Must Have:
- Enterprise change management
- Influence/coordination across orgs
- Program design and management
- Software supply chain security, application security, open source software governance, SBOM concepts and generation, enterprise governance and operating model design, SDLC and software engineering practices, GitHub, Jenkins, Artifact, cloud environments, stakeholder management, requirements gathering, executive communications, roadmap development, budgeting and staffing planning, cross-functional leadership and influence.
Nice To Have:
Job Profile Summary:
We are seeking an experienced cybersecurity and software supply chain professional to help design and establish a new Enterprise Open-Source Management Program. This individual will work across Cyber Security, Software Engineering, DevOps, Asset Management, Architecture, and Technology teams to define the program's operating model, governance framework, roadmap, staffing strategy, budget requirements, and implementation approach.
The ideal candidate possesses a strong understanding of software supply chain security, secure software development practices, and open-source software risk management. Success in this role requires the ability to operate in ambiguous environments, influence across organizational boundaries, facilitate alignment among diverse stakeholder groups, and translate strategic objectives into actionable plans that can be implemented at enterprise scale.
This is a senior individual contributor role responsible for driving the definition and maturation of enterprise capabilities that improve visibility, governance, and risk management associated with open-source software, libraries, packages, containers, and related development artifacts.
General Function:
Responsible for defining, prioritizing, and managing the development of an Enterprise Open-Source Management Program that supports the organization's cybersecurity, risk management, and software development objectives.
Will partner with Cyber Security, Software Engineering, DevOps, Asset Management, Risk, Legal, Compliance, Architecture, and Technology leadership teams to establish a strategic roadmap and operational framework for managing open-source software across the enterprise.
Will support the identification, evaluation, and prioritization of people, process, technology, and governance capabilities necessary to create a sustainable program focused on software supply chain security, open-source governance, vulnerability management, and regulatory readiness.
Acts as a facilitator, strategist, and change agent, driving alignment among stakeholders while advancing initiatives that reduce organizational risk and improve visibility into the software ecosystem.
Essential Duties & Responsibilities:
- Lead the design and development of an Enterprise Open-Source Management Program, including governance, operating model, scope, roadmap, and implementation strategy.
- Facilitate collaboration among Cyber Security, Software Engineering, DevOps, Asset Management, Architecture, Risk Management, and related teams to establish program requirements and priorities.
- Partner with stakeholders to evaluate current-state capabilities, identify gaps, and define future-state processes supporting open-source governance and software supply chain security.
- Develop program proposals, business cases, staffing plans, budget estimates, and implementation roadmaps for executive review and approval.
- Define enterprise processes for open-source software intake, approval, exception management, and ongoing governance activities.
- Develop recommendations for policies, standards, controls, and supporting procedures related to open-source software management and software supply chain risk.
- Support development of a Software Bill of Materials (SBOM) strategy and associated processes that improve visibility into software components, dependencies, and associated risks.
- Facilitate proof-of-concept activities and pilot implementations that validate proposed processes, technologies, and operating models.
- Evaluate tooling capabilities and assist with technology assessments, vendor reviews, and solution recommendations that support program objectives.
- Partner with development teams to understand software development workflows and ensure program recommendations can be effectively integrated into existing engineering practices.
- Drive stakeholder alignment by facilitating workshops, working groups, governance forums, and executive-level discussions.
- Provide transparency and ongoing communications regarding program status, strategic recommendations, risks, dependencies, and milestones.
- Monitor industry trends, emerging threats, regulatory developments, and leading practices associated with open-source software governance and software supply chain security.
- Develop educational materials, guidance, and communication artifacts that support adoption of program principles and expectations throughout the organization.
- Influence outcomes and drive decision-making without direct authority across highly matrixed teams and organizations.
Minimum Knowledge, Skills & Abilities Required:
- Bachelor s degree in computer science, Cybersecurity, Information Systems, Engineering, Business, or a related field, or equivalent combination of education and experience.
- 5+ years of experience in cybersecurity, application security, software development, technology governance, software supply chain security, DevSecOps, or related disciplines.
- Experience leading complex cross-functional initiatives involving multiple stakeholder groups and competing priorities.
- Demonstrated ability to operate effectively in ambiguous environments and transform high-level objectives into actionable implementation plans.
- Strong written and verbal communication skills, including experience developing executive presentations, business cases, and strategic recommendations.
- Ability to influence outcomes and drive decisions across organizations without direct management authority.
- Understanding software development lifecycle (SDLC) practices and modern software delivery methodologies.