System Security Engineer Cyber-Supply Chain Risk Management

PeopleTec, Inc.

Huntsville (AL)

On-site

USD 110,000 - 170,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

PeopleTec, Inc. seeks a System Security Engineer specializing in Cyber-Supply Chain Risk Management (C-SCRM) to support the Huntsville, AL program. You will secure software supply chains by analyzing third-party code and build processes, and present findings to senior leadership.

You will coordinate with PMO and external partners to ensure SBOMs, SCA/SAST standards, and risk mitigations are implemented across the lifecycle, from design to sustainment. U.S.

Qualifications

  • 5+ years of relevant experience.
  • Demonstrated experience in C-SCRM, particularly within defense or aerospace industries.
  • Knowledge of SPDX/CycloneDX, Software Composition Analysis (SCA), SAST/DAST, VEX, and FIPS 140-3 validation.
  • Must meet DoDI 8140.03 Defense Cyber Workforce requirements: 622 Intermediate or 652 Intermediate.
  • Strong knowledge of industry standards and defense requirements.
  • Excellent communication and presentation skills.
  • Ability to lead a multidisciplinary team.
  • Previous experience in a U.S. Government Program Office is required.
  • Travel: 25%
  • Must be a U.S. Citizen
  • Active DoD Secret clearance required on hire.

Responsibilities

  • Provide technical support and security engineering in C-SCRM across the system lifecycle.
  • Mandate and manage SBOMs for all procured and open-source software.
  • Perform deep-dive vulnerability analysis and code provenance checks on third-party libraries.
  • Establish SCA and SAST requirements within vendor onboarding.
  • Develop and maintain SBOMs, Third-Party Software Vulnerability Reports, and Supplier Attestation Forms.
  • Ensure compliance with defense and industry standards by managing C-SCRM processes.
  • Interface with internal teams and external organizations to coordinate C-SCRM objectives.
  • Prepare and present C-SCRM findings and improvement plans to senior management.
  • Conduct strategic planning to support program objectives.
  • Provide technical expertise to peer engineers across teams.

Skills

C-SCRM
SBOM
Vulnerability analysis
Communication
Travel 25%

Education

Bachelor's degree in CS/Engineering

Tools

SPDX/CycloneDX
SCA
SAST/DAST
FIPS 140-3

Job description

Opportunity

PeopleTec is currently seeking a System Security Engineer Cyber-Supply Chain Risk Management (C-SCRM) to support our Huntsville, AL location.

The candidate will serve as a System Security Engineer Cyber-Supply Chain Risk Management (C-SCRM) within a Project Management Office (PMO) within PAE Fires and will be responsible for providing technical support to the program's Chief Engineer and the Technical Chief. The candidate will secure the software supply chain by analyzing third-party code, dependencies, and build processes for vulnerabilities and malicious logic before integration across the system lifecycle (design, development, acquisition, integration, testing, fielding, and sustainment). The candidate will prepare and present C-SCRM findings, reports, and improvement plans to senior management and stakeholders. Will work within a multidisciplinary security and engineering team to achieve program goals. Perform other tasks as assigned by the Chief Engineer and/or Technical Chief.

The candidate will be required to interface with internal PMs across PAE Fires and external organizations to include HQDA, ASA(ALT), JIATF 401, ATEC, AMCOM, and others for coordination and synchronization of C-SCRM technical and programmatic objectives.

Duties:

  • Provide technical support and security engineering in C-SCRM across the system lifecycle (design, development, acquisition, integration, testing, fielding, and sustainment).
  • Mandate and manage Software Bills of Materials (SBOMs) for all procured and open-source software.
  • Perform deep-dive vulnerability analysis and code provenance checks on third-party libraries.
  • Establish Software Composition Analysis (SCA) and Static Analysis (SAST) requirements within vendor onboarding.
  • Develop and maintain the Consolidated Program Software Bill of Materials (SBOM), Third-Party Software Vulnerability Reports, and Supplier Secure Software Attestation Forms.
  • Ensure compliance with defense and industry standards by managing C-SCRM processes effectively.
  • Interface with internal teams and external organizations to coordinate C-SCRM objectives and strategies.
  • Prepare and present C-SCRM findings, reports, and improvement plans to senior management and stakeholders.
  • Conduct strategic planning and coordination to support program objectives.
  • Provide technical expertise to support peer engineers within the Technology Security, Program Protection, Cyber Security, and Technical Management teams.
  • Use digital tools and methodologies to analyze supply chain risks, manufacturer/supplier relationships, and foreign ownership and controlling influence.
  • Perform other tasks as assigned by the Chief Engineer and/or Technical Chief.
Qualifications

