Unknown Company

Open Source Software Security Engineer – Software Supply Chain

nc • Posted Yesterday
Onsite Full Time IT & Technology


  • Define policies, standards, and control requirements for approved open source usage, dependency hygiene, SBOM generation, secure package sourcing, and software supply chain risk management

  • Establish OSS intake, approval, tracking, ownership, version management, vulnerability remediation, end-of-life retirement, and exception governance processes

  • Design and implement automated CI/CD security gates for curated OSS usage, dependency scanning, license checks, artifact validation, provenance controls, build-time enforcement, and policy-based blocking

  • Identify and reduce risks from vulnerable dependencies, malicious packages, dependency confusion, typosquatting, compromised maintainers, insecure build artifacts, and unauthorized package sources

  • Establish controls for trusted package sources, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure release practices

  • Establish capabilities to detect, assess, and respond to open source supply chain threats, zero-day vulnerabilities, compromised dependencies, and security incidents

  • Support deployment, tuning, and integration of software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools

  • Develop reporting on OSS risk posture, remediation velocity, policy exceptions, preventative-control adoption, and high-risk dependency reduction

  • Create guidance, playbooks, reusable patterns, and consultation models for engineering teams

  • Partner with CI/CD, DevSecOps, application security, engineering, platform, and risk teams


Requirements



  • Bachelor’s degree or equivalent education, training, and work-related experience

  • Minimum of 5 years of experience in security engineering or related cybersecurity roles

  • Advanced knowledge in cybersecurity principles, theories, and concepts

  • Proven experience in software development lifecycle security practices

  • Advanced knowledge of threat modeling, security testing, and penetration testing

  • Experience implementing and managing complex information security technologies

  • Advanced cybersecurity certifications (e.g., CISSP, CISM, CEH, GIAC) (preferred)

  • Experience with security automation, orchestration, and advanced threat detection tools (preferred)

  • Familiarity with emerging cybersecurity technologies, industry trends, and strategic risk management (preferred)

  • Experience in application security, software supply chain security, DevSecOps, vulnerability management, secure engineering, or related cybersecurity functions (preferred)

  • Strong understanding of open source software governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats (preferred)

  • Working knowledge of OWASP, NIST SSDF, SLSA, and related secure development guidance (preferred)

  • Experience applying software supply chain security practices, including provenance, build integrity, artifact signing, secure package repositories, dependency trust, and CI/CD pipeline hardening (preferred)

  • Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, and developer workflows (preferred)

  • Experience with scripting or automation using Python, PowerShell, Bash, or similar (preferred)

  • Ability to partner with engineering, platform, cloud, risk, audit, and compliance stakeholders (preferred)

  • Ability to translate technical risk into executive-ready reporting, measurable outcomes, and actionable remediation plans (preferred)

  • English language fluency required

  • Must work onsite, office-centric, 5 days a week


Demonstrates advanced knowledge in cybersecurity principles, threat modeling, and software supply chain security, with proven experience in implementing security practices throughout the software development lifecycle. Capable of establishing governance processes for open source software and managing security technologies to mitigate risks effectively.


Highest-signal resume keywords



  • Cybersecurity Principles

  • Software Supply Chain Security

  • Threat Modeling

  • CI/CD Security Practices

  • Advanced Cybersecurity Certifications


Hard Skills



  • Security Engineering

  • Vulnerability Management

  • Software Development Lifecycle Security

  • Security Automation

  • Penetration Testing

  • Dependency Management

  • Artifact Signing

  • Scripting (Python, PowerShell, Bash)

  • Open Source Software Governance

  • Security Testing


Soft Skills



  • Collaboration

  • Communication

  • Problem-Solving


Certifications & Qualifications



  • CISSP

  • CISM

  • CEH
  • GIAC


Industry Keywords



  • SBOM

  • DevSecOps

  • OWASP

  • NIST SSDF

  • SLSA

  • Security Incident Response

  • Dependency Confusion

  • Typosquatting

  • Compromised Dependencies

  • Zero-Day Vulnerabilities


Tools & Technologies



  • CI/CD Platforms

  • Software Composition Analysis (SCA)

  • Package Managers

  • Build Systems

  • Artifact Repositories

#J-18808-Ljbffr

Open Source Software Security Engineer – Software Supply Chain in nc at Unknown Company

This position is listed as full time and onsite.

Back to Job Search