Cyber Security Risk Management Specialist

4 weeks ago


Alexandria, Virginia, United States ASRC Federal Full time
Job Summary

ASRC Federal is seeking a highly skilled Cybersecurity Supply Chain Risk Management professional to join our team at DMDC. In this critical role, you will oversee the development and maintenance of a Software Bill of Materials (SBoM) to ensure the organization's software supply chain complies with cybersecurity standards.

Key Responsibilities:
  • Develop and Maintain SBoM: Create and update a comprehensive Software Bill of Materials (SBoM) for the organization, ensuring accurate tracking of software components.
  • Implement and Manage Sonatype SBoM Tool: Implement and manage the Sonatype SBoM tool, ensuring secure integration of software libraries and dependencies.
  • Perform Regular Analysis: Perform regular analysis of SBoM scans, identifying potential security risks and vulnerabilities.
  • Collaborate with Stakeholders: Collaborate with legal and compliance teams to ensure open-source software adheres to licensing requirements.
  • Lead Supply Chain Risk Management Efforts: Lead supply chain risk management efforts, ensuring unauthorized or risky software components are not integrated into systems.
  • Develop and Maintain Risk Register: Develop and maintain a risk register for supply chain risks, identifying critical suppliers and high-risk areas.
  • Establish Security Controls: Establish and enforce security controls, policies, and procedures to mitigate supply chain risks.
  • Implement Risk Mitigation Strategies: Lead efforts to implement risk mitigation strategies, including vendor audits and continuous monitoring.
  • Conduct Due Diligence: Conduct due diligence of suppliers, ensuring adherence to cybersecurity standards and best practices.
  • Manage Vendor Relationships: Manage relationships with vendors, focusing on improving supply chain resilience and resolving cybersecurity issues.
  • Support Audits: Support audits and maintain documentation related to supply chain cybersecurity compliance.
Required Qualifications:
  • Active secret clearance is required.
  • Bachelor's degree in computer science, cybersecurity, information technology, or a related field. Equivalent work experience may be considered.
  • Demonstrate and maintain knowledge to meet DOD 8140 requirements through education, training, or personnel certification.
  • 8+ years of experience in information technology/cybersecurity operations.
  • Experience with supply chain risk management in the context of software development and cybersecurity.
  • Familiarity with Sonatype tools and SBoM concepts.
  • Strong understanding of open-source software licensing models and compliance.
  • Familiarity with supply chain technologies and their potential cybersecurity risks.
  • Knowledge of cybersecurity practices, especially in a DoD context.

ASRC Federal and its Subsidiaries are Equal Opportunity / Affirmative Action employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.



  • Alexandria, Virginia, United States BizFirst LLC Full time

    Cyber Security SpecialistWe are seeking a highly skilled Cyber Security Specialist to join our team at BizFirst LLC. As a Cyber Security Specialist, you will play a critical role in ensuring the security and integrity of our systems and data.Key Responsibilities:Implement, manage, and monitor security measures to protect our infrastructure and comply with...


  • Alexandria, Virginia, United States Assurance Technology Full time

    Job Summary: We are seeking a highly skilled Cyber Security Engineer to join our team at Assurance Technology. The successful candidate will have extensive experience in system and application security, with a strong background in Risk Management Framework (RMF) processes and advanced cyber security tools and methods.Key Responsibilities:Install, maintain,...


  • Alexandria, Virginia, United States Insight Global Full time

    Job Title: Cyber Security SpecialistLocation: Hybrid | 3 Days On-site a weekClearance: TS(SCI Eligible)Pay: 140k-175kOverview:Insight Global is working with the Army Military Intelligence (MI) program to support the overall strategy and migration to evaluate and potentially re-invent how Army MI delivers IT services and the use of Intelligence data and...


  • Alexandria, Virginia, United States Arlo Solutions Full time

    Job SummaryArlo Solutions is seeking a highly skilled Cyber Analyst to join our team. The successful candidate will provide technical expertise and policy oversight support for the development of cyber workforce and readiness policy guidance in DoD.Key ResponsibilitiesConduct deliberate analysis supporting the development of cyber workforce and readiness...


  • Alexandria, Virginia, United States KMS Solutions, LLC Full time

    Job OverviewKMS Solutions, LLC is a leading provider of technical management and solutions services, specializing in engineering, analysis, and cyber security. As a Navy Qualified Validator III, you will play a critical role in supporting the Department of Defense and other government agencies in ensuring the security and compliance of their systems.Key...


  • Alexandria, Virginia, United States Arlo Solutions Full time

    **Job Summary**Arlo Solutions is seeking a highly skilled Cyber Analyst to join our team. As a Cyber Analyst, you will play a critical role in supporting the development of cyber workforce and readiness policy guidance in the Department of Defense (DoD).**Key Responsibilities**Conduct deliberate analysis to support the development of cyber workforce and...


