OpportunityPeopleTec is currently seeking a System Security Engineer Cyber-Supply Chain Risk Management (C-SCRM) to support our Huntsville, AL location.
The candidate will serve as a System Security Engineer Cyber-Supply Chain Risk Management (C-SCRM) within a Project Management Office (PMO) within PAE Fires and will be responsible for providing technical support to the program's Chief Engineer and the Technical Chief. The candidate will secure the software supply chain by analyzing third-party code, dependencies, and build processes for vulnerabilities and malicious logic before integration across the system lifecycle (design, development, acquisition, integration, testing, fielding, and sustainment). The candidate will prepare and present C-SCRM findings, reports, and improvement plans to senior management and stakeholders. Will work within a multidisciplinary security and engineering team to achieve program goals. Perform other tasks as assigned by the Chief Engineer and/or Technical Chief.
The candidate will be required to interface with internal PMs across PAE Fires and external organizations to include HQDA, ASA(ALT), JIATF 401, ATEC, AMCOM, and others for coordination and synchronization of C-SCRM technical and programmatic objectives.
Duties:
- Provide technical support and security engineering in C-SCRM across the system lifecycle (design, development, acquisition, integration, testing, fielding, and sustainment).
- Mandate and manage Software Bills of Materials (SBOMs) for all procured and open-source software.
- Perform deep-dive vulnerability analysis and code provenance checks on third-party libraries.
- Establish Software Composition Analysis (SCA) and Static Analysis (SAST) requirements within vendor onboarding.
- Develop and maintain the Consolidated Program Software Bill of Materials (SBOM), Third-Party Software Vulnerability Reports, and Supplier Secure Software Attestation Forms.
- Ensure compliance with defense and industry standards by managing C-SCRM processes effectively.
- Interface with internal teams and external organizations to coordinate C-SCRM objectives and strategies.
- Prepare and present C-SCRM findings, reports, and improvement plans to senior management and stakeholders.
- Conduct strategic planning and coordination to support program objectives.
- Provide technical expertise to support peer engineers within the Technology Security, Program Protection, Cyber Security, and Technical Management teams.
- Use digital tools and methodologies to analyze supply chain risks, manufacturer/supplier relationships, and foreign ownership and controlling influence.
- Perform other tasks as assigned by the Chief Engineer and/or Technical Chief.
Qualifications
Required Skills/Experience:
- 5+ years of relevant experience. Additional education may be substituted for years of experience.
- Demonstrated experience in C-SCRM, particularly within defense or aerospace industries.
- Knowledge of SPDX/CycloneDX, Software Composition Analysis (SCA), SAST/DAST, VEX, and FIPS 140-3 validation.
- Must meet minimum DoDI 8140.03 Defense Cyber Workforce qualification requirements in one of the following work roles: 622 (Secure Software Assessor) at the "Intermediate" level, or 652 (Security Architect) at the "Intermediate" level.
- Strong knowledge of industry standards and defense requirements.
- Excellent communication and presentation skills.
- Ability to lead and work within a multidisciplinary team.
- Previous experience working in a U.S. Government Program Office (required).
- Must be a U.S. Citizen
- An active DoD Secret clearance is required to perform this work. Candidates are required to have an active Secret clearance upon hire, and the ability to maintain this level of clearance during their employment.
Education Requirements:
- Bachelor's degree in Computer Science, Engineering, or a related technical discipline
Desired Skills:
- Top Secret clearance preferred
- DoDI 8140.03 qualification at the "Advanced" level for work role 622 (Secure Software Assessor) or 652 (Security Architect)