Supply Chain Risk Manager

Remote: 
Full Remote
Contract: 
Work from: 

Offer summary

Qualifications:

Bachelor's degree in a relevant field., 5+ years of experience in supply chain risk management., Strong understanding of supply chain logistics and cybersecurity integrity., US Citizenship is required..

Key responsibilities:

  • Analyze and improve the organization's supply chain efficiency.
  • Conduct cyber supply chain risk assessments and manage supplier risks.
  • Develop and implement a Cyber SCRM Program and certification processes.
  • Lead a multi-disciplined team and manage budgets effectively.

General Dynamics Information Technology logo
General Dynamics Information Technology XLarge https://www.gdit.com
10001 Employees
See all jobs

Job description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

None

Clearance Level Must Be Able to Obtain:

None

Public Trust/Other Required:

MBI Full 5C (T3)

Job Family:

Cyber Security

Job Qualifications:

Skills:

Risk Management, Supply Chain, Supply Chain Logistics, Supply Chain Risk Management, Supply Chain Risks

Certifications:

None

Experience:

5 + years of related experience

US Citizenship Required:

Yes

Job Description:

GDIT is seeking a Supply Chain Risk Manager wit expertise in Supply Chain Risk Management (SCRM) activities and related methodologies.

Responsibilities:

  • Analyze organization’s supply chain, uncover inefficiencies, and establish best practices
  • Research and test new hardware or software for useability and cybersecurity integrity
  • Perform hardware and software reverse engineering
  • Write analytically and present technical information to a non-technical audience
  • Lead a multi-disciplined team effectively and efficiently
  • Manage budgets and an organization’s resources
  • Make recommendations for a company’s processes and procedures
  • Maintain a current understanding of supply chain logistics and research upcoming technologies
  • Manage cloud services and automation technologies to ensure data is secure 

Required Skills and Experience:

  • Bachelors and 5+ yrs related experience 
  • Developing a SCRM Plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of the CDC systems, system components or system services. Identifying and addressing weaknesses or deficiencies in the supply chain elements and processes
  • Developing a Cyber SCRM Program. Including defining objectives, scope, key initiatives, team roles, lines of responsibility, RACI matrix, coordinating mechanism, methodologies for performing thorough supply risk assessments to identify vulnerabilities, threats, and potential impacts on the cyber supply chain. 
  • Conducting cyber supply chain risk assessments across the enterprise to identify potential vulnerabilities, disruptions, and threats. This includes performing due diligence on proposed, new, or existing suppliers and establishing ongoing monitoring procedures to manage supplier risks effectively.
  • Evaluating current and potential cyber suppliers (software & hardware) to ensure they meet established risk management criteria. Conduct cyber threat assessments of suppliers to assess their reliability and risk level. This includes collecting relevant data on suppliers, software developers’ locations, capabilities, financial health, Foreign Ownership, Control or Influence (FOCI), foreign data retention, and potential risks (e.g., geopolitical events, natural disasters, cyber threats, current number of unaddressed CVEs). 
  • Developing a cyber supplier certification program to ensure suppliers and software developers meet the organization’s standards and requirements under federal regulations and guidelines, including OPM, White House Directives (Executive Order (EO) 14028), and NIST Special Publications (NIST 800-53 rev. 5).
  • Facilitating the evaluation of the implementation of Cyber SCRM technologies and tools. Collaborate with identifying, evaluating, and implementing technology solutions and tools necessary for effective Cyber SCRM activities. This includes database systems for managing supplier information and risk analysis tools.
  • Creating monthly communication awareness related to SCRM. Enhancing the organization's understanding and capabilities in managing supply chain risks, and promoting a culture of risk awareness across the enterprise.
  • Establishing metrics and benchmarks for evaluating the effectiveness of the eSCRM program and provide recommendations for ongoing improvements based on performance data and emerging risks. Designing dashboards and reports to communicate supply chain risk posture to key stakeholders.
  • Reporting all identified potential vulnerabilities, disruptions, and threats to the appropriate CDC office(s) within a 24 hour time period. Assisting in developing of counterfeit identification and detection training, verifying suppliers’ claims of conformance to security, product/component integrity, and validity/inspection of their genuine components (including hardware, software, and firmware). Covering available mitigation strategies and methods for reviewing and protecting development plans. 
  • Establishing and maintaining unique identification of CDC systems and critical system components for tracking through the supply chain.
  • Assisting in the development and implementation of an anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system. This includes maintaining configuration control over the system components awaiting service or repair and scanning for counterfeit system components.
  • Must have experience working at the CDC and currently supporting the CDC Attack Surface Management program.

#GDITFedHealth

The likely salary range for this position is $110,614 - $138,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

None

Telecommuting Options:

Remote

Work Location:

Any Location / Remote

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee’s date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Required profile

Experience

Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Team Leadership
  • Communication
  • Problem Solving

Risk Manager Related jobs