Open Source Software Security Engineer – Software Supply Chain

Jobtailor

North Carolina

On-site

USD 120,000 - 180,000

Full time

39 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a security-focused engineer to lead governance for open source usage and software supply chain controls. You will implement automated gates, manage OSS intake, and drive remediation for vulnerable dependencies while coordinating with CI/CD, DevSecOps, and risk teams.

The role emphasizes policy development, artifact signing, and secure release practices, with on-site collaboration and a strong focus on reducing supply chain risks.

Qualifications

  • Bachelor’s degree or equivalent education, training, and work-related experience.
  • Minimum of 5 years of experience in security engineering or related cybersecurity roles.
  • Advanced knowledge in cybersecurity principles, theories, and concepts.
  • Proven experience in software development lifecycle security practices.
  • Advanced knowledge of threat modeling, security testing, and penetration testing.
  • Experience implementing and managing complex information security technologies.
  • Advanced cybersecurity certifications (e.g., CISSP, CISM, CEH, GIAC) (preferred).
  • Experience with security automation, orchestration, and advanced threat detection tools (preferred).
  • Familiarity with emerging cybersecurity technologies, industry trends, and strategic risk management (preferred).
  • Experience in application security, software supply chain security, DevSecOps, vulnerability management, secure engineering, or related cybersecurity functions (preferred).
  • Strong understanding of open source software governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats (preferred).
  • Working knowledge of OWASP, NIST SSDF, SLSA, and related secure development guidance (preferred).
  • Experience applying software supply chain security practices, including provenance, build integrity, artifact signing, secure package repositories, dependency trust, and CI/CD pipeline hardening (preferred).
  • Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, and developer workflows (preferred).
  • Experience with scripting or automation using Python, PowerShell, Bash, or similar (preferred).
  • Ability to partner with engineering, platform, cloud, risk, audit, and compliance stakeholders (preferred).
  • Ability to translate technical risk into executive-ready reporting, measurable outcomes, and actionable remediation plans (preferred).
  • English language fluency required.

Responsibilities

  • Define policies, standards, and control requirements for approved open source usage, dependency hygiene, SBOM generation, secure package sourcing, and software supply chain risk management.
  • Establish OSS intake, approval, tracking, ownership, version management, vulnerability remediation, end-of-life retirement, and exception governance processes.
  • Design and implement automated CI/CD security gates for curated OSS usage, dependency scanning, license checks, artifact validation, provenance controls, build-time enforcement, and policy-based blocking.
  • Identify and reduce risks from vulnerable dependencies, malicious packages, dependency confusion, typosquatting, compromised maintainers, insecure build artifacts, and unauthorized package sources.
  • Establish controls for trusted package sources, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure release practices.
  • Establish capabilities to detect, assess, and respond to open source supply chain threats, zero-day vulnerabilities, compromised dependencies, and security incidents.
  • Support deployment, tuning, and integration of software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools.
  • Develop reporting on OSS risk posture, remediation velocity, policy exceptions, preventative-control adoption, and high-risk dependency reduction.
  • Create guidance, playbooks, reusable patterns, and consultation models for engineering teams.
  • Partner with CI/CD, DevSecOps, application security, engineering, platform, and risk teams.

Skills

Security Engineering
Vulnerability Management
Threat Modeling
CI/CD Security
Security Automation
Open Source Governance
SAST/DAST
DevSecOps
Communication
Problem-Solving

Education

Bachelor’s degree or equivalent education

Tools

CI/CD Platforms
Software Composition Analysis (SCA)
Package Managers
Build Systems
Artifact Repositories

Job description


  • Define policies, standards, and control requirements for approved open source usage, dependency hygiene, SBOM generation, secure package sourcing, and software supply chain risk management

  • Establish OSS intake, approval, tracking, ownership, version management, vulnerability remediation, end-of-life retirement, and exception governance processes

  • Design and implement automated CI/CD security gates for curated OSS usage, dependency scanning, license checks, artifact validation, provenance controls, build-time enforcement, and policy-based blocking

  • Identify and reduce risks from vulnerable dependencies, malicious packages, dependency confusion, typosquatting, compromised maintainers, insecure build artifacts, and unauthorized package sources

  • Establish controls for trusted package sources, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure release practices

  • Establish capabilities to detect, assess, and respond to open source supply chain threats, zero-day vulnerabilities, compromised dependencies, and security incidents

