Job Description
We are seeking a Senior Product Owner IV, Enterprise Open Source Management Program to lead the design and implementation planning for an enterprise open source governance and software supply chain security strategy. The ideal candidate will have strong experience in software supply chain security, open source risk management, and secure software development practices and a proven ability to operate across stakeholder groups to translate strategy into executable roadmaps at enterprise scale.
Responsibilities
- Lead the design and development of an Enterprise Open Source Management Program, including governance, operating model, scope, roadmap, and implementation strategy.
- Facilitate collaboration among Cyber Security, Software Engineering, DevOps, Asset Management, Architecture, Risk Management, Legal, and Compliance to establish program requirements and priorities.
- Evaluate current-state capabilities, identify gaps, and define future-state processes supporting open source governance and software supply chain security.
- Develop program proposals, business cases, staffing plans, budget estimates, and implementation roadmaps for executive review and approval.
- Define enterprise processes for open source software intake, approval, exception management, and ongoing governance activities.
- Recommend policies, standards, controls, and procedures related to open source management and software supply chain risk.
- Support development of a Software Bill of Materials (SBOM) strategy to improve visibility into components, dependencies, and risks.
- Lead proofs of concept and pilot implementations to validate processes, technologies, and operating models.
- Assess tooling, conduct vendor reviews, and provide solution recommendations aligned to program objectives.
- Partner with development teams to integrate program controls into existing SDLC and engineering workflows.
- Drive stakeholder alignment via workshops, working groups, governance forums, and executive discussions.
- Provide transparent communications on status, recommendations, risks, dependencies, and milestones.
- Monitor industry trends, emerging threats, regulatory developments, and leading practices in OSS governance and supply chain security.
- Create educational materials and guidance that support adoption of program principles across the enterprise.
- Influence outcomes and decisions across matrixed teams without direct authority.
Required Skills & Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Business, or related field, or equivalent experience.
- 5+ years in cybersecurity, application security, software development, technology governance, software supply chain security, or DevSecOps.
- Experience leading complex cross-functional initiatives with multiple stakeholder groups and competing priorities.
- Ability to operate in ambiguous environments and convert strategy into actionable implementation plans.
- Strong written and verbal communication skills, including executive presentations and business cases.
- Proven influence without authority across matrixed organizations.
- Understanding of SDLC practices and modern software delivery methodologies.
Preferred Skills
- Experience with open source governance platforms, SBOM generation tools, and supply chain security solutions.
- Background in regulatory readiness, risk management frameworks, and policy development.
Why BCforward?
- At BCforward, we believe in advancing lives and careers. When you join our team, you gain access to:
- Competitive compensation and benefits
- Opportunities for growth with global clients
- A supportive, inclusive culture that values innovation and people
- Exposure to cutting-edge technologies and projects
About Our Commitment
BCforward is an equal opportunity employer. We value diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, age, disability, or veteran status.