Supply Chain Security Specialist

Vanguard Group, Inc.

$90K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of relevant work experience required.
  • Undergraduate degree or equivalent experience; graduate degree preferred.
  • 7-10+ years in AppSec, DevSecOps, or platform security.
  • Hands-on experience with Software Composition Analysis (SCA) and pipeline security.
  • Preferred certifications: CISSP, CSSLP, AAISM or equivalent.
  • Proficiency in programming/scripting languages like Python, Java, and YAML.

Responsibilities

  • Define and manage the enterprise software supply chain security strategy and roadmap.
  • Establish policies for software bill of materials (SBOM), artifact signing, and dependency usage.
  • Embed security controls throughout the software development life cycle (SDLC) and CI/CD pipelines.
  • Implement and enforce controls for SBOM generation, validation, and artifact integrity.
  • Lead risk-based vulnerability management for open-source and third-party components in collaboration with stakeholders.
  • Develop remediation workflows, SLAs, and exception handling procedures for supply chain risks.
  • Own and optimize tooling strategy for software composition analysis, container scanning, and security automation.

Benefits

  • Flexible work options and schedules.
  • Professional development opportunities.
  • Access to a diverse and inclusive work environment.
  • Comprehensive health and wellness benefits.
Full Job Description

Core Responsibilities

  • Define and own enterprise software supply chain security strategy, roadmap, and governance

  • Establish policies and guardrails for SBOM, artifact signing, provenance, and dependency usage

  • Embed security controls across SDLC, CI/CD pipelines, and artifact repositories

  • Implement and enforce SBOM generation, validation, and artifact integrity controls

  • Collaborate with stakeholders and lead risk-based vulnerability management for open-source and third‑party components

  • Collaborate with stakeholders and define remediation workflows, SLAs, and exception handling for supply chain risks

  • Own tooling strategy for SCA, container scanning, and supply chain security automation

  • Integrate and optimize security tooling within CI/CD for scalable enforcement

  • Maintain inventory and visibility of dependencies, SBOMs, and third-/fourth-party exposure

  • Partner with AppSec, DevSecOps, and platform teams to drive secure development adoption

  • Enable developers via playbooks, guardrails, and self-service secure consumption patterns

  • Define metrics and report on supply chain risk posture, remediation effectiveness, and maturity

Nice-to-Have

  • Experience with AI/ML pipeline security

  • Exposure to AIBOM / advanced SBOM evolution

  • Knowledge of zero-trust supply chain models

Qualifications

  • Minimum of five years related work experience.

  • Undergraduate degree or equivalent combination of training and experience. Graduate degree preferred.

  • 7–10+ years in AppSec / DevSecOps / platform security

  • Hands-on experience with SCA + pipeline security

  • Certifications preferred (CISSP, CSSLP, AAISM or equivalent etc.)

  • Programming/scripting (Python, Java, YAML)

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

Similar Jobs

More Jobs at Vanguard Group, Inc.

More Information Technology Jobs

Find similar Supply Chain Security Specialist jobs: