Hybrid Software Supply Chain Specialist

Posted 3 weeks ago

Apply now

About the role

  • Conduct vendor risk assessments based on security, compliance, and performance criteria.
  • Maintain and update vendor scorecards, flag underperforming suppliers for escalation.
  • Track vendor remediation plans and monitor follow-through.
  • Assist in onboarding new software vendors by auditing their security posture and documentation.
  • Support implementation and maintenance of software composition analysis (SCA) tools, SBOM generation/ingestion tools, and pipeline integrations.
  • Validate SBOMs submitted by vendors for correctness, depth, and format (e.g., SPDX, CycloneDX).
  • Help automate checks for license compliance, vulnerability scanning, and component provenance verification.
  • Apply and enforce existing vendor security policies, guidelines, and checklists consistently across projects.
  • Assist in reviewing third-party software requests from development teams, ensuring they meet policy criteria.
  • Escalate nonconforming proposals or exceptions to the Manager for review.
  • Monitor open source and third-party component vulnerabilities, mapping them to affected product lines and dependencies.
  • Help perform root cause or upstream traceability analysis for supply chain vulnerabilities.
  • Provide impact assessments and assist in remediation tracking.
  • Act as liaison between vendors, product teams, legal, procurement, and security/engineering stakeholders.
  • Schedule and lead vendor technical reviews, workshops, and follow-ups.
  • Prepare status reports, dashboards, and executive summaries for the Manager and leadership.
  • Support internal and external audits of supplier security practices and supply chain compliance.
  • Prepare evidence, documentation, and findings for audit reviews.
  • Help maintain supplier assurance programs and track compliance metrics.

Requirements

  • Bachelor’s degree in Supply Chain Management, Information Security, Software Engineering, or related field
  • 2+ years of experience in supply chain management, software and supply chain security, third-party risk, or a related area
  • Familiarity with SBOM standards (SPDX, CycloneDX), software composition analysis tools (e.g. Snyk, Black Duck, Mend), and vulnerability databases
  • Willingness to travel up to 10–15%
  • Legal authorization to work in the United States

Benefits

  • Health insurance
  • 401(k)
  • Paid parental leave
  • Vacation and holiday leave
  • Flexible time off plans
  • Tuition reimbursement
  • Employee Assistance Program
  • Employee resource groups
  • Recognition programs

Job title

Software Supply Chain Specialist

Job type

Experience level

JuniorMid level

Salary

$71,000 - $100,000 per year

Degree requirement

Bachelor's Degree

Tech skills

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job