System Security Engineer Cyber-Supply Chain Risk Management
Job Description
PeopleTec, Inc. is seeking a System Security Engineer for Cyber-Supply Chain Risk Management (C-SCRM) to support the Huntsville, AL location onsite. In this role, you will help strengthen the software supply chain by analyzing third-party code, dependencies, and build processes, then translating results into findings and improvement plans for senior leadership through the program PMO.
Why this role
- Support a program mission by securing software across the full system lifecycle: design, development, acquisition, integration, testing, fielding, and sustainment.
- Own and maintain core supply chain artifacts including SBOM governance, vulnerability reporting, and supplier secure software attestation forms.
- Collaborate across a multidisciplinary set of teams and coordinate objectives with internal and external organizations.
- Deliver clear, actionable reporting by preparing C-SCRM findings, reports, and improvement plans for senior management and stakeholders.
Responsibilities
- Provide technical support and security engineering for C-SCRM across the system lifecycle (design, development, acquisition, integration, testing, fielding, and sustainment).
- Mandate and manage Software Bills of Materials (SBOMs) for all procured and open-source software.
- Perform deep-dive vulnerability analysis and code provenance checks on third-party libraries.
- Establish Software Composition Analysis (SCA) and Static Analysis (SAST) requirements within vendor onboarding.
- Develop and maintain the Consolidated Program SBOM, Third-Party Software Vulnerability Reports, and Supplier Secure Software Attestation Forms.
- Ensure compliance with defense and industry standards by effectively managing C-SCRM processes.
- Interface with internal teams and external organizations to coordinate C-SCRM objectives and strategies.
- Prepare and present C-SCRM findings, reports, and improvement plans to senior management and stakeholders.
- Conduct strategic planning and coordination aligned to program objectives.
- Provide technical expertise to peer engineers within Technology Security, Program Protection, Cyber Security, and Technical Management teams.
- Use digital tools and methodologies to analyze supply chain risks, manufacturer/supplier relationships, and foreign ownership and controlling influence.
- Complete other tasks as assigned by the Chief Engineer and/or Technical Chief.
Requirements
- 5+ years of relevant experience. Additional education may be substituted for years of experience.
- Demonstrated experience in C-SCRM, particularly in defense or aerospace contexts.
- Knowledge of SPDX/CycloneDX, SCA, SAST/DAST, VEX, and FIPS 140-3 validation.
- Must meet minimum DoDI 8140.03 Defense Cyber Workforce qualification requirements in one of the following work roles:
- 622 (Secure Software Assessor) at the Intermediate level, or
- 652 (Security Architect) at the Intermediate level.
- Strong knowledge of industry standards and defense requirements.
- Excellent communication and presentation skills.
- Ability to lead and work within a multidisciplinary team.
- Previous experience working in a U.S. Government Program Office (required).
- Travel: 25%.
- U.S. Citizenship required.
- DoD Secret clearance is required. Candidates must have an active Secret clearance upon hire and the ability to maintain it.
Technologies
- SPDX, CycloneDX
- Software Composition Analysis (SCA)
- SAST/DAST
- VEX
- FIPS 140-3
Preferred
- Top Secret clearance preferred.
- DoDI 8140.03 qualification at the Advanced level for work role 622 (Secure Software Assessor) or 652 (Security Architect).
Program support & coordination
You will provide technical support to the program’s Chief Engineer and Technical Chief, securing the software supply chain by evaluating third-party code, dependencies, and build processes for vulnerabilities and malicious logic before integration across the lifecycle. The role also involves coordination and synchronization of C-SCRM technical and programmatic objectives with internal PMs across PAE Fires and external organizations including HQDA, ASA(ALT), JIATF 401, ATEC, AMCOM, and others.