
Senior OS Engineer — Linux Security & Container Supply Chain
RapidFort, Inc.Base Salary
$150k - $200k/yr
Responsibilities
- Own end-to-end CVE remediation across Linux operating system packages and system libraries.
- Analyze vulnerabilities, validate upstream fixes, determine patching or backporting strategies, and rebuild or curate packages across multiple Linux distributions.
- Build and maintain secure, minimal, production-ready container images while reducing attack surfaces and validating image integrity, compatibility, and runtime stability.
- Generate and maintain SBOMs and implement provenance, signing, artifact trust, reproducible builds, and software supply chain security controls.
- Design and scale automated pipelines for OS patching, package rebuilding, vulnerability analysis, and container image generation.
- Partner with platform, DevOps, infrastructure, security, and engineering teams to integrate secure OS layers and support stable production baselines.
Requirements
- At least five years of experience in Linux systems engineering, OS engineering, platform engineering, DevSecOps, or release engineering.
- Deep expertise in Linux operating systems and Debian, RHEL, Ubuntu, and Alpine distributions.
- Strong experience with apt, rpm, dnf, and apk package management systems.
- Hands-on experience patching, rebuilding, or maintaining operating system packages.
- Strong understanding of Linux internals, system-level libraries, dependencies, ABI compatibility, and package lifecycle management.
- Experience with container internals, Linux runtime behavior, CVE remediation, SBOMs, software provenance, signing, and artifact trust models.
- Familiarity with SLSA, reproducible builds, and CI/CD pipelines for OS or system-level build processes.
- Strong scripting or programming ability in Python, Bash, Go, or C/C++, plus strong debugging skills across Linux systems and build environments.
- Preferred experience includes maintaining Linux distributions or open-source OS projects, building minimal or hardened container images, using Koji, OBS, Launchpad, or mock, kernel hardening, low-level OS security modules, and contributing to open-source security, Linux, or container ecosystems.
Benefits
- Health, dental, and vision insurance.
- Paid time off.
- Equity participation.
About RapidFort, Inc.
RapidFort, Inc. is a leading software supply chain security company that provides an innovative platform designed to automatically secure container applications and accelerate compliance processes. The company's comprehensive solution addresses critical cybersecurity challenges by removing up to 95% of Common Vulnerabilities and Exposures (CVEs) from container images without requiring any code changes. RapidFort's unified platform offers three core capabilities: curated near-zero CVE container images with FIPS 140-3 validation and daily builds, DevTime protection tools that generate Software Bill of Materials (SBOM) and Real Bill of Materials (RBOM) for vulnerability remediation, and RunTime protection that automatically secures unused components and reduces software attack surfaces by 60-90%. The platform serves organizations seeking to reduce development costs by 10%, accelerate software releases by 2-3 weeks, and achieve faster compliance with FedRAMP, cATO, CMMC, and SOC2 standards. RapidFort's solution integrates seamlessly with existing development workflows and technology stacks, consuming less than 1% system overhead while providing comprehensive security hardening. Trusted by government agencies including the U.S. Air Force and Space Force, as well as enterprise customers, RapidFort addresses the growing challenge of software supply chain security by eliminating "zombie code" – the 50-90% of unused software components that create unnecessary security risks. The company's approach enables organizations to spend more time building products rather than maintaining and updating dormant code, ultimately strengthening security posture while improving operational efficiency.