Develop C-SCRM KPIs and KRIs for cybersecurity supply chain risk assessment and monitoring. Create a C-SCRM training program plan, detailing subject matter, cadence, format, and audiences.
Numbers & Facts
Location
Baltimore, MD
Description
Supply Chain Risk Management Analyst
Bethesda, MD | Onsite | 12-month Contract
Day-to-day Responsibilities:
Develop a RACI matrix to define roles and responsibilities for C-SCRM.
Create a C-SCRM training program plan, detailing subject matter, cadence, format, and audiences.
Assist in formulating a Software Bill of Materials (SBOM) Strategy for software supply chain security.
Develop C-SCRM KPIs and KRIs for cybersecurity supply chain risk assessment and monitoring.
Integrate C-SCRM processes into the agency's risk management framework and vulnerability management.
Contribute to the development of a C-SCRM risk register and refine the agency's C-SCRM strategy and policies.
Required Skills:
Knowledge of Cyber Supply Chain Risk Management including NIST 800-161
Preferred Skills:
Knowledge of SBOMs and Cyber Supply Chain Risk Management workflows