OSS-SIRT Engineer Lead: Open Source Security & Automation

The Linux Foundation

United States

On-site

USD 170,000 - 185,000

Full time

13 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

The Linux Foundation is seeking a Senior OSS-SIRT Engineer to serve as the technical authority for vulnerability triage, tooling, and automation across OSS projects. You will lead OSV-based triage workflows, design ingestion pipelines, and coordinate with maintainers and researchers on complex disclosures, while aligning with OSV Schema, CWE, CVSS/EPSS, VEX, and SBOM formats.

Candidates should have 8+ years in security engineering or PSIRT, hands-on OSS vulnerability disclosure, and scripting

Qualifications

  • 8+ years in security engineering, PSIRT, or vulnerability research roles.
  • Hands-on experience with OSS vulnerability disclosure and triage.
  • Strong understanding of software supply chain security.

Responsibilities

  • Lead vulnerability triage and validation using OSV-based workflows
  • Design and improve ingestion, linting, and curation pipelines
  • Coordinate with maintainers, researchers, and CNAs on complex disclosures
  • Develop and maintain automation tooling (APIs, CLIs, GitHub Actions, CI hooks)
  • Ensure alignment with OSV Schema, CWE, CVSS/EPSS, VEX, and SBOM formats
  • Support incident response for high-severity, multi-project vulnerabilities
  • Provide technical guidance to the OSS-SIRT Director on feasibility and risk

Skills

Security engineering
Scripting (Python/Go)
Vulnerability disclosure

Tools

OSV
GitHub Advisories
SBOM tooling

Job description

The Linux Foundation is seeking a Senior OSS-SIRT Engineer to serve as the technical authority for vulnerability triage, tooling, and automation across OSS projects. You will lead OSV-based triage workflows, design ingestion pipelines, and coordinate with maintainers and researchers on complex disclosures, while aligning with OSV Schema, CWE, CVSS/EPSS, VEX, and SBOM formats.

Candidates should have 8+ years in security engineering or PSIRT, hands-on OSS vulnerability disclosure, and scripting

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior OSS-SIRT Engineer - Hybrid
Senior OSS-SIRT Engineer - Hybrid

The Linux Foundation • United States

On-site
USD 170,000 - 185,000
OSS-SIRT Engineer: Open Source Vulnerability Ops
OSS-SIRT Engineer: Open Source Vulnerability Ops

Linux Foundation Co • United States

Remote
USD 140,000 - 155,000
Open Source Security Engineer — Software Supply Chain
Open Source Security Engineer — Software Supply Chain

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Senior OSS Security Engineer: Secure Software Supply Chain
Senior OSS Security Engineer: Secure Software Supply Chain

Truist • Atlanta (GA)

On-site
USD 140,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+4
OSS Security Lead: Software Supply Chain & Governance
OSS Security Lead: Software Supply Chain & Governance

Socket.dev • Charlotte (NC)

On-site
USD 160,000 - 200,000
Medical
Dental
Vision
+4
OSS Security & Supply Chain Engineer
OSS Security & Supply Chain Engineer

Crump Life Insurance Svcs Inc • Charlotte (NC)

On-site
USD 105,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+5
Senior OSS Security Engineer: Software Supply Chain Lead
Senior OSS Security Engineer: Software Supply Chain Lead

Socket.dev • Charlotte (NC)

On-site
USD 140,000 - 180,000
Benefits package
Paid time off
Security Engineer for Open Source Frameworks
Security Engineer for Open Source Frameworks

Vercel • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
PSIRT Lead — Vulnerability Lifecycle & Bug Bounty
PSIRT Lead — Vulnerability Lifecycle & Bug Bounty

Replit • California (MO)

On-site
USD 150,000 - 210,000
Competitive Salary & Equity
401(k) Program with 4% match (US Only)
Health, Dental, Vision and Life Ins.
+9
Senior Security Researcher: Vulnerability & Exploitation
Senior Security Researcher: Vulnerability & Exploitation

Research Innovations Incorporated • San Antonio (FL)

On-site
USD 150,000 - 210,000
Flexible work schedules
Health insurance
Paid time off
+3