Principal Software Engineer (Supply Chain Security)

nineDots.io

Greater London

Hybrid

GBP 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity
Flexible UK working
Health & wellbeing benefits
Generous annual leave
Professional development support

Job summary

nineDots.io is seeking a Principal Software Engineer to lead the Supply Chain Trust effort, building the next generation of provenance for software delivery. You will own greenfield capabilities, shape architecture, and drive security-focused product development for enterprise customers.

You will mentor engineers, define data models for artifact relationships, and deliver scalable ingestion and validation pipelines across CI/CD and artifact registries.

Qualifications

  • Deep backend, platform, or security engineering experience in a product environment.
  • Proven ability to own complex product capabilities beyond DevOps/SRE.
  • Experience designing scalable ingestion pipelines for high-volume, evolving data.
  • Strong data modelling for metadata and graph relationships.
  • Experience building APIs for enterprise or partner integrations.
  • Familiarity with multi-tenant SaaS security, access control, and auditability.

Responsibilities

  • Designing and shipping provenance ingestion services for CI/CD systems, artifact registries, signed bundles, and customer-uploaded artifacts.
  • Processing provenance and attestation formats including SLSA, in-toto, SBOM attestations, and Sigstore bundles.
  • Designing storage models for signed metadata, artifact graphs, build relationships, and downstream usage.
  • Building validation engines that verify cryptographic integrity and evaluate attestations against customer trust policies.
  • Developing reliable APIs that make provenance data queryable, auditable, and useful.
  • Solving high-volume ingestion, storage, performance, and schema-evolution challenges.
  • Working with product, customer success, and engineering to turn enterprise security requirements into valuable product capabilities.
  • Setting a high standard for security, correctness, observability, and technical decision-making.
  • Mentoring engineers through design discussions, documentation, code reviews, and open collaboration.

Skills

Artifact management
Supply chain provenance
Backend engineering
Product ownership
High-volume data pipelines
Data modelling (metadata, graphs)
APIs for enterprise/partners
Security & cryptography
Multi-tenant SaaS security
Communication & collaboration

Education

Tools

Python
AWS
Terraform

Job description

Principal Software Engineer, Supply Chain Security

Artifact Provenance - SLSA - SBOMs - Cryptography - Greenfield Platform Engineering

Join a fast-growing, developer-first technology company building critical infrastructure for modern software delivery.

You will help create the next generation of software supply chain trust systems, giving organisations verifiable traceability from source code to built artifact and every downstream environment in which it is used.

The Role

As a Principal Software Engineer within the Supply Chain Trust team, you will design and build systems that capture, validate, store, and expose software build provenance.

This goes beyond identifying where an artifact came from. Customers need to understand how it was built, what went into it, whether its provenance can be trusted, and where it was used across pipelines and deployments.

You will take substantial ownership of this greenfield capability, influencing its architecture, technical direction, engineering standards, and evolution into a secure product used by enterprise customers.

This is a product engineering role for someone with deep backend, platform, or security experience. It is not a pure DevOps or SRE position.

What You Will Be Doing
  • Designing and shipping provenance ingestion services for CI/CD systems, artifact registries, signed bundles, and customer-uploaded artifacts.
  • Processing provenance and attestation formats including SLSA, in-toto, SBOM attestations, and Sigstore bundles.
  • Designing storage models for signed metadata, artifact graphs, build relationships, and downstream usage.
  • Building validation engines that verify cryptographic integrity and evaluate attestations against customer trust policies.
  • Developing reliable APIs that make provenance data queryable, auditable, and useful.
  • Solving high-volume ingestion, storage, performance, and schema-evolution challenges.
  • Working with product, customer success, and engineering to turn enterprise security requirements into valuable product capabilities.
  • Setting a high standard for security, correctness, observability, and technical decision-making.
  • Mentoring engineers through design discussions, documentation, code reviews, and open collaboration.
What You Need To Succeed
  • Strong knowledge of artifact management, software supply chains, provenance, or build security.
  • Practical familiarity with SLSA, in-toto, Sigstore, DSSE, SBOMs, SPDX, or CycloneDX.
  • An understanding of signing and verification, key material, ECDSA or RSA, certificate chains, keyless signing, and transparency logs.
  • At least five years of production backend engineering experience.
  • Evidence that you have built and owned complex product capabilities, rather than working exclusively in DevOps or SRE.
  • Experience designing scalable ingestion pipelines for varied, high-volume, schema-evolving data.
  • Strong data-modelling skills, particularly for metadata, graphs, and queryable relationships.
  • Experience building and versioning APIs for enterprise customers or third-party integrations.
  • Familiarity with multi-tenant SaaS systems, including isolation, access control, and auditability.
  • Strong communication skills and the judgement to balance thoughtful architecture with iterative delivery.

Python is the preferred backend language, with AWS and Terraform used across the platform. However, deep supply chain security expertise is more important than an exact technology match.

The Opportunity

You will work on a technically demanding problem at the centre of how software is built, secured, and delivered.

The role offers significant greenfield ownership, direct influence over a critical product capability, and the opportunity to help define how organisations establish trust across increasingly complex software supply chains.

The package includes equity, flexible UK working, comprehensive health and wellbeing benefits, generous annual leave, and dedicated support for professional development.

Applicants must be based in the UK and have the right to work independently without sponsorship.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Software Engineer (Provenance)
Staff Software Engineer (Provenance)

SLAMcore • United Kingdom

On-site
GBP 70,000 - 90,000
Equity
Comprehensive health insurance
Professional development budget
+2
Principal Software Engineer, Supply Chain Security — Equity
Principal Software Engineer, Supply Chain Security — Equity

nineDots.io • Greater London

Hybrid
GBP 120,000 - 160,000
Equity
Flexible UK working
Health & wellbeing benefits
+2
Staff Software Engineer: Provenance & Supply Chain Platform
Staff Software Engineer: Provenance & Supply Chain Platform

Cloudsmith • United Kingdom

On-site
GBP 70,000 - 90,000
Equity
Comprehensive health insurance
Professional development budget
+2
Principal Software Engineer (DevSecOps)
Principal Software Engineer (DevSecOps)

United States Digital Space LLC • Luton

Hybrid
GBP 54,000 - 70,000
Senior Application Security Engineer
Senior Application Security Engineer

Cloudsmith • Belfast City District

On-site
GBP 90,000 - 130,000
Equity
Health, dental, vision insurance
Generous annual leave
+3
Lead Software Security Engineer
Lead Software Security Engineer

United States Digital Space LLC • Greater London

Hybrid
GBP 120,000 - 150,000
Pension scheme
Generous holiday allowance
Ongoing learning and professional development
Core IP Security Software Engineer
Core IP Security Software Engineer

G-Research • Greater London

On-site
GBP 70,000 - 110,000
Competitive compensation
Lunch via Just Eat for Business
35 days’ annual leave
+4
Principal Security Architect & Engineering Lead
Principal Security Architect & Engineering Lead

Coba IT Consultants • England

On-site
GBP 81,000 - 86,000
15% bonus
Enhanced pension scheme
Private medical insurance
+5
Security Engineering Lead
Security Engineering Lead

United States Digital Space LLC • Greater London

On-site
GBP 120,000 - 150,000
Equity in an early-stage tech company
25 days holiday plus local public hols
Apple hardware
+4
Product Engineer - Full Stack
Product Engineer - Full Stack

Oritain • Greater London

Hybrid
GBP 70,000 - 95,000
Paid Leave- 35 days
Birthday Off
Volunteering Leave Allowance
+8