Jobs and Careers
HI

Cyber Supply Chain Risk Management Policy and Governance Lead (Intelligence Analyst 5) - 20035

HII
United Statesfull_timeVerifiedPosted 22 Jul 2024
💰 $165,000/yr($118,635/yr – $165,000/yr)

About the role

Requisition Number: 20035 

Required Travel: 0 - 10% 

Employment Type: Full Time/Salaried/Exempt

Anticipated Salary Range: $118,635.00 - $165,000.00 

Security Clearance: TS/SCI  

Level of Experience: Senior HI

 

This opportunity resides with Command, Control, Communications, Computers, Cyber, Intelligence, Surveillance and Reconnaissance (C5ISR), a business group within HII’s Mission Technologies division. From towers to processors, we design, develop, integrate and manage the sensors, systems and other assets necessary to support integrated intelligence, surveillance and reconnaissance (ISR) operations, exploitation and analysis for the Intelligence Community, the military services, geographic and functional combatant commands and DoD agencies. 

 

Meet HII’s Mission Technologies Division
Our team of more than 7,000 professionals worldwide delivers all-domain expertise and advanced technologies in service of mission partners across the globe. Mission Technologies is leading the next evolution of national defense – the data evolution - by accelerating a breadth of national security solutions for government and commercial customers. Our capabilities range from C5ISR, AI and Big Data, cyber operations and synthetic training environments to fleet sustainment, environmental remediation and the largest family of unmanned underwater vehicles in every class. Find the role that’s right for you. Apply today. We look forward to meeting you.

 

To learn more about Mission Technologies, click here for a short video: https://vimeo.com/732533072 

 

Who We Are

HII - Mission Technologies is seeking a Cyber Supply Chain Risk Management (CSCRM) Governance Lead. This position will focus on developing policies and procedures to structure a SCRM program intended to mitigate risks associated with the agency's supply chain and third-party vendors. This role involves creating and maintaining a comprehensive cyber risk management framework, ensuring compliance with security standards and regulatory requirements, and overseeing governance processes to protect the organization’s assets and data. They will also work to develop and incorporate contract and acquisition policies with associated terms and conditions to ensure all agreements align with the agency's security standards and risk management objectives. 

What You Will Do

Policy Creation and Governance: 
Develop Comprehensive Cyber Supply Chain Policies: 
•    Establish policies that define the security requirements and expectations for all supply chain partners and third-party vendors. 
•    Ensure policies cover key areas such as data protection, incident response, access controls, and secure software development. 
•    Align policies with industry standards (e.g., NIST SP 800-161) and regulatory requirements (e.g., GDPR, CCPA). 
Policy Implementation and Enforcement: 
•    Develop procedures to enforce compliance with established policies. 
•    Implement monitoring mechanisms to ensure adherence to policies and procedures. 
•    Collaborate with internal teams to integrate policy requirements into procurement and vendor management processes. 
Continuous Improvement and Policy Updates: 
•    Regularly review and update policies to address new threats and vulnerabilities. 
•    Gather feedback from stakeholders to improve policy effectiveness. 
•    Stay informed about industry best practices and regulatory changes to ensure policies remain current. 

Risk Management Framework: 
Design and Maintain Risk Management Framework: 
•    Create a framework for identifying, assessing, and mitigating risks associated with the supply chain and third-party vendors. 
•    Implement risk assessment tools and methodologies to evaluate the security posture of vendors and suppliers. 
•    Develop risk mitigation strategies and action plans to address identified vulnerabilities. 
Integrate Risk Management with Governance: 
•    Ensure the risk management framework is integrated with governance processes to provide oversight and accountability. 
•    Establish key risk indicators (KRIs) and key performance indicators (KPIs) to monitor the effectiveness of risk management activities. 

Governance and Oversight: 
Establish Governance Committees: 
•    Form and lead governance committees or working groups focused on third-party risk management. 
•    Develop governance structures to ensure clear roles, responsibilities, and accountability. 
•    Develop and Maintain Risk Registers: Create and maintain third-party risk registers to document and track identified risks. 
Monitor and Report on Governance Activities: 
•    Generate regular reports on th

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

HII

View company profile →