
Open Source Software Security Engineer - Software Supply Chain
Truist Financial Corporation5 days ago
Richmond, VA, USA +3 moreSenior
Base Salary
$105k - $130k/yr
Responsibilities
- Define policies, standards, and control requirements for approved open source usage, dependency hygiene, SBOM generation, secure package sourcing, and software supply chain risk management.
- Establish OSS intake, approval, tracking, ownership, version management, vulnerability remediation, retirement, and exception-governance processes.
- Design and implement automated CI/CD security gates for OSS usage, dependency scanning, license checks, artifact validation, provenance, build-time enforcement, and high-risk component blocking.
- Reduce risks from vulnerable dependencies, malicious packages, dependency confusion, typosquatting, compromised maintainers, insecure artifacts, and unauthorized package sources.
- Establish controls for trusted package sources, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure releases.
- Detect and respond to open source supply chain threats, malicious package campaigns, zero-day vulnerabilities, compromised dependencies, and security incidents.
- Support deployment, tuning, and integration of software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools.
- Develop reporting on OSS risk posture, remediation velocity, policy exceptions, preventative-control adoption, and high-risk dependency reduction.
- Create developer guidance, playbooks, reusable patterns, and consultation models for secure open source decisions.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- At least 5 years of experience in security engineering or related cybersecurity roles.
- Advanced knowledge of cybersecurity principles, theories, and concepts.
- Proven experience with software development lifecycle security practices.
- Advanced knowledge of threat modeling, security testing, and penetration testing.
- Experience implementing and managing complex information security technologies.
- Preferred advanced cybersecurity certifications such as CISSP, CISM, CEH, or GIAC.
- Experience with security automation, orchestration, advanced threat detection, application security, software supply chain security, DevSecOps, vulnerability management, secure engineering, or related cybersecurity functions.
- Strong understanding of open source governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats.
- Working knowledge of OWASP, NIST Secure Software Development Framework (SSDF), Supply-chain Levels for Software Artifacts (SLSA), and related secure development guidance.
- Experience applying provenance, build integrity, artifact signing, secure package repositories, dependency trust, and CI/CD pipeline hardening.
- Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, and developer workflows.
- Experience with scripting or automation using Python, PowerShell, Bash, or similar languages.
- Ability to partner with engineering, platform, cloud, risk, audit, and compliance stakeholders and translate technical risk into actionable guidance and executive-ready reporting.
Benefits
- Annual base salary of $105,000-$130,000 plus available incentive pay.
- Medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan for eligible regular teammates working 20 or more hours per week.
- At least 10 vacation days, 10 sick days, and paid holidays during the first year, prorated as applicable.
- Depending on position and division, eligibility may include a defined benefit pension plan, restricted stock units, and/or deferred compensation plan.
- Regular, non-temporary position on the first shift in the United States; benefit eligibility varies by division and work status.