Sr. Program Manager - Cybersecurity Supply Chain Risk Management; C-SCRM
Listed on 2026-01-25
-
IT/Tech
Cybersecurity, IT Project Manager, IT Consultant, Systems Analyst
Overview
CRG is seeking a Senior Program Manager to lead Cybersecurity Supply Chain Risk Management (C-SCRM) Program, ensuring that risks associated with third-party information and communications technology (ICT) and operational technology (OT) suppliers are identified, assessed, and mitigated. This role requires strategic vision, expertise in cybersecurity and supply chain risk, and the ability to coordinate across multiple stakeholders including internal and external federal government partners, industry, and other federal agencies and interagency organizations.
Responsibilities- Work in close collaboration with the Department’s C-SCRM Director under the auspices of the Office of the Enterprise Chief Information Security Officer (E-CISO).
- Establish/manage program goals, performance metrics, and reporting mechanisms to measure Program effectiveness in support of the State Department’s C-SCRM Strategic Plan and Roadmap and in alignment with federal mandates/directives (e.g., NIST SP 800-161, EO 14028).
- Provide executive-level briefings and recommendations to senior leadership.
- Identify, assess, prioritize, and mitigate C-SCRM Program risks to ensure the Program’s overall success and progress.
- Collaborate with State Department bureaus, offices, and posts, other federal agencies, and external partner organizations to grow and strengthen the Department’s C-SCRM Program.
- Represent and serve as a program leader in interagency cross-departmental and/or working groups efforts.
- Manage cross-functional teams, budgets, and schedules to deliver on-time, high-quality products and services in support of the Program’s goals and objectives.
- Drive the adoption of best practices in project management, risk management, acquisition management, and supply chain risk management assessments.
- Develop project scopes and objectives, involving all relevant stakeholders and ensuring technical feasibility.
- Experience communicating clearly and effectively in both writing and verbally to audiences with differing levels of technical understanding.
- Excellent client-facing and internal communication skills
- Outstanding organizational skills including attention to detail, providing quality control, and multi-tasking skills.
On-site/Hybrid. Main office located in Washington, DC
Required Qualifications- Active Secret Clearance required.
- Bachelor’s Degree in Information Technology, Computer Science, or related field (Master’s is preferred).
- Project Management Institute (PMI) Project Management Professional (PMP) Certification is preferred.
- 10+ years in program/project management. Some cybersecurity or supply chain risk management experience preferred.
- Experience leading strategic planning and process improvement initiatives.
- Technical experience with cloud platforms and cloud-based IT solutions and technologies.
- Excellent leadership, communication, customer services, and organizational skills.
- Technical certification related to business transformation technology is preferred (i.e., Microsoft Power Platform).
- 5+ years of experience specifically leading projects for the (DOS) is preferred.
- Strong understanding of federal acquisition regulations, contract management, including acquisitions processes.
- Demonstrated self-starter with a high level of energy, proven record as a team player, outstanding communicator with demonstrated political savvy, unquestionable integrity, credibility, and character, strong leadership, team-building, critical thinking, and problem-solving skills.
Ongoing events continue to affect the global industrial base and compromise to federal networks have increased the urgency of C-SCRM in building and maintaining trust and assurance in the products, services and suppliers of information communications technology (ICT) and operational technology (OT) for the Department of State.
Cyber supply chain risks, associated with an organization’s decreased visibility into and understanding of how information, communications, and ICT/OT are acquired, developed, integrated, and deployed; and how the services acquired are delivered. C-SCRM risks are also associated with processes, procedures and practices used to ensure…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).