Supply Chain Risk Management (SCRM) Lead
On-siteFalls Church, Virginia, United States
Job Summary
Develop and implement supply chain risk management programs assessing and mitigating risks from third-party vendors, commercial software, and supply chain dependencies. Coordinate vendor security assessments, establish SCRM policies, and interface with contracting and acquisition teams on security requirements. Manage 30-80 third-party vendor relationships requiring security assessment, conducting 20-40 vendor security assessments annually and reviewing 50-150 commercial software products for supply chain risk. Analyze software composition and third-party dependencies, develop 5-15 SCRM policies and procedures, and monitor vendor security posture for changes and incidents. Support comprehensive cybersecurity operations for the Advana platform across three classified networks (NIPR, SIPR, JWICS).
Required Qualifications
- Clearance: Secret (NIPR), Top Secret (SIPR), or TS/SCI Eligible (JWICS) based on network assignment
- Bachelor's Degree in Information Technology, Cybersecurity, Computer Science, or related field
- 10+ years cybersecurity
- 3+ years supply chain risk management or third-party risk
- CISSP required
- U.S. Citizen required
- On-premises work required at Suffolk Building, Falls Church, VA
- No remote work options available
- Standard business hours with operational flexibility
- Understanding of supply chain security threats
- Understanding of vendor risk assessment methodologies
- Understanding of Software Composition Analysis
- Understanding of NIST 800-161
Desired Qualifications
- CISM, CRISC, or procurement certifications desired
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.