Supply Chain Risk Management Lead

Reposted 8 Days Ago
Be an Early Applicant
3 Locations
In-Office
Expert/Leader
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
The Supply Chain Risk Management Lead is responsible for overseeing risk governance for software and vendor supply chains, integrating automated tools, assessing vendor security, and ensuring compliance with cybersecurity policies across classified and unclassified environments.
Summary Generated by Built In
Job Summary & Responsibilities

Everforth ECS is seeking a Supply Chain Risk Management Lead to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. Please Note: This position is contingent upon contract award.

The War Data Platform (WDP) is a key initiative within the U.S. Department of War's (DoW) AI‑First strategy introduced in early 2026. The WDP focuses on operational warfighting data and aims to accelerate the deployment of artificial intelligence (AI) on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, and supports collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts. 

• The Supply Chain Risk Management (SCRM) Lead SME serves as the senior enterprise authority for software and vendor supply chain risk governance across the WDP Core Integration program, directing the full lifecycle of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements, and federal cybersecurity mandates. In this role, the specialist integrates automated supply chain risk tooling, Software Bill of Materials governance, vendor security assessment programs, and threat intelligence monitoring to reduce WDP exposure to supply chain-based attacks and sustain authoritative, audit-ready risk transparency for Authorizing Officials, program leadership, and Government oversight personnel.
• Leads enterprise Supply Chain Risk Management activities supporting Department of War information systems across unclassified and classified environments.
• Designs and executes supply chain risk governance frameworks addressing third-party vendors, commercial software, open-source components, and external service providers throughout the system lifecycle.
• Directs vendor security assessments evaluating cybersecurity posture, access controls, data handling practices, and compliance with federal and DoW requirements.
• Oversees software supply chain reviews including component provenance analysis, dependency mapping, and Software Bill of Materials validation to identify exposure to compromised or high-risk suppliers.
• Coordinates closely with contracting officers, acquisition teams, legal advisors, and system owners to integrate security requirements into procurement actions, vendor onboarding, and contract modifications.
• Maintains risk registers documenting third-party threats, mitigation strategies, residual risk, and acceptance decisions supporting Risk Management Framework activities.
• Provides advisory support to Authorizing Officials, Senior Information Security Officers, and program leadership on supply chain risk posture and emerging threat vectors.
• Monitors threat intelligence, Government advisories, and industry reporting related to supply chain compromise to inform proactive mitigation actions.
• Produces supply chain risk assessments, vendor security reports, and executive briefings supporting authorization decisions and continuous monitoring.
• Drives consistent risk transparency, lifecycle accountability, and mission resilience by reducing exposure to supply chain-based attacks and strengthening trust in system dependencies.
• Performs other duties as assigned.

Preferred Qualifications

• Current Secret security clearance with the ability to obtain and maintain a Top Secret (TS) security clearance with Sensitive Compartmented Information (SCI).
• 15 or more years of progressive experience in cybersecurity, with demonstrated specialization in Supply Chain Risk Management, vendor risk governance, or software assurance programs supporting large-scale federal or defense information systems.
• Active DoW/DoD IAM Level I baseline certification, satisfied by one of the following: CompTIA Security+ CE, ISC² CAP, ISC² SSCP, or GIAC GSLC.
• Demonstrated experience designing and operating enterprise SCRM governance frameworks that address third-party software components — including COTS, GOTS, and open-source AI technologies — through automated vulnerability detection and scanning, component provenance analysis, and transitive dependency mapping across the full system development lifecycle.
• Proven ability to create, maintain, and govern Software Bill of Materials documentation for complex software platforms, including management of SBOM artifacts across 150 or more systems with recurring authorization obligations and integration into automated ingest-time scanning pipelines.
• Experience coordinating SCRM activities with contracting officers, acquisition teams, legal advisors, and system owners to embed supply chain security requirements into procurement actions, vendor onboarding agreements, and contract modification packages in compliance with DFARS 252.204-7020, NIST SP 800-171, and applicable DoW acquisition policy.
• Demonstrated experience supporting Risk Management Framework authorization activities, including generation and maintenance of supply chain risk artifacts in eMASS or Xacta, management of Plan of Action and Milestone remediation activities, and preparation of Body of Evidence packages supporting formal Government risk adjudication and audit defense.
• Proven ability to develop and present supply chain risk assessments, vendor security evaluation reports, and executive briefings to Authorizing Officials, Senior Information Security Officers, and program leadership audiences in support of authorization decisions and continuous monitoring obligations.
• Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
• Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).

Skills Required

  • 15 or more years of progressive experience in cybersecurity, preferably in Supply Chain Risk Management
  • Current Secret security clearance with ability to obtain Top Secret clearance
  • Active DoW/DoD IAM Level I baseline certification (e.g., CompTIA Security+ CE)
  • Experience designing and operating SCRM governance frameworks
  • Ability to create and maintain Software Bill of Materials documentation
  • Experience coordinating SCRM with teams for procurement actions
  • Knowledge of Risk Management Framework authorization processes
  • Strong problem-solving and decision-making capabilities

ECS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.

  • Healthcare Strength ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
  • Retirement Support A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
  • Parental & Family Support Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.

ECS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fairfax, VA
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Jobs

Comcast Logo Comcast

Senior Software Engineer

Digital Media • Information Technology • News + Entertainment
Hybrid
Reston, VA, USA
115000 Employees

TransUnion Logo TransUnion

Site Reliability Engineer

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
6 Locations
13000 Employees
113K-188K Annually

Deepgram Logo Deepgram

Enterprise Account Executive

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
2 Locations
150 Employees
125K-150K Annually

Deepgram Logo Deepgram

Research Engineer, Machine Learning Systems

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
3 Locations
150 Employees
150K-250K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account