Engineering Management, or related discipline from an accredited college or university is required. Five (5) years of additional SE experience may be substituted for a bachelor's degree.
- Preferred certifications may include:
- CISSP
- CSSLP
- Security+
- GIAC certifications
- Certified SCRM Professional
- Cloud security certifications Application security certifications Published Required Skills
- Experience in software supply chain security, cybersecurity analysis, application security, or SCRM.
- Strong understanding of:
- Software Bills of Materials (SBOMs)
- Open-source software ecosystems
- Software composition analysis (SCA)
- Vulnerability management
- Secure software development
- Familiarity with:
- Common Criteria
- NIAP evaluation concepts
- NIST cybersecurity guidance
- Federal software security initiatives
- Knowledge of software package managers and ecosystems such as: * npm
- PyPI
- Maven
- NuGet
- GitHub repositories
- Ability to analyze complex software dependency structures and identify risk indicators.
- Experience writing technical analytical reports and communicating findings to technical and non-technical audiences.
LCAT Domain Experience Needed
- IA and cybersecurity architectures, concepts, principles, use cases, and standards;
- Experience with SBOM and software analysis tools such as:
- Dependency-Track
- Syft
- Grype
- Black Duck
- Snyk
- Sonatype Nexus
- Mend.io
- Anchore
- Familiarity with:
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Malware analysis
- Reverse engineering
- Code signing validation
- Understanding of:
- Supply chain attacks
- Dependency confusion
- Typosquatting
- Build system compromise
- Malicious open-source package activity
- Experience evaluating software vendor security maturity and secure development lifecycle practices.
- Knowledge of cloud-native software architectures and container security. TS/SCI with polygraph is required. Apply now How would you like to verify your identity? Continue with phoneVerify with a one-time text code Continue with emailVerify with a one-time code Powered by iSolved Talent Acquisition
- Sign Up For Job Alerts!
- Name You must type a name. Email You must type a valid email. Location (city, state or zip code) You must select a location. Accept Terms of Service
Resume File You must select a file. Upload Resume upload later Thank you for subscribing to receive job alerts. You should start receiving emails in the next week. Your file is uploading. Please wait a few seconds. Enter your phone number if you'd like to receive job alerts for in via text message. Phone number You must type a phone number. Please indicate if you agree to Refer.io's Subscriber Communication Policy. Please indicate if you agree to Refer.io's Subscriber Communication Policy.
Select an option
Yes, I agree to be contacted by text messages
No, I do not agree to receive text messages You must agree to our Subscriber Communication Policy in order to receive text messages from Refer.io. Yes, why not? Not now Refer.io can assist in your job search. Please answer the following questions to amplify your search results. Education status
Education status
In School
Graduated
Never Attended
Partially completed You must select an education status answer. Work status
Work status
Currently employed
Out of work
Temporary job You must select a work status answer. Job search status
Job search status
Actively looking for a job
Passively looking for a job
Not looking for a job You must select a job search status answer. Seeking for
Employment goal
Similar Job to What I Do Now
Progress to a Higher Job in the Same Field
Jump to a New Field of Work You must select a seeking status answer. Job type
Job type
Full Time
Part Time
From Home You must select a job type answer. Next powered by Refer.io Refer.io Follow Us On Social Media Share This Job Hiring Software Maintained by isolved Talent Acquisition - © 2026 Refresh Search the FAQ here Go
Common Job Questions
Similar jobs
- VA
Senior AI Software Engineer (TS/SCI) - Vantor
Vantor
Herndon, VA🇺🇸$145k - $205k/yrHybrid4 days agoMicroservicesAgileC+++10Technology - VA
Senior AI Software Engineer (TS/SCI with CI Poly) - Vantor
Vantor
Herndon, VA🇺🇸$145k - $205k/yrHybrid4 days agoMicroservicesAgileC+++10Technology - LE
Principal Software Developer
NewLeidos
Gaithersburg, MD🇺🇸$131.3k - $237.3k/yrHybridYesterdayC++PythonTechnology - LE
Sr. Software Developer
Leidos
Gaithersburg, MD🇺🇸$87.1k - $157.4k/yrHybrid2 months agoAnsibleC++Perl+1Technology - LE
Software Engineer
Leidos
Chula Vista, CA🇺🇸$87.1k - $157.4k/yrHybrid1 week agoMATLABEmbedded SystemsC+++3Technology - CA
Lead Software Engineer - IBM iSeries
NewCox Automotive
Atlanta, GA🇺🇸$122.6k - $204.4k/yrHybrid2 days agoStakeholder ManagementTechnology