
Senior OS Engineer — Linux Security & Container Supply Chain
RapidFort, Inc.5 months ago
Remote, United StatesSenior
Base Salary
$150k - $200k/yr
Responsibilities
- Own end-to-end CVE remediation across Linux operating system packages and system libraries.
- Analyze vulnerabilities, validate upstream fixes, determine patching or backporting strategies, and rebuild or curate packages across multiple Linux distributions.
- Build and maintain secure, minimal, production-ready container images while reducing attack surfaces and validating image integrity, compatibility, and runtime stability.
- Generate and maintain SBOMs and implement provenance, signing, artifact trust, reproducible builds, and software supply chain security controls.
- Design and scale automated pipelines for OS patching, package rebuilding, vulnerability analysis, and container image generation.
- Partner with platform, DevOps, infrastructure, security, and engineering teams to integrate secure OS layers and support stable production baselines.
Requirements
- At least five years of experience in Linux systems engineering, OS engineering, platform engineering, DevSecOps, or release engineering.
- Deep expertise in Linux operating systems and Debian, RHEL, Ubuntu, and Alpine distributions.
- Strong experience with apt, rpm, dnf, and apk package management systems.
- Hands-on experience patching, rebuilding, or maintaining operating system packages.
- Strong understanding of Linux internals, system-level libraries, dependencies, ABI compatibility, and package lifecycle management.
- Experience with container internals, Linux runtime behavior, CVE remediation, SBOMs, software provenance, signing, and artifact trust models.
- Familiarity with SLSA, reproducible builds, and CI/CD pipelines for OS or system-level build processes.
- Strong scripting or programming ability in Python, Bash, Go, or C/C++, plus strong debugging skills across Linux systems and build environments.
- Preferred experience includes maintaining Linux distributions or open-source OS projects, building minimal or hardened container images, using Koji, OBS, Launchpad, or mock, kernel hardening, low-level OS security modules, and contributing to open-source security, Linux, or container ecosystems.
Benefits
- Health, dental, and vision insurance.
- Paid time off.
- Equity participation.
About RapidFort, Inc.
RapidFort builds a SaaS platform for securing containerized applications and the software supply chain, offering curated near‑zero CVE images, SBOM/RBOM generation, and runtime hardening to reduce attack surface. It serves enterprises and U.S. public‑sector customers, including defense work that requires U.S. citizenship for some roles. Founded in 2020 and headquartered in Sunnyvale, California, the company is privately held.