Title: Senior Cybersecurity/Software Supply Chain Program Lead or Architect
Location: Remote
Duration: 6+ months contract
Cybersecurity + Software Supply Chain + Open-Source Governance + DevSecOps + Program Strategy
TECHNICAL SKILLS
Must Have
Enterprise change management
Influence/coordination across orgs
Program design and management
Software supply chain security, application security, open-source software governance, SBOM concepts and generation, enterprise governance and operating model design, SDLC and software engineering practices, GitHub, Jenkins, Artifactory, cloud environments, stakeholder management, requirements gathering, executive communications, roadmap development, budgeting and staffing planning, cross-functional leadership and influence.
Nice To Have
Open-Source Program Office (OSPO) experience, open-source policy development, software composition analysis (SCA) tools, ServiceNow, vulnerability management, container registries, DevSecOps, secure software development frameworks, exception management processes, technology evaluations and vendor assessments, proof-of-concept facilitation, third-party risk management, regulatory and compliance environments.
Policy Development
Vulnerability Management, open source/supply chain cyber security
JOB DESCRIPTION
Job Profile Summary
Lead the design and implementation planning for Fifth Third's Enterprise Open-Source Management Program and software supply chain security strategy.
We are seeking an experienced cybersecurity and software supply chain professional to help design and establish a new Enterprise Open-Source Management Program. This individual will work across Cyber Security, Software Engineering, DevOps, Asset Management, Architecture, and Technology teams to define the program's operating model, governance framework, roadmap, staffing strategy, budget requirements, and implementation approach.
The ideal candidate possesses a strong understanding of software supply chain security, secure software development practices, and open-source software risk management. Success in this role requires the ability to operate in ambiguous environments, influence across organizational boundaries, facilitate alignment among diverse stakeholder groups, and translate strategic objectives into actionable plans that can be implemented at enterprise scale.
This is a senior individual contributor role responsible for driving the definition and maturation of enterprise capabilities that improve visibility, governance, and risk management associated with open-source software, libraries, packages, containers, and related development artifacts.
General Function
Responsible for defining, prioritizing, and managing the development of an Enterprise Open-Source Management Program that supports the organization's cybersecurity, risk management, and software development objectives.
Will partner with Cyber Security, Software Engineering, DevOps, Asset Management, Risk, Legal, Compliance, Architecture, and Technology leadership teams to establish a strategic roadmap and operational framework for managing open-source software across the enterprise.
Will support the identification, evaluation, and prioritization of people, process, technology, and governance capabilities necessary to create a sustainable program focused on software supply chain security, open-source governance, vulnerability management, and regulatory readiness.
Acts as a facilitator, strategist, and change agent, driving alignment among stakeholders while advancing initiatives that reduce organizational risk and improve visibility into the software ecosystem.
Essential Duties & Responsibilities
Supervisory Responsibilities
None.
This position operates as a senior individual contributor and is expected to lead through influence, collaboration, communication, and subject matter expertise.
Minimum Knowledge, Skills, & Abilities Required