Supply Chain Risk Manager

General Atomics Aeronautical Systems

Poway (CA)

On-site

USD 100,000 - 183,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Travel less than 25%

Job summary

General Atomics Aeronautical Systems, Inc. (GA-ASI) seeks an experienced leader to assess and mitigate supplier cybersecurity and supply chain risks. The role coordinates with supply chain, program management, engineering, cybersecurity, and suppliers to address third party cyber risk, resilience, and regulatory compliance.

The position develops mitigation strategies, oversees risk posture, and supports production, quality, schedule, and customer requirements. Travel up to 25% may be required.

Qualifications

  • Bachelor’s degree and 11+ years in supply chain, risk management, cybersecurity, or defense-related program support.
  • Working knowledge of cybersecurity requirements within the defense industrial base (DFARS, NIST SP 800-171, and CMMC).
  • CISSP, CompTIA Security+, CISA, or CMMC certification is highly desirable.
  • Preference for candidates with third-party/vendor risk management and supply chain/subcontracts experience.
  • Ability to identify and assess risk, analyze data, and develop mitigation strategies.

Responsibilities

  • Administer and support the third party risk management program by collecting, reviewing, and assessing supplier cybersecurity information.
  • Evaluate supplier cybersecurity posture against DFARS flow down requirements and track remediation.
  • Interface with suppliers to communicate risk findings and coordinate remediation activities.
  • Collaborate with cybersecurity, compliance, and legal teams to document and monitor supplier risk.
  • Develop processes aligning supply chain risk management with NIST SP 800-161 and DoD cybersecurity requirements.
  • Monitor defense cybersecurity regulations and update assessment criteria accordingly.
  • Ensure proper handling of sensitive information including CUI per requirements.
  • Conduct risk assessments and provide actionable mitigation recommendations.
  • Prepare and deliver risk status updates to stakeholders.

Skills

Risk assessment
Cybersecurity compliance
Data analysis
Stakeholder communication
Independent work
Cross-functional leadership

Education

Bachelor's degree in business, supply chain, cybersecurity, engineering, or a related discipline

Tools

SAP
Optro
Bitsight
Resilinc
Microsoft Office

Job description

Job Summary General Atomics Aeronautical Systems, Inc. (GA-ASI), an affiliate of General Atomics, is a world leader in proven, reliable remotely piloted aircraft and tactical reconnaissance radars, as well as advanced high-resolution surveillance systems. General Atomics Aeronautical Systems, Inc. (GA-ASI), an affiliate of General Atomics, is a world leader in proven, reliable remotely piloted aircraft and tactical reconnaissance radars, as well as advanced high-resolution surveillance systems.This position is responsible for assessing and mitigating supplier cybersecurity and supply chain risks that may impact program execution, compliance, and mission assurance. This role serves as a liaison between the supply chain organization, program management, engineering, cybersecurity, and external suppliers to address third party cyber risk, supply chain risk, operational resilience, and regulatory compliance concerns. The position continually reviews supplier and product line risk posture, assesses emerging issues, and develops mitigation strategies to support production, quality, schedule, and customer requirements. Decisions made in this role directly influence program outcomes, supplier performance, and the organization\'s overall compliance posture. This position sits at the intersection of cybersecurity compliance and supply chain management. Applications are welcomed from candidates whose background is primarily in third party risk management, cybersecurity compliance, information assurance, or governance and risk, as well as from candidates with a supply chain background. Preference will be given to applicants who bring both. DUTIES AND RESPONSIBILITIES: Third Party and Supplier Cybersecurity Risk

