Supply Chain Risk Manager
25539.5313
Apply to this job Until 10/5/2026 First posted May 29, 2026 Last posted August 6, 2026
Job description
General Atomics Aeronautical Systems, Inc. (GA-ASI), an affiliate of General Atomics, is a world leader in proven, reliable remotely piloted aircraft and tactical reconnaissance radars, as well as advanced high-resolution surveillance systems.
This position is responsible for assessing and mitigating supplier cybersecurity and supply chain risks that may impact program execution, compliance, and mission assurance. This role serves as a liaison between the supply chain organization, program management, engineering, cybersecurity, and external suppliers to address third party cyber risk, supply chain risk, operational resilience, and regulatory compliance concerns.
The position continually reviews supplier and product line risk posture, assesses emerging issues, and develops mitigation strategies to support production, quality, schedule, and customer requirements. Decisions made in this role directly influence program outcomes, supplier performance, and the organization's overall compliance posture.
This position sits at the intersection of cybersecurity compliance and supply chain management. Applications are welcomed from candidates whose background is primarily in third party risk management, cybersecurity compliance, information assurance, or governance and risk, as well as from candidates with a supply chain background. Preference will be given to applicants who bring both.
DUTIES AND RESPONSIBILITIES:
Third Party and Supplier Cybersecurity Risk
We recognize and appreciate the value and contributions of individuals with diverse backgrounds and experiences and welcome all qualified individuals to apply.
This position is responsible for assessing and mitigating supplier cybersecurity and supply chain risks that may impact program execution, compliance, and mission assurance. This role serves as a liaison between the supply chain organization, program management, engineering, cybersecurity, and external suppliers to address third party cyber risk, supply chain risk, operational resilience, and regulatory compliance concerns.
The position continually reviews supplier and product line risk posture, assesses emerging issues, and develops mitigation strategies to support production, quality, schedule, and customer requirements. Decisions made in this role directly influence program outcomes, supplier performance, and the organization's overall compliance posture.
This position sits at the intersection of cybersecurity compliance and supply chain management. Applications are welcomed from candidates whose background is primarily in third party risk management, cybersecurity compliance, information assurance, or governance and risk, as well as from candidates with a supply chain background. Preference will be given to applicants who bring both.
DUTIES AND RESPONSIBILITIES:
Third Party and Supplier Cybersecurity Risk
- Administer and support the third party risk management program by collecting, reviewing, and assessing supplier cybersecurity compliance information, including SOC 2 reports, Supplier Performance Risk System (SPRS) scores, and CMMC certification and compliance artifacts.
- Evaluate supplier cybersecurity posture against applicable DFARS flow down requirements, identify compliance gaps, and track supplier remediation to closure.
- Interface directly with suppliers to communicate cybersecurity risk findings, understand root causes, and coordinate remediation activities, including support to suppliers working to close cybersecurity gaps and strengthen compliance with contractual and regulatory requirements.
- Work closely with cybersecurity, compliance, and legal teams to ensure supplier risk is accurately documented, monitored, escalated, and reflected in supplier onboarding, qualification, and ongoing performance review.
- Develop and maintain processes that align supply chain risk management practices with NIST SP 800-161 and applicable Department of Defense (DoD) cybersecurity requirements, integrating cybersecurity supply chain risk management into existing supply chain and governance workflows.
- Monitor changes to defense industrial base cybersecurity regulations, including CMMC implementation milestones, and update supplier assessment criteria, processes, and flow down practices accordingly.
- Ensure sensitive and proprietary information, including Controlled Unclassified Information (CUI), is properly identified and handled in accordance with contractual, regulatory, and company requirements.
- Conduct structured supply chain risk assessments for assigned product lines, evaluating supplier criticality, single points of failure, operational resilience, and cybersecurity posture.
- Develop and implement mitigation strategies that address identified risks, and support program and supply chain leadership in risk informed decision making.
- Research, identify, and validate supply chain risk signals using internal data sources, supplier information, and external intelligence tools, and translate those signals into actionable recommendations.
- Serve as the primary point of coordination between supply chain organizations and program offices, ensuring alignment on risk priorities, mitigation plans, and program requirements.
- Interpret and administer policies, processes, and procedures that impact supply chain risk management activities.
- Prepare and deliver progress reports, risk assessments, briefings, and presentations to internal stakeholders and customers, communicating risk status, trends, and mitigation strategies to both technical and non-technical audiences.
- Maintain the strict confidentiality of sensitive information.
- Responsible for observing all laws, regulations, and other applicable obligations wherever and whenever business is conducted on behalf of the Company.
- Responsible for ensuring work is accomplished in a safe manner in accordance with established operating procedures and practices.
- Other duties as assigned or required.
We recognize and appreciate the value and contributions of individuals with diverse backgrounds and experiences and welcome all qualified individuals to apply.
About this role
Summary
Assess and mitigate supply chain and cybersecurity risks for aerospace programs
Job title
Supply Chain Risk Manager
Experience level
none
Industry
aerospace
Location requirements
Remote work possible, no specific location stated
Salary
Not specified
Management role
No
Skills & keywords
Required skills
cybersecurityrisk managementsupply chaincomplianceregulatory knowledge
Preferred skills
NIST SP 800-161CMMCDFARSSOC 2CUI
Specializations
cybersecuritysupply chain riskrisk assessmentcompliance
Locations
Structured locations inferred from the posting.
No structured locations extracted for this role yet.