Freelancer for Software Supply Chain and Vulnerability Management (d/f/m)
Remote
Univention GmbH
Open Source Identity & Access Management für Bildungssektor und Öffentliche Verwaltung: 35 Mio. verwaltete Identitäten • Über 20 Jahre ErfahrungWas dich erwartet
- Help improve our workflows and tooling for supply chain vulnerability management, including generating, signing, and publishing SBOMs, performing CVE scans, and efficiently analyzing scan results
- Play a key role in monitoring container images for known security vulnerabilities while automating continuous security checks
- Contribute to the implementation of tools and processes for assessing vulnerabilities and generating/publishing Vulnerability Exploitability (VEX) information
- Enhance license management and compliance monitoring by generating SBOMs and validating the results of automatic license detection
Was du mitbringst
- Strong experience in supply chain security monitoring, particularly SBOMs, CVE/CVSS, and VEX
- Hands-on experience with open-source security scanners (e.g., Trivy), including scanner operation and interpreting security findings
- Experience in VEX generation, maintenance, and publishing
- Familiarity with OCI registries and Linux container artifacts (e.g., Harbor registry, Docker images, Helm charts)
- Experience in automating security workflows using GitLab CI pipelines
Was wir dir bieten
- A company that is 100% committed to open source
- A professional work environment with flat hierarchies and a culture of mutual respect
- A supportive and open-minded team that values collaboration, integrity, and transparency
Interested? Apply online via our application form or send an email to jobs@univention.de. Let us know your availability and daily rate.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
10
7
0
Tags: Compliance CVSS Docker GitLab Helm Linux Monitoring Open Source Vulnerabilities Vulnerability management
Perks/benefits: Transparency
Region:
Remote/Anywhere
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information System Security Officer jobsInformation Security Specialist jobsSenior Security Analyst jobsSenior Cloud Security Engineer jobsSystems Engineer jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsSenior Information Security Analyst jobsInformation Security Manager jobsCyber Security Specialist jobsSenior Network Security Engineer jobsIT Security Analyst jobsChief Information Security Officer jobsIT Security Engineer jobsSecurity Consultant jobsSecurity Specialist jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsSenior Information Security Engineer jobsSenior Cyber Security Engineer jobsSenior Product Security Engineer jobsCyber Threat Intelligence Analyst jobsCyber Security Architect jobsSecurity Operations Analyst jobsCybersecurity Specialist jobs
TS/SCI jobsEDR jobsSaaS jobsBash jobsJava jobsTop Secret jobsThreat detection jobsTerraform jobsSplunk jobsRMF jobsIDS jobsSDLC jobsIPS jobsSOC 2 jobsSQL jobsMalware jobsFinance jobsForensics jobsCompTIA jobsDocker jobsActive Directory jobsGIAC jobsIntrusion detection jobsITIL jobsDoDD 8570 jobs
VPN jobsOWASP jobsHIPAA jobsCRISC jobsIT infrastructure jobsAnsible jobsTCP/IP jobsCCSP jobsData Analytics jobsClearance Required jobsNIST 800-53 jobsOSCP jobsMITRE ATT&CK jobsBanking jobsZero Trust jobsCISO jobsUNIX jobsSOAR jobsDNS jobsIndustrial jobsJira jobsSOX jobsEndpoint security jobsPolygraph jobsJavaScript jobs