Senior Engineer, Secure Software Supply Chain - Remote
Core
Design, build, and support reusable software, services, and workflows to strengthen software supply chain security while improving developer experience.
Role type
Senior IC DevSecOps/Platform Engineer
Builds
Secure-by-default software delivery capabilities, reusable templates, and integrations for engineering teams
Domain
Financial services, software supply chain security, DevSecOps
Required skills
Software engineering, platform engineering, DevSecOps, application security engineering, dependency and package management, artifact repositories, container registries, CI/CD integrations, vulnerability detection, secrets detection, software provenance, policy-as-code, container image security, modern programming languages (Java, Python, Go, C#, TypeScript, JavaScript), automated testing, source control, build processes, deployment, monitoring, operational support
Preferred skills
SLSA, Sigstore, Cosign, in-toto, OpenSSF guidance, Backstage, GitHub Actions, Artifactory, Cloudsmith, Nexus, npm, NuGet, Maven, PyPI, Kubernetes, OpenShift, AWS, Azure, hybrid cloud environments
Technologies
AWS, Azure, C#, CI/CD, Cloud, DevSecOps, GitHub, Java, JavaScript, Kubernetes, Maven, Nexus, NPM, OpenShift, Python, Security, TypeScript, DevOps
Responsibilities
Evaluate, design, build, test, integrate, and support reusable software, services, workflows, and integrations that strengthen software supply chain security; Integrate automated security controls into source control, CI/CD, artifact, container, and release workflows; Create intuitive, self-service secure software delivery capabilities that development teams can readily adopt; Partner with application teams to understand build, package, artifact, container, and release workflows and identify friction and opportunities; Define and use metrics to assess adoption, developer experience, reliability, and security outcomes; Collaborate with engineering productivity, information security, and customer engineering teams to turn security requirements into practical tools, integrations, workflows, and delivery recommendations