Назад
Company hidden
обновлено 10 дней назад

Manager, Software Supply Chain Security (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Manager, Software Supply Chain Security (Cybersecurity): Leading secure-by-design controls across code, dependencies, developer tooling, build and release pipelines, containers, and third-party software with an accent on software supply chain governance, open-source security, and software bill of materials coverage. Focus on building a high-performing security team, defining measurable outcomes, embedding controls across engineering workflows, and balancing security effectiveness with developer experience.

Location: Hybrid role based in Austin, Texas, or Warren, Michigan, with on-site attendance at least 3 times per week. Relocation benefits are available under company policy.

Company

hirify.global develops vehicles, products, and digital experiences with a focus on safer, more sustainable, and equitable mobility.

What you will do

  • Lead the strategy, roadmap, and daily operations of the Software Supply Chain Security function.
  • Build and develop a high-performing team through hiring, coaching, performance management, and workforce planning.
  • Own security outcomes and KPIs covering dependency risk, SBOM coverage, third-party software, pipeline controls, and container security.
  • Partner with engineering, developer platform, cloud, infrastructure, procurement, and risk teams to embed secure-by-design controls into delivery workflows.
  • Establish policies, standards, and reusable guardrails for open-source software, software provenance, build integrity, artifact security, and developer tooling.
  • Prioritize investments, allocate resources, and lead change initiatives that improve security effectiveness, operational consistency, and developer experience.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field.
  • 8+ years of experience in cybersecurity, application security, platform security, software engineering, or a closely related technical field.
  • 3+ years of people leadership experience, including hiring, coaching, performance management, and organizational planning.
  • 3+ years leading or owning programs in software supply chain security, secure software delivery, build pipeline security, container security, or third-party software risk.
  • Experience across at least two technical domains, such as source control, build systems, artifact repositories, cloud platforms, containers, developer tooling, or software governance.
  • Experience defining and improving operational metrics and KPIs, influencing cross-functional stakeholders, and driving significant technical and operational decisions. GM does not provide immigration-related sponsorship; candidates must not require sponsorship now or in the future.

Nice to have

  • Advanced degree in Cybersecurity, Computer Science, Engineering, Business, or a related field.
  • Experience leading software supply chain security in a large, complex enterprise.
  • Experience with SBOM programs, open-source software governance, software composition analysis, artifact signing, or build provenance.
  • Experience with developer platforms, CI/CD pipelines, container platforms, cloud-native environments, or IDE governance.
  • Experience leading transformation initiatives that balance security, reliability, usability, and engineering speed.

Culture & Benefits

  • Hybrid work with regular in-person collaboration at the assigned location.
  • Relocation benefits may be available for qualifying candidates.
  • Benefits and total rewards support employee well-being at work and at home.
  • Inclusive workplace focused on belonging, equal opportunity, and meaningful change.

Hiring process

  • Role-related assessments and pre-employment screening may be required where applicable.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →