×
Register Here to Apply for Jobs or Post Jobs. X

Source Software Security Engineer – Software Supply Chain

Job in High Point, Guilford County, North Carolina, 27264, USA
Listing for: Jobtailor
Full Time position
Listed on 2026-09-22
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 180000 USD Yearly USD 120000.00 180000.00 YEAR
Job Description & How to Apply Below
Position: Open Source Software Security Engineer – Software Supply Chain
  • Define policies, standards, and control requirements for approved open source usage, dependency hygiene, SBOM generation, secure package sourcing, and software supply chain risk management
  • Establish OSS intake, approval, tracking, ownership, version management, vulnerability remediation, end-of-life retirement, and exception governance processes
  • Design and implement automated CI/CD security gates for curated OSS usage, dependency scanning, license checks, artifact validation, provenance controls, build-time enforcement, and policy-based blocking
  • Identify and reduce risks from vulnerable dependencies, malicious packages, dependency confusion, typo squatting, compromised maintainers, insecure build artifacts, and unauthorized package sources
  • Establish controls for trusted package sources, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure release practices
  • Establish capabilities to detect, assess, and respond to open source supply chain threats, zero-day vulnerabilities, compromised dependencies, and security incidents
  • Support deployment, tuning, and integration of software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools
  • Develop reporting on OSS risk posture, remediation velocity, policy exceptions, preventative-control adoption, and high-risk dependency reduction
  • Create guidance, playbooks, reusable patterns, and consultation models for engineering teams
  • Partner with CI/CD, Dev Sec Ops , application security, engineering, platform, and risk teams
Requirements
  • Bachelor’s degree or equivalent education, training, and work-related experience
  • Minimum of 5 years of experience in security engineering or related cybersecurity roles
  • Advanced knowledge in cybersecurity principles, theories, and concepts
  • Proven experience in software development lifecycle security practices
  • Advanced knowledge of threat modeling, security testing, and penetration testing
  • Experience implementing and managing complex information security technologies
  • Advanced cybersecurity certifications (e.g., CISSP, CISM, CEH, GIAC) (preferred)
  • Experience with security automation, orchestration, and advanced threat detection tools (preferred)
  • Familiarity with emerging cybersecurity technologies, industry trends, and strategic risk management (preferred)
  • Experience in application security, software supply chain security, Dev Sec Ops , vulnerability management, secure engineering, or related cybersecurity functions (preferred)
  • Strong understanding of open source software governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats (preferred)
  • Working knowledge of OWASP, NIST SSDF, SLSA, and related secure development guidance (preferred)
  • Experience applying software supply chain security practices, including provenance, build integrity, artifact signing, secure package repositories, dependency trust, and CI/CD pipeline hardening (preferred)
  • Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, and developer workflows (preferred)
  • Experience with scripting or automation using Python, Power Shell, Bash, or similar (preferred)
  • Ability to partner with engineering, platform, cloud, risk, audit, and compliance stakeholders (preferred)
  • Ability to translate technical risk into executive-ready reporting, measurable outcomes, and actionable remediation plans (preferred)
  • English language fluency required
  • Must work onsite, office-centric, 5 days a week

Demonstrates advanced knowledge in cybersecurity principles, threat modeling, and software supply chain security, with proven experience in implementing security practices throughout the software…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary