> Markdown version of [/jobs/ext/2634762-scrm-emerging-technology-security-analyst](https://www.wearedevelopers.com/jobs/ext/2634762-scrm-emerging-technology-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SCRM/Emerging Technology Security Analyst - **Company:** K2Share LLC - **Location:** Washington, DC, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing Security, Cyber Security, Software Engineering, Technical Data Management Systems, Data Logging, Information Technology - **Published:** August 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=aa061ee35295bde5 ## About the Role * Bachelor's degree in cybersecurity, information technology, risk management, or a related field. Equivalent experience considered in lieu of degree. * Four or more years in cybersecurity risk, third-party or vendor risk, or security compliance analysis. * Demonstrated experience performing third-party or supply chain security risk assessments and producing written risk analyses and mitigation recommendations. * Working knowledge of federal software supply chain policy - OMB M-21-30, M-22-18, and M-23-16 - and NIST SP 800-218. * Familiarity with the NIST AI Risk Management Framework and the security and governance considerations specific to AI-enabled systems. * Strong written analysis skills. This position produces recurring written deliverables reviewed by the OCISO. Preferred Qualifications * SBOM generation, ingestion, and analysis experience. * Experience with FedRAMP package review and third-party SaaS security assessment. * Experience developing AI governance intake and review workflows, including model documentation and disclosure review. * Familiarity with the FCC Covered List and covered equipment and services screening obligations. Applicants must be willing to take a drug test and submit to a credit and background investigation as part of the selection process. The U.S. government restricts access by Foreign Nationals to certain types of technology and technical data. Consequently, this posting is intended only for U.S. citizens. ## Description Support the client's Supply Chain Risk Management (SCRM) program and the security review of AI-enabled and emerging technologies. This position analyzes third-party and technology-related security risk, maintains SCRM records and documentation, identifies gaps in current SCRM practice, and provides risk analysis and secure-implementation recommendations for software, systems, and services that incorporate AI or other emerging capabilities affecting enterprise risk., * Support the operation and enhancement of the client's SCRM activities, including documentation support, stakeholder coordination, and maintenance of SCRM records. * Analyze third-party and technology-related security risks and prepare risk mitigation recommendations. * Identify gaps in current SCRM practices and recommend improvements to process, monitoring, governance, and reporting. * Support evaluation of the security posture of third-party technologies and evolving cyber risks. * Support AI security-related compliance, vulnerability, and risk activities for software, systems, services, and tools incorporating AI-enabled functions or emerging technologies. * Perform security review support and risk analysis; develop recommendations for secure implementation and governance considerations. * Coordinate with stakeholders on the security implications of emerging technical capabilities. * Support secure adoption assessments for modernization, automation, and analytics opportunities. * Apply OMB M-21-30, M-22-18, and M-23-16; NIST software supply chain security guidance; NIST SP 800-218 (Secure Software Development Framework); and the NIST AI Risk Management Framework and Playbook. * Maintain currency with emerging NIST publications on AI topics and translate them into practical review criteria. * Support compliance with the client's Secure and Trustworthy Artificial Intelligence Policy, including the written-approval workflow, required disclosures covering training data sources, learning cutoff dates and model limitations, human-oversight requirements, output review controls, and AI activity logging. ## Related Videos - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [The Avengers Initiative (Practical Ethics for Software Engineers)](https://www.wearedevelopers.com/videos/2070-the-avengers-initiative-practical-ethics-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Official Opening of WeAreDevelopers World Congress 2026](https://www.wearedevelopers.com/videos/100000-official-opening-of-wearedevelopers-world-congress-2026) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship)