Software Supply Chain Security Specialist supporting secure software supply chain in the United States. Requires 2+ years of experience and a Bachelor’s degree.
Responsibilities
Conduct vendor risk assessments based on security, compliance, and performance criteria.
Maintain and update vendor scorecards, flag underperforming suppliers for escalation.
Track vendor remediation plans and monitor follow-through.
Assist in onboarding new software vendors by auditing their security posture and documentation.
Support implementation and maintenance of software composition analysis (SCA) tools, SBOM generation/ingestion tools, and pipeline integrations.
Validate SBOMs submitted by vendors for correctness, depth, and format (e.g., SPDX, CycloneDX).
Help automate checks for license compliance, vulnerability scanning, and component provenance verification.
Apply and enforce existing vendor security policies, guidelines, and checklists consistently across projects.
Assist in reviewing third-party software requests from development teams, ensuring they meet policy criteria.
Escalate nonconforming proposals or exceptions to the Manager for review.
Monitor open source and third-party component vulnerabilities, mapping them to affected product lines and dependencies.
Help perform root cause or upstream traceability analysis for supply chain vulnerabilities.
Provide impact assessments and assist in remediation tracking.
Act as liaison between vendors, product teams, legal, procurement, and security/engineering stakeholders.
Schedule and lead vendor technical reviews, workshops, and follow-ups.
Prepare status reports, dashboards, and executive summaries for the Manager and leadership.
Support internal and external audits of supplier security practices and supply chain compliance.
Prepare evidence, documentation, and findings for audit reviews.
Help maintain supplier assurance programs and track compliance metrics.
Requirements
Bachelor’s degree in Supply Chain Management, Information Security, Software Engineering, or related field
2+ years of experience in supply chain management, software and supply chain security, third-party risk, or a related area
Familiarity with SBOM standards (SPDX, CycloneDX), software composition analysis tools (e.g. Snyk, Black Duck, Mend), and vulnerability databases
Supply Chain Technician managing procurement, logistics, and inventory for AEG Power Solutions. Ensuring timely and accurate documentation within the supply chain to meet production demands.
Inventory Control Associate managing inventory records and supplies for laboratory testing services at Certified Group. Ensuring accuracy in inventory management and compliance with safety standards.
Warehouse Manager overseeing operations and logistics for warehouse efficiency at JVCKENWOOD USA. Leading a team and ensuring compliance with safety and company standards.
Supply Chain Supervisor overseeing operations and staff management at Tiffin and Willard hospitals. Ensuring compliance, efficiency, and customer satisfaction in supply chain processes.
Automotive engineer developing solutions for autonomous vehicles and digitalisation in a global consulting firm. Optimizing performance and sustainability for the mobility industry.
Supply Planner leading the S&OP process for Action brands across Germany, Belgium, Netherlands, and France. Collaborating with sales and marketing to ensure excellent customer service and inventory management.
Global Supply Chain Planner for Personal Systems managing demand and supply chain planning processes. Collaborating with cross - functional teams to drive efficiency and customer satisfaction in operations.
Supply Chain Data Quality Analyst responsible for collecting and analyzing large datasets. Collaborating with teams to provide data - driven solutions and visualizations.