  • Administer and support the third party risk management program by collecting, reviewing, and assessing supplier cybersecurity compliance information, including SOC 2 reports, Supplier Performance Risk System (SPRS) scores, and CMMC certification and compliance artifacts.
  • Evaluate supplier cybersecurity posture against applicable DFARS flow down requirements, identify compliance gaps, and track supplier remediation to closure.
  • Interface directly with suppliers to communicate cybersecurity risk findings, understand root causes, and coordinate remediation activities, including support to suppliers working to close cybersecurity gaps and strengthen compliance with contractual and regulatory requirements.
  • Work closely with cybersecurity, compliance, and legal teams to ensure supplier risk is accurately documented, monitored, escalated, and reflected in supplier onboarding, qualification, and ongoing performance review.
  • Develop and maintain processes that align supply chain risk management practices with NIST SP 800-161 and applicable Department of Defense (DoD) cybersecurity requirements, integrating cybersecurity supply chain risk management into existing supply chain and governance workflows.
  • Monitor changes to defense industrial base cybersecurity regulations, including CMMC implementation milestones, and update supplier assessment criteria, processes, and flow down practices accordingly.
  • Ensure sensitive and proprietary information, including Controlled Unclassified Information (CUI), is properly identified and handled in accordance with contractual, regulatory, and company requirements.
Supply Chain Risk and Program Support
  • Conduct structured supply chain risk assessments for assigned product lines, evaluating supplier criticality, single points of failure, operational resilience, and cybersecurity posture.
  • Develop and implement mitigation strategies that address identified risks, and support program and supply chain leadership in risk informed decision making.
  • Research, identify, and validate supply chain risk signals using internal data sources, supplier information, and external intelligence tools, and translate those signals into actionable recommendations.
  • Serve as the primary point of coordination between supply chain organizations and program offices, ensuring alignment on risk priorities, mitigation plans, and program requirements.
  • Interpret and administer policies, processes, and procedures that impact supply chain risk management activities.
  • Prepare and deliver progress reports, risk assessments, briefings, and presentations to internal stakeholders and customers, communicating risk status, trends, and mitigation strategies to both technical and non-technical audiences.
General
  • Maintain the strict confidentiality of sensitive information.
  • Responsible for observing all laws, regulations, and other applicable obligations wherever and whenever business is conducted on behalf of the Company.
  • Responsible for ensuring work is accomplished in a safe manner in accordance with established operating procedures and practices.
  • Other duties as assigned or required.
We recognize and appreciate the value and contributions of individuals with diverse backgrounds and experiences and welcome all qualified individuals to apply.Job Qualifications
  • Typically requires a Bachelor’s degree in business, supply chain, cybersecurity, engineering, or a related discipline and eleven or more years of progressively complex experience in supply chain, risk management, cybersecurity, or defense related program support, with at least five of those years in supply chain. Equivalent experience may be substituted in lieu of education.
  • Must demonstrate a working knowledge of cybersecurity requirements within the defense industrial base, including DFARS clauses 252.204-7012, 252.204-7020, and 252.204-7021, NIST SP 800-171, and the Cybersecurity Maturity Model Certification (CMMC) framework.
  • CISSP, CompTIA Security+, CISA, or CMMC certification, such as Certified Professional (CCP) or Certified Assessor (CCA), is highly desirable.
  • Preference will be given to applicants with demonstrated experience in third party or vendor risk management, and to applicants with direct supply chain, procurement, or subcontracts experience.
  • Preference will be given to applicants familiar with supply chain risk management principles and NIST SP 800-161.
  • Must possess the ability to identify and assess risk, analyze and interpret data, and develop practical mitigation strategies for complex and non-routine issues. Strong analytical, communication, documentation, presentation, and interpersonal skills are required.
  • Must demonstrate the ability to work independently, lead cross functional efforts, and influence stakeholders across organizational boundaries. Experience interfacing directly with suppliers and supporting remediation activities is preferred.
  • Familiarity with enterprise and risk management tools such as SAP, Optro (formerly AuditBoard), Altana, Bitsight, Resilinc, and Microsoft Office applications is desired.
  • Applicant must be a U.S. citizen and must either have, or be eligible to obtain, a Secret clearance.
  • Must be able to work extended hours and travel as required. Travel is expected to be less than 25 percent.
Job Type: Full-Time Salary Salary range: 100,290 - 183,098
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Supply Chain Cyber Risk Manager
Senior Supply Chain Cyber Risk Manager

General Atomics Aeronautical Systems • Poway (CA)

On-site
USD 100,000 - 183,000
Travel less than 25%
Project Manager
Project Manager

General Atomics Aeronautical Systems • Poway (CA)

On-site
USD 73,000 - 130,000
Risk Assessment Analyst
Risk Assessment Analyst

Insight Global • Alexandria (VA)

Hybrid
USD 130,000 - 150,000
Alternate Contract Special Security Officer (CSSO)
Alternate Contract Special Security Officer (CSSO)

General Atomics Aeronautical Systems • Poway (CA)

On-site
USD 74,000 - 129,000
Cybersecurity Supply Chain Risk Management SCRM Analyst
Cybersecurity Supply Chain Risk Management SCRM Analyst

JCD Staffing • Washington

On-site
USD 100,000 - 130,000
Cybersecurity Audit Analyst
Cybersecurity Audit Analyst

Elevate Ventures • Huntsville (AL)

On-site
USD 74,000 - 110,000
Procurement Compliance Specialist
Procurement Compliance Specialist

General Atomics Aeronautical Systems • Poway (CA)

On-site
USD 62,510 - 105,628
Supply Chain Risk Management (SCRM) Lead
Supply Chain Risk Management (SCRM) Lead

ZTI Solutions LLC • Falls Church (VA)

On-site
USD 100,000 - 130,000
4 Weeks Paid Time Off
All Federal Holidays Paid
Four Percent Matching 401K
+1
Cybersecurity Audit Analyst
Cybersecurity Audit Analyst

Applied Aerospace • Huntsville (AL)

On-site
USD 70,000 - 90,000
Cybersecurity Manager/ISSO
Cybersecurity Manager/ISSO

General Dynamics Information Technology • Morningside (MD)

On-site
USD 124,093 - 165,600
Medical plan options
401(k) plan with company match
Paid time off