Software Supply Chain Security Specialist

Vanguard

Malvern (Chester County)

On-site

USD 150,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Vanguard seeks a Software Supply Chain SME to act as the technical authority securing end-to-end software supply chain risk across the SDLC. You will set security standards, integrate SBOM and artifact signing controls, and lead governance while partnering with AppSec, DevSecOps, and engineering teams to reduce supply chain risk.

You will own tooling strategy for SCA and CI/CD security, drive remediation workflows, and deliver governance metrics to leadership.

Qualifications

  • Minimum of five years related work experience.
  • 7–10+ years in AppSec / DevSecOps / platform security.
  • Hands-on experience with SCA + pipeline security.
  • Certifications preferred (CISSP, CSSLP, AAISM or equivalent).

Responsibilities

  • Define and own enterprise software supply chain security strategy, roadmap, and governance.
  • Embed security controls across SDLC, CI/CD pipelines, and artifact repositories.
  • Collaborate with AppSec, DevSecOps, and engineering teams to drive vulnerability remediation.
  • Define metrics and report on supply chain risk posture, remediation effectiveness.

Skills

Python
Java
YAML

Education

Bachelor's degree
Graduate degree preferred

Job description

The Software Supply Chain SME serves as the technical authority responsible for securing the end-to-end software supply chain, ensuring the integrity, provenance, and risk posture of all code, dependencies, and artifacts across the SDLC. This role defines and enforces security standards, integrates controls within CI/CD pipelines, and leads enterprise initiatives such as SBOM adoption, artifact signing, and open-source risk management. The SME partners with AppSec, DevSecOps, and engineering teams to embed secure development practices, drive vulnerability remediation, and enhance developer enablement—while providing governance, metrics, and strategic guidance to reduce supply chain risk at scale.

Core Responsibilities
  • Define and own enterprise software supply chain security strategy, roadmap, and governance
  • Establish policies and guardrails for SBOM, artifact signing, provenance, and dependency usage
  • Embed security controls across SDLC, CI/CD pipelines, and artifact repositories
  • Implement and enforce SBOM generation, validation, and artifact integrity controls
  • Collaborate with stakeholders and lead risk-based vulnerability management for open-source and third‑party components
  • Collaborate with stakeholders and define remediation workflows, SLAs, and exception handling for supply chain risks
  • Own tooling strategy for SCA, container scanning, and supply chain security automation
  • Integrate and optimize security tooling within CI/CD for scalable enforcement
  • Maintain inventory and visibility of dependencies, SBOMs, and third-/fourth-party exposure
  • Partner with AppSec, DevSecOps, and platform teams to drive secure development adoption
  • Enable developers via playbooks, guardrails, and self-service secure consumption patterns
  • Define metrics and report on supply chain risk posture, remediation effectiveness, and maturity
Nice to Have
  • Experience with AI/ML pipeline security
  • Exposure to AIBOM / advanced SBOM evolution
  • Knowledge of zero-trust supply chain models
Qualifications
  • Minimum of five years related work experience.
  • Undergraduate degree or equivalent combination of training and experience. Graduate degree preferred.
  • 7–10+ years in AppSec / DevSecOps / platform security
  • Hands‑on experience with SCA + pipeline security
  • Certifications preferred (CISSP, CSSLP, AAISM or equivalent etc.)
  • Programming/scripting (Python, Java, YAML)
Sponsorship

Vanguard is not offering visa sponsorship for this position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Supply Chain Security Architect
Software Supply Chain Security Architect

Vanguard • Malvern

On-site
USD 150,000 - 210,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
Senior Software Supply Chain Security Lead
Senior Software Supply Chain Security Lead

State Street • Quincy (MA)

On-site
USD 120,000 - 217,500
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Software Engineer – SBOM & Compliance
Software Engineer – SBOM & Compliance

ThunderSoft • San Diego (CA)

On-site
USD 85,000 - 110,000
Software Supply Chain Security Engineer
Software Supply Chain Security Engineer

State Street • Quincy (MA)

On-site
USD 90,000 - 158,000
401K with company match
Comprehensive medical, dental, vision
Paid time off
+3
Senior DevSecOps Engineer
Senior DevSecOps Engineer

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
Software Supply Chain Security Engineer
Software Supply Chain Security Engineer

State Street • Austin (TX)

On-site
USD 90,000 - 158,000
401K with company match
Medical, dental, vision coverage
Paid time off
DevSecOps Engineer: Software Supply Chain Security
DevSecOps Engineer: Software Supply Chain Security

State Street • Quincy (MA)

On-site
USD 90,000 - 158,000
401K with company match
Comprehensive medical, dental, vision
Paid time off
+3
Software Supply Chain Security Engineer
Software Supply Chain Security Engineer

State Street • Atlanta (GA)

On-site
USD 90,000 - 158,000
401K with company match
Health, dental, vision insurance
Paid time off and family leave
+3