1

Supply Chain Risk Management Jobs in Houston, TX

Head of Supply Chain

Houston, TX ยท On-site +1

$173K - $196K/yr

Establish supply chain risk management processes for long-lead, sole-source, and ITAR-controlled items * Represent supply chain in program reviews, EAC/ETC processes, and executive S&OP * Partner ...

Director Supply Chain

Houston, TX ยท On-site

$173K - $196K/yr

Director Supply Chain (M4) For more than three decades, Crown Castle has led the way in shared ... Establish and oversee third-party risk management programs addressing supplier financial health ...

Director Supply Chain

Houston, TX

$173K - $196K/yr

Director Supply Chain (M4) For more than three decades, Crown Castle has led the way in shared ... Establish and oversee third-party risk management programs addressing supplier financial health ...

Supply Chain Execution Manager

Houston, TX ยท On-site

$99K - $232K/yr

... management - Applying analytical thinking to solve complex supply chain issues - Leading supply chain transformation initiatives - Managing supply chain risk effectively Travel Requirements Up to 60 ...

Risk Management & Process Improvement Identify material shortages, supplier issues, and operational ... Contribute to broader supply chain scaling efforts as OCI continues to grow. Required ...

next page

Showing results 1-20

Supply Chain Risk Management information

See Houston, TX salary details

$38.7K

$95.8K

$139.4K

How much do supply chain risk management jobs pay per year?

As of Aug 12, 2026, the average yearly pay for supply chain risk management in Houston, TX is $95,798.00, according to ZipRecruiter salary data. Most workers in this role earn between $76,400.00 and $114,600.00 per year, depending on experience, location, and employer.

What does a supply chain risk management do?

A supply chain risk management professional identifies and assesses potential disruptions in the supply chain, such as supplier failures, natural disasters, or geopolitical issues. They develop strategies to mitigate these risks, ensuring continuity and resilience in supply operations, often using tools like risk assessment software and data analysis. This role requires strong analytical skills and knowledge of supply chain processes.

What are the most common challenges faced in supply chain risk management?

Supply Chain Risk Management professionals frequently deal with challenges such as disruptions from geopolitical events, natural disasters, supplier reliability issues, and fluctuating market conditions. Balancing cost efficiency with resilience, maintaining real-time visibility across complex networks, and coordinating responses among multiple internal and external partners are also key aspects of the job. You may need to anticipate and respond quickly to risks, requiring both analytical forecasting and decisive action under pressure. Overcoming these challenges involves continuous monitoring, adaptation of strategies, and effective cross-departmental collaboration, which can make the work dynamic and rewarding for those who enjoy problem-solving in fast-paced environments.

What is supply chain risk management?

A Supply Chain Risk Management job involves identifying, assessing, and mitigating risks that could disrupt the supply chain. Professionals in this role analyze potential threats such as supplier failures, geopolitical issues, cybersecurity risks, and natural disasters. They develop contingency plans, implement risk mitigation strategies, and work with suppliers and internal teams to ensure business continuity. The goal is to minimize disruptions, optimize resilience, and protect the organization's operational and financial performance.

What are the key skills and qualifications needed to thrive in supply chain risk management?

To thrive in Supply Chain Risk Management, you need strong analytical skills, an understanding of logistics and risk assessment, and a relevant bachelor's degree (such as supply chain management, business, or engineering). Familiarity with ERP systems, risk analysis software, and certifications like Certified Supply Chain Professional (CSCP) or Certified in Risk and Information Systems Control (CRISC) are commonly required. Excellent problem-solving abilities, effective communication, and adaptability help you collaborate with various stakeholders and navigate changing circumstances. These skills are vital for proactively identifying, evaluating, and mitigating risks to ensure stable and resilient supply chain operations.

What job categories do people searching Supply Chain Risk Management jobs in Houston, TX look for? The top searched job categories for Supply Chain Risk Management jobs in Houston, TX are:
Infographic showing various Supply Chain Risk Management job openings in Houston, TX as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 11% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $95,798 per year, or $46.1 per hour.