  • Alexandria, Virginia, United States clearAvenue, LLC Full time

    Job Summary:Safeguard information system assets by identifying and resolving potential and actual security threats. Protect system integrity by defining access privileges, control structures, and resources. Stay up-to-date with cloud cyber security guidelines (NIST) and ensure compliance with paperwork and reviews. Recognize security issues by identifying...


  • Alexandria, Virginia, United States Hamdan Resources Full time

    Job OverviewHamdan Resources is seeking a highly skilled Cyber Analyst II to join our team. As a key member of our cyber operations team, you will provide technical expertise and policy oversight support for the Office of the Principal Cyber Advisor (PCA). Your primary responsibility will be to deliver consistent, responsive, and technical cyberspace...


  • Alexandria, Virginia, United States ASRC Federal Holding Company Full time

    Cyber Security Support Services Program OverviewThe Cyber Security Support Services Program Manager will oversee the management of Cyber Security Support Services contract activities, reporting to the Sr Director, Defense Programs. This role will provide oversight and guidance to program managers to ensure the successful delivery of Cyber Security Support...


  • Alexandria, Virginia, United States ASRC Federal Holding Company Full time

    Job Title: Cyber Security AnalystJob Summary:ASRC Federal is seeking a Cyber Security Analyst to provide cybersecurity monitoring and incident response services to a U.S. Government client. This role involves monitoring and analyzing network traffic, handling security incidents, and preparing situational awareness reports.Key Responsibilities:Monitor and...


  • Alexandria, Virginia, United States ASRC Federal Full time

    Cyber Security Support Services OverviewASRC Federal is seeking a highly skilled Cyber Security Support Services professional to oversee the management of contract activities, reporting to the Sr Director, Defense Programs. In this role, the individual will be responsible for delivering mission-critical solutions to the U.S. Department of Defense, supporting...


  • Alexandria, Virginia, United States Booz Allen Hamilton Full time

    Job SummaryWe are seeking a highly skilled Cyber Security Architect to join our team at Booz Allen Hamilton. As a key member of our team, you will design and develop secure systems for the DoD, utilizing your expertise in cyber engineering and architecture to identify and implement ways to harden systems and reduce their attack surface.As a Cyber Edge...


  • Alexandria, Virginia, United States Human Resources Research Organization Full time

    About the JobWe are seeking a skilled Cyber Engineer to join our team at the Human Resources Research Organization (HumRRO). As a non-profit leader in applied research, evaluation, and analytics, we work with federal and state government agencies, private sector organizations, and professional associations.Key Responsibilities:Assist in performing...


  • Alexandria, Virginia, United States DirectViz Solutions, LLC Full time

    Job DescriptionDirectViz Solutions, LLC is a rapidly growing government contractor that provides strategic services to meet mission IT needs for government customers. We offer innovative information technology solutions to government clients through the knowledge and expertise of our dedicated employees. Our company is an employee-centric employer that...


  • Alexandria, Virginia, United States Leidos Full time

    Job Summary:The Leidos Digital Modernization sector is seeking a highly skilled Cyber Security Watch Officer to join the GSMO effort in Alexandria, VA. As a key member of the team, you will be responsible for supporting 24x7 operations and providing expert-level cybersecurity services to ensure the security and integrity of our networks.Key...


  • Alexandria, Virginia, United States Human Resources Research Organization Full time

    About the JobWe are seeking a skilled Cyber Engineer I-III to join our team at the Human Resources Research Organization. This role is crucial in maintaining and enhancing our organization's cybersecurity posture.The ideal candidate will be involved in various aspects of our security operations, from conducting vulnerability assessments to analyzing security...


  • Alexandria, Virginia, United States ASRC Federal Holding Company Full time

    Job Title: Cyber Security Operations Center AnalystLocation: RemoteClearance Required: Secret Clearance or greater (Must be Cleared and Verified by the FSO)Description (scope of work):ASRC Federal is seeking a Cyber Security Operations Center Analyst to provide cybersecurity monitoring and incident response services to a U.S. Government client. This role...


  • Alexandria, Virginia, United States Booz Allen Hamilton Full time

    Job Overview:We're seeking a skilled Cyber Edge Software Security Architect to join our team at Booz Allen Hamilton. As a key member of our team, you'll design and develop secure systems for the DoD, utilizing your expertise in cyber engineering and architecture to create solutions that withstand even the most advanced cyber threats.Key...


  • Alexandria, Virginia, United States Systems Planning and Analysis, Inc Full time

    Overview:At Systems Planning and Analysis, Inc., we deliver high-impact, technical solutions to complex national security issues. Our team is highly collaborative and produces results that matter. We offer opportunity, unique challenges, and a clear-sighted commitment to our mission.The Strategic Division supports high-reliability organizations, including...


  • Alexandria, Virginia, United States Information International Associates Full time

    Cyber Threat Intelligence LeadKeyLogic is seeking a highly skilled Cyber Threat Intelligence Lead to enable our operational counterparts with advanced analytics support. The ideal candidate will provide technical support on-call to a 24x7 cyber program in the areas of cyber threat intelligence, cyber hunt, and incident response. The position requires a...