Required Skills/Experience:

  • 5+ years of relevant experience. Additional education may be substituted for years of experience.
  • Demonstrated experience in C-SCRM, particularly within defense or aerospace industries.
  • Knowledge of SPDX/CycloneDX, Software Composition Analysis (SCA), SAST/DAST, VEX, and FIPS 140-3 validation.
  • Must meet minimum DoDI 8140.03 Defense Cyber Workforce qualification requirements in one of the following work roles: 622 (Secure Software Assessor) at the "Intermediate" level, or 652 (Security Architect) at the "Intermediate" level.
  • Strong knowledge of industry standards and defense requirements.
  • Excellent communication and presentation skills.
  • Ability to lead and work within a multidisciplinary team.
  • Previous experience working in a U.S. Government Program Office (required).
  • Travel: 25%
  • Must be a U.S. Citizen
  • An active DoD Secret clearance is required to perform this work. Candidates are required to have an active Secret clearance upon hire, and the ability to maintain this level of clearance during their employment.

Education Requirements:

  • Bachelor's degree in Computer Science, Engineering, or a related technical discipline

Desired Skills:

  • Top Secret clearance preferred
  • DoDI 8140.03 qualification at the "Advanced" level for work role 622 (Secure Software Assessor) or 652 (Security Architect)
Overview

People First. Technology Always.

PeopleTec, Inc. is an employee-owned small business founded in Huntsville, AL that provides exceptional customer support by employing and retaining a highly skilled workforce.

Culture: The name \"PeopleTec\" was deliberately chosen to remind us of our core value system - our people. Our company's foundation was built on placing our employees and customers first. With an award-winning atmosphere, we have matured into a company that boasts the best and brightest across multiple technical fields.

Career: At PeopleTec, we value your long-term goals. Whether it's through our continuing-education opportunities, our robust training programs, or our \"People First\" benefits package, PeopleTec truly believes that our best investments are our people.

Come Experience It.

#cjpost #dpost

EEO Statement

PeopleTec, Inc. is an Equal Employment Opportunity employer and provides reasonable accommodation for qualified individuals with disabilities and disabled veterans in its job application procedures. If you have any difficulty using our online system and you need an accommodation due to a disability, you may use the following email address, applicationhelp@peopletec.com and/or phone number (256.319.3800) to contact us about your interest in employment with PeopleTec, Inc.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, citizenship, ancestry, marital status, protected veteran status, disability status or any other status protected by federal, state, or local law. PeopleTec, Inc. participates in E-Verify.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

System Security Engineer Cyber-Supply Chain Risk Management
System Security Engineer Cyber-Supply Chain Risk Management

PeopleTec • Huntsville (AL)

On-site
USD 110,000 - 160,000
System Security Engineer AT and Supply Chain Risk Management
System Security Engineer AT and Supply Chain Risk Management

PeopleTec • Huntsville (AL)

On-site
USD 120,000 - 180,000
System Security Engineer AT and Supply Chain Risk Management
System Security Engineer AT and Supply Chain Risk Management

PeopleTec, Inc. • Huntsville (AL)

On-site
USD 120,000 - 170,000
Systems Integration Engineer
Systems Integration Engineer

PeopleTec, Inc. • Huntsville (AL)

On-site
USD 90,000 - 130,000
Program-Level Software Systems Engineer
Program-Level Software Systems Engineer

PeopleTec, Inc. • Huntsville (AL)

On-site
USD 120,000 - 180,000
Program-Level Software Systems Engineer
Program-Level Software Systems Engineer

PeopleTec • Huntsville (AL)

On-site
USD 120,000 - 180,000
Business Title Information Systems Security Manager (ISSM)
Business Title Information Systems Security Manager (ISSM)

PeopleTec, Inc. • Colorado Springs (CO), Northern (KY)

Hybrid
USD 130,000 - 170,000
Program Security Analyst
Program Security Analyst

UNAVAILABLE • Colorado Springs (CO)

On-site
USD 110,000 - 140,000
Systems Integration Engineer
Systems Integration Engineer

PeopleTec • Huntsville (AL)

On-site
USD 90,000 - 130,000
Business Title Program Security Analyst
Business Title Program Security Analyst

PeopleTec, Inc. • Colorado Springs (CO), Northern (KY)

Hybrid
USD 110,000 - 140,000