  • Support deployment, tuning, and integration of software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools

  • Develop reporting on OSS risk posture, remediation velocity, policy exceptions, preventative-control adoption, and high-risk dependency reduction

  • Create guidance, playbooks, reusable patterns, and consultation models for engineering teams

  • Partner with CI/CD, DevSecOps, application security, engineering, platform, and risk teams


Requirements


  • Bachelor’s degree or equivalent education, training, and work-related experience

  • Minimum of 5 years of experience in security engineering or related cybersecurity roles

  • Advanced knowledge in cybersecurity principles, theories, and concepts

  • Proven experience in software development lifecycle security practices

  • Advanced knowledge of threat modeling, security testing, and penetration testing

  • Experience implementing and managing complex information security technologies

  • Advanced cybersecurity certifications (e.g., CISSP, CISM, CEH, GIAC) (preferred)

  • Experience with security automation, orchestration, and advanced threat detection tools (preferred)

  • Familiarity with emerging cybersecurity technologies, industry trends, and strategic risk management (preferred)

  • Experience in application security, software supply chain security, DevSecOps, vulnerability management, secure engineering, or related cybersecurity functions (preferred)

  • Strong understanding of open source software governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats (preferred)

  • Working knowledge of OWASP, NIST SSDF, SLSA, and related secure development guidance (preferred)

  • Experience applying software supply chain security practices, including provenance, build integrity, artifact signing, secure package repositories, dependency trust, and CI/CD pipeline hardening (preferred)

  • Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, and developer workflows (preferred)

  • Experience with scripting or automation using Python, PowerShell, Bash, or similar (preferred)

  • Ability to partner with engineering, platform, cloud, risk, audit, and compliance stakeholders (preferred)

  • Ability to translate technical risk into executive-ready reporting, measurable outcomes, and actionable remediation plans (preferred)

  • English language fluency required

  • Must work onsite, office-centric, 5 days a week


Demonstrates advanced knowledge in cybersecurity principles, threat modeling, and software supply chain security, with proven experience in implementing security practices throughout the software development lifecycle. Capable of establishing governance processes for open source software and managing security technologies to mitigate risks effectively.


Highest-signal resume keywords


  • Cybersecurity Principles

  • Software Supply Chain Security

  • Threat Modeling

  • CI/CD Security Practices

  • Advanced Cybersecurity Certifications


Hard Skills


  • Security Engineering

  • Vulnerability Management

  • Software Development Lifecycle Security

  • Security Automation

  • Penetration Testing

  • Dependency Management

  • Artifact Signing

  • Scripting (Python, PowerShell, Bash)

  • Open Source Software Governance

  • Security Testing


Soft Skills


  • Collaboration

  • Communication

  • Problem-Solving


Certifications & Qualifications


  • CISSP

  • CISM

  • CEH
  • GIAC


Industry Keywords


  • SBOM

  • DevSecOps

  • OWASP

  • NIST SSDF

  • SLSA

  • Security Incident Response

  • Dependency Confusion

  • Typosquatting

  • Compromised Dependencies

  • Zero-Day Vulnerabilities


Tools & Technologies


  • CI/CD Platforms

  • Software Composition Analysis (SCA)

  • Package Managers

  • Build Systems

  • Artifact Repositories

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Supply Chain Security Engineer
Software Supply Chain Security Engineer

Jobtailor • Massachusetts

On-site
USD 140,000 - 180,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Director of Cyber Security
Director of Cyber Security

Jobtailor • Concord (MA)

Hybrid
USD 180,000 - 260,000
Vulnerability Management Technical Lead
Vulnerability Management Technical Lead

Jobtailor • San Francisco (CA)

On-site
USD 180,000 - 230,000
Staff Corporate Security Engineer
Staff Corporate Security Engineer

Jobtailor • Lehi (UT)

On-site
USD 120,000 - 180,000
Penetration Testing Engineer II
Penetration Testing Engineer II

Jobtailor • Bentonville (AR)

On-site
USD 80,000 - 110,000
Senior Product Security
Senior Product Security

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000
Information Security Specialist – Regional
Information Security Specialist – Regional

Jobtailor • Missouri

On-site
USD 90,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Senior Information Security Analyst – CSIRT
Senior Information Security Analyst – CSIRT

Jobtailor • Mount Laurel Township (NJ)

On-site
USD 110,000 - 170,000