Cybersecurity Supply Chain Risk Management (C-SCRM) Subject Matter Expert

Remote • Posted 1 hour ago • Updated 1 hour ago
Full Time
No Travel Required
Remote
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

📋 Comparing job requirements...

Job Details

Skills

  • C SCRM
  • ERMM
  • NIST
  • OMB/EO
  • QUANTUM CRYPTOGRAPHY
  • Top secret clearance with SCI eligible
  • Supply chain risk
  • Cybersecurity
  • NIST SP 800

Summary

InterSec is hiring a C-SCRM Subject Matter Expert to support a GSA Federal Acquisition Service (FAS) engagement. This role helps mature the agency''s Cyber Supply Chain Risk Management program from a compliance based model into a proactive, enterprise wide, risk informed capability. You will serve as Key Personnel, leading framework standardization, vendor risk assessment improvements, and Post Quantum Cryptography (PQC) readiness analysis for the agency''s C SCRM Service Center.

What You''ll Do

  • Lead development of a standardized, enterprise wide C SCRM Risk Assessment Framework aligned to NIST SP 800 161 Rev. 1
  • Contribute to the C SCRM Strategy and Implementation Plan, including governance approach and a phased roadmap
  • Advise on Post Quantum Cryptography readiness for the acquisition marketplace, including cryptographic bill of materials (CBOM) concepts and vendor cryptographic posture assessment
  • Evaluate current vendor and entity risk assessment processes (ownership, foreign influence, cybersecurity posture, criticality, prohibited sources) and recommend improvements
  • Improve C SCRM documentation practices, including templates, naming conventions, and version control
  • Review and enhance the existing C SCRM questionnaire and develop scoring metrics
  • Support project execution and develop guidance materials for Category Managers, Contracting Officers, and customer agencies
  • Coordinate with agency PQC migration leads, the CIO office, and federal partners such as NIST and CISA

What You''ll Need

  • 3+ years building or maturing a risk management program, including C SCRM
  • Experience across supply chain risk domains: framework design, vendor and entity risk assessment, risk documentation and reporting
  • CISSP, CISM, or CRISC certification
  • Working knowledge of NIST SP 800 161 Rev. 1 and federal C SCRM policy drivers (Section 889, FASCSA, EO 14028)
  • Active Top Secret clearance with SCI eligibility, or ability to obtain SCI eligibility promptly
  • Strong written and oral communication skills, with the ability to work independently on complex, ambiguous problems

Nice to Have

  • Familiarity with Post Quantum Cryptography transition guidance (NIST PQC standards, OMB/EO direction) and supply chain implications
  • Experience applying AI or automation to risk assessment, monitoring, or compliance workflows
  • Prior support of a GSA, DoD, or intelligence community C SCRM, ERM, or acquisition program
  • Experience developing training curricula or federal acquisition workforce guidance
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91120868
  • Position Id: 9058704
  • Posted 1 hour ago

Company Info

About InterSec Inc.

Founded in 2013, as one of the boutique cybersecurity providers, InterSec, Inc. employs continuous cyber innovation, sophisticated tradecraft, and top talent to deliver results. Our diverse clients span Commercial, State, and Federal agencies. Our deep cyber and industry expertise is earned through hands-on experience, from Cybersecurity Program setup to Operational Security. In a time where the profound impact of information technology is almost impossible to comprehend, we are cognizant of ever-increasing cybersecurity risks of the connected world and is equipped with the required expertise to provide a full range of cybersecurity services including program management, governance, cybersecurity, and risk management to its Federal, State, and Commercial customers. Our cyber security services meet mission critical objectives in a secure and compliant manner.

About_Company_One
Contact the job poster
NJ

Nicayla Javer

Recruiter @ InterSec Inc.
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs