Sr. Cyber Supply Chain Risk Management SME (C-SCRM) (Intelligence Analyst 4) - 18827

Huntington Ingalls Industries
Woodlawn, MD
Full-time
  • Advise CMS DSI personnel on cybersecurity supply chain risk management (C-SCRM) policy and standard operating procedures.
  • Identify all CMS vendors / suppliers who have ICT products / services that connect to or traverse Centers for Medicare & Medicaid Services (CMS) networks.

This includes analyzing active contracts lists and reviewing completed Information Security Certification forms.

  • Review / evaluate products against known threats, known exploitable vulnerabilities (KEVs), and Common Vulnerabilities and Exposures (CVEs).
  • Develop and maintain processes related to C-SCRM and ICT risk assessments.
  • Analyze C-SCRM-related data and convey the threat level to senior leadership along with a recommendation on how to best mitigate risk.
  • Evaluate and monitor software supplier adherence to Secure Software Development Framework (SSDF) attestations and other cybersecurity contractual requirements (especially for Executive Order defined critical software)
  • Review and evaluate software supplier SBOMs for supply chain risks, and provide cyber-focused risk mitigation recommendations within Supply Chain Risk Assessments
  • Review and evaluate existing and prospective suppliers Service Organization Control (SOC) 2 reports.
  • Review, evaluate, and continuously monitor prospective and existing supplier cyber hygiene, illuminated through 3rd party due diligence tools or other government tools.
  • Develop the supplier cyber evaluation portion of the supply chain risk assessment reports.
  • Collaborate and liaison with CMS' cybersecurity staff to gather and include relevant information into reports.
  • Identify resources used to conduct or enhance the SCRA assessment and collaborate with the government to obtain access.
  • Contribute to development and evaluation of pre-acquisition vendor / supplier questionnaires.
  • Assist with development and implementation of cyber-related supplier risk event / incident responses.
  • Identify resources used to conduct or enhance the SCRA assessment and collaborate with the government to obtain access.

What We Are Looking For

9 years relevant experience with Bachelors in related field; 7 years relevant experience with Masters in related field;

4 years relevant experience with PhD or Juris Doctorate in related field; or High School Diploma or equivalent and 13 years relevant experience

  • Familiarity with cybersecurity practices to integrate cybersecurity and C-SCRM.
  • Knowledge of commercially available C-SCRM tools and proficiency in analyzing ICT products / services and understanding both supply chain risk and cybersecurity frameworks and standards.
  • Good quantitative and analytical skills
  • Demonstrated ability to use MS Office Suite to include Word, PowerPoint, and Excel.
  • Superior oral and written communication skills
  • Ability to effectively interact with senior executives from Government and Industry
  • Ability to create and foster a cooperative work environment.
  • Self-directed, detail oriented in completing assigned tasks, able to adapt to changing work efforts and manage impact of shifting priorities.
  • Availability for occasional travel.

Preferred : Bonus Points For...

Bachelor's degree in business administration, supply chain management, logistics, cybersecurity, information technology, or related field.

Master's degree is preferred.

6+ years' experience in supply chain risk. Specific focus on cyber supply chain management (C-SCRM) is preferred.

Physical Requirements

May require working in an office, industrial, shipboard, or laboratory environment. Capable of climbing ladders and tolerating confined spaces and extreme temperature variances.

  • HII is more than a job - it's an opportunity to build a new future. We offer competitive benefits such as best-in-class medical, dental and vision plan choices;
  • wellness resources; employee assistance programs; Savings Plan Options (401(k)); financial planning tools, life insurance;

employee discounts; paid holidays and paid time off; tuition reimbursement; as well as early childhood and post-secondary education scholarships.

Why HII

We build the world's most powerful, survivable naval ships and defense technology solutions that safeguard our seas, sky, land, space and cyber.

Our diverse workforce includes skilled tradespeople; artificial intelligence, machine learning (AI / ML) experts; engineers;

technologists; scientists; logistics experts; and business administration professionals.

Recognized as one of America's top large company employers, we are a values and ethics driven organization that puts people's safety and well-being first.

