Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Senior Supply Chain Cybersecurity Specialist image - Rise Careers
Job details

Senior Supply Chain Cybersecurity Specialist - job 2 of 2

Senior Supply Chain Cybersecurity Specialist

Company:

The Boeing Company

The Boeing Company’s Third-Party Risk & Resilience Program Management Office, operating within the Boeing Enterprise Security organization, is currently seeking a Senior Supply Chain Cybersecurity Specialist to join the team in Everett, WA; Arlington, VA;  Auburn, WA; Berkeley, MO; Chicago, IL; Colorado Springs, CO; El Segundo, CA; Englewood, CO; Hazelwood, MO; Houston, TX; Huntington Beach, CA; Huntsville, AL; Jacksonville, FL; Kennedy Space Center, FL; Kent, WA; Long Beach, CA; Mesa, AZ; Miami, FL; North Charleston, SC; Ogden, UT; Oklahoma City, OK; Plano, TX; Portland, OR; Renton, WA; Ridley Park, PA; Saint Charles, MO; San Antonio, TX; Seal Beach, CA; or Tukwila, WA. 

Step into a critical role that safeguards Boeing's assets and operations across our complex global supply chain! We are seeking a key contributor to drive our program’s growth while performing essential Cyber Supply Chain Risk Management (Cyber-SCRM) operational duties. Our program strategically collaborates with Procurement, Contracts, Legal, Enterprise Security, Supply Chain, and Corporate Compliance functions to proactively identify, assess, and mitigate cybersecurity risks throughout the third-party lifecycle.

In this dynamic, high-volume environment, you will play a vital role in current Third-Party Risk Management (TPRM) transformation projects while executing ongoing risk management activities. As a crucial interface, you will effectively communicate complex cybersecurity concepts to both technical and non-technical audiences, including senior management and third-party representatives.

We are looking for a self-driven team player with a deep understanding of cybersecurity principles, risk management frameworks (such as NIST 800-161 and NIST 800-171), and supply chain dynamics. You will exercise sound judgment, operate with significant autonomy, and influence stakeholders, directly contributing to the protection of Boeing's critical assets. This is your chance to actively shape the future of our C-SCRM program, impacting program development and implementation while helping the team transition to sustained operational excellence as the program matures. If you’re ready to make a meaningful impact in a vital area of our business, we want you on our team!

Position Responsibilities:

  • Contribute to the development, documentation, and implementation of the TPRM governance model, strategy, policies, and operating procedures

  • Participate in the configuration and implementation of a Third-Party Risk Management (TPRM) technology platform

  • Assist in designing and implementing an inherent risk assessment methodology, including questionnaire development and risk scoring logic within the TPRM tool

  • Help establish and document processes for validating supplier due diligence information, such as certifications and questionnaires

  • Collaborate on developing requirements and testing plans for integrating the TPRM platform with other internal Boeing systems (Procurement, Contracts, Security systems, etc.)

  • Support the adoption and refinement of AI/automation tools for TPRM tasks like contract review and due diligence assistance

  • Assist in developing communication materials and training for internal stakeholders and suppliers regarding updated TPRM processes and requirements

  • Conduct and evolve comprehensive cybersecurity risk assessments of current and potential suppliers using established methodologies

  • Analyze assessment results, supplier environments, and threat intelligence to identify, prioritize, and document cybersecurity risks and control gaps

  • Develop, negotiate, and track pragmatic risk mitigation and corrective action plans with suppliers

  • Serve as a key cybersecurity subject matter expert during procurement activities (SOWs, RFIs/RFPs/RFS) and contract negotiations, ensuring appropriate cybersecurity clauses are included and enforced

  • Define and communicate cybersecurity control requirements to suppliers based on risk assessments, data sensitivity, service criticality, and regulatory obligations (NIST 800-171, CMMC, etc.)

  • Review and present technical reports and briefings on supplier cybersecurity postures and associated risks to various stakeholders

  • Act as a cybersecurity SME, providing guidance and consultation to internal teams and business partners on supply chain security matters

  • Contribute to the continuous improvement of new TPRM processes, tools, and metrics

This position is hybrid. The selected candidate will be required to perform some work onsite at one of the listed location options. This is at the hiring team’s discretion and could potentially change in the future.

