Government and Public Sector - Cybersecurity - Supply Chain Risk Management - Manager
McLean, VA, US, 22102
EY
Mit unseren vier integrierten Geschäftsbereichen — Wirtschaftsprüfung und prüfungsnahe Dienstleistungen, Steuerberatung, Unternehmensberatung und Strategy and Transactions — sowie unserem Branchenwissen unterstützen wir unsere Mandanten dabei,...From strategy to execution, the Government & Public Sector practice of Ernst & Young provides a full range of consulting and audit services to help our Federal, State, Local and Education clients implement new ideas to help achieve their mission outcomes. We deliver real change and measurable results through our diverse, high-performing teams, quality work at the highest professional standards, operational know-how from across our global organization, and creative and bold ideas that drive innovation. We enable our government clients to achieve their mission of protecting the nation and serving the people; increasing public safety; improving healthcare for our military, veterans and citizens; delivering essential public services; and helping those in need. EY is ready to help our government build a better working world.
The Opportunity
We are seeking a Cybersecurity – Supply Chain Risk Management (C-SCRM) Manager who could oversee teams in the implementation, development, maintenance, and enhancement of C-SCRM solution(s). This role will be responsible for managing cross-functional teams, optimizing processes, and leveraging technology to enable the assessment, evaluation and identification of C-SCRM risks within suppliers’ products, services, and software. The ideal candidate will have a strong background in C-SCRM, product management, cybersecurity, and risk management.
Your Key Responsibilities
- Lead a C-SCRM team focused on implementing / managing a C-SCRM solution aligned with organizational goals and regulatory requirements.
- Oversee the development and implementation of C-SCRM processes and technologies, ensuring they are efficient, effective, and scalable.
- Develop and implement C-SCRM policies, procedures, and frameworks in alignment with industry standards and regulatory requirements.
- Manage a cross-functional team, including cybersecurity analysts, business analyst, and technology specialists, to deliver high-quality C-SCRM services.
- Collaborate with stakeholders to define product vision, roadmap, and key performance indicators (KPIs) for the C-SCRM solution.
- Drive ongoing enhancements to the C-SCRM solution, leveraging feedback from users and stakeholders to improve functionality and user experience.
- Maintain and effectively operate a C-SCRM solution, including, but not limited to, regular program updates, audit response support, and compliance checks.
- Stay informed about industry trends, emerging threats, and best practices in C-SCRM and cybersecurity to inform product strategy.
- Prepare and present reports on the C-SCRM solutions performance, risks, and opportunities to senior management and other stakeholders.
- Support Business Development and Practice Development initiatives to expand and advance EY’s C-SCRM services and capabilities throughout the Government & Public Sector.
Skills and attributes for Success
- Experience with C-SCRM frameworks, standards, and regulations such as NIST 800-161, NIST 800-53, NIST 800-218, NDAA 889, FISMA, and other related cybersecurity laws and regulations
- Proven experience in managing cross-functional teams and driving process improvements.
- Excellent analytical, strategic thinking, and communication skills.
- Familiarity overseeing the maintenance, operations, and enhancements of technology solutions used in C-SCRM (e.g., risk assessment tools, GRC technologies, and data solutions).
- Familiarity with multiple risk lenses utilized to support C-SCRM evaluations such as cybersecurity and foreign interest.
To qualify for the role, you must have
- Bachelor's degree in a related field
- A minimum of 5 years of related work experience
- Must be able to obtain and maintain a Secret-level clearance or higher
- CISSP, CISM, CISA, CRISC, CGRC or other relevant certification
- Must be comfortable working in the greater Washington, DC area in-person as needed
Due to the nature of our work in the Government and Public Sector, work may be required to be completed at client, EY and/or contractor sites. Our goal is to assign professionals to projects within a commutable distance of their work location office. In certain circumstances, travel may be required beyond your work location based on client and project needs. Candidates should be willing to travel 20 – 30% or more.
What we look for
We are looking for people who strive to lead themselves, their teams, and their communities, people who can foster effective team work to drive results. We are interested in authentic communicators with the ability to collaborate with EY colleagues across various teams who want to develop personally and professionally in a dynamic organization.
What we offer We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $143,500 to $263,200. The salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $172,200 to $299,100. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
Tags: C CGRC CISA CISM CISSP Clearance Compliance CRISC FISMA KPIs NIST NIST 800-53 Risk assessment Risk management Strategy
Perks/benefits: Career development Flex hours Flex vacation Health care Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.