Staff Supply Chain & Build-System Security Engineer
Tasks
- Build and review SBOMs and AIBOM artifacts
- Build dependency graphs and reachability analyses
- Enforce OIDC and trusted publisher migration
- Harden GitHub Actions and enforce pinned dependencies
- Harden runner deployment and identity scoping
- Identify blast radius
- Investigate malicious package incidents
- Lead customer software supply chain risk engagements
- Prioritize findings by exploitability
- Recommend CI CD pipeline hardening
- Reverse engineer obfuscated install scripts
- Triage supply chain findings from code scanning pipeline
- Validate true positives and eliminate noise
Perks/Benefits
- N/A
Skills/Tech-stack
AIBOM | Artifact signing | Build provenance | CI/CD | Dependency Pinning | Dependency graphs | Git | GitHub Actions | Go Modules | In-toto | JavaScript | Malware triage | Maven Central | Npm | NuGet | OIDC | PyPI | Python | Reachability analysis | Reverse Engineering | Runner Isolation | Rust | SBOM | SBOM Artifact Signing | SBOM Build Provenance | SLSA | Secrets management | Sigstore | Software Supply Chain | Software supply chain security | Static Analysis | Supply chain security | Trusted Publisher
Education
N/A
Related jobs
-
Senior-level Full TimeColumbus, GA, United States9h ago
-
Senior PKI Engineer USD 124K-179KActive Directory Certificate Services | Ansible | Bash | Certificate Authority | Certificate Lifecycle ManagementHybrid onsite/remote work | Secret clearance required | TS clearance requiredSenior-level Full TimeFAIRFAX, VA, United States9h ago
-
Ansible | Authentication | CentOS | Enterprise Linux | JBossSenior-level Full TimeAnnapolis Junction, MD11h ago
-
Adversarial Machine Learning | Anomaly Detection | Cloud Security | Machine Learning | PythonSecurity clearance premiumsMid-level Full TimeNaples, United States11h ago
-
Senior Cloud Software Engineer USD 135K-195KAPI Design | AWS | Alerting | Artifact governance | AzureSecurity clearance supportSenior-level Full TimeDayton, OH11h ago
-
Senior-level Full TimeDayton, OH11h ago
-
RRC - Database Administrator IV USD 96KAPI Integration | Autosys | Bash | Batch scheduling | CI/CDCareer development | Flexible work schedules | Health insurance | Paid time off | Retirement plan 401kMid-level Full TimeTexas-Austin12h ago
-
Senior-level Full TimeUSA-FL-Tampa, USA-FL-Fort Walton Beach13h ago
-
Mid-level Full TimeHuntsville, Alabama, United States13h ago
-
Security Engineer III, Cyber Threat Hunter USD 107K-188KAmazon Web Services | Analytic Rules | Cloud Security | Cloud security monitoring | Detection and ResponseSenior-level Full TimeArlington/Rosslyn, Virginia, United States; Baltimore, Maryland, …13h ago
-
Staff Software Engineer, Agentic AI, Trust and Safety USD 207K-301KAgentic AI | Anti-abuse | Anti-abuse systems | Architecture ownership | Artificial IntelligenceSenior-level Full TimeKirkland, WA, USA14h ago
-
AI/ML | AI/ML Infrastructure | Agent Orchestration | Automated Debugging | C++Senior-level Full TimeSunnyvale, CA, USA; Kirkland, WA, USA14h ago
-
AWS | Automation | Azure | Cloud Security | Cortex XSOAR401k program | Car discounts | Cruise discounts | Dental benefits | Employee assistance programSenior-level Full TimeFort Worth, TX, US18h ago
-
Application Security Engineer USD 210K-300KAPI Security Top 10 | AWS | Advanced Security | Application Security | AuthenticationSenior-level Full TimeMiami, FL1d ago
-
Application Security Engineer USD 195K-244KAI Agents | API Security Top 10 | AWS IAM | Advanced Security | Application SecuritySenior-level Full TimeSeattle, WA1d ago
-
BEV | Bayesian Methods | CUDA | Machine Learning | Metrics OptimizationSenior-level Full TimeFoster City, CA1d ago
-
Principal Software Engineer, Cryptography USD 254K-336KAppArmor | Architecture Review | C++ | Certificate Systems | Cryptographic agilitySenior-level Full TimeBoston, Massachusetts, United States; Costa Mesa, …1d ago
-
DevOps Engineer USD 129K-171KAir-gapped | Air-gapped networks | Ansible | Argo CD | Automated testingMid-level Full TimeReston, Virginia, United States1d ago
-
Dev Infra Software Engineer, Air Defense USD 166K-220KAWS | C++ | CI/CD | Distributed Systems | DockerMid-level Full TimeIrvine, California, United States1d ago
-
Senior Network Administrator USD 113K-149K8021X | ACL | Access Control | Ansible | BGPOn-call rotation | Travel for deploymentsSenior-level Full TimeAshville, Ohio, United States1d ago
-
Senior-level Full TimeAshville, Ohio, United States1d ago
-
Mid-level Full TimeCosta Mesa, California, United States1d ago
-
Staff Security Engineer, Proactive Security USD 193K-285KAWS | Access Management | CI/CD | Cause analysis | Distributed Systems11 paid holidays | 401k matching | Commuter benefits match | Dental insurance | Disability insuranceSenior-level Full TimeUnited States - Remote R1d ago
-
Senior Full Stack Engineer (Remote) USD 180K-250KDevOps | Go | JavaScript | Node.js | React.jsLunch stipend | Office in San Francisco | Offsites and conferences | Remote work | Work setup budgetSenior-level Full TimeUnited States R1d ago
-
Information Technology Senior Consultant Level 5 Columbia, MD TS/SCI Full Scope Polygraph USD 180K-250KCertification and accreditation | Flask | Git | Gnocchi | GolangSenior-level Full TimeColumbia, MD1d ago