Basic Qualifications (Required Skills/Experience):

  • 3+ years of experience with cybersecurity, information protection and/or risk management

  • 3+ years of experience in working information technology, risk, or compliance

  • 3+ years of experience with managing vendors, contracts, and/or working with supply chain processes or systems

Preferred Qualifications (Desired Skills/Experience):

  • Bachelor's degree or higher in Cybersecurity, Information Technology, Risk Management, Computer Science, or a related field

  • Cybersecurity certifications such as: CTPRP, CTPRA, C3PRM, CRISC, CISSP, CISM, Security+

  • Experience with C-SCRM frameworks, particularly NIST SP 800-161r1

  • Experience working with cybersecurity or risk management frameworks (e.g., NIST CSF, ISO 27001)

  • Experience participating in technology implementation projects, especially GRC/TPRM tools

  • Experience in process design, documentation, and improvement

  • Experience evaluating, implementing, or using GRC platforms and/or specialized TPRM tools

  • Experience with application of regulatory frameworks relevant to aerospace and defense (e.g., NIST SP 800-171, CMMC, DFARS, ITAR)

  • Experience with contract review and negotiation related to cybersecurity requirements

  • Experience with project management principles and practices

  • Experience working and communicating asynchronously with teammates and cross-functional partners

Drug Free Workplace:

Boeing is a Drug Free Workplace where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies.

Pay & Benefits:

At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.  

The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.

The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.

Pay is based upon candidate experience and qualifications, as well as market and business considerations.

Summary pay range: $107,100 – $167,900

Language Requirements:

Not Applicable

Education:

Not Applicable

Relocation:

Relocation assistance is not a negotiable benefit for this position.

Export Control Requirement:

This position must meet export control compliance requirements. To meet export control compliance requirements, a “U.S. Person” as defined by 22 C.F.R. §120.15 is required. “U.S. Person” includes U.S. Citizen, lawful permanent resident, refugee, or asylee.

Safety Sensitive:

This is not a Safety Sensitive Position.

Security Clearance:

This position requires the ability to obtain a U.S. Security Clearance for which the U.S. Government requires U.S. Citizenship. An interim and/or final U.S. Secret Clearance Post-Start is required.

Visa Sponsorship:

Employer will not sponsor applicants for employment visa status.

Contingent Upon Award Program

This position is not contingent upon program award

Shift:

Shift 1 (United States of America)

Stay safe from recruitment fraud! The only way to apply for a position at Boeing is via our Careers website. Learn how to protect yourself from recruitment fraud - Recruitment Fraud Warning

Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.

EEO is the law

Boeing EEO Policy

Request an Accommodation

Applicant Privacy


Boeing Participates in E – Verify

Right to Work Statement

Boeing Glassdoor Company Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Boeing DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Boeing
Boeing CEO photo
David Calhoun
Approve of CEO

Average salary estimate

$137500 / YEARLY (est.)
min
max
$107100K
$167900K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Supply Chain Cybersecurity Specialist, Boeing

Join The Boeing Company as a Senior Supply Chain Cybersecurity Specialist at our Everett, WA location and be part of a dynamic team committed to safeguarding our assets across a complex global supply chain! In this critical role, you will be driving the growth of our Third-Party Risk & Resilience Program Management Office, collaborating closely with Procurement, Legal, Enterprise Security, and other key players to manage cybersecurity risks throughout the third-party lifecycle. This position isn’t just about mitigating risks; it’s about making a meaningful impact as part of our ongoing transformation projects and operational duties. You’ll need a sharp understanding of cybersecurity principles, particularly related to NIST frameworks, and you’ll exercise autonomy in your decision-making while influencing stakeholders. Your expertise will be crucial in developing processes and tools for risk management, conducting comprehensive risk assessments, and advising on cybersecurity protocols to protect our critical assets. Whether you're designing assessments, validating supplier compliance, or helping enhance our technology platform, your contributions will shape the future of our C-SCRM program. We are looking for a self-driven team player who thrives in a high-volume environment. With a chance to train internal stakeholders and communicate with suppliers, you will help ensure that Boeing maintains the highest standard of cybersecurity. If you’re eager to be part of a team that’s leading the charge in supply chain cybersecurity, we invite you to explore this exciting opportunity with us!

Frequently Asked Questions (FAQs) for Senior Supply Chain Cybersecurity Specialist Role at Boeing
What are the primary responsibilities of a Senior Supply Chain Cybersecurity Specialist at The Boeing Company?

