Cybersecurity SCRM Expert

4 days ago


Harrisburg, Pennsylvania, United States Cherokee Nation Businesses Full time
Cybersecurity SCRM Expert Job Description

This position requires the ability to obtain a Public Trust. We are seeking a highly knowledgeable and experienced Cybersecurity Subject Matter Expert (SME) and Supply Chain Risk Management (SCRM) Analyst to provide expert-level systems analysis, design, integration, and implementation advice on complex cybersecurity challenges, with a specific focus on managing supply chain risks. The successful candidate will contribute to all phases of study development, assist with SCRM program management efforts, and conduct security risk assessments of third-party vendors. Additionally, the Analyst will play a critical role in enhancing cybersecurity awareness through training programs and ensuring adherence to federal regulations, including NIST SP 800-53 Rev. 5 and OMB M-22-18.

Responsibilities
• Provide high-level analysis, design, and integration advice on complex cybersecurity challenges, particularly within the realm of supply chain risk management (SCRM).
• Assist the SCRM Task Lead with managing and governing the organization's cybersecurity SCRM program, ensuring that procedures are up-to-date and aligned with federal regulations.
• Identify and categorize supply chain vendors into risk levels based on services and products provided and conduct thorough security risk assessments to identify gaps against security controls and requirements.
• Develop and maintain a framework for proactively managing cybersecurity supply chain risks, addressing issues such as counterfeit insertion, tampering, unauthorized production, theft, and insertion of malicious code throughout the Software Development Life Cycle (SDLC).
• Integrate SCRM concepts into the organization's Information Security Continuous Monitoring (ISCM) program, as part of the transition to NIST SP 800-53 Rev. 5.
• Support the implementation of OMB M-22-18 and assist in integrating the Secure Software Development Framework (SSDF) into the SDLC and ISCM processes.
• Establish and contribute to a Cyber Workforce Training, Education, and Awareness Program, including the creation of certificate pathways for key cybersecurity roles, with a focus on setting training requirements and ensuring accountability.
• Assist the customer in developing and maintaining a well-trained cybersecurity workforce that can achieve and maintain necessary industry certifications and academic credentials.
• Support the Information System Security Officer (ISSO) function by assisting in the development of Authority to Operate (ATO) packages and strategizing ways to centralize the ISSO support function.
• Prepare and deliver senior management presentations, reports, and briefings on the progress of cybersecurity initiatives, SCRM efforts, and workforce development.

Requirements
• Bachelor's degree in Cybersecurity, Information Technology, or a related field.
• Minimum 5 years of experience in cybersecurity, with a focus on supply chain risk management (SCRM) and cybersecurity program management.
• Possesses IAT Level II certification (e.g., CompTIA Security+, GIAC, or equivalent).
• Strong understanding of NIST SP 800-53 Rev. 5, federal cybersecurity regulations, and supply chain risk management frameworks.
• Experience conducting security risk assessments for third-party vendors and identifying compliance gaps.
• Familiarity with the Information Security Continuous Monitoring (ISCM) process and the integration of SCRM concepts into cybersecurity frameworks.
• Ability to manage complex projects and collaborate with cross-functional teams to achieve cybersecurity goals.
• Experience supporting the ISSO function and developing ATO packages.
• Strong written and verbal communication skills, with the ability to present complex technical information to both technical and non-technical audiences.
• Experience with Secure Software Development Framework (SSDF) and its integration into organizational processes preferred.
• Familiarity with the implementation of OMB M-22-18 and other federal cybersecurity regulations preferred.
• Proven track record of managing and maintaining cybersecurity workforce training programs, including certification tracking and development preferred.
• Past applicable job experience may include, but is not limited to: Cyber Security Specialist, Security Risk Management Analyst, or Information Security Consultant

  • Harrisburg, Pennsylvania, United States Delphi-US Full time

    Cybersecurity Expert WantedWe are seeking a highly skilled Cybersecurity Expert to join our team at Delphi-US. As a Cybersecurity Expert, you will be responsible for protecting our clients' networks and systems from cyber threats.Key Responsibilities:Monitor and analyze network traffic to identify potential security threatsImplement and maintain security...


  • Harrisburg, Pennsylvania, United States Department Of Defense Full time

    Job SummaryWe are seeking a highly skilled Cybersecurity Specialist to join our team at the Department of Defense. As a key member of our cybersecurity team, you will be responsible for ensuring the security and integrity of our cloud computing environments.Key ResponsibilitiesPerform threat and cybersecurity assessments of cloud computing environments to...

  • Product Attorney

    1 week ago


    Harrisburg, Pennsylvania, United States Eaton Corporation Full time

    Job Title: Product Attorney - Cybersecurity SpecialistEaton Corporation is seeking a highly skilled Product Attorney - Cybersecurity Specialist to join our team. The successful candidate will collaborate closely with cross-functional teams across the globe and provide legal support and guidance to Eaton's product teams.The Product Attorney - Cybersecurity...

  • Product Attorney

    3 weeks ago


    Harrisburg, Pennsylvania, United States Eaton Corporation Full time

    Job Title: Product Attorney - Cybersecurity SpecialistEaton Corporation is seeking a highly skilled and motivated Product Attorney specializing in Cybersecurity to join our team. The position is a hybrid work model and is based in Cleveland, OH or Pittsburgh, PA.Position Overview:The successful candidate will collaborate closely with cross-functional teams...

  • Product Attorney

    2 weeks ago


    Harrisburg, Pennsylvania, United States Eaton Corporation Full time

    Product Attorney - Cybersecurity SpecialistEaton Corporation is seeking a highly skilled and motivated Product Attorney specializing in Cybersecurity to join our team. This role is a hybrid work model and is based in Cleveland, OH or Pittsburgh, PA.Position OverviewThe successful candidate will collaborate closely with cross-functional teams across the globe...


  • Harrisburg, Pennsylvania, United States SHI GmbH Full time

    Job SummaryThe Presales Security Solutions Engineer will work as a customer-facing security expert, taking a consultative approach to security projects and having a holistic understanding of how security technology enables business. This role will also develop and deliver new security services offerings to address customer requests and opportunities.About...


  • Harrisburg, Pennsylvania, United States KPMG Full time

    Job SummaryKPMG is seeking a highly skilled Director, Senior Cloud Security Architect to join our Global Information Solution Group organization. The ideal candidate will have a strong background in cloud security, with a minimum of ten years of experience in security architecture, threat modeling, identity management, and authentication.Key Responsibilities...

  • Senior SOC Analyst

    3 weeks ago


    Harrisburg, United States Motion Recruitment Partners LLC Full time

    Senior SOC Analyst / LogRhythm/ Pennsylvania Harrisburg, PA Hybrid Contract $64/hr - $64/hr Are you a Senior SOC Analyst with an expertise in LogRhythm? There is a 6-month contract position available at a government agency for those located in PA. This agency serves the community and supports individuals financially that are driven to pursue their...

  • Senior SOC Analyst

    3 weeks ago


    Harrisburg, United States Motion Recruitment Full time

    Are you a Senior SOC Analyst with an expertise in LogRhythm? There is a 6-month contract position available at a government agency for those located in PA. This agency serves the community and supports individuals financially that are driven to pursue their education. Within this role, you will be responsible for developing and supporting all aspects of the...


  • Harrisburg, United States TechTrueUp Full time

    Company Description Smart IMS provides consulting services across a broad spectrum of technology and planning needs, including but not limited to: design, engineering, architecture, program/project management, business analysis & requirements definition, quality assurance, database administration, disaster recovery & continuity planning, cybersecurity, cloud...