Unlock Full Resume Report
ATS Pass
Missing keywords
Tailored AI suggestions
Job match analysis
Interview-focused insights
New offer - be the first one to apply!
September 14, 2026
Open Source Software LEAD Security Engineer - Software Supply Chain
Senior
160,000 - 200,000 USD/yr
Greensboro, NC
Apply now
Quick Facts
- Role: Open Source Software (OSS) Lead Security Engineer
Description
Own the practical execution of open source software security across governance, engineering workflows, tooling, automation, and risk reduction. Lead enterprise governance and preventative controls that enable secure OSS use and reduce software supply chain exposure throughout the SDLC, partnering with CI/CD, DevSecOps, application security, engineering, platform, and risk teams.
Responsibilities
- Lead, mentor, and develop a team of security engineers, analysts, and contractors for OSS governance and software supply chain security initiatives
- Define policies, standards, and control requirements for approved OSS usage, dependency hygiene, SBOM generation, secure package sourcing, and supply chain risk management
- Establish OSS intake, approval, tracking, ownership, version management, vulnerability remediation, end-of-life retirement, and exception governance
- Design and implement automated CI/CD security gates for curated OSS usage, dependency scanning, license checks, artifact validation, provenance controls, build-time enforcement, and policy-based blocking
- Identify and reduce risks from vulnerable dependencies, malicious packages, dependency confusion, typosquatting, compromised maintainers, insecure build artifacts, and unauthorized package sources
- Establish controls for trusted package sources, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure release practices
- Establish capabilities to identify, assess, and respond to OSS supply chain threats and security incidents
- Deploy, tune, and integrate software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools
- Develop reporting on OSS risk posture, remediation velocity, policy exceptions, adoption of preventative controls, and reduction of high-risk dependencies
- Create guidance, playbooks, and reusable patterns to enable secure OSS decisions early in the lifecycle
- Manage and prioritize work across full-time team members and contracted resources to execute objectives, remediation efforts, and strategic initiatives
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience
- Minimum 10 years of experience in security engineering or related cybersecurity roles
- Deep specialized knowledge in cybersecurity principles, theories, and concepts
- Extensive experience in software development lifecycle security practices
- Expertise in threat modeling, security testing, and penetration testing
- Proven experience implementing and managing complex information security technologies
- Strong understanding of OSS governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats
- Working knowledge of OWASP, NIST Secure Software Development Framework (SSDF), Supply-chain Levels for Software Artifacts (SLSA), and related standards
- Experience applying software supply chain security practices (provenance, build integrity, artifact signing, secure package repositories, dependency trust, CI/CD pipeline hardening)
- Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, and developer workflows
- Scripting/automation experience (Python, PowerShell, Bash, or similar)
- Ability to partner with engineering/platform/cloud/risk/audit/compliance stakeholders and provide practical remediation guidance
- Ability to translate technical risk into executive-ready reporting and actionable remediation plans
- English fluency required
Benefits
- Medical, dental, vision, life insurance, disability, accidental death and dismemberment
- Tax-preferred savings accounts and 401k plan
- No less than 10 days of vacation (prorated based on hire date) and 10 sick days (prorated)
- Paid holidays
- Potential eligibility for pension, restricted stock units, and/or deferred compensation depending on position/division
Similar jobs you might like

Open Source Software LEAD Security Engineer - Software Supply Chain
Truist
Senior
Technology
Raleigh, NC
$160K - $200K/yr
15m ago

Software Engineer [Multiple Positions Available]
JPMorgan Chase
Senior
Technology
Columbus, OH
$105K - $105K/yr
19m ago

Sr Director of Data Science
Waystar
Senior
Technology
Lehi, UT
$100K - $100K/yr
4m ago

Senior Manager, Core Infrastructure Engineering- Nashville, TN
Oracle
Mid
Remote
$146K - $306K/yr
17s ago
Application Security Engineer (F/M)
AXA IT Solutions
Senior
Technology
Warsaw, MZ, Poland · On-site
0K zł - 0K zł/yr
9 days ago
Application Security Engineer (F/M)
AXA IT Solutions
Senior
Technology
Warsaw, MZ, Poland · On-site
0K zł - 0K zł/yr
10 days ago
Lead Security Operations Engineer
Gainsight
Senior
Technology
Wrocław, Pl-Ds, Poland · On-site
300K zł - 342K zł/yr
1 days ago

Staff Power Systems Engineer, Mechanical Design
Celestica
Senior
Technology
NH · Remote
$118K - $118K/yr
13m ago

Staff Systems Administrator – Endpoint Engineering
Relativity
Senior
Technology
Krakow, MA, Poland · Remote
250K zł - 374K zł/yr
12 days ago

Senior Director of Software Engineering (Infrastructure)
JPMorgan Chase
Mid
$195K - $195K/yr
17s ago