Unlock Full Resume Report

New offer - be the first one to apply!

September 14, 2026

Open Source Software LEAD Security Engineer - Software Supply Chain

Senior

160,000 - 200,000 USD/yr

Greensboro, NC

Quick Facts

  • Role: Open Source Software (OSS) Lead Security Engineer

Description

Own the practical execution of open source software security across governance, engineering workflows, tooling, automation, and risk reduction. Lead enterprise governance and preventative controls that enable secure OSS use and reduce software supply chain exposure throughout the SDLC, partnering with CI/CD, DevSecOps, application security, engineering, platform, and risk teams.

Responsibilities

  • Lead, mentor, and develop a team of security engineers, analysts, and contractors for OSS governance and software supply chain security initiatives
  • Define policies, standards, and control requirements for approved OSS usage, dependency hygiene, SBOM generation, secure package sourcing, and supply chain risk management
  • Establish OSS intake, approval, tracking, ownership, version management, vulnerability remediation, end-of-life retirement, and exception governance
  • Design and implement automated CI/CD security gates for curated OSS usage, dependency scanning, license checks, artifact validation, provenance controls, build-time enforcement, and policy-based blocking
  • Identify and reduce risks from vulnerable dependencies, malicious packages, dependency confusion, typosquatting, compromised maintainers, insecure build artifacts, and unauthorized package sources
  • Establish controls for trusted package sources, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure release practices
  • Establish capabilities to identify, assess, and respond to OSS supply chain threats and security incidents
  • Deploy, tune, and integrate software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools
  • Develop reporting on OSS risk posture, remediation velocity, policy exceptions, adoption of preventative controls, and reduction of high-risk dependencies
  • Create guidance, playbooks, and reusable patterns to enable secure OSS decisions early in the lifecycle
  • Manage and prioritize work across full-time team members and contracted resources to execute objectives, remediation efforts, and strategic initiatives

Requirements

  • Bachelor’s degree or equivalent education, training, and work-related experience
  • Minimum 10 years of experience in security engineering or related cybersecurity roles
  • Deep specialized knowledge in cybersecurity principles, theories, and concepts
  • Extensive experience in software development lifecycle security practices
  • Expertise in threat modeling, security testing, and penetration testing
  • Proven experience implementing and managing complex information security technologies
  • Strong understanding of OSS governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats
  • Working knowledge of OWASP, NIST Secure Software Development Framework (SSDF), Supply-chain Levels for Software Artifacts (SLSA), and related standards
  • Experience applying software supply chain security practices (provenance, build integrity, artifact signing, secure package repositories, dependency trust, CI/CD pipeline hardening)
  • Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, and developer workflows
  • Scripting/automation experience (Python, PowerShell, Bash, or similar)
  • Ability to partner with engineering/platform/cloud/risk/audit/compliance stakeholders and provide practical remediation guidance
  • Ability to translate technical risk into executive-ready reporting and actionable remediation plans
  • English fluency required

Benefits

  • Medical, dental, vision, life insurance, disability, accidental death and dismemberment
  • Tax-preferred savings accounts and 401k plan
  • No less than 10 days of vacation (prorated based on hire date) and 10 sick days (prorated)
  • Paid holidays
  • Potential eligibility for pension, restricted stock units, and/or deferred compensation depending on position/division

Similar jobs you might like