> Markdown version of [/jobs/ext/532197-cybersecurity-supply-chain-risk-management-subject-matter-expert-anticipated-position](https://www.wearedevelopers.com/jobs/ext/532197-cybersecurity-supply-chain-risk-management-subject-matter-expert-anticipated-position). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Supply Chain Risk Management Subject Matter Expert (Anticipated Position) - **Company:** Navanti Group - **Location:** Arlington, VA, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Decision Support Systems, Software Version Control - **Published:** June 14, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b6055956893a966c ## About the Role Do you have experience in Technical documentation?, * Minimum 3 years of experience establishing or supporting risk management programs, including C-SCRM * Demonstrated experience across the PWS task areas, including C-SCRM documentation, vendor risk assessment, questionnaire/scoring methodology, strategy development, and guide development * High-level cybersecurity or risk management certification, such as CISSP, CISM, or CRISC * Active Top Secret clearance with SCI eligibility * Strong knowledge of NIST SP 800-161, cybersecurity supply chain risk management, federal acquisition risk, and cyber risk frameworks * Strong written and oral communication skills * Ability to work independently with senior Government stakeholders Preferred Qualifications: * Experience supporting GSA, DHS, DoD, IC, or other federal cybersecurity or acquisition programs * Experience with Section 889, FASCSA, supplier risk, foreign ownership/control/influence concerns, prohibited source analysis, or acquisition assurance * Experience developing federal SOPs, implementation plans, risk frameworks, scoring rubrics, stakeholder guides, and executive briefings * Familiarity with AI-enabled risk management, automation, post-quantum cryptography planning, continuous monitoring, and enterprise C-SCRM maturity models ## Description The C-SCRM Subject Matter Expert will support GSA FAS/ASD in maturing its Cybersecurity Supply Chain Risk Management program from a compliance-focused model to a proactive, risk-informed enterprise capability. The SME will assess current C-SCRM practices, improve documentation and risk assessment processes, support strategy development, recommend scoring methodologies, develop practical C-SCRM guides, and advise stakeholders on cybersecurity, supplier risk, acquisition risk, and emerging technology considerations., * Lead assessment of current C-SCRM documentation practices and recommend standardized templates, naming conventions, version control practices, and collaboration processes * Review current vendor risk assessment processes covering supplier ownership, foreign influence, cybersecurity posture, product or service criticality, supply chain dependencies, and prohibited source risks * Develop recommendations for improving consistency, repeatability, accuracy, and usefulness of C-SCRM risk assessments * Review existing C-SCRM questionnaires and recommend improvements to question clarity, evidence collection, applicability, scoring, and risk-informed decision support * Develop or support development of a standardized C-SCRM Risk Assessment Framework * Support development of a C-SCRM Strategy and Implementation Plan, including priorities, governance approach, maturity objectives, roadmap, milestones, dependencies, and responsible parties * Assist with planning, coordination, tracking, and execution of C-SCRM projects * Develop C-SCRM guides, standard operating procedures, frameworks, briefings, and other written deliverables as requested * Support integration of C-SCRM into acquisition processes and stakeholder workflows * Provide expert analysis related to NIST SP 800-161, cybersecurity risk management, enterprise risk management, acquisition assurance, supplier risk, and emerging cybersecurity requirements * Support monthly status reporting, technical meetings, deliverable reviews, and Government stakeholder engagement * Work with minimal direction and produce executive-ready written products ## Related Videos - [Securing your application software supply-chain](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Edit Your Future: Queerverse Radical AI](https://www.wearedevelopers.com/videos/909-edit-your-future-queerverse-radical-ai) - [Augmented Intelligence for transport planning: Human in the Loop Modelling](https://www.wearedevelopers.com/videos/72-augmented-intelligence-for-transport-planning-human-in-the-loop-modelling) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)