Supply Chain Risk Manager

Clearance Level
None
Category
Cyber Security
Location
Remote, Working from the USA
Key Skills For Success

Risk Management

Supply Chain

Supply Chain Logistics

Supply Chain Risk Management

Supply Chain Risks

REQ#: RQ201506
Public Trust: MBI Full 5C (T3)
Requisition Type: Regular
Your Impact

Own your opportunity to work alongside federal civilian agencies. Make an impact by providing services that help the government ensure the well being of U.S. citizens.

Job Description

GDIT is seeking a Supply Chain Risk Manager wit expertise in Supply Chain Risk Management (SCRM) activities and related methodologies.

Responsibilities:

  • Analyze organization’s supply chain, uncover inefficiencies, and establish best practices
  • Research and test new hardware or software for useability and cybersecurity integrity
  • Perform hardware and software reverse engineering
  • Write analytically and present technical information to a non-technical audience
  • Lead a multi-disciplined team effectively and efficiently
  • Manage budgets and an organization’s resources
  • Make recommendations for a company’s processes and procedures
  • Maintain a current understanding of supply chain logistics and research upcoming technologies
  • Manage cloud services and automation technologies to ensure data is secure 

Required Skills and Experience:

  • Bachelors and 5+ yrs related experience 
  • Developing a SCRM Plan for managing supply chain risks associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of the CDC systems, system components or system services. Identifying and addressing weaknesses or deficiencies in the supply chain elements and processes
  • Developing a Cyber SCRM Program. Including defining objectives, scope, key initiatives, team roles, lines of responsibility, RACI matrix, coordinating mechanism, methodologies for performing thorough supply risk assessments to identify vulnerabilities, threats, and potential impacts on the cyber supply chain. 
  • Conducting cyber supply chain risk assessments across the enterprise to identify potential vulnerabilities, disruptions, and threats. This includes performing due diligence on proposed, new, or existing suppliers and establishing ongoing monitoring procedures to manage supplier risks effectively.
  • Evaluating current and potential cyber suppliers (software & hardware) to ensure they meet established risk management criteria. Conduct cyber threat assessments of suppliers to assess their reliability and risk level. This includes collecting relevant data on suppliers, software developers’ locations, capabilities, financial health, Foreign Ownership, Control or Influence (FOCI), foreign data retention, and potential risks (e.g., geopolitical events, natural disasters, cyber threats, current number of unaddressed CVEs). 
  • Developing a cyber supplier certification program to ensure suppliers and software developers meet the organization’s standards and requirements under federal regulations and guidelines, including OPM, White House Directives (Executive Order (EO) 14028), and NIST Special Publications (NIST 800-53 rev. 5).
  • Facilitating the evaluation of the implementation of Cyber SCRM technologies and tools. Collaborate with identifying, evaluating, and implementing technology solutions and tools necessary for effective Cyber SCRM activities. This includes database systems for managing supplier information and risk analysis tools.
  • Creating monthly communication awareness related to SCRM. Enhancing the organization's understanding and capabilities in managing supply chain risks, and promoting a culture of risk awareness across the enterprise.
  • Establishing metrics and benchmarks for evaluating the effectiveness of the eSCRM program and provide recommendations for ongoing improvements based on performance data and emerging risks. Designing dashboards and reports to communicate supply chain risk posture to key stakeholders.
  • Reporting all identified potential vulnerabilities, disruptions, and threats to the appropriate CDC office(s) within a 24 hour time period. Assisting in developing of counterfeit identification and detection training, verifying suppliers’ claims of conformance to security, product/component integrity, and validity/inspection of their genuine components (including hardware, software, and firmware). Covering available mitigation strategies and methods for reviewing and protecting development plans. 
  • Establishing and maintaining unique identification of CDC systems and critical system components for tracking through the supply chain.
  • Assisting in the development and implementation of an anti-counterfeit policy and procedures that include the means to detect and prevent counterfeit components from entering the system. This includes maintaining configuration control over the system components awaiting service or repair and scanning for counterfeit system components.
  • Must have experience working at the CDC and currently supporting the CDC Attack Surface Management program.

#GDITFedHealth
Work Requirements
Years of Experience

5 + years of related experience

* may vary based on technical training, certification(s), or degree

Certification

Travel Required

None

Citizenship

U.S. Citizenship Required

Salary and Benefit Information

The likely salary range for this position is $110,614 - $138,000. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
View information about benefits and our total rewards program.

About Our Work

We are GDIT. A global technology and professional services company that delivers technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across over 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber and application development. Together with our customers, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans