Program Manager, Cybersecurity Supply Chain Risk Management (C-SCRM)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Program Manager, Cybersecurity Supply Chain Risk Management (C-SCRM) (OT/IT Cybersecurity): Establishing and governing an enterprise-wide cybersecurity supply chain risk management program for nuclear-sector operational technology and information technology with an accent on supplier assurance, secure procurement, and regulatory compliance. Focus on assessing complex supplier ecosystems, evaluating software and firmware provenance, managing OT-constrained remediation, and presenting residual risk decisions to executive leadership.
Location: Full-time onsite in Houston, Texas, United States.
Salary: $165,576–$199,833 target annual pay range; full annual range of $148,447–$232,188.
Company
develops nuclear energy technology and operates in a highly regulated critical-infrastructure environment.
What you will do
- Develop and govern the enterprise C-SCRM program across nuclear OT, digital instrumentation and controls, and corporate IT environments.
- Lead supplier lifecycle management, including risk assessments, due diligence, contracting, onboarding, continuous monitoring, reassessment, and offboarding.
- Define supplier security requirements covering software integrity, code signing, firmware assurance, SBOMs, secure SDLC practices, and sub-tier supplier transparency.
- Coordinate technical assurance activities such as supplier audits, FAT/SAT, configuration verification, architecture reviews, and vulnerability remediation.
- Perform qualitative and quantitative risk assessments, maintain risk evidence, and develop KRIs and KPIs for program maturity and supplier health.
- Prepare for audits and US NRC reviews while communicating supply chain threats, mitigations, and accepted risks to senior leadership.
Requirements
- Bachelor’s degree in cybersecurity, computer science, engineering, or a related field, or 12 years of equivalent full-time nuclear industry cybersecurity experience.
- At least 8 years of full-time cybersecurity experience focused on supply chain risk, vendor management, or secure procurement.
- Experience across OT/ICS and IT cybersecurity, including digital I&C systems, embedded controllers, industrial networking, and enterprise IT infrastructure.
- NSCP 800-161 Foundation Certificate or equivalent is required, along with detailed knowledge of NIST SP 800-161, NIST SP 800-82, and relevant NIST SP 800-53 control families.
- Familiarity with nuclear-sector guidance, including NEI 08-09, RG 5.71, RIS 2015-08 Rev 1, and secure digital I&C implementation requirements.
- Must be eligible to work under Department of Energy 10 CFR Part 810 and work onsite in Houston, Texas.
Nice to have
- Certifications such as CISSP, CISM, CRISC, GICSP, CISA, or ISA/IEC 62443.
- Experience in nuclear energy, critical infrastructure, or similarly regulated sectors.
- Knowledge of SPDX, CycloneDX, NIST SP 800-218, OT protocols, deterministic network architectures, and physical or functional separation concepts.
Culture & Benefits
- Full-time employee position with compensation determined by experience, education, training, and internal equity.
- Work within a safety-focused and quality-driven nuclear technology environment.
- Reasonable accommodations are available for qualified individuals with disabilities.
- Employee benefits are provided through ’s corporate benefits program.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →