About this role
Job Req ID: 30370
About Supermicro:
Supermicro® is a Top Tier provider of advanced server, storage, and networking solutions for Data Center, Cloud Computing, Enterprise IT, Hadoop/ Big Data, Hyperscale, HPC and IoT/Embedded customers worldwide. We are the #5 fastest growing company among the Silicon Valley Top 50 technology firms. Our unprecedented global expansion has provided us with the opportunity to offer a large number of new positions to the technology community. We seek talented, passionate, and committed engineers, technologists, and business leaders to join us.
Job Summary:
Supermicro is seeking a Supply Chain Risk & Trade Compliance Specialist to establish and operate a dedicated Federal Supply Chain Risk Management (SCRM) and trade compliance program for SMCI Federal. Reporting to the Director of Federal Compliance, this role bridges federal supply chain security, export controls, and vendor risk governance. This position operates as a dedicated federal resource distinct from, but closely coordinated with, existing commercial Global Trade Compliance (GTC) operations. You will own bill-of-materials tracking (HBOM/SBOM), supplier risk scoring across security and non-security domains, restricted-vendor screening (e.g., NDAA Section 889/1260H), export classifications (ITAR/EAR), and country-of-origin verification required to secure government and defense sales pipelines.
Essential Duties and Responsibilities:
Supply Chain Risk Management (SCRM) Program & Vendor Risk Scoring
- Program Build: Build, operate, and maintain a dedicated SCRM program for federal-bound products, including complete Hardware Bill of Materials (HBOM) and Software Bill of Materials (SBOM) tracking across active federal server and storage platforms.
- Vendor Tiering & Composite Scoring: Develop and maintain a vendor criticality tiering model and a composite risk-scoring methodology spanning security posture, component/supply chain integrity, trade compliance, financial viability, and geopolitical/concentration risk — driving differentiated assessment depth and reassessment cadence by tier.
Supplier Vetting & Vendor Screening
- Core Vetting: Conduct third-party supply chain risk assessments, including supplier cybersecurity posture evaluations, counterfeit parts prevention reviews, restricted-vendor screening (NDAA Section 889/1260H / Entity List), and country-of-origin (TAA/BAA) verification.
- Extended Risk Domains: Incorporate financial viability monitoring, sub-processor/Nth-party visibility, and supplier business continuity/disaster recovery capability into vendor risk assessments; leverage continuous, outside-in security ratings tools to supplement self-reported vendor data.
- Repeatable Screening: Embed repeatable SCRM and trade screening gates into the federal product request process, so new federal SKUs are screened before they're built, not after.
Federal Trade Compliance & Export Controls
- Export Classification: Perform technical Export Control Classification (ECCN and ITAR USML categorization) for federal product lines.
- Licensing & Screening: Support federal export licensing, technology diversion monitoring, and regulatory compliance reviews under EAR and ITAR.
Facility Reviews, Contracts & Governance
- Facility & On-Site Reviews: Conduct annual supply chain, manufacturing, and facility security reviews; document audit findings and track remediation plans across hardware components and sub-tier suppliers.
- Legal & Contract Coordination: Partner with Legal on vendor contract terms — audit rights, data handling and residency requirements, insurance minimums, and breach-notification flow-down — to ensure SCRM requirements are contractually enforceable, not just operationally tracked.
- Vendor Governance: Participate in a cross-functional vendor risk review process (Legal, Security/GRC, business) supporting risk acceptance, remediation, or termination decisions.
Cross-Functional Integration & Monitoring
- GTC Coordination: Coordinate with the existing commercial Global Trade Compliance function to extend and connect — rather than duplicate — trade compliance capability for federal-specific requirements.
- Program Visibility: Collaborate with Procurement, Engineering, and Operations to maintain audit-ready records and execute ongoing supplier reassessment cycles, with dashboards for leadership visibility.
Qualifications:
- Education: Bachelor's degree in Supply Chain Management, International Trade, Computer Science, Engineering, or related field.
- Experience: 5+ years of direct experience in supply chain risk management, federal trade compliance, export controls, or defense supply chain assurance.
- Regulatory Expertise: Deep expertise in SCRM frameworks (NIST SP 800-161), Federal Acquisition Regulation (FAR/DFARS) supply chain clauses, NDAA restricted vendor rules, Export Administration Regulations (EAR), and International Traffic in Arms Regulations (ITAR).
- Technical Aptitude: Strong proficiency in evaluating Hardware/Software Bills of Materials (HBOM/SBOM), conducting component trace-back analysis, and navigating complex, multi-tier supply chain networks.
- Ability to design and operate a risk-scoring methodology that synthesizes multiple, non-uniform risk domains into a single, actionable output.
Preferred Qualifications
- Credentials: Certified Supply Chain Professional (CSCP), CMMC RP, or specialized Trade Compliance Certifications.
- Systems: Hands-on experience with SAP, SAP GTS, enterprise ERP platforms, or automated restricted-party screening tools; familiarity with continuous vendor security rating platforms (e.g., BitSight, SecurityScorecard).
- Industry: Background in server hardware, electronics manufacturing, semiconductor, or aerospace & defense supply chains.
Salary Range
$101,000 - $132,000
The salary offered will depend on several factors, including your location, level, education, training, specific skills, years of experience, and comparison to other employees already in this role. In addition to a comprehensive benefits package, candidates may be eligible for other forms of compensation, such as participation in bonus and equity award programs.
EEO Statement
Supermicro is an Equal Opportunity Employer and embraces diversity in our employee population. It is the policy of Supermicro to provide equal opportunity to all qualified applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status or special disabled veteran, marital status, pregnancy, genetic information, or any other legally protected status.