
Software Supply Chain Security Engineer
Cerebras Systems17 hours ago
Responsibilities
- Define and implement security requirements for artifact build pipelines, including maturing SLSA processes.
- Partner with platform, infrastructure, networking, and hardware teams to identify supply chain gaps and deliver end-to-end artifact security solutions.
- Develop threat models for each layer of the build and deployment stack, including trust boundaries and first- and third-party mechanisms.
- Work with engineering leads and DevOps architects to incorporate secure supply chain principles from the beginning of development.
- Balance engineering outcomes with security controls to enable fast and secure delivery.
- Document security posture and strategy for technical and nontechnical audiences.
Requirements
- 8–10 years of experience with software supply chain and SDLC topics, including secure code management, build pipeline hardening, artifact signing and attestation, and end-to-end integration.
- Master's degree in computer science or PhD preferred.
- Strong hands-on engineering abilities in DevOps and SDLC contexts.
- Ability to work in fragmented and legacy build environments; experience modernizing stacks is a plus.
- Familiarity with AWS, Jenkins, SLSA, and secure artifact provenance and build practices is a plus.
- Strong written communication skills and ability to make security concepts approachable to non-specialists.
- Direct experience with agentic workflows and deep understanding of LLM and reasoning cycles.
Benefits
- Opportunity to work on Cerebras's AI platform and high-performance AI supercomputers.
- Opportunities to publish and open source AI research.
- Startup vitality with job stability and a simple, non-corporate work culture.
- Inclusive, equal-opportunity environment emphasizing continuous learning, growth, and support.
About Cerebras Systems
Cerebras Systems designs and sells AI compute systems built around its wafer-scale WSE-3 processor, delivered as the CS-3 appliance and via the Cerebras Cloud. It targets enterprises, model labs, and government users needing fast training and inference, and offers on‑prem and cloud deployments. Privately held and headquartered in Sunnyvale, California, the company announced a multi-year partnership with OpenAI to deploy large-scale inference capacity.