Software Supply Chain Security Specialist supporting secure software supply chain in the United States. Requires 2+ years of experience and a Bachelor’s degree.
Responsibilities
Conduct vendor risk assessments based on security, compliance, and performance criteria.
Maintain and update vendor scorecards, flag underperforming suppliers for escalation.
Track vendor remediation plans and monitor follow-through.
Assist in onboarding new software vendors by auditing their security posture and documentation.
Support implementation and maintenance of software composition analysis (SCA) tools, SBOM generation/ingestion tools, and pipeline integrations.
Validate SBOMs submitted by vendors for correctness, depth, and format (e.g., SPDX, CycloneDX).
Help automate checks for license compliance, vulnerability scanning, and component provenance verification.
Apply and enforce existing vendor security policies, guidelines, and checklists consistently across projects.
Assist in reviewing third-party software requests from development teams, ensuring they meet policy criteria.
Escalate nonconforming proposals or exceptions to the Manager for review.
Monitor open source and third-party component vulnerabilities, mapping them to affected product lines and dependencies.
Help perform root cause or upstream traceability analysis for supply chain vulnerabilities.
Provide impact assessments and assist in remediation tracking.
Act as liaison between vendors, product teams, legal, procurement, and security/engineering stakeholders.
Schedule and lead vendor technical reviews, workshops, and follow-ups.
Prepare status reports, dashboards, and executive summaries for the Manager and leadership.
Support internal and external audits of supplier security practices and supply chain compliance.
Prepare evidence, documentation, and findings for audit reviews.
Help maintain supplier assurance programs and track compliance metrics.
Requirements
Bachelor’s degree in Supply Chain Management, Information Security, Software Engineering, or related field
2+ years of experience in supply chain management, software and supply chain security, third-party risk, or a related area
Familiarity with SBOM standards (SPDX, CycloneDX), software composition analysis tools (e.g. Snyk, Black Duck, Mend), and vulnerability databases
Supply Chain Officer managing order fulfilment and logistics for the ICRC in Dnipro. Carrying out tasks according to logistical and financial procedures while ensuring client satisfaction.
Senior Talent Acquisition Partner leading hiring for Resmed’s Global Supply Chain in APAC. Focusing on attracting talent for industrial, manufacturing, engineering, and supply chain roles.
Project Manager optimizing supply chain logistics in the e - commerce sector for Vente - unique.com. Collaborating with teams to enhance warehouse performance and integrate new fulfillment clients.
Director of Supply Chain responsible for managing construction supply chain for NTT India Data Centers. Leading a team in strategic planning, sourcing, and contract negotiations.
Supply Chain Planner ensuring efficient planning and optimization of the end - to - end supply chain. Involves collaboration with production, procurement, logistics, and external suppliers.
Supply Chain Intern position at Nestlé Waters in Brussels focused on supply chain improvement projects and data management. Engaging with cross - functional teams and contributing to daily operations in a dynamic work environment.
Logistics Coordinator ensuring smooth movement of goods and coordinating transport schedules. Collaborating with teams to ensure timely delivery and compliance with regulations in a hybrid role.
Lead Supply Chain Planning workstreams in client - focused international projects at Infosys Consulting. Work autonomously and deliver outstanding results leveraging supply chain expertise.
Manage procurement functions for aeroderivative supply chain at GE Aerospace while developing supplier relationships and managing POs. Ensure compliance with aerospace quality and regulatory standards.
Analyst, Supply Chain overseeing asset lifecycle management at T - Mobile. Ensuring accurate tracking and optimization of serialized and non - serialized assets throughout their lifecycle.