Software Supply Chain Security Specialist
Core
Define and own enterprise software supply chain security strategy, governance, and tooling to secure SDLC pipelines and manage third-party component risks.
Role type
Senior IC software supply chain security specialist
Builds
Secure CI/CD pipelines, SBOM generation/validation workflows, and automated dependency risk controls
Domain
Financial services / Software Supply Chain Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SCA, pipeline security, SBOM management, CI/CD integration, Python, Java, YAML, risk-based vulnerability management, tooling strategy
Preferred skills
AI/ML pipeline security, AIBOM, advanced SBOM evolution, zero-trust supply chain models, CISSP, CSSLP, AAISM
Technologies
AI, CI/CD, DevSecOps, Java, Python, Security
Responsibilities
Define enterprise software supply chain security strategy, roadmap, and governance; Establish policies and guardrails for SBOMs, artifact signing, and provenance; Embed security controls across SDLC, CI/CD pipelines, and artifact repositories; Implement and enforce SBOM generation, validation, and artifact integrity controls; Collaborate with stakeholders to lead risk-based vulnerability management for open-source and third-party components; Help define remediation workflows, SLAs, and exception handling for supply chain risks; Own the tooling strategy for SCA, container scanning, and supply chain security automation; Integrate and optimize security tools within CI/CD for scalable enforcement; Maintain inventory and visibility of dependencies, SBOMs, and third- and fourth-party exposure; Partner with AppSec, DevSecOps, and platform teams to drive secure development adoption; Enable developers through playbooks, guardrails, and self-service secure consumption patterns; Define metrics and report on supply chain risk posture, remediation effectiveness, and maturity