Program Manager, Cybersecurity Supply Chain Risk Management

NuScale Power

Houston, TX โ€ข On-site

$136K/yr

Full-time

Re-posted 28 days ago


Job description

Job Summary:
NuScale Power is seeking a Program Manager for their Cybersecurity Supply Chain Risk Management program. This role involves leading an interdisciplinary team to establish, govern, and implement a comprehensive cybersecurity program focusing on both Operational Technology and Information Technology, ensuring compliance with various NIST standards and nuclear sector guidance.
Responsibilities:
โ€ข Develop and manage the enterprise Cโ€‘SCRM program for OT (digital I&C platforms, field devices, PLCs, networked sensors, safetyโ€‘related cyber systems) and IT (commercial software, COTS hardware, servers, cloud services, network equipment).
โ€ข Create and maintain policies, standards, and procedures aligned to NIST SP 800โ€‘161 and NIST SP 800โ€‘53 SR, SA, RA, PM control families.
โ€ข Integrate nuclear sector guidance (NEI 08โ€‘09, RG-5.71, RIS 2015โ€‘08 Rev 1) into supply chain expectations for safetyโ€‘related and securityโ€‘related digital systems.
โ€ข Establish supplier risk tiering and criticality criteria covering safetyโ€‘related functions, digital asset categorization, and impacts on plant operations and corporate environments.
โ€ข Lead the Cโ€‘SCRM Steering Committee and drive alignment between Supply Chain, Engineering, Plant Services Cyber Security, Legal, QA, and Supplier Quality Assurance
โ€ข Oversee the complete supplier lifecycle: inherent risk assessments, due diligence, technical evaluation, contracting, onboarding, continuous monitoring, reassessment, and offboarding.
โ€ข Ensure contractual language includes security requirements, SBOM/MBOM deliverables, secure SDLC expectations, vulnerability disclosure procedures, and subโ€‘tier supplier transparency.
โ€ข Implement structured workflows for thirdโ€‘party risk assessments that incorporate NIST SP 800โ€‘53 SR/SA obligations, NEI 08โ€‘09 defensive architecture principles, and NIST SP 800โ€‘82 OT constraints.
โ€ข Coordinate supplier audits and assessments, ensuring traceability of security commitments and evidence of control effectiveness.
โ€ข Define and enforce minimum security requirements for suppliers, including software integrity controls, code signing, firmware assurance, and supply chain provenance.
โ€ข Evaluate SBOMs for software, firmware, and embedded system components; drive vulnerability assessment and remediation plans based on exploitability in OT/ICS contexts.
โ€ข Oversee technical acceptance processes such as Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT), configuration verification, deterministic communication requirements, and architecture compliance checks for digital I&C components.
โ€ข Support secure engineering design reviews for systems that integrate COTS hardware, virtualized servers, network infrastructure, and embedded digital components.
โ€ข Coordinate risk analysis and compensating control strategies where patching or upgrading is constrained in OT environments.
โ€ข Perform qualitative and quantitative supply chain risk assessments covering vendor security posture, component integrity, lifecycle support, and cyber threat exposure.
โ€ข Document risk findings, residual risk calculations, and recommended mitigations; present clear decision options to executive leadership.
โ€ข Develop Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) to track program maturity and supplier health.
โ€ข Maintain centralized risk evidence repositories supporting compliance and audit readiness.
โ€ข Ensure the Cโ€‘SCRM program adheres to NIST SP 800โ€‘161, NIST SP 800โ€‘53, NIST SP 800โ€‘82, NEI 08โ€‘09, RG 5.71, and RIS 2015โ€‘08 Rev 1 requirements.
โ€ข Prepare for internal audits, external assessments, and US NRC reviews; provide documentation showing control compliance and technical baselines.
โ€ข Coordinate with Engineering and Plant Services Cyber Security to ensure digital I&C assets meet expectations for secure procurement, configuration control, and lifecycle management.
โ€ข Develop training and communication materials to improve supply chain security awareness across engineering, operations, IT, and procurement teams.
โ€ข Coach project managers, system owners, and procurement professionals on secure supplier interactions and risk evaluation processes.
โ€ข Communicate supply chain threats, vulnerabilities, mitigations, and accepted risks to senior leadership in clear, actionable terms.
Qualifications:
Required:
โ€ข A minimum of a bachelorโ€™s degree in Cybersecurity, Computer Science, Engineering, or related field is required.
โ€ข Alternatively, an additional 4 years (12 years total) of equivalent full-time nuclear industry cyber security experience may be considered in lieu of a degree.
โ€ข NSCP 800-161 Foundation Certificate or equivalent is required.
โ€ข A minimum of 8 years of full-time cybersecurity experience with a focus on supply chain risk, vendor management, or secure procurement is required.
โ€ข Must have experience across OT/ICS and IT cybersecurity, including digital I&C systems, embedded controllers, industrial networking, and enterprise IT infrastructure.
โ€ข Detailed knowledge of NIST SP 800โ€‘161, NIST SP 800โ€‘82, and NIST SP 800โ€‘53 control families related to supply chain, assurance, and risk assessment (SR/SA/RA/PM).
โ€ข Familiarity with nuclear regulatory guidance including NEI 08โ€‘09, RG 5.71, and RIS 2015โ€‘08 Rev 1.
โ€ข Demonstrated ability to lead crossโ€‘disciplinary teams and manage complex supplier ecosystems.
โ€ข Strong written and verbal communication skills; ability to influence at all organizational levels.
โ€ข Eligible to work under Department of Energy 10 CFR Part 810.
Preferred:
โ€ข Professional certifications such as CISSP, CISM, CRISC, GICSP, CISA, or ISA/IEC 62443 certificates are preferred.
โ€ข Experience in nuclear energy, critical infrastructure, or similarly regulated sectors preferred.
โ€ข Working knowledge of SBOM formats (SPDX, CycloneDX) and secure software development lifecycle (SSDLC) practices (e.g., NIST SP 800-218).
โ€ข Understanding of OT protocols, deterministic network architectures, physical/functional separation concepts, and secure digital I&C implementation (e.g., Regulatory Guide 1.152, Revision 3, Regulatory Position C.2).
Company:
NuScale Power has developed a small modular reactor (SMR) to supply energy for electrical generation and other heat process applications. Founded in 2007, the company is headquartered in Corvallis, USA, with a team of 201-500 employees. The company is currently Growth Stage.