Security Engineer II: Open-Source & Supply Chain Defender

NEPSE Trading

Northern (KY)

Hybrid

USD 120,000 - 180,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CrowdStrike is seeking a Security Engineer II to strengthen the security of our open-source footprint and upstream dependencies. You will assess risks, design controls, and implement repository guardrails across GitHub organizations, while monitoring for malicious packages and automating security checks.

You will collaborate on cross-cutting projects to harden internal and public-facing code repositories, and you will apply secure coding practices and SDLC knowledge in a remote-friendly

Qualifications

  • Experience implementing and monitoring software security systems.
  • Strong working experience with GitHub, including repository administration, GitHub Actions, branch protection rules, and access management.
  • Familiarity with other source control management tools (e.g., BitBucket, GitLab)
  • Familiarity with artifact storage tools like Artifactory and S3.
  • Experience identifying and mitigating open-source risks (SCA, dependency management, licensing risks).
  • Experience working with and securing configurations of Linux and/or other Unix-like variants.
  • Proficiency in one or more common scripting languages, such as Python, Golang, Shell, or JavaScript, to automate security checks.
  • Domain knowledge of the software development lifecycle (SDLC), secure coding practices, code reviews, and source control security.
  • Collaborative mindset with experience contributing to cross-team security projects and initiatives.
  • Experience utilizing AI technologies to enhance decision-making, streamline workflows, or automate vulnerability triage.
  • Efficient communicator with strong writing skills, comfortable working in a remote environment.
  • Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.

Responsibilities

  • Assess risk and provide security guidance to engineers across the company on open-source software usage and repository configurations.
  • Implement and maintain controls and processes to secure public and private GitHub organizations, including repository guardrails and secret scanning.
  • Harden open-source code usage, development, ingestion, and distribution across the enterprise.
  • Investigate open-source dependencies and third-party packages to mitigate supply chain risks (e.g., typosquatting, dependency confusion).
  • Advocate for secure coding and open-source compliance practices to the wider engineering organization.
  • Contribute to the delivery of security initiatives aimed at hardening CrowdStrike’s software supply chain and code-hosting environments.

Skills

GitHub administration
GitHub Actions
Branch protection
Access management
Open-source risk assessment
Python
Golang
Shell
JavaScript
Linux
Secure coding

Tools

Artifactory
S3
Splunk
DataDog
LogScale
Prometheus
Jenkins
Argo CD

Job description

CrowdStrike is seeking a Security Engineer II to strengthen the security of our open-source footprint and upstream dependencies. You will assess risks, design controls, and implement repository guardrails across GitHub organizations, while monitoring for malicious packages and automating security checks.

You will collaborate on cross-cutting projects to harden internal and public-facing code repositories, and you will apply secure coding practices and SDLC knowledge in a remote-friendly

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II: Open-Source & Supply Chain (Remote)
Security Engineer II: Open-Source & Supply Chain (Remote)

CrowdStrike, Inc. • Virginia (IL)

Remote
USD 100,000 - 145,000
Market leader compensation
Wellness programs
Vacation and holidays
+5
Security Engineer II — Open-Source & Supply-Chain
Security Engineer II — Open-Source & Supply-Chain

CrowdStrike Holdings, Inc. • Northern (KY)

Hybrid
USD 100,000 - 145,000
Market leader compensation
Wellness programs
Generous vacation
+5
Product Security & Automation Software Engineer
Product Security & Automation Software Engineer

JobCubby • Northern (KY)

Hybrid
USD 120,000 - 180,000
Market leader in compensation andEqui?
Wellness programs
Vacation and holidays
+2
Engineer II, Software Assurance, Product Security
Engineer II, Software Assurance, Product Security

NEPSE Trading • Northern (KY)

Hybrid
USD 120,000 - 180,000
Senior Endpoint Security Engineer - Remote
Senior Endpoint Security Engineer - Remote

CrowdStrike • United States

On-site
USD 160,000 - 250,000
Market-leading compensation
Equity awards
Wellness programs
+5
Advanced Cloud Security Research Engineer II
Advanced Cloud Security Research Engineer II

CrowdStrike Holdings, Inc. • Northern (KY)

Hybrid
USD 100,000 - 145,000
Health insurance
401k plan
Paid time off
+1
Application Security Engineer: Threat Modeling & Secure SDLC
Application Security Engineer: Threat Modeling & Secure SDLC

CrowdStrike • United States

On-site
USD 120,000 - 180,000
Market-leading compensation
Wellness programs
PTO & holidays
+4
Cloud Security Research Engineer II
Cloud Security Research Engineer II

CrowdStrike • Maine

On-site
USD 100,000 - 145,000
Competitive compensation
Equity awards
Wellness programs
+5
Product Security Engineer: AI-Driven Automation
Product Security Engineer: AI-Driven Automation

CrowdStrike Holdings, Inc. • Town of Texas (WI)

Hybrid
USD 120,000 - 180,000
Equity awards
Wellness programs
Generous vacation
+3
Senior AppSec Engineer: Secure Coding & Threat Modeling
Senior AppSec Engineer: Secure Coding & Threat Modeling

CrowdStrike • United States

On-site
USD 160,000 - 250,000