North AmericaFull TimeEngineering
Remotely
Listed on 3 job boards, which is a stronger signal than one board alone.
automationsecuritycnacveembargoeslinux foundation
Also available on
Job Description
📋 Description
- You’ll lead vulnerability management for Chainguard’s security pipeline, focusing on novel
- Own measurement, disclosure, and reporting of our vulnerability pipeline at scale.
- Calibrate response processes based on emerging trends and coordinate embargoes with customers and
- Run CNA program to assign new CVEs as needed and coordinate with industry bodies.
- Represent Chainguard publicly to advance industry standards and norms.
- Collaborate with AI model vendors to shape the future of software supply chain security.
🎯 Requirements
- 7+ years in software security, open source maintenance, or vulnerability disclosure management.
- Strong understanding of responsible disclosure.
- Experience automating pipelines and processes at large scale with minimal human intervention.
- Deep experience with open source communities.
- Experience coordinating with public sector or standards bodies; ability to engage with Linux
🎁 Benefits
- Flexible Remote-First Culture with team meetups and a stipend for coworking, phone, and internet.
- Equity options with long-term vesting opportunities.
- 100% covered health, vision, and dental premiums for you and dependents.
- Unlimited/∞ Flexible Time Off and 18 weeks Paid Parental Leave for birthing parents.
Back to all jobs