
Open Source Software Senior Security Engineer - Software Supply Chain
Truist Financial Corporation5 days ago
Richmond, VA, USA +3 moreSenior
Base Salary
$140k - $180k/yr
Responsibilities
- Define policies, standards, and control requirements for approved open source usage, dependency hygiene, SBOM generation, secure package sourcing, and software supply chain risk management.
- Establish OSS intake, approval, tracking, ownership, version management, vulnerability remediation, retirement, and exception governance processes.
- Design and implement automated CI/CD security gates for dependency scanning, license checks, artifact validation, provenance controls, and policy-based blocking.
- Identify and reduce risks involving vulnerable dependencies, malicious packages, dependency confusion, typosquatting, compromised maintainers, insecure artifacts, and unauthorized package sources.
- Establish controls for trusted package sources, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure releases.
- Develop capabilities to detect and respond to open source supply chain threats, zero-day vulnerabilities, compromised dependencies, and security incidents.
- Support deployment, tuning, and integration of software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools.
- Develop risk reporting and metrics covering OSS risk posture, remediation velocity, policy exceptions, preventative-control adoption, and high-risk dependency reduction.
- Create guidance, playbooks, reusable patterns, and consultation models that enable engineering teams to make secure open source decisions.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- Minimum of 7 years of experience in security engineering or related cybersecurity roles.
- Deep specialized knowledge of cybersecurity principles, theories, and concepts.
- Proven experience with software development lifecycle security practices.
- Deep knowledge of threat modeling, security testing, and penetration testing.
- Experience implementing and managing complex information security technologies.
- Preferred: advanced cybersecurity certifications such as CISSP, CISM, CEH, or GIAC.
- Preferred: experience with security automation, orchestration, advanced threat detection, application security, software supply chain security, DevSecOps, vulnerability management, or secure engineering.
- Strong understanding of open source governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats.
- Working knowledge of OWASP, NIST Secure Software Development Framework, SLSA, and related secure development guidance.
- Experience applying provenance, build integrity, artifact signing, secure package repository, dependency trust, and CI/CD pipeline-hardening practices.
- Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, and developer workflows.
- Experience with scripting or automation using Python, PowerShell, Bash, or similar languages.
- Ability to partner with engineering, platform, cloud, risk, audit, and compliance stakeholders and translate technical risk into practical remediation guidance and executive-ready reporting.
Benefits
- Medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401(k) plan are available to eligible regular teammates working 20 or more hours per week.
- At least 10 days of vacation, 10 sick days, and paid holidays are provided during the first year, prorated as applicable.
- Depending on the position and division, eligibility may include a defined benefit pension plan, restricted stock units, and/or deferred compensation plan.
- This is a regular, non-temporary position on the first shift in the United States; specific benefit eligibility depends on work status, position, and division.