What are the responsibilities and job description for the Supply Chain Risk Manager position at General Atomics and Affiliated Companies?
General Atomics Aeronautical Systems, Inc. (GA-ASI), an affiliate of General Atomics, is a world leader in proven, reliable remotely piloted aircraft and tactical reconnaissance radars, as well as advanced high-resolution surveillance systems.
This position is responsible for identifying, assessing, and mitigating supply chain and cybersecurity risks that may impact program execution, compliance, and mission assurance. The role serves as a liaison between the supply chain organization, program management, engineering, cybersecurity, and external suppliers to address supply chain risk, operational resilience, and regulatory compliance concerns. The position continually reviews supplier and product line risk posture, assesses emerging issues, and develops mitigation strategies to support production, quality, schedule, and customer requirements. The role is responsible for decisions that influence program outcomes, supplier performance, and compliance posture, where failure to effectively manage risk may result in program delays, increased cost, or regulatory exposure.
DUTIES AND RESPONSIBILITIES:
This position is responsible for identifying, assessing, and mitigating supply chain and cybersecurity risks that may impact program execution, compliance, and mission assurance. The role serves as a liaison between the supply chain organization, program management, engineering, cybersecurity, and external suppliers to address supply chain risk, operational resilience, and regulatory compliance concerns. The position continually reviews supplier and product line risk posture, assesses emerging issues, and develops mitigation strategies to support production, quality, schedule, and customer requirements. The role is responsible for decisions that influence program outcomes, supplier performance, and compliance posture, where failure to effectively manage risk may result in program delays, increased cost, or regulatory exposure.
DUTIES AND RESPONSIBILITIES:
- The Supply Chain Risk Manager conducts structured supply chain risk assessments for assigned product lines, evaluating supplier criticality, single points of failure, operational resilience, and cybersecurity posture. The role develops and implements mitigation strategies to address identified risks and supports program and supply chain leadership in risk informed decision making.
- The position serves as a primary point of coordination between supply chain organizations and program offices, ensuring alignment on risk priorities, mitigation plans, and program requirements. This includes interpreting and administering policies, processes, and procedures that impact supply chain risk management activities.
- The role researches, identifies, and validates supply chain risk signals using internal data sources, supplier information, and external intelligence tools. These insights are used to identify emerging risks, assess potential impact, and recommend corrective actions.
- The Supply Chain Risk Manager interfaces directly with suppliers to communicate risk findings, understand root causes, and coordinate remediation activities. This includes supporting suppliers in addressing cybersecurity gaps and strengthening compliance with applicable contractual and regulatory requirements.
- The position supports the third-party risk management program by collecting, reviewing, and assessing supplier cybersecurity compliance information. The role works closely with cybersecurity and compliance teams to ensure supplier risk is accurately documented, monitored, and escalated as appropriate.
- The role develops and maintains processes to align supply chain risk management practices with NIST SP 800 161 and applicable Department of War cybersecurity requirements. This includes integrating cybersecurity supply chain risk management into existing supply chain and governance workflows.
- The Supply Chain Risk Manager prepares and delivers progress reports, risk assessments, briefings, and presentations to internal stakeholders and customers. The role effectively communicates risk status, trends, and mitigation strategies to technical and non-technical audiences.
- The position ensures sensitive and proprietary information, including Controlled Unclassified Information, is properly identified and handled in accordance with contractual, regulatory, and company requirements.
- The role is responsible for ensuring all applicable laws, regulations, and other obligations are observed wherever and whenever business is conducted on behalf of the Company. The position ensures work is accomplished in a safe manner in accordance with established operating procedures and practices.
- Additional functions include other duties as assigned or required.
Job Qualifications
- Typically requires a Bachelor’s degree in business, supply chain, cybersecurity, engineering, or a related discipline and eleven or more years of progressively complex experience in supply chain, risk management, cybersecurity, or defense related program support, with at least five of those years in supply chain. Equivalent experience may be substituted in lieu of education.
- Must demonstrate a strong understanding of supply chain risk management principles, cybersecurity requirements within the defense industrial base, and third party risk management practices. This includes working knowledge of DFARS clauses 252.204 7012, 252.204 7020, and 252.204 7021, as well as familiarity with NIST SP 800 171, NIST SP 800 161, and the Cybersecurity Maturity Model Certification framework.
- Must possess the ability to identify and assess risk, analyze and interpret data, and develop practical mitigation strategies for complex and non-routine issues. Strong analytical, communication, documentation, presentation, and interpersonal skills are required.
- Must demonstrate the ability to work independently, lead cross functional efforts, and influence stakeholders across organizational boundaries. Experience interfacing directly with suppliers and supporting remediation activities is required.
- Candidate must either have, or be eligible to obtain, a Secret clearance.
- Familiarity with enterprise and risk management tools such as SAP, Optro (formerly AuditBoard), Altana, Bitsight, Resilinc, and Microsoft Office applications is desired.
- Must be able to work extended hours and travel as required.
Job Category
Contracts/Sub Contracts/Purchasing
Experience Level
Senior (8 years)
Workstyle
Onsite
Full-Time/Part-Time
Full-Time Salary
Pay Range Low
100,290
Pay Range High
183,098
Travel Percentage Required
0% - 25%
Relocation Assistance Provided?
No
US Citizenship Required?
Yes
Clearance Required?
Desired
Clearance Level
Secret