Cybersecurity Supply Chain Risk Management (C-SCRM) Subject Matter Expert

InterSec Inc.
Dice Job Match Score™
📋 Comparing job requirements...
Job Details
Skills
- C SCRM
- ERMM
- NIST
- OMB/EO
- QUANTUM CRYPTOGRAPHY
- Top secret clearance with SCI eligible
- Supply chain risk
- Cybersecurity
- NIST SP 800
Summary
InterSec is hiring a C-SCRM Subject Matter Expert to support a GSA Federal Acquisition Service (FAS) engagement. This role helps mature the agency''s Cyber Supply Chain Risk Management program from a compliance based model into a proactive, enterprise wide, risk informed capability. You will serve as Key Personnel, leading framework standardization, vendor risk assessment improvements, and Post Quantum Cryptography (PQC) readiness analysis for the agency''s C SCRM Service Center.
What You''ll Do
- Lead development of a standardized, enterprise wide C SCRM Risk Assessment Framework aligned to NIST SP 800 161 Rev. 1
- Contribute to the C SCRM Strategy and Implementation Plan, including governance approach and a phased roadmap
- Advise on Post Quantum Cryptography readiness for the acquisition marketplace, including cryptographic bill of materials (CBOM) concepts and vendor cryptographic posture assessment
- Evaluate current vendor and entity risk assessment processes (ownership, foreign influence, cybersecurity posture, criticality, prohibited sources) and recommend improvements
- Improve C SCRM documentation practices, including templates, naming conventions, and version control
- Review and enhance the existing C SCRM questionnaire and develop scoring metrics
- Support project execution and develop guidance materials for Category Managers, Contracting Officers, and customer agencies
- Coordinate with agency PQC migration leads, the CIO office, and federal partners such as NIST and CISA
What You''ll Need
- 3+ years building or maturing a risk management program, including C SCRM
- Experience across supply chain risk domains: framework design, vendor and entity risk assessment, risk documentation and reporting
- CISSP, CISM, or CRISC certification
- Working knowledge of NIST SP 800 161 Rev. 1 and federal C SCRM policy drivers (Section 889, FASCSA, EO 14028)
- Active Top Secret clearance with SCI eligibility, or ability to obtain SCI eligibility promptly
- Strong written and oral communication skills, with the ability to work independently on complex, ambiguous problems
Nice to Have
- Familiarity with Post Quantum Cryptography transition guidance (NIST PQC standards, OMB/EO direction) and supply chain implications
- Experience applying AI or automation to risk assessment, monitoring, or compliance workflows
- Prior support of a GSA, DoD, or intelligence community C SCRM, ERM, or acquisition program
- Experience developing training curricula or federal acquisition workforce guidance
- Dice Id: 91120868
- Position Id: 9058704
- Posted 1 hour ago
Company Info
About InterSec Inc.
Founded in 2013, as one of the boutique cybersecurity providers, InterSec, Inc. employs continuous cyber innovation, sophisticated tradecraft, and top talent to deliver results. Our diverse clients span Commercial, State, and Federal agencies. Our deep cyber and industry expertise is earned through hands-on experience, from Cybersecurity Program setup to Operational Security. In a time where the profound impact of information technology is almost impossible to comprehend, we are cognizant of ever-increasing cybersecurity risks of the connected world and is equipped with the required expertise to provide a full range of cybersecurity services including program management, governance, cybersecurity, and risk management to its Federal, State, and Commercial customers. Our cyber security services meet mission critical objectives in a secure and compliant manner.

Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs