Supply Chain Risk Management Tool Specialist SME

Posted 22 Days Ago
Be an Early Applicant
3 Locations
In-Office
Expert/Leader
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
The Supply Chain Risk Management Tool Specialist SME is responsible for managing and improving automated tools for supply chain risk analysis, compliance, and security within the Department of War's War Data Platform, while coordinating with various teams to ensure risk assessments and remediation actions are effectively implemented.
Summary Generated by Built In
Job Summary & Responsibilities

Everforth ECS is seeking a Supply Chain Risk Management Tool Specialist SME to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. Please Note: This position is contingent upon contract award.

The War Data Platform (WDP) is a key initiative within the U.S. Department of War's (DoW) AI-First strategy introduced in early 2026. The WDP separates business and financial data from operational warfighting data, aiming to accelerate the deployment of artificial intelligence (AI) on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, and supports collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts.

The Supply Chain Risk Management Tool Specialist SME serves as WDP's senior technical authority for the automated detection, tracking, and assessment of software and third-party supply chain risk across DoW information systems. This role directly sustains WDP's enterprise SCRM program by operating and continuously improving the automated tooling that underpins software component analysis, Software Bill of Materials governance, and supply chain threat visibility across the full WDP software portfolio and its classified and unclassified delivery environments.

• Provides specialized technical execution for Supply Chain Risk Management by operating and sustaining automated tooling that identifies, tracks, and assesses third-party and software supply chain risk across DoW information systems.
• Configures and operates Software Composition Analysis platforms, vulnerability intelligence services, and vendor risk management tools to detect insecure dependencies, exposed libraries, and high-risk components embedded within mission applications.
• Analyzes Software Bills of Materials to validate component provenance, licensing constraints, dependency relationships, and exposure to known or emerging threats.
• Correlates supply chain findings with vulnerability databases, threat intelligence feeds, and government advisories to support timely risk identification and prioritization.
• Maintains continuous visibility into supply chain posture by monitoring alerting pipelines, ingestion workflows, and tool integrations with security operations and vulnerability management platforms.
• Coordinates with development teams, system owners, and cybersecurity engineers to validate findings, document mitigation actions, and support remediation planning.
• Produces technical reports, assessment artifacts, and data inputs supporting Risk Management Framework authorization activities, supply chain risk reviews, and leadership briefings.
• Supports audit readiness by maintaining traceable evidence, tool outputs, and analytical summaries within approved repositories.
• Advances program values of transparency, defensibility, and mission resilience by strengthening automated detection of supply chain threats and improving confidence in software and vendor dependencies.
• Performs other duties as assigned.

Preferred Qualifications

• Current Secret security clearance with the ability to obtain and maintain a Top Secret (TS) security clearance with Sensitive Compartmented Information (SCI).
• A minimum of 12 years of experience in cybersecurity, supply chain risk management, or a closely related discipline within a federal, defense, or intelligence community environment, with demonstrated senior-level expertise in software supply chain risk analysis, automated SCRM tooling operations, and Software Bill of Materials governance across enterprise-scale government or defense programs.
• Active IAM Level I certification, satisfied by one of the following: CompTIA Security+ CE, ISC² CAP, ISC² SSCP, or GIAC GSLC.
• Demonstrated hands-on experience configuring and operating Software Composition Analysis platforms, vulnerability intelligence services, and vendor risk management tools, including the ability to design and maintain automated ingestion workflows, alerting pipelines, and tool integrations with SIEM, vulnerability management, and security operations platforms in classified and unclassified environments.
• Proven ability to analyze and interpret Software Bills of Materials at an enterprise scale — including transitive dependency mapping, component provenance validation, licensing risk identification, and correlation with government vulnerability databases, threat intelligence feeds, and national security advisories — to produce defensible, audit-ready risk assessments supporting RMF authorization activities.
• Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
• Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).

Skills Required

  • Minimum 12 years of experience in cybersecurity or supply chain risk management
  • Current Secret security clearance with ability to obtain Top Secret clearance
  • Active IAM Level I certification
  • Experience with Software Composition Analysis platforms and vendor risk tools
  • Ability to analyze Software Bills of Materials

ECS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.

  • Healthcare Strength ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
  • Retirement Support A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
  • Parental & Family Support Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.

ECS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fairfax, VA
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Jobs

Wells Fargo Logo Wells Fargo

Personal Banker Denbigh Branch

Fintech • Financial Services
Hybrid
Newport News, VA, USA
205000 Employees
Hybrid
Vinton, VA, USA
205000 Employees

Wells Fargo Logo Wells Fargo

Operations Coordinator

Fintech • Financial Services
Hybrid
Reston, VA, USA
205000 Employees
Hybrid
Woodbridge, VA, USA
205000 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account