×
Register Here to Apply for Jobs or Post Jobs. X

Source Software Security Engineer – Software Supply Chain

Job in Asheville, Buncombe County, North Carolina, 28814, USA
Listing for: Jobtailor
Full Time position
Listed on 2026-09-05
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 120000 - 180000 USD Yearly USD 120000.00 180000.00 YEAR
Job Description & How to Apply Below
Position: Open Source Software Security Engineer – Software Supply Chain
  • Define policies, standards, and control requirements for approved open source usage, dependency hygiene, SBOM generation, secure package sourcing, and software supply chain risk management
  • Establish OSS intake, approval, tracking, ownership, version management, vulnerability remediation, end-of-life retirement, and exception governance processes
  • Design and implement automated CI/CD security gates for curated OSS usage, dependency scanning, license checks, artifact validation, provenance controls, build-time enforcement, and policy-based blocking
  • Identify and reduce risks from vulnerable dependencies, malicious packages, dependency confusion, typo squatting, compromised maintainers, insecure build artifacts, and unauthorized package sources
  • Establish controls for trusted package sources, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure release practices
  • Establish capabilities to detect, assess, and respond to open source supply chain threats, zero-day vulnerabilities, compromised dependencies, and security incidents
  • Support deployment, tuning, and integration of software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools
  • Develop reporting on OSS risk posture, remediation velocity, policy exceptions, preventative-control adoption, and high-risk dependency reduction
  • Create guidance, playbooks, reusable patterns, and consultation models for engineering teams
  • Partner with CI/CD, Dev Sec Ops , application security, engineering, platform, and risk teams
Requirements
  • Bachelor’s degree or equivalent education, training, and work-related experience
  • Minimum of 5 years of experience in security engineering or related cybersecurity roles
  • Advanced knowledge in cybersecurity principles, theories, and concepts
  • Proven experience in software development lifecycle security practices
  • Advanced knowledge of threat modeling, security testing, and penetration testing
  • Experience implementing and managing complex information security technologies
  • Advanced cybersecurity certifications (e.g., CISSP, CISM, CEH, GIAC) (preferred)
  • Experience with security automation, orchestration, and advanced threat detection tools (preferred)
  • Familiarity with emerging cybersecurity technologies, industry trends, and strategic risk management (preferred)
  • Experience in application security, software supply chain security, Dev Sec Ops , vulnerability management, secure engineering, or related cybersecurity functions (preferred)
  • Strong understanding of open source software governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats (preferred)
  • Working knowledge of OWASP, NIST SSDF, SLSA, and related secure development guidance (preferred)
  • Experience applying software supply chain security practices, including provenance, build integrity, artifact signing, secure package repositories, dependency trust, and CI/CD pipeline hardening (preferred)
  • Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, and developer workflows (preferred)
  • Experience with scripting or automation using Python, Power Shell, Bash, or similar (preferred)
  • Ability to partner with engineering, platform, cloud, risk, audit, and compliance stakeholders (preferred)
  • Ability to translate technical risk into executive-ready reporting, measurable outcomes, and actionable remediation plans (preferred)
  • English language fluency required
  • Must work onsite, office-centric, 5 days a week

Demonstrates advanced knowledge in cybersecurity principles, threat modeling, and software supply chain security, with proven experience in implementing security practices throughout the software development lifecycle. Capable of establishing governance processes for open source software and managing security technologies to mitigate risks effectively.

Highest-signal resume keywords
  • Cybersecurity Principles
  • Software Supply Chain Security
  • Threat Modeling
  • CI/CD Security Practices
  • Advanced Cybersecurity Certifications
Hard Skills
  • Security Engineering
  • Vulnerability Management
  • Software Development Lifecycle Security
  • Security Automation
  • Penetration Testing
  • Dependency Management
  • Artifact Signing
  • Scripting (Python, Power Shell, Bash)
  • Open Source Software Governance
  • Security Testing
Soft Skills
  • Collaboration
  • Communication
  • Problem-Solving
Certifications & Qualifications
  • CISSP
  • CISM
  • CEH
  • GIAC
Industry Keywords
  • SBOM
  • Dev Sec Ops
  • OWASP
  • NIST SSDF
  • SLSA
  • Security Incident Response
  • Dependency Confusion
  • Typo squatting
  • Compromised Dependencies
  • Zero-Day Vulnerabilities
Tools & Technologies
  • CI/CD Platforms
  • Software Composition Analysis (SCA)
  • Package Managers
  • Build Systems
  • Artifact Repositories
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary