Haystack
← Back to Jobs
Full time
Administrative
MA

Acquisition Security Risk Analyst

MANTECHQuantico, Virginia🇺🇸United StatesPosted Oct 2, 2026

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Quantico, Virginia, United States

Job Description

MANTECH seeks a motivated, career and customer-oriented Acquisition Security Risk Analyst to support our USMC contract out of Quantico, VA.


The Acquisition Security Risk Analyst will serve as a strategic author and systems security architect capable of conceptualizing, structuring, and authoring an enterprise-grade Acquisition Security Risk Posture Guide to weave disparate risk domains into a cohesive operational framework across the acquisition lifecycle.


Job Responsibilities include but are not limited to:

  • Authoring an enterprise-grade Acquisition Security Risk Posture Guide that integrates Critical Program Information (CPI), Criticality Analysis, SCRM/C-SCRM, Counterintelligence, and System Security Engineering.
  • Translating complex defense acquisition mandates into practical playbooks, decision trees, and operational risk frameworks for Program Managers, Chief Engineers, and Security Officers.
  • Mapping Mission-Critical Functions (MCFs) and Mission-Critical Components (MCCs) down to hardware, firmware, and software to support robust Criticality Analysis workflows.
  • Structuring supplier risk tiers, provenance verification, and Software/Hardware Bill of Materials (SBOM/HBOM) governance into acquisition milestones.
  • Incorporating Anti-Tamper, microelectronics trust, and hardware assurance measures to safeguard against reverse engineering, counterfeit parts, and physical exploitation.
  • Integrating Critical Program Information (CPI) protection, horizontal protection workflows, and supply chain threat feeds into acquisition milestone decisions.
  • Aligning contractor network compliance standards, such as DFARS , NIST SP 800-171, and CMMC, with delivered product security and enterprise risk frameworks.

Mandatory Qualifications:

  • Bachelor's degree with at least 5 years of experience in System Security Engineering, Program Protection, or Supply Chain Risk Management. An additional 2 years of experience may be substituted in lieu of degree.
  • Demonstrated experience authoring program protection guidance, governance playbooks, or enterprise security frameworks within defense acquisition pathways.
  • Deep knowledge of DoD acquisition policies including DoDI 5000.83, DoDI 5200.44, DoDI 5200.39, and DoDI 5000.90.
  • Strong familiarity with federal supply chain standards, including NIST SP 800-161 Rev. 1, NIST SP 800-160 Vols. 1 & 2, and NIST SP 800-53 Rev. 5.
  • Experience integrating Critical Program Information (CPI) identification, Counterintelligence (CI) feeds, and foreign ownership/influence (FOCI) regulations into risk mitigation strategies.
  • Proven ability to design assessment rubrics and scoring models to evaluate vendor security postures and analyze risk data, (e.g SBOM/HBOM).

Preferred Qualifications:

  • Certified Information Systems Security Professional (CISSP), Certified Authorization Professional (CAP), or related DoD 8570/8140 IAM Level II/III certifications.
  • Hands-on experience working within the Adaptive Acquisition Framework (AAF) pathways and applying the DoD Risk, Issue, and Opportunity (RIO) Management Guide.
  • Familiarity with microelectronics trust requirements, NDAA Section 889 compliance, and Federal Acquisition Security Council (FASC) exclusion guidelines.
  • Self-starter with exceptional technical authoring skills and the ability to collaborate across multidisciplinary engineering and program management teams.

Security Clearance Required:

  • Must have a current / active DoW Top Secret / SCI

Physical Requirements:

  • Sedentary work

Similar jobs