Description: RemoteLead the design and implementation planning for our client's Enterprise Open Source Management Program and software supply chain security strategy. Operate across Cyber Security, Software Engineering, DevOps, Asset Management, Architecture, and Technology teams to define the program's operating model, governance framework, roadmap, staffing strategy, budget requirements, and implementation approach. This senior individual contributor will drive enterprise capabilities that improve visibility, governance, and risk management for open source software, libraries, packages, containers, and related development artifacts.
Due to client requirements, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.Rate: $85.00 to $95.00/hr. w2
Responsibilities: - Lead the design and development of an Enterprise Open Source Management Program, including governance, operating model, scope, roadmap, and implementation strategy.
- Facilitate collaboration among Cyber Security, Software Engineering, DevOps, Asset Management, Architecture, Risk Management, and related teams to establish program requirements and priorities.
- Partner with stakeholders to evaluate current-state capabilities, identify gaps, and define future-state processes supporting open source governance and software supply chain security.
- Develop program proposals, business cases, staffing plans, budget estimates, and implementation roadmaps for executive review and approval.
- Define enterprise processes for open source software intake, approval, exception management, and ongoing governance activities.
- Develop recommendations for policies, standards, controls, and supporting procedures related to open source software management and software supply chain risk.
- Support development of a Software Bill of Materials (SBOM) strategy and associated processes that improve visibility into software components, dependencies, and associated risks.
- Facilitate proof-of-concept activities and pilot implementations that validate proposed processes, technologies, and operating models.
- Evaluate tooling capabilities and assist with technology assessments, vendor reviews, and solution recommendations that support program objectives.
- Partner with development teams to understand software development workflows and ensure program recommendations can be effectively integrated into existing engineering practices.
- Drive stakeholder alignment by facilitating workshops, working groups, governance forums, and executive-level discussions.
- Provide transparency and ongoing communications regarding program status, strategic recommendations, risks, dependencies, and milestones.
- Monitor industry trends, emerging threats, regulatory developments, and leading practices associated with open source software governance and software supply chain security.
- Develop educational materials, guidance, and communication artifacts that support adoption of program principles and expectations throughout the organization.
- Influence outcomes and drive decision-making without direct authority across highly matrixed teams and organizations.
Experience Requirements: - 5+ years in cybersecurity, application security, software development, technology governance, software supply chain security, DevSecOps, or related disciplines.
- Experience leading complex cross-functional initiatives with multiple stakeholder groups and competing priorities.
- Ability to operate effectively in ambiguous environments and translate strategic objectives into actionable implementation plans.
- Strong written and verbal communication skills, including executive presentations, business cases, and strategic recommendations.
- Ability to influence outcomes and drive decisions without direct management authority.
- Understanding of SDLC practices and modern software delivery methodologies.
Education Requirements: Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Business, or related field, or equivalent combination of education and experience.
Recruitment Transparency NoticeEliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team (, ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process.Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.
W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.If you have any indication of fraudulent activity, please contact .About Eliassen Group:Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!