EngineerJobs.io
← Back to all jobs

Job Description

PeopleTec, Inc. is seeking a System Security Engineer for Cyber-Supply Chain Risk Management (C-SCRM) to support the Huntsville, AL location onsite. In this role, you will help strengthen the software supply chain by analyzing third-party code, dependencies, and build processes, then translating results into findings and improvement plans for senior leadership through the program PMO.

Why this role

  • Support a program mission by securing software across the full system lifecycle: design, development, acquisition, integration, testing, fielding, and sustainment.
  • Own and maintain core supply chain artifacts including SBOM governance, vulnerability reporting, and supplier secure software attestation forms.
  • Collaborate across a multidisciplinary set of teams and coordinate objectives with internal and external organizations.
  • Deliver clear, actionable reporting by preparing C-SCRM findings, reports, and improvement plans for senior management and stakeholders.

Responsibilities

  • Provide technical support and security engineering for C-SCRM across the system lifecycle (design, development, acquisition, integration, testing, fielding, and sustainment).
  • Mandate and manage Software Bills of Materials (SBOMs) for all procured and open-source software.
  • Perform deep-dive vulnerability analysis and code provenance checks on third-party libraries.
  • Establish Software Composition Analysis (SCA) and Static Analysis (SAST) requirements within vendor onboarding.
  • Develop and maintain the Consolidated Program SBOM, Third-Party Software Vulnerability Reports, and Supplier Secure Software Attestation Forms.
  • Ensure compliance with defense and industry standards by effectively managing C-SCRM processes.
  • Interface with internal teams and external organizations to coordinate C-SCRM objectives and strategies.
  • Prepare and present C-SCRM findings, reports, and improvement plans to senior management and stakeholders.
  • Conduct strategic planning and coordination aligned to program objectives.
  • Provide technical expertise to peer engineers within Technology Security, Program Protection, Cyber Security, and Technical Management teams.
  • Use digital tools and methodologies to analyze supply chain risks, manufacturer/supplier relationships, and foreign ownership and controlling influence.
  • Complete other tasks as assigned by the Chief Engineer and/or Technical Chief.

Requirements

  • 5+ years of relevant experience. Additional education may be substituted for years of experience.
  • Demonstrated experience in C-SCRM, particularly in defense or aerospace contexts.
  • Knowledge of SPDX/CycloneDX, SCA, SAST/DAST, VEX, and FIPS 140-3 validation.
  • Must meet minimum DoDI 8140.03 Defense Cyber Workforce qualification requirements in one of the following work roles:
    • 622 (Secure Software Assessor) at the Intermediate level, or
    • 652 (Security Architect) at the Intermediate level.
  • Strong knowledge of industry standards and defense requirements.
  • Excellent communication and presentation skills.
  • Ability to lead and work within a multidisciplinary team.
  • Previous experience working in a U.S. Government Program Office (required).
  • Travel: 25%.
  • U.S. Citizenship required.
  • DoD Secret clearance is required. Candidates must have an active Secret clearance upon hire and the ability to maintain it.

Technologies

  • SPDX, CycloneDX
  • Software Composition Analysis (SCA)
  • SAST/DAST
  • VEX
  • FIPS 140-3

Preferred

  • Top Secret clearance preferred.
  • DoDI 8140.03 qualification at the Advanced level for work role 622 (Secure Software Assessor) or 652 (Security Architect).

Program support & coordination

You will provide technical support to the program’s Chief Engineer and Technical Chief, securing the software supply chain by evaluating third-party code, dependencies, and build processes for vulnerabilities and malicious logic before integration across the lifecycle. The role also involves coordination and synchronization of C-SCRM technical and programmatic objectives with internal PMs across PAE Fires and external organizations including HQDA, ASA(ALT), JIATF 401, ATEC, AMCOM, and others.

Similar Jobs