> Markdown version of [/jobs/ext/2878009-senior-product-owner-iv](https://www.wearedevelopers.com/jobs/ext/2878009-senior-product-owner-iv). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Product Owner IV - **Company:** BC Forward - **Location:** Cincinnati, OH, United States (Remote available) - **Experience:** Expert - **Salary:** $187,200.0 - $208,000.0 - **Contract:** Temporary contract - **Skills:** Cyber Security, Information Systems, DevOps, Open Source Technology, Systems Development Life Cycle, Software Engineering, Software Security, Information Technology, Free and Open-Source Software, Devsecops - **Published:** September 13, 2026 - **Apply:** https://www.jofdav.com/jobs/59694628-senior-product-owner-iv ## About the Role We are seeking a Senior Product Owner IV, Enterprise Open Source Management Program to lead the design and implementation planning for an enterprise open source governance and software supply chain security strategy. The ideal candidate will have strong experience in software supply chain security, open source risk management, and secure software development practices and a proven ability to operate across stakeholder groups to translate strategy into executable roadmaps at enterprise scale., * Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Business, or related field, or equivalent experience. * 5+ years in cybersecurity, application security, software development, technology governance, software supply chain security, or DevSecOps. * Experience leading complex cross-functional initiatives with multiple stakeholder groups and competing priorities. * Ability to operate in ambiguous environments and convert strategy into actionable implementation plans. * Strong written and verbal communication skills, including executive presentations and business cases. * Proven influence without authority across matrixed organizations. * Understanding of SDLC practices and modern software delivery methodologies. Preferred Skills: * Experience with open source governance platforms, SBOM generation tools, and supply chain security solutions. * Background in regulatory readiness, risk management frameworks, and policy development. ## Description * Lead the design and development of an Enterprise Open Source Management Program, including governance, operating model, scope, roadmap, and implementation strategy. * Facilitate collaboration among Cyber Security, Software Engineering, DevOps, Asset Management, Architecture, Risk Management, Legal, and Compliance to establish program requirements and priorities. * Evaluate current-state capabilities, identify gaps, and define future-state processes supporting open source governance and software supply chain security. * Develop program proposals, business cases, staffing plans, budget estimates, and implementation roadmaps for executive review and approval. * Define enterprise processes for open source software intake, approval, exception management, and ongoing governance activities. * Recommend policies, standards, controls, and procedures related to open source management and software supply chain risk. * Support development of a Software Bill of Materials (SBOM) strategy to improve visibility into components, dependencies, and risks. * Lead proofs of concept and pilot implementations to validate processes, technologies, and operating models. * Assess tooling, conduct vendor reviews, and provide solution recommendations aligned to program objectives. * Partner with development teams to integrate program controls into existing SDLC and engineering workflows. * Drive stakeholder alignment via workshops, working groups, governance forums, and executive discussions. * Provide transparent communications on status, recommendations, risks, dependencies, and milestones. * Monitor industry trends, emerging threats, regulatory developments, and leading practices in OSS governance and supply chain security. * Create educational materials and guidance that support adoption of program principles across the enterprise. * Influence outcomes and decisions across matrixed teams without direct authority. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [The Future of Open Source: A Deep Dive - Scott Chacon at WeAreDevelopers World Congress 2024](https://www.wearedevelopers.com/magazine/471-the-future-of-open-source-a-deep-dive-scott-chacon-at-wearedevelopers-world-congress-2024) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)