Supply Chain Risk Management
CurrentAs a key contributor to the Cyber Supply Chain Risk Management (C-SCRM) process, I conduct thorough vendor risk assessments, helping to identify and mitigate supply chain risks. My responsibilities include researching and analyzing hardware and software acquisitions to uncover vulnerabilities and provide vendor risk scores and threat intelligence to decision-makers.I monitor and analyze system inventory reports to identify supply chain risks, including vulnerabilities that could compromise security. By delivering regular SCRM risk assessment reports with actionable recommendations, I ensure management is equipped to address risks strategically.As a member of the Supply Chain Risk Management team, I assist defense clients in analyzing and implementing next-generation secure supply chain capabilities. This includes overseeing the execution of risk assessment programs, identifying supply chain threats, and recommending mitigation strategies. I conduct in-depth research into emerging threats, vulnerabilities, and consequences, especially regarding hardware and software from untrusted manufacturers.In support of the National Risk Management Center (NRMC), I help develop and refine supply chain analytical requirements. I coordinate and lead the creation of pre-planned reports and studies to support NRMC’s supply chain program. Additionally, I develop briefing materials and recommendations for decision-makers to help guide risk mitigation strategies.I actively participate in internal discussions on risk and data analysis as required by NRMC management and assist the Government in conducting reviews and recommendations to aid the government in approving of risk acceptance memorandums and create risk profiles for client information systems.