
Software Supply Chain Security Manager
- Shakopee, MN
- Permanent
- Full-time
- Vendor and Third-Party Software Oversight
- Lead supplier reviews to improve service levels, costs, and program support.
- Manage and update supplier scorecards and eliminate underperforming suppliers. Develop a framework for assessing and monitoring vendors for security and compliance, collaborating across Procurement, Legal, and Engineering to set security requirements.
- Ensure adherence to secure practices and define risk management KPIs.
- Design for Supply Chain:
- Engage in software sourcing reviews and new product development, supporting design changes and implementation
- Software Supply Chain Security
- Assess risks from open-source and commercial software, oversee approval processes using a centralized analysis system, and support vulnerability management for supply chain threats.
- SBOM Management and Transparency
- Guide vendors in providing compliant SBOMs, collaborate on tools to verify this data, and ensure compliance with regulations like the EU Cyber Resilience Act.
- Compliance and Assurance
- Lead efforts to ensure adherence to global standards, conduct audits, and build an Emerson supplier assurance program incorporating security controls.
- Cross-Functional Collaboration
- Act as an expert in vendor risk management, supporting various departments, and advising on secure software integration and management.
- Bachelor's degree in computer science, Cybersecurity, Supply Chain Management, or a related discipline
- Minimum of 4+ years' experience in software supply chain, product cybersecurity, or third-party risk management
- Strong skills in communication, negotiation, and collaboration, with experience managing vendor relationships and familiarity with SCA tools and SBOM standards
- Ability to travel up to 20%
- Legal authorization to work in the United States
- Experience in industrial automation, medical devices, or embedded product sectors.
- Oracle ERP/MRP knowledge.
- Proven ability to influence others as needed when resources are at a premium to complete required tasks.
- Hands-on knowledge of software provenance, artifact signing, or SLSA levels
- Familiarity with regulatory frameworks including EU CRA, U.S. EO 14028, and IEC 62443.
- Working knowledge of DevSecOps practices and CI/CD pipeline integration.
- Professional certification (C.P.M. or APICS) or equivalent strongly desired.