Regardless of your role or where you serve, at HII, you'll find a supportive and welcoming environment, competitive benefits, and valuable educational and training programs for continual career growth at every stage of your career.

Together we are working to ensure a future where everyone can be free and thrive.

Today's challenges are bigger than ever, and the nation needs the best of us. It's why we're focused on hiring, developing and nurturing our diversity.

We believe that diversity among our workforce strengthens the organization, stimulates creativity, promotes the exchange of ideas and enriches the work lives of all our employees.

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, physical or mental disability, age, or veteran status or any other basis protected by federal, state, or local law.

Do You Need Assistance?

If you need a reasonable accommodation for any part of the employment process, please send an e-mail to buildyourcareer@hii-co.

com and let us know the nature of your request and your contact information. Reasonable accommodations are considered on a case-by-case basis.

Please note that only those inquiries concerning a request for reasonable accommodation will be responded to from this email address.

Additionally, you may also call 1-844-849-8463 for assistance. Press #3 for HII Mission Technologies.

30+ days ago
Related jobs
Huntington Ingalls Industries
Woodlawn, Maryland

Review and evaluate software supplier SBOMs for supply chain risks, and provide cyber-focused risk mitigation recommendations within Supply Chain Risk Assessments. Advise CMS DSI personnel on cybersecurity supply chain risk management (C-SCRM) policy and standard operating procedures. Develop the su...

LMI
Baltimore, Maryland

Analyze and assess CMS SCRM program progress and performance toward implementation and adherence to supply chain risk management principles, policies and procedures. Work collaboratively with internal CMS staff, external federal government agencies, and industry in developing and implementing overar...

Promoted
Blend360
Columbia, Maryland

We are looking for BI Senior Analyst with a minimum of 2 years consulting experience in ThoughtSpot based either at Columbia, MD or Denver, CO although we are open to remote as well if you are truly exceptional and have strong client-facing experience. Collaborate with cross-functional teams (Data E...

Promoted
Booz Allen Hamilton
Fort Meade, Maryland

Develop intelligence products, guides, and briefs, including daily analytical briefings and products, pattern and trend analysis, intelligence preparation of the environment (IPOE), collection and request for information (RFI) management, target system analysis and intelligence support to planning. ...

Promoted
Northrop Grumman Corp. (JP)
Linthicum Heights, Maryland

Bachelor’s degree and 6+ years of supply chain, procurement, business management and/or related experience, OR 4+ years of supply chain, procurement, business management and/or related with a master’s degree (4+ years of additional relevant experience may be considered in lieu of a bachelor's degree...

Gormat
Annapolis Junction, Maryland

Bachelor's degree in System Engineering, Computer Science, Information Systems, Engineering Science, Engineering Management, or related discipline from an accredited college or university is required. ...

Element Fleet Management
Baltimore, Maryland

Senior Business Intelligence Analyst. We are re-defining the fleet management industry to be people first, then business – delivering on our promise of a superior client experience. Excellent at planning, organizational, and time management skills, with demonstrated evidence of and proven analytical...

Booz Allen Hamilton
Linthicum Heights, Maryland

This Senior Cyber Intelligence Analyst position supports the DoD client and is responsible for leading and conducting fused intelligence analysis to enable the tracking and exploitation of Malicious Cyber Actors' tactics, training, and procedures (TTPs) and indicators of compromise (IOCs), and devel...

Johns Hopkins Medicine
Baltimore, Maryland

As a valued member of the Supply Chain Integration team, you will specialize in one or more of these crucial supply chain activities: Inventory Management, Supply and Demand Forecasting, Strategic Sourcing Lifecycle and Event Management, Contracting Lifecycle, Master Data Management, Procure to Pay ...

Office of the Director of National Intelligence
Maryland

Serves as Human Capital liaison & consultant on a diverse spectrum of HC functions at the Office of Naval Intelligence. Provides HC advisory services to the senior leadership, management officials & commanders. Provides comprehensive advisory & consultative services to all management levels within t...