PeopleTec

System Security Engineer Cyber-Supply Chain Risk Management

PeopleTec$100K — $120K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of relevant experience, preferably in defense or aerospace sectors.
  • Proficiency in C-SCRM practices and methodologies.
  • Familiarity with SPDX/CycloneDX, Software Composition Analysis (SCA), SAST/DAST, and VEX.
  • Must meet DoDI 8140.03 requirements in either Secure Software Assessor or Security Architect role at 'Intermediate' level.
  • Strong knowledge of compliance standards and defense requirements.
  • Excellent communication and presentation skills for stakeholder engagement.
  • Ability to thrive within and lead multidisciplinary teams.

Responsibilities

  • Provide technical support and security engineering for C-SCRM across the system lifecycle.
  • Manage Software Bills of Materials (SBOMs) for procured and open-source software.
  • Conduct in-depth vulnerability analysis and provenance verification on third-party libraries.
  • Establish SCA and SAST requirements during vendor onboarding.
  • Maintain documentation including SBOMs and third-party software vulnerability reports.
  • Ensure C-SCRM process compliance with industry standards.
  • Coordinate C-SCRM objectives with internal teams and external organizations.
  • Prepare and present C-SCRM findings and improvement plans to senior management.

Benefits

  • Opportunity to work within a multidisciplinary team environment.
  • Engagement with high-level stakeholders and decision-makers.
  • Support for professional growth with technical expertise and guidance.
  • Exposure to advanced security engineering practices in a defense context.
  • Travel opportunities, which may enrich professional experience.
Full Job Description
Opportunity

PeopleTec is currently seeking a System Security Engineer Cyber-Supply Chain Risk Management (C-SCRM) to support our Huntsville, AL location.

 

The candidate will serve as a System Security Engineer Cyber-Supply Chain Risk Management (C-SCRM) within a Project Management Office (PMO) within PAE Fires and will be responsible for providing technical support to the program's Chief Engineer and the Technical Chief. The candidate will secure the software supply chain by analyzing third-party code, dependencies, and build processes for vulnerabilities and malicious logic before integration across the system lifecycle (design, development, acquisition, integration, testing, fielding, and sustainment). The candidate will prepare and present C-SCRM findings, reports, and improvement plans to senior management and stakeholders. Will work within a multidisciplinary security and engineering team to achieve program goals. Perform other tasks as assigned by the Chief Engineer and/or Technical Chief. 

 

The candidate will be required to interface with internal PMs across PAE Fires and external organizations to include HQDA, ASA(ALT), JIATF 401, ATEC, AMCOM, and others for coordination and synchronization of C-SCRM technical and programmatic objectives. 

 

Duties:

  • Provide technical support and security engineering in C-SCRM across the system lifecycle (design, development, acquisition, integration, testing, fielding, and sustainment). 
  • Mandate and manage Software Bills of Materials (SBOMs) for all procured and open-source software. 
  • Perform deep-dive vulnerability analysis and code provenance checks on third-party libraries. 
  • Establish Software Composition Analysis (SCA) and Static Analysis (SAST) requirements within vendor onboarding. 
  • Develop and maintain the Consolidated Program Software Bill of Materials (SBOM), Third-Party Software Vulnerability Reports, and Supplier Secure Software Attestation Forms. 
  • Ensure compliance with defense and industry standards by managing C-SCRM processes effectively. 
  • Interface with internal teams and external organizations to coordinate C-SCRM objectives and strategies. 
  • Prepare and present C-SCRM findings, reports, and improvement plans to senior management and stakeholders. 
  • Conduct strategic planning and coordination to support program objectives. 
  • Provide technical expertise to support peer engineers within the Technology Security, Program Protection, Cyber Security, and Technical Management teams. 
  • Use digital tools and methodologies to analyze supply chain risks, manufacturer/supplier relationships, and foreign ownership and controlling influence. 
  • Perform other tasks as assigned by the Chief Engineer and/or Technical Chief. 
Qualifications

Required Skills/Experience:

  • 5+ years of relevant experience. Additional education may be substituted for years of experience. 
  • Demonstrated experience in C-SCRM, particularly within defense or aerospace industries. 
  • Knowledge of SPDX/CycloneDX, Software Composition Analysis (SCA), SAST/DAST, VEX, and FIPS 140-3 validation. 
  • Must meet minimum DoDI 8140.03 Defense Cyber Workforce qualification requirements in one of the following work roles: 622 (Secure Software Assessor) at the "Intermediate" level, or 652 (Security Architect) at the "Intermediate" level. 
  • Strong knowledge of industry standards and defense requirements. 
  • Excellent communication and presentation skills. 
  • Ability to lead and work within a multidisciplinary team. 
  • Previous experience working in a U.S. Government Program Office (required). 
  • Travel: 25%
  • Must be a U.S. Citizen
  • An active DoD Secret clearance is required to perform this work. Candidates are required to have an active Secret clearance upon hire, and the ability to maintain this level of clearance during their employment.

 

Education Requirements:

  • Bachelor's degree in Computer Science, Engineering, or a related technical discipline

Desired Skills:

  • Top Secret clearance preferred
  • DoDI 8140.03 qualification at the "Advanced" level for work role 622 (Secure Software Assessor) or 652 (Security Architect)

About PeopleTec

PeopleTec, Inc. is a defense contractor that provides engineering and technical services to the United States Department of Defense and other government agencies. The company was founded in 2005 and is headquartered in Huntsville, Alabama. PeopleTec specializes in systems engineering, cybersecurity, and software development. The company has received numerous awards for its work, including the 2019 North Alabama Better Business Bureau Torch Award for Ethics and the 2018 Huntsville/Madison County Chamber of Commerce Small Business of the Year Award. PeopleTec has a strong commitment to giving back to the community and supports a variety of charitable organizations.
Learn more about PeopleTec
Size
500 employees
Industry
Net Income
$10 million
Founded
2005
5 Year Trend
+20%
Revenue
$100 million

Similar Jobs

More Jobs at PeopleTec

More Aerospace & Defense Jobs

Find similar System Security Engineer Cyber-Supply Chain Risk Management jobs: