Cybersecurity Supply Chain Risk Management Subject Matter Expert (Anticipated Position)

Navanti Group
Arlington, VA, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cyber Security Decision Support Systems Software Version Control

Job description

The C-SCRM Subject Matter Expert will support GSA FAS/ASD in maturing its Cybersecurity Supply Chain Risk Management program from a compliance-focused model to a proactive, risk-informed enterprise capability. The SME will assess current C-SCRM practices, improve documentation and risk assessment processes, support strategy development, recommend scoring methodologies, develop practical C-SCRM guides, and advise stakeholders on cybersecurity, supplier risk, acquisition risk, and emerging technology considerations., * Lead assessment of current C-SCRM documentation practices and recommend standardized templates, naming conventions, version control practices, and collaboration processes

  • Review current vendor risk assessment processes covering supplier ownership, foreign influence, cybersecurity posture, product or service criticality, supply chain dependencies, and prohibited source risks
  • Develop recommendations for improving consistency, repeatability, accuracy, and usefulness of C-SCRM risk assessments
  • Review existing C-SCRM questionnaires and recommend improvements to question clarity, evidence collection, applicability, scoring, and risk-informed decision support
  • Develop or support development of a standardized C-SCRM Risk Assessment Framework
  • Support development of a C-SCRM Strategy and Implementation Plan, including priorities, governance approach, maturity objectives, roadmap, milestones, dependencies, and responsible parties
  • Assist with planning, coordination, tracking, and execution of C-SCRM projects
  • Develop C-SCRM guides, standard operating procedures, frameworks, briefings, and other written deliverables as requested
  • Support integration of C-SCRM into acquisition processes and stakeholder workflows
  • Provide expert analysis related to NIST SP 800-161, cybersecurity risk management, enterprise risk management, acquisition assurance, supplier risk, and emerging cybersecurity requirements
  • Support monthly status reporting, technical meetings, deliverable reviews, and Government stakeholder engagement
  • Work with minimal direction and produce executive-ready written products

Requirements

Do you have experience in Technical documentation?, * Minimum 3 years of experience establishing or supporting risk management programs, including C-SCRM

  • Demonstrated experience across the PWS task areas, including C-SCRM documentation, vendor risk assessment, questionnaire/scoring methodology, strategy development, and guide development
  • High-level cybersecurity or risk management certification, such as CISSP, CISM, or CRISC
  • Active Top Secret clearance with SCI eligibility
  • Strong knowledge of NIST SP 800-161, cybersecurity supply chain risk management, federal acquisition risk, and cyber risk frameworks
  • Strong written and oral communication skills
  • Ability to work independently with senior Government stakeholders

Preferred Qualifications:

  • Experience supporting GSA, DHS, DoD, IC, or other federal cybersecurity or acquisition programs
  • Experience with Section 889, FASCSA, supplier risk, foreign ownership/control/influence concerns, prohibited source analysis, or acquisition assurance
  • Experience developing federal SOPs, implementation plans, risk frameworks, scoring rubrics, stakeholder guides, and executive briefings
  • Familiarity with AI-enabled risk management, automation, post-quantum cryptography planning, continuous monitoring, and enterprise C-SCRM maturity models

About the company

Navanti Group is a young company with significant growth potential, and we offer rapid advancement for those who excel. The success of our company lies in the quality of our people, which is why we will work hard to foster your talents and develop your career.

Do really interesting work Work on innovative projects in international security, countering radicalization, new media, and business development.

Have a voice We eschew traditional hierarchies because they stunt potential. We believe everyone has unique value to add regardless of age or title. We celebrate great ideas that can help our clients meet their objectives, and so we have institutionalized the practice of idea-sharing and development at all levels.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Evaluating supply chain risk with AI security assistants

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:24 min

Introducing human-in-the-loop decision support for logistics planning

Stefan Petrov · LIVE

3:46 min

Core terminology and audiences for interpretable artificial intelligence

Karol Przystalski · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:59 min

Building operational accountability by transferring fragility within teams

Jan de Vries Jan de Vries · World Congress 2026 Europe

3:21 min

Automating complete quality assurance pipelines with artificial intelligence

Evelyn Haslinger · LIVE

Videos

See all

Related articles

See all