NextPath Jobs

Enterprise Risk Analyst

True Anomaly · Denver, CO or Long Beach, CA or Washington, DC or SF Bay Area

Posted 2026-04-24 · Verified live 2026-09-18

See how your real experience scores against this role — our AI drafts an honest, verifiable resume tailor. Nothing invented, ever. You approve everything.

Get matched — join the waitlist Apply on company site ↗

About this role

<p>Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.</p>

<p><u>OUR MISSION</u></p>

<p>True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.</p>

<p><u>OUR VALUES</u></p>

<ul>

<li><strong>Be the offset.</strong>&nbsp;We create asymmetric advantages with creativity and ingenuity.</li>

<li><strong>What would it take?</strong>&nbsp;We challenge assumptions to deliver ambitious results.</li>

<li><strong>It’s the people.</strong>&nbsp;Our team is our competitive advantage and we are better together.</li>

</ul><p><strong>Your Mission</strong>&nbsp;</p>

<p>We are seeking a driven and detail-oriented Enterprise Risk Analyst to support two distinct but interconnected lines of effort: Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role in executing risk assessments,&nbsp;maintaining&nbsp;program documentation, tracking remediation activities, and building the data foundation that powers executive-level risk decision-making.&nbsp;</p>

<p>This role is ideal for a mid-career risk professional who is fluent in frameworks such as NIST RMF and CMMC, is developing practical experience with risk quantification methodologies like FAIR and&nbsp;OCTAVE, and&nbsp;is eager to grow within a fast-paced aerospace and defense SaaS environment. You will work closely with engineering, security, legal, compliance, and operations teams to help&nbsp;identify, document, and track risk across the enterprise and its third-party supply chain.&nbsp;</p>

<p>&nbsp;</p>

<p><strong>Responsibilities:</strong></p>

<p>&nbsp;</p>

<p><strong>Enterprise Risk Management</strong>&nbsp;</p>

<ul>

<li>Support the design, execution, and continuous improvement of the enterprise risk management program under the direction of the Senior Enterprise Risk Manager.&nbsp;</li>

</ul>

<ul>

<li>Assist&nbsp;in conducting structured risk assessments using OCTAVE or similar threat-and-asset-centric methodologies, documenting findings, threat profiles, and recommended mitigations.&nbsp;</li>

</ul>

<ul>

<li>Support the application of FAIR&nbsp;methodology&nbsp;to help quantify risks in financial terms and contribute to risk prioritization analyses for leadership.&nbsp;</li>

</ul>

<ul>

<li>Maintain and update the enterprise risk register, ensuring accuracy of risk ratings, ownership assignments, remediation status, and residual risk tracking.&nbsp;</li>

</ul>

<ul>

<li>Build and&nbsp;maintain&nbsp;program dashboards, KPI/KRI reports, and status tracking using tools such as Jira, Confluence, enterprise GRC platforms, and MS Project.&nbsp;</li>

</ul>

<ul>

<li>Assist&nbsp;with audit readiness activities including evidence collection, pre-assessment preparation, control documentation, and post-audit remediation tracking.&nbsp;</li>

</ul>

<ul>

<li>Support POA&amp;M management for IL5 and IL6 environments, tracking open items to closure and escalating blockers to the Enterprise Risk Manager.&nbsp;</li>

</ul>

<ul>

<li>Contribute to the development and maintenance of risk policies, standards, and guidelines aligned to NIST SP 800-53 Rev. 5, NIST SP 800-171, RMF, and CMMC Level 3.&nbsp;</li>

</ul>

<ul>

<li>Coordinate and track internal audit schedules, findings, and corrective action plans across business units.&nbsp;</li>

</ul>

<p><strong>Third-Party Vendor Risk Management</strong>&nbsp;</p>

<ul>

<li>Execute vendor risk assessments as part of the onboarding and periodic review lifecycle, including security questionnaire administration, documentation review, and risk scoring.&nbsp;</li>

</ul>

<ul>

</ul>

One of thousands of fresh listings refreshed nightly, built for cleared & defense careers.

Browse all jobs