Software Supply Chain Security Specialist supporting secure software supply chain in the United States. Requires 2+ years of experience and a Bachelor’s degree.
Responsibilities
Conduct vendor risk assessments based on security, compliance, and performance criteria.
Maintain and update vendor scorecards, flag underperforming suppliers for escalation.
Track vendor remediation plans and monitor follow-through.
Assist in onboarding new software vendors by auditing their security posture and documentation.
Support implementation and maintenance of software composition analysis (SCA) tools, SBOM generation/ingestion tools, and pipeline integrations.
Validate SBOMs submitted by vendors for correctness, depth, and format (e.g., SPDX, CycloneDX).
Help automate checks for license compliance, vulnerability scanning, and component provenance verification.
Apply and enforce existing vendor security policies, guidelines, and checklists consistently across projects.
Assist in reviewing third-party software requests from development teams, ensuring they meet policy criteria.
Escalate nonconforming proposals or exceptions to the Manager for review.
Monitor open source and third-party component vulnerabilities, mapping them to affected product lines and dependencies.
Help perform root cause or upstream traceability analysis for supply chain vulnerabilities.
Provide impact assessments and assist in remediation tracking.
Act as liaison between vendors, product teams, legal, procurement, and security/engineering stakeholders.
Schedule and lead vendor technical reviews, workshops, and follow-ups.
Prepare status reports, dashboards, and executive summaries for the Manager and leadership.
Support internal and external audits of supplier security practices and supply chain compliance.
Prepare evidence, documentation, and findings for audit reviews.
Help maintain supplier assurance programs and track compliance metrics.
Requirements
Bachelor’s degree in Supply Chain Management, Information Security, Software Engineering, or related field
2+ years of experience in supply chain management, software and supply chain security, third-party risk, or a related area
Familiarity with SBOM standards (SPDX, CycloneDX), software composition analysis tools (e.g. Snyk, Black Duck, Mend), and vulnerability databases
Senior Supply Chain Analyst optimizing inventory for a multi - node fulfillment network in direct - to - patient healthcare. Collaborating with internal teams and external partners for supply planning and risk management.
Senior Logistics Manager leading operations in distribution and transportation within a major logistics company. Responsible for customer satisfaction and strategic planning in the Mid - Atlantic region.
Logistics Manager overseeing efficient supply chain solutions at Ryder in Minnesota. Managing teams and ensuring compliance within transportation and logistics divisions.
Supply Chain Manager managing customer service operations at Hitachi Energy in Europe. Collaborate with teams to innovate for sustainable solutions and efficient service.
Sr. Inventory Control Manager at Jabil overseeing inventory control operations across manufacturing facilities. Leading team, optimizing policies, and collaborating cross - functionally to ensure operational efficiency.
Coordenador de Performance e Planejamento na Riachuelo, responsável por indicadores de Supply Chain e coordenação de equipe. Contribuindo para decisões estratégicas com análises e dashboards.
Senior Buyer at Comecer managing procurement process and optimizing supply chain operations. Involves strategic sourcing, vendor management, and problem solving in a collaborative environment.
Demand Planner at Resideo optimizing customer and product - level forecasts for informed business decisions. Collaborating across functions to ensure insights translate to actionable strategies.