Open Source Security Engineer — Software Supply Chain

Jobtailor

North Carolina

On-site

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a security-focused engineer to lead governance for open source usage and software supply chain controls. You will implement automated gates, manage OSS intake, and drive remediation for vulnerable dependencies while coordinating with CI/CD, DevSecOps, and risk teams.

The role emphasizes policy development, artifact signing, and secure release practices, with on-site collaboration and a strong focus on reducing supply chain risks.

Qualifications

  • Bachelor’s degree or equivalent education, training, and work-related experience.
  • Minimum of 5 years of experience in security engineering or related cybersecurity roles.
  • Advanced knowledge in cybersecurity principles, theories, and concepts.
  • Proven experience in software development lifecycle security practices.
  • Advanced knowledge of threat modeling, security testing, and penetration testing.
  • Experience implementing and managing complex information security technologies.
  • Advanced cybersecurity certifications (e.g., CISSP, CISM, CEH, GIAC) (preferred).
  • Experience with security automation, orchestration, and advanced threat detection tools (preferred).
  • Familiarity with emerging cybersecurity technologies, industry trends, and strategic risk management (preferred).
  • Experience in application security, software supply chain security, DevSecOps, vulnerability management, secure engineering, or related cybersecurity functions (preferred).
  • Strong understanding of open source software governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats (preferred).
  • Working knowledge of OWASP, NIST SSDF, SLSA, and related secure development guidance (preferred).
  • Experience applying software supply chain security practices, including provenance, build integrity, artifact signing, secure package repositories, dependency trust, and CI/CD pipeline hardening (preferred).
  • Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, and developer workflows (preferred).
  • Experience with scripting or automation using Python, PowerShell, Bash, or similar (preferred).
  • Ability to partner with engineering, platform, cloud, risk, audit, and compliance stakeholders (preferred).
  • Ability to translate technical risk into executive-ready reporting, measurable outcomes, and actionable remediation plans (preferred).
  • English language fluency required.

Responsibilities

  • Define policies, standards, and control requirements for approved open source usage, dependency hygiene, SBOM generation, secure package sourcing, and software supply chain risk management.
  • Establish OSS intake, approval, tracking, ownership, version management, vulnerability remediation, end-of-life retirement, and exception governance processes.
  • Design and implement automated CI/CD security gates for curated OSS usage, dependency scanning, license checks, artifact validation, provenance controls, build-time enforcement, and policy-based blocking.
  • Identify and reduce risks from vulnerable dependencies, malicious packages, dependency confusion, typosquatting, compromised maintainers, insecure build artifacts, and unauthorized package sources.
  • Establish controls for trusted package sources, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure release practices.
  • Establish capabilities to detect, assess, and respond to open source supply chain threats, zero-day vulnerabilities, compromised dependencies, and security incidents.
  • Support deployment, tuning, and integration of software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools.
  • Develop reporting on OSS risk posture, remediation velocity, policy exceptions, preventative-control adoption, and high-risk dependency reduction.
  • Create guidance, playbooks, reusable patterns, and consultation models for engineering teams.
  • Partner with CI/CD, DevSecOps, application security, engineering, platform, and risk teams.

Skills

Security Engineering
Vulnerability Management
Threat Modeling
CI/CD Security
Security Automation
Open Source Governance
SAST/DAST
DevSecOps
Communication
Problem-Solving

Education

Bachelor’s degree or equivalent education

Tools

CI/CD Platforms
Software Composition Analysis (SCA)
Package Managers
Build Systems
Artifact Repositories

Job description

Jobtailor is seeking a security-focused engineer to lead governance for open source usage and software supply chain controls. You will implement automated gates, manage OSS intake, and drive remediation for vulnerable dependencies while coordinating with CI/CD, DevSecOps, and risk teams.

The role emphasizes policy development, artifact signing, and secure release practices, with on-site collaboration and a strong focus on reducing supply chain risks.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps & Software Supply Chain Security Engineer
DevSecOps & Software Supply Chain Security Engineer

Jobtailor • Massachusetts

On-site
USD 140,000 - 180,000
Security Engineer II: Open-Source & Supply Chain (Remote)
Security Engineer II: Open-Source & Supply Chain (Remote)

CrowdStrike, Inc. • Virginia (IL)

Remote
USD 100,000 - 145,000
Market leader compensation
Wellness programs
Vacation and holidays
+5
Security Engineer II: Open-Source & Supply Chain Defender
Security Engineer II: Open-Source & Supply Chain Defender

NEPSE Trading • Northern (KY)

Hybrid
USD 120,000 - 180,000
Software Supply Chain Security Specialist
Software Supply Chain Security Specialist

Vanguard • Malvern

On-site
USD 150,000 - 210,000
Security Engineer II — Open-Source & Supply-Chain
Security Engineer II — Open-Source & Supply-Chain

CrowdStrike Holdings, Inc. • Northern (KY)

Hybrid
USD 100,000 - 145,000
Market leader compensation
Wellness programs
Generous vacation
+5
OSS Security & Supply Chain Engineer
OSS Security & Supply Chain Engineer

Crump Life Insurance Svcs Inc • Charlotte (NC)

On-site
USD 105,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+5
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
Open Source Software Security Engineer – Software Supply Chain
Open Source Software Security Engineer – Software Supply Chain

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Senior Software Supply Chain Security Lead
Senior Software Supply Chain Security Lead

STATE STREET CORPORATION • Quincy (MA)

On-site
USD 120,000 - 217,500
401(k) with company match
Comprehensive benefits
OSS-SIRT Engineer Lead: Open Source Security & Automation
OSS-SIRT Engineer Lead: Open Source Security & Automation

The Linux Foundation • United States

On-site
USD 170,000 - 185,000