SCRM/Emerging Technology Security Analyst
K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.
Our four core values define how we show up every day:
- Respect Others - We lead with respect, building trust and connection.
- Internally Driven - We are relentlessly compelled to accomplish our objectives.
- Collaborative Innovation - We create by listening, sharing, and working together.
- Client Success - We hold our clients' mission as our own.
We believe in people who are accountable, curious, and motivated to make an impact that matters.
Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.
Position Summary
Support the client’s Supply Chain Risk Management (SCRM) program and the security review of AI-enabled and emerging technologies. This position analyzes third-party and technology-related security risk, maintains SCRM records and documentation, identifies gaps in current SCRM practice, and provides risk analysis and secure-implementation recommendations for software, systems, and services that incorporate AI or other emerging capabilities affecting enterprise risk.
Key Responsibilities
- Support the operation and enhancement of the client’s SCRM activities, including documentation support, stakeholder coordination, and maintenance of SCRM records.
- Analyze third-party and technology-related security risks and prepare risk mitigation recommendations.
- Identify gaps in current SCRM practices and recommend improvements to process, monitoring, governance, and reporting.
- Support evaluation of the security posture of third-party technologies and evolving cyber risks.
- Support AI security-related compliance, vulnerability, and risk activities for software, systems, services, and tools incorporating AI-enabled functions or emerging technologies.
- Perform security review support and risk analysis; develop recommendations for secure implementation and governance considerations.
- Coordinate with stakeholders on the security implications of emerging technical capabilities.
- Support secure adoption assessments for modernization, automation, and analytics opportunities.
- Apply OMB M-21-30, M-22-18, and M-23-16; NIST software supply chain security guidance; NIST SP 800-218 (Secure Software Development Framework); and the NIST AI Risk Management Framework and Playbook.
- Maintain currency with emerging NIST publications on AI topics and translate them into practical review criteria.
- Support compliance with the client’s Secure and Trustworthy Artificial Intelligence Policy, including the written-approval workflow, required disclosures covering training data sources, learning cutoff dates and model limitations, human-oversight requirements, output review controls, and AI activity logging.