Supply Chain Risk Management Lead

Falls Church, VA, US • Posted 11 hours ago • Updated 11 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

🛠️ Calibrating flux capacitors...

Job Details

Skills

  • Finance
  • Collaboration
  • Security Analysis
  • WAR
  • Threat Analysis
  • DoD
  • Security+
  • Customer Engagement
  • SSCP
  • COTS
  • Mapping
  • Bill Of Materials
  • Documentation
  • Legal
  • Procurement
  • Onboarding
  • NIST SP 800 Series
  • eMASS
  • XACTA
  • Auditing
  • Risk Assessment
  • Evaluation
  • Information Security
  • Continuous Monitoring
  • Problem Solving
  • Conflict Resolution
  • Decision-making
  • Communication
  • Management
  • Security Clearance
  • Information Systems
  • CISSP
  • DevSecOps
  • Product Research
  • Regulatory Compliance
  • Reporting
  • Continuous Integration
  • Continuous Delivery
  • SIPRNet
  • JWICS
  • Risk Management Framework
  • Risk Management
  • Authorization
  • Workflow
  • Access Control
  • Machine Learning (ML)
  • Supply Chain Management
  • Open Source
  • Cloud Computing
  • Acquisition
  • Leadership
  • SAP BASIS
  • Law
  • Artificial Intelligence
  • Cyber Security
  • Partnership
  • Innovation
  • Accountability

Summary

Job Description

Everforth ECS is seeking a Supply Chain Risk Management Lead to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon contract award.

The War Data Platform (WDP) is a key initiative within the U.S. Department of War's (DoW) AI-First strategy introduced in early 2026. The WDP separates business and financial data from operational warfighting data, aiming to accelerate the deployment of artificial intelligence (AI) on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, and supports collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts.

The Supply Chain Risk Management (SCRM) Lead SME serves as the senior enterprise authority for software and vendor supply chain risk governance across the WDP Core Integration program, directing the full lifecycle of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements, and federal cybersecurity mandates. In this role, the specialist integrates automated supply chain risk tooling, Software Bill of Materials governance, vendor security assessment programs, and threat intelligence monitoring to reduce WDP exposure to supply chain-based attacks and sustain authoritative, audit-ready risk transparency for Authorizing Officials, program leadership, and Government oversight personnel.
Leads enterprise Supply Chain Risk Management activities supporting Department of War information systems across unclassified and classified environments.
Designs and executes supply chain risk governance frameworks addressing third-party vendors, commercial software, open-source components, and external service providers throughout the system lifecycle.
Directs vendor security assessments evaluating cybersecurity posture, access controls, data handling practices, and compliance with federal and DoW requirements.
Oversees software supply chain reviews including component provenance analysis, dependency mapping, and Software Bill of Materials validation to identify exposure to compromised or high-risk suppliers.
Coordinates closely with contracting officers, acquisition teams, legal advisors, and system owners to integrate security requirements into procurement actions, vendor onboarding, and contract modifications.
Maintains risk registers documenting third-party threats, mitigation strategies, residual risk, and acceptance decisions supporting Risk Management Framework activities.
Provides advisory support to Authorizing Officials, Senior Information Security Officers, and program leadership on supply chain risk posture and emerging threat vectors.
Monitors threat intelligence, Government advisories, and industry reporting related to supply chain compromise to inform proactive mitigation actions.
Produces supply chain risk assessments, vendor security reports, and executive briefings supporting authorization decisions and continuous monitoring.
Drives consistent risk transparency, lifecycle accountability, and mission resilience by reducing exposure to supply chain-based attacks and strengthening trust in system dependencies.
Performs other duties as assigned.

Required Skills

Current Secret security clearance with the ability to obtain and maintain a Top Secret (TS) security clearance with Sensitive Compartmented Information (SCI).
15 or more years of progressive experience in cybersecurity, with demonstrated specialization in Supply Chain Risk Management, vendor risk governance, or software assurance programs supporting large-scale federal or defense information systems.
Active DoW/DoD IAM Level I baseline certification, satisfied by one of the following: CompTIA Security+ CE, ISC CAP, ISC SSCP, or GIAC GSLC.
Demonstrated experience designing and operating enterprise SCRM governance frameworks that address third-party software components - including COTS, GOTS, and open-source AI technologies - through automated vulnerability detection and scanning, component provenance analysis, and transitive dependency mapping across the full system development lifecycle.
Proven ability to create, maintain, and govern Software Bill of Materials documentation for complex software platforms, including management of SBOM artifacts across 150 or more systems with recurring authorization obligations and integration into automated ingest-time scanning pipelines.
Experience coordinating SCRM activities with contracting officers, acquisition teams, legal advisors, and system owners to embed supply chain security requirements into procurement actions, vendor onboarding agreements, and contract modification packages in compliance with DFARS , NIST SP 800-171, and applicable DoW acquisition policy.
Demonstrated experience supporting Risk Management Framework authorization activities, including generation and maintenance of supply chain risk artifacts in eMASS or Xacta, management of Plan of Action and Milestone remediation activities, and preparation of Body of Evidence packages supporting formal Government risk adjudication and audit defense.
Proven ability to develop and present supply chain risk assessments, vendor security evaluation reports, and executive briefings to Authorizing Officials, Senior Information Security Officers, and program leadership audiences in support of authorization decisions and continuous monitoring obligations.
Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).

Desired Skills

Active Top Secret (TS) security clearance with Sensitive Compartmented Information (SCI) eligibility.
Active Certified Information Systems Security Professional (CISSP) certification or equivalent advanced cybersecurity credential, consistent with DoW key personnel cybersecurity qualification standards and demonstrating expanded qualifications beyond the IAM Level I baseline requirement.
Demonstrated experience implementing automated Supply Chain Risk Management tooling within a DevSecOps delivery pipeline, including ingest-time software and container scanning, malicious code detection, multi-source product research aggregation, and automated compliance report generation integrated with CI/CD pipeline governance across NIPRNet, SIPRNet, and JWICS.
Familiarity with the DoW transition from the seven-step Risk Management Framework to the five-phase Cybersecurity Risk Management Continuum, including demonstrated ability to adapt SCRM governance frameworks, vendor assessment criteria, and authorization artifact workflows to support active, automated defense postures aligned to evolving DoW cybersecurity mandates.
Experience supporting Zero Trust Architecture implementation as it relates to supply chain risk reduction, including demonstrated ability to apply micro-segmentation, Attribute-Based Access Control, and least-privilege access enforcement to minimize lateral movement risk from compromised third-party components across multi-enclave enterprise environments.
Background supporting SCRM governance for AI/ML platform programs, including experience evaluating supply chain risk exposure associated with open-source AI models, third-party data pipelines, and commercial AI tooling integrated into classified cloud-native environments, with demonstrated ability to produce risk-informed acquisition recommendations for program leadership and Government Authorizing Officials.

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We value:
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10112MAN
  • Position Id: 3747
  • Posted 11 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Fairfax, Virginia

2d ago

Full-time

USD 62,644.00 - 89,491.00 per year

Alexandria, Virginia

Today

Full-time

USD 107,900.00 - 195,050.00 per year

Alexandria, Virginia

Today

Full-time

USD 131,300.00 - 237,350.00 per year

Alexandria, Virginia

Today

Full-time

USD 131,300.00 - 237,350.00 per year

Search all similar jobs