Software Engineer (Information Security (Open Source Compliance))

Centraprise

Jersey City (NJ)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading tech firm is seeking a Software Engineer specializing in Information Security and Open Source Compliance. Responsibilities include automating audits, conducting risk assessments, and ensuring compliance with licenses like GPL and MIT. Candidates should have over 7 years of experience in embedded software development and a solid background in security roles. This position emphasizes collaboration with cross-functional teams to align on security and compliance policies. Ideal for experts in software security and compliance management.

Qualifications

  • 7+ years in embedded software development, plus 2+ years in a security-focused role.
  • Deep familiarity with GPL/LGPL/MPL/MIT/Apache requirements.
  • Proficient with CMake, Clang/LLVM, cross compilers.

Responsibilities

  • Automate audits of binaries and source for license usage.
  • Conduct formal risk assessments and ensure compliance with licenses.
  • Communicate complex build processes to various audiences.

Skills

Embedded software development
Security-focused role experience
Compliance expertise
CMake proficiency
GitOps practices
Power BI dashboards

Tools

CMake
GitHub Actions
JFrog Artifactory

Job description

Overview

Job Title: Software Engineer (Information Security (Open Source Compliance))

Location: Dallas, TX (5 day onsite)

Duration: Long-term

Engineering & Automation (Embedded + SDLC)

Automate audits of binaries and source for license usage; run SCA and produce SBOMs (CycloneDX/SPDX).

Standardize reproducible build engineering with CMake and Clang/LLVM; manage dependencies via Conan and Snapcraft(where applicable).

Govern artifacts in JFrog Artifactory with dependency health checks via JFrog Xray.

Operationalize GitOps (GitHub/GitLab) and design CI/CD pipelines using GitHub Actions / GitLab CI.

Responsibilities
  • Automate audits of binaries and source for license usage; run SCA and produce SBOMs (CycloneDX/SPDX).
  • Standardize reproducible build engineering with CMake and Clang/LLVM; manage dependencies via Conan and Snapcraft(where applicable).
  • Govern artifacts in JFrog Artifactory with dependency health checks via JFrog Xray.
  • Operationalize GitOps (GitHub/GitLab) and design CI/CD pipelines using GitHub Actions / GitLab CI.
  • Security Testing & Vulnerability Management:
    • Triage third-party vulnerabilities and assess results from CodeQL, SonarQube, and related scanners; drive fix plans across firmware and supporting services.
    • Create, publish, and continually revalidate Open Source Candidates (GPL/MPL and others) with reproducible build scripts, license texts, copyright notices, and end-user instructions.
    • Triage and resolve revalidation build errors (toolchain, linking, dependency, packaging), ensuring public distribution materials remain accurate.
  • Compliance & Governance:
    • Conduct formal risk assessments to identify threats and vulnerabilities and recommend mitigating controls.
    • Ensure compliance with open source licenses and applicable standards (e.g., ISO 27001, ISO/IEC 5230:2020, SOC 2) in partnership with Engineering, Legal, and external stakeholders.
    • Evaluate proposed libraries before integration (GPL/LGPL/MPL/MIT/Apache), document obligations (attribution, source offer, relinking), and guide compliant implementation patterns (static vs. dynamic link, dual license scenarios).
  • Documentation, Training & Enablement:
    • Author/update SOPs, Working Instructions, developer-facing runbooks, and public distribution READMEs.
    • Develop and deliver open source and product-based GRC training to employees and contractors.
    • Communicate complex build processes, package management, and license implications to technical and non-technical audiences.
    • Lead incident response (identify, contain, recover), conduct post-incident reviews, and recommend program and control improvements.
    • Monitor industry trends and best practices in Open Source License Compliance; propose program updates proactively.
  • Data & Reporting:
    • Publish compliance/security dashboards in Power BI; use SQL to analyze SBOM coverage, license risk, vulnerability posture, and release readiness for executive decision-making.
  • Collaboration & Stakeholder Management:
    • Work cross-functionally with engineering teams, Legal, and senior leadership for status updates, new requirements intake, and policy alignment; engage external partners (ODMs, vendors, consultants) to meet compliance obligations.
Qualifications
  • 7+ years in embedded software development (Linux kernel, device/firmware), plus 2+ years in a security-focused role (DevSecOps/AppSec/Compliance).
  • Licensing & Policy: Deep, practical familiarity with GPL/LGPL/MPL/MIT/Apache requirements (attribution, source publication, relinking, derivative work analysis) and enforcement throughout the SDLC.
  • Build, Packaging & Artifacts: Proficient with CMake, Clang/LLVM, cross compilers; package with Conan/Snapcraft; govern artifacts in JFrog Artifactory with risk analysis via JFrog Xray.
  • CI/CD & GitOps: Hands-on with GitHub Actions / GitLab CI and GitOps practices (GitHub/GitLab) for policy as code and environment orchestration.
  • Testing & Vulnerability Triage: Skilled at integrating and interpreting SAST/DAST/IAST results; practical experience with CodeQL, SonarQube, ScanCode, and SBOM tooling (SPDX/CycloneDX).
  • Data & Communication: Able to build Power BI dashboards, write SQL, and translate complex technical topics into clear narratives for technical and non-technical audiences.
  • Documentation & Training: Exceptional writing quality for SOPs, Working Instructions, and public distribution artifacts; experienced trainer for OSS/GRC topics.
  • Collaboration: Comfortable influencing cross-functional roadmaps and mediating license/security trade-offs with engineering, Legal, and external partners.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineer – SBOM & Compliance
Software Engineer – SBOM & Compliance

ThunderSoft • San Diego (CA)

On-site
USD 85,000 - 110,000
Senior Software Engineer-Open Source Security & Compliance
Senior Software Engineer-Open Source Security & Compliance

Centraprise • Jersey City (NJ)

On-site
USD 120,000 - 150,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Information Security and Compliance Manager
Information Security and Compliance Manager

Transhield, Inc. • Elkhart (IN)

On-site
USD 120,000 - 180,000
Engineer, Senior
Engineer, Senior

ALTEN • San Diego (CA)

On-site
USD 90,000 - 120,000
Linux Engineer
Linux Engineer

Insight Global • San Diego (CA)

On-site
USD 180,000 - 260,000
Compliance Engineer
Compliance Engineer

IDEMIA Group • Chantilly (VA)

On-site
USD 80,000 - 110,000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Germany (OH)

On-site
USD 120,000 - 160,000