Назад
Company hidden
22 часа назад

Program Manager, Cybersecurity Supply Chain Risk Management (C-SCRM)

165 576 - 199 833$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Program Manager, Cybersecurity Supply Chain Risk Management (C-SCRM) (OT/IT Cybersecurity): Establishing and governing an enterprise-wide cybersecurity supply chain risk management program for nuclear-sector operational technology and information technology with an accent on supplier assurance, secure procurement, and regulatory compliance. Focus on assessing complex supplier ecosystems, evaluating software and firmware provenance, managing OT-constrained remediation, and presenting residual risk decisions to executive leadership.

Location: Full-time onsite in Houston, Texas, United States.

Salary: $165,576–$199,833 target annual pay range; full annual range of $148,447–$232,188.

Company

hirify.global develops nuclear energy technology and operates in a highly regulated critical-infrastructure environment.

What you will do

  • Develop and govern the enterprise C-SCRM program across nuclear OT, digital instrumentation and controls, and corporate IT environments.
  • Lead supplier lifecycle management, including risk assessments, due diligence, contracting, onboarding, continuous monitoring, reassessment, and offboarding.
  • Define supplier security requirements covering software integrity, code signing, firmware assurance, SBOMs, secure SDLC practices, and sub-tier supplier transparency.
  • Coordinate technical assurance activities such as supplier audits, FAT/SAT, configuration verification, architecture reviews, and vulnerability remediation.
  • Perform qualitative and quantitative risk assessments, maintain risk evidence, and develop KRIs and KPIs for program maturity and supplier health.
  • Prepare for audits and US NRC reviews while communicating supply chain threats, mitigations, and accepted risks to senior leadership.

Requirements

  • Bachelor’s degree in cybersecurity, computer science, engineering, or a related field, or 12 years of equivalent full-time nuclear industry cybersecurity experience.
  • At least 8 years of full-time cybersecurity experience focused on supply chain risk, vendor management, or secure procurement.
  • Experience across OT/ICS and IT cybersecurity, including digital I&C systems, embedded controllers, industrial networking, and enterprise IT infrastructure.
  • NSCP 800-161 Foundation Certificate or equivalent is required, along with detailed knowledge of NIST SP 800-161, NIST SP 800-82, and relevant NIST SP 800-53 control families.
  • Familiarity with nuclear-sector guidance, including NEI 08-09, RG 5.71, RIS 2015-08 Rev 1, and secure digital I&C implementation requirements.
  • Must be eligible to work under Department of Energy 10 CFR Part 810 and work onsite in Houston, Texas.

Nice to have

  • Certifications such as CISSP, CISM, CRISC, GICSP, CISA, or ISA/IEC 62443.
  • Experience in nuclear energy, critical infrastructure, or similarly regulated sectors.
  • Knowledge of SPDX, CycloneDX, NIST SP 800-218, OT protocols, deterministic network architectures, and physical or functional separation concepts.

Culture & Benefits

  • Full-time employee position with compensation determined by experience, education, training, and internal equity.
  • Work within a safety-focused and quality-driven nuclear technology environment.
  • Reasonable accommodations are available for qualified individuals with disabilities.
  • Employee benefits are provided through hirify.global’s corporate benefits program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →