Freelancer for Software Supply Chain and Vulnerability Management (d/f/m)
Remote
Univention GmbH
Open Source Identity & Access Management für Bildungssektor und Öffentliche Verwaltung: 35 Mio. verwaltete Identitäten • Über 20 Jahre ErfahrungWas dich erwartet
- Help improve our workflows and tooling for supply chain vulnerability management, including generating, signing, and publishing SBOMs, performing CVE scans, and efficiently analyzing scan results
- Play a key role in monitoring container images for known security vulnerabilities while automating continuous security checks
- Contribute to the implementation of tools and processes for assessing vulnerabilities and generating/publishing Vulnerability Exploitability (VEX) information
- Enhance license management and compliance monitoring by generating SBOMs and validating the results of automatic license detection
Was du mitbringst
- Strong experience in supply chain security monitoring, particularly SBOMs, CVE/CVSS, and VEX
- Hands-on experience with open-source security scanners (e.g., Trivy), including scanner operation and interpreting security findings
- Experience in VEX generation, maintenance, and publishing
- Familiarity with OCI registries and Linux container artifacts (e.g., Harbor registry, Docker images, Helm charts)
- Experience in automating security workflows using GitLab CI pipelines
Was wir dir bieten
- A company that is 100% committed to open source
- A professional work environment with flat hierarchies and a culture of mutual respect
- A supportive and open-minded team that values collaboration, integrity, and transparency
Interested? Apply online via our application form or send an email to jobs@univention.de. Let us know your availability and daily rate.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
1
1
0
Tags: Compliance CVSS Docker GitLab Helm Linux Monitoring Open Source Vulnerabilities Vulnerability management
Perks/benefits: Transparency
Region:
Remote/Anywhere
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Specialist jobsSenior Cloud Security Engineer jobsInformation System Security Officer jobsSenior Security Analyst jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsInformation Security Manager jobsSystems Engineer jobsSenior Information Security Analyst jobsSenior Network Security Engineer jobsIT Security Engineer jobsCyber Security Specialist jobsIT Security Analyst jobsChief Information Security Officer jobsSecurity Specialist jobsSecurity Consultant jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsSenior Information Security Engineer jobsSenior Cyber Security Engineer jobsSenior Product Security Engineer jobsCyber Threat Intelligence Analyst jobsCyber Security Architect jobsThreat Intelligence Analyst jobsSenior Software Engineer jobs
Java jobsEncryption jobsEDR jobsBash jobsTS/SCI jobsIDS jobsIPS jobsThreat detection jobsSQL jobsTerraform jobsSDLC jobsSplunk jobsMalware jobsTop Secret jobsFinance jobsDocker jobsForensics jobsSOC 2 jobsRMF jobsActive Directory jobsCompTIA jobsIntrusion detection jobsITIL jobsOWASP jobsGIAC jobs
DoDD 8570 jobsVPN jobsAnsible jobsHIPAA jobsOSCP jobsIT infrastructure jobsData Analytics jobsTCP/IP jobsUNIX jobsCCSP jobsCRISC jobsSAP jobsBanking jobsSANS jobsSOAR jobsSOX jobsJavaScript jobsMITRE ATT&CK jobsSecurity strategy jobsClearance Required jobsMachine Learning jobsZero Trust jobsDNS jobsJira jobsPolygraph jobs