Unlock Full Resume Report
ATS Pass
Missing keywords
Tailored AI suggestions
Job match analysis
Interview-focused insights
New offer - be the first one to apply!
September 14, 2026
Open Source Software LEAD Security Engineer - Software Supply Chain
Senior
160,000 - 200,000 USD/yr
Raleigh, NC
Apply now
Quick Facts
The Open Source Software (OSS) Lead Security Engineer owns the practical execution of open source software security across governance, engineering workflows, tooling, automation, and risk reduction.
Description
This role combines security program leadership with hands-on technical delivery to build secure-by-default OSS lifecycle capabilities and reduce software supply chain exposure. You will lead OSS security governance, software supply chain security, CI/CD preventative control integration, and proactive management of risks across dependencies, builds, packages, artifacts, and provenance. The role partners with CI/CD, DevSecOps, application security, engineering, platform, and risk teams to ensure open source components and release processes are approved, continuously monitored, remediated, and safely integrated into enterprise applications and delivery pipelines.
Responsibilities
- Lead, mentor, and develop a team of security engineers, analysts, and contractors for open source governance and software supply chain security initiatives
- Define policies, standards, and control requirements for approved OSS usage, dependency hygiene, SBOM generation, secure package sourcing, and software supply chain risk management
- Establish OSS intake, approval, tracking, ownership, version management, vulnerability remediation, end-of-life retirement, and exception governance processes
- Design and implement automated security gates for curated OSS usage, dependency scanning, license checks, artifact validation, provenance controls, build-time enforcement, and policy-based blocking of high-risk components
- Identify and reduce risks such as vulnerable dependencies, malicious packages, dependency confusion, typosquatting, compromised maintainers, insecure build artifacts, and unauthorized package sources
- Establish controls for trusted package sources, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure release practices
- Establish capabilities to detect and respond to open source supply chain threats, malicious package campaigns, zero-day vulnerabilities, compromised dependencies, and security incidents
- Support deployment and integration of software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools
- Develop reporting and metrics for OSS risk posture, remediation velocity, policy exceptions, preventative control adoption, and reduction of high-risk dependencies
- Create guidance, playbooks, reusable patterns, and consultation models to help engineering teams make secure OSS decisions early
- Manage and prioritize work across full-time teammates and contracted resources; coordinate resources, budgets, vendor relationships, and deliverables
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience
- Minimum 10 years of experience in security engineering or related cybersecurity roles
- Deep specialized knowledge in cybersecurity principles, theories, and concepts
- Extensive experience in software development lifecycle security practices
- Expertise in threat modeling, security testing, and penetration testing
- Proven experience implementing and managing complex information security technologies
Preferred Qualifications
- Demonstrated leadership experience managing technical cybersecurity, DevSecOps, application security, or software supply chain security teams
- Advanced cybersecurity certifications (CISSP, CISM, CEH, GIAC)
- Experience with security automation, orchestration, and advanced threat detection tools
- Familiarity with emerging cybersecurity technologies, industry trends, and strategic risk management
- Experience with application security, software supply chain security, DevSecOps, vulnerability management, secure engineering
- Strong understanding of open source governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats
- Working knowledge of security and software supply chain frameworks/standards including OWASP, NIST SSDF, SLSA
- Experience applying supply chain security practices: provenance, build integrity, artifact signing, secure repositories, dependency trust, CI/CD pipeline hardening
- Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, and developer workflows
- Experience scripting/automation using Python, PowerShell, Bash, or similar
Benefits
All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, including medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan. Teammates also receive at least 10 days of vacation (prorated in year one), 10 sick days (prorated), and paid holidays; depending on position and division, additional benefits may include defined benefit pension plan, restricted stock units, and/or deferred compensation plan.
Similar jobs you might like

Open Source Software LEAD Security Engineer - Software Supply Chain
Truist
Senior
Technology
Greensboro, NC
$160K - $200K/yr
5m ago

Software Engineer [Multiple Positions Available]
JPMorgan Chase
Senior
Technology
Columbus, OH
$105K - $105K/yr
9m ago
Application Security Engineer (F/M)
AXA IT Solutions
Senior
Technology
Warsaw, MZ, Poland · On-site
0K zł - 0K zł/yr
9 days ago
Application Security Engineer (F/M)
AXA IT Solutions
Senior
Technology
Warsaw, MZ, Poland · On-site
0K zł - 0K zł/yr
10 days ago
Lead Security Operations Engineer
Gainsight
Senior
Technology
Wrocław, Pl-Ds, Poland · On-site
300K zł - 342K zł/yr
1 days ago

Staff Power Systems Engineer, Mechanical Design
Celestica
Senior
Technology
NH · Remote
$118K - $118K/yr
2m ago

Staff Systems Administrator – Endpoint Engineering
Relativity
Senior
Technology
Krakow, MA, Poland · Remote
250K zł - 374K zł/yr
12 days ago

Cyber Security Engineer
Cyclad
Senior
Technology
Kraków, Poland · Remote
0K zł - 0K zł/yr
5 days ago

Electrical Engineer Hardware Section Leader
Raytheon
Senior
Technology
McKinney, TX
$173K - $173K/yr
1 days ago
Cyber Tooling SME Engineer
Haleon
Senior
Technology
Poznan, Poland · On-site
158K zł - 218K zł/yr
9 days ago