Government and Public Sector - Cybersecurity - Supply Chain Risk Management - Manager
EYAbout the role
Government & Public Sector – Cybersecurity – Supply Chain Risk Management - Manager
From strategy to execution, the Government & Public Sector practice of Ernst & Young provides a full range of consulting and audit services to help our Federal, State, Local and Education clients implement new ideas to help achieve their mission outcomes. We deliver real change and measurable results through our diverse, high-performing teams, quality work at the highest professional standards, operational know-how from across our global organization, and creative and bold ideas that drive innovation. We enable our government clients to achieve their mission of protecting the nation and serving the people; increasing public safety; improving healthcare for our military, veterans and citizens; delivering essential public services; and helping those in need. EY is ready to help our government build a better working world.
The Opportunity
We are seeking a Cybersecurity – Supply Chain Risk Management (C-SCRM) Manager who could oversee teams in the implementation, development, maintenance, and enhancement of C-SCRM solution(s). This role will be responsible for managing cross-functional teams, optimizing processes, and leveraging technology to enable the assessment, evaluation and identification of C-SCRM risks within suppliers’ products, services, and software. The ideal candidate will have a strong background in C-SCRM, product management, cybersecurity, and risk management.
Your Key Responsibilities
- Lead a C-SCRM team focused on implementing / managing a C-SCRM solution aligned with organizational goals and regulatory requirements.
- Oversee the development and implementation of C-SCRM processes and technologies, ensuring they are efficient, effective, and scalable.
- Develop and implement C-SCRM policies, procedures, and frameworks in alignment with industry standards and regulatory requirements.
- Manage a cross-functional team, including cybersecurity analysts, business analyst, and technology specialists, to deliver high-quality C-SCRM services.
- Collaborate with stakeholders to define product vision, roadmap, and key performance indicators (KPIs) for the C-SCRM solution.
- Drive ongoing enhancements to the C-SCRM solution, leveraging feedback from users and stakeholders to improve functionality and user experience.
- Maintain and effectively operate a C-SCRM solution, including, but not limited to, regular program updates, audit response support, and compliance checks.
- Stay informed about industry trends, emerging threats, and best practices in C-SCRM and cybersecurity to inform product strategy.
- Prepare and present reports on the C-SCRM solutions performance, risks, and opportunities to senior management and other stakeholders.
- Support Business Development and Practice Development initiatives to expand and advance EY’s C-SCRM services and capabilities throughout the Government & Public Sector.
Skills and attributes for Success
- Experience with C-SCRM frameworks, standards, and regulations such as NIST 800-161, NIST 800-53, NIST 800-218, NDAA 889, FISMA, and other related cybersecurity laws and regulations
- Proven experience in managing cross-functional teams and driving process improvements.
- Excellent analytical, strategic thinking, and communication skills.
- Familiarity overseeing the maintenance, operations, and enhancements of technology solutions used in C-SCRM (e.g., risk assessment tools, GRC technologies, and data solutions).
- Familiarity with multiple risk lenses utilized to support C-SCRM evalua
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s