As a Senior Supply Chain Cybersecurity Specialist at The Boeing Company, your primary responsibilities include developing and executing the Third-Party Risk Management governance model, assessing cybersecurity risks throughout the supply chain, and collaborating with various departments to ensure supplier compliance with cybersecurity protocols. This encompasses everything from establishing risk assessment methodologies to negotiating cybersecurity clauses during procurement activities.

Join Rise to see the full answer
What skills and qualifications are required for the Senior Supply Chain Cybersecurity Specialist position at Boeing?

To excel as a Senior Supply Chain Cybersecurity Specialist at Boeing, candidates typically need over three years of experience in cybersecurity, risk management, or compliance, along with a solid understanding of frameworks like NIST 800-161. Preferred qualifications include a bachelor's degree in a related field and relevant cybersecurity certifications such as CISSP, CISM, or CRISC to effectively manage and communicate complex cybersecurity strategies.

Join Rise to see the full answer
How does The Boeing Company support professional development for Senior Supply Chain Cybersecurity Specialists?

At The Boeing Company, professional development is a priority for Senior Supply Chain Cybersecurity Specialists. You will have access to training resources that are essential for advancing your skills in risk management, cybersecurity frameworks, and vendor negotiations. Additionally, you’ll engage in continuous learning opportunities that aid in adapting to evolving cybersecurity landscapes, ensuring that your contributions remain valuable and impactful.

Join Rise to see the full answer
What role does collaboration play in the Senior Supply Chain Cybersecurity Specialist position at Boeing?

Collaboration is critical for a Senior Supply Chain Cybersecurity Specialist at The Boeing Company, as this role requires working closely with teams in Procurement, Legal, and Enterprise Security. You’ll need to effectively communicate risks and solutions, facilitate discussions on cybersecurity protocols, and ensure that all stakeholders are aligned in protecting Boeing’s assets throughout the supply chain.

Join Rise to see the full answer
What impact does a Senior Supply Chain Cybersecurity Specialist have on Boeing's overall cybersecurity posture?

A Senior Supply Chain Cybersecurity Specialist significantly enhances Boeing's overall cybersecurity posture by implementing robust risk management strategies, conducting thorough risk assessments on suppliers, and ensuring compliance with established cybersecurity frameworks. By actively participating in the development and refinement of processes and tools, you’ll directly contribute to a resilient and secure supply chain, ultimately protecting critical assets and operations.

Join Rise to see the full answer
Common Interview Questions for Senior Supply Chain Cybersecurity Specialist
Can you describe your experience with risk management frameworks, particularly NIST frameworks?

In your response, focus on specific projects where you’ve applied NIST frameworks such as NIST 800-161 or NIST 800-171. Explain how you've used these frameworks to assess risks, develop mitigation strategies, and communicate findings to stakeholders. Highlight any quantifiable outcomes from your efforts to illustrate your impact.

Join Rise to see the full answer
What strategies do you use to assess cybersecurity risks in third-party suppliers?

When assessing cybersecurity risks in third-party suppliers, I employ a combination of methodologies, including conducting comprehensive risk assessments and utilizing questionnaires tailored to the supplier's environment. I systematically analyze threat intelligence and the suppliers' past cyber incidents to prioritize risk areas and develop actionable mitigation plans.

Join Rise to see the full answer
How do you handle communication with non-technical stakeholders regarding cybersecurity issues?

To effectively communicate with non-technical stakeholders, I focus on simplifying complex concepts by using relatable analogies and visuals. I ensure to relate the importance of cybersecurity to their specific interests or departments, emphasizing how risks may directly affect their operations and the overall business.

Join Rise to see the full answer
Describe a challenge you've faced while managing supply chain risk. How did you overcome it?

In a previous role, I faced a challenge when a critical supplier had compliance issues. I collaborated with the supplier to identify deficiencies and created a tailored action plan to address their vulnerabilities. By maintaining open communication and providing support, we were able to meet compliance standards and enhance their cybersecurity posture.

Join Rise to see the full answer
What tools have you used for Third-Party Risk Management, and how have they benefited your assessments?

I've utilized several tools for Third-Party Risk Management, such as GRC platforms. These tools have streamlined the risk assessment process by automating data collection and providing a structured approach to scoring and evaluating risks. Their ability to maintain updated supplier information has significantly improved decision-making and compliance tracking.

Join Rise to see the full answer
How do you stay updated on the latest cybersecurity threats relevant to supply chains?

I stay updated on the latest cybersecurity threats by subscribing to industry newsletters, attending relevant webinars, and participating in professional cybersecurity forums. Additionally, I regularly review threat intelligence reports that focus on supply chain vulnerabilities to anticipate potential risks and proactively address them.

Join Rise to see the full answer
What is your approach to negotiating cybersecurity clauses in contracts?

In negotiating cybersecurity clauses, my approach involves thorough preparation, understanding industry standards and regulations, and knowing the specific cybersecurity needs of both Boeing and the supplier. I emphasize creating mutually beneficial agreements that ensure compliance while being realistic about the supplier's capabilities.

Join Rise to see the full answer
How do you ensure the effective documentation of risk management processes?

To ensure effective documentation, I adhere to a systematic approach that includes clear templates for risk assessments and developing well-defined procedures. I also foster collaboration with team members to maintain accuracy and ensure that all documentation reflects current processes and best practices.

Join Rise to see the full answer
Can you provide an example of how you've implemented a new risk management process?

In my last role, I implemented a new risk management process by first conducting a comprehensive analysis of existing protocols. I gathered stakeholder input to design a more effective framework that utilized automated assessments. After piloting the process and revising based on feedback, it was officially integrated into our operations, leading to improved compliance rates.

Join Rise to see the full answer
What role do you think automation plays in supply chain cybersecurity risk management?

Automation plays a crucial role in enhancing supply chain cybersecurity risk management. It streamlines repetitive tasks like assessments and reporting, reducing manual errors while allowing for real-time analysis of vulnerabilities. By leveraging automation, teams can focus on strategic decision-making and risk mitigation efforts, thus elevating overall cybersecurity posture.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Join Boeing Communications to craft engaging content that tells compelling stories for employees while utilizing your video and communication skills.

Photo of the Rise User
Posted 5 days ago

As a senior Cost Account Management Support Analyst, you will play a pivotal role in supporting Boeing's H47 Chinook program through technical data management and alignment with engineering standards.

Photo of the Rise User
Posted 12 days ago

Join the Georgia Client’s Office of Information Technology as a Cybersecurity Analyst, where you will enhance the security posture of the organization through monitoring and managing cybersecurity tools.

Photo of the Rise User
Posted 6 days ago

Join Fortified Health Security as a Third Party Risk Analyst, where you'll manage TPRM services and ensure compliance with regulatory standards in the healthcare industry.

Photo of the Rise User

The Pennsylvania Turnpike Commission is looking for an IT Training Analyst to enhance training through innovative learning options and materials.

CodeNinja Remote No location specified
Posted 10 days ago

A dynamic role as a Denodo Administrator awaits, where you'll ensure the robustness of our data virtualization infrastructure.

Photo of the Rise User
Posted 11 days ago

Join Colibri as a Director of IT to spearhead innovative strategies in CRM and eCommerce while fostering team collaboration and growth.

Photo of the Rise User
Posted 5 days ago

Join Leidos as an Insider Threat Senior Analyst to support the Social Security Administration's mission in safeguarding sensitive data.

Photo of the Rise User
Posted 9 days ago

As a Sr. Principal AI Security Researcher, you'll drive innovations in cybersecurity at Palo Alto Networks by addressing the latest threats to AI systems.

Sluhn Hybrid Allentown, PA - 1110 American Parkway
Posted 5 days ago

St. Luke's University Health Network seeks an experienced Director to lead IT business management and operations focused on enhancing healthcare delivery through technology.

Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Rapid Growth
Passion for Exploration
Dare to be Different
Dental Insurance
Life insurance
Health Savings Account (HSA)
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Mental Health Resources
401K Matching
Paid Time-Off
Snacks
Photo of the Rise User
Posted 8 months ago
Photo of the Rise User
Inclusive & Diverse
Diversity of Opinions
Work/Life Harmony
Dare to be Different
Reward & Recognition
Empathetic
Take Risks
Growth & Learning
Transparent & Candid
Mission Driven
Passion for Exploration
Feedback Forward
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Learning & Development
Paid Time-Off
Maternity Leave
Social Gatherings
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)

The story of our company is woven together from thousands of individual stories of engineers and technicians. Scientists and thinkers. Innovators and dreamers. Equity, diversity and inclusion are crucial to our employees, our stakeholders, and our...

1057 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 19, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!