
Open Source Software LEAD Security Engineer - Software Supply Chain
Truist Financial Corporation5 days ago
Richmond, VA, USA +3 moreStaff+
Base Salary
$160k - $200k/yr
Responsibilities
- Lead, mentor, and develop security engineers, analysts, and contractors working on OSS governance and software supply chain security.
- Define policies, standards, controls, and lifecycle processes for approved open source usage, dependency management, SBOM generation, vulnerability remediation, and exception governance.
- Design and implement automated CI/CD controls for dependency scanning, license checks, artifact validation, provenance, build enforcement, and high-risk component blocking.
- Identify and reduce risks involving vulnerable dependencies, malicious packages, dependency confusion, typosquatting, compromised maintainers, insecure artifacts, and unauthorized package sources.
- Establish trusted package source, dependency provenance, build integrity, artifact signing, repository hygiene, tamper resistance, and secure release controls.
- Develop threat detection and response capabilities for malicious package campaigns, zero-day vulnerabilities, compromised dependencies, and software supply chain incidents.
- Support deployment, tuning, and integration of software composition analysis, SBOM, package repository, vulnerability management, and developer workflow tools.
- Create risk reporting, metrics, playbooks, reusable patterns, and consultation models for engineering teams.
- Manage resources, budgets, vendor relationships, contractors, operational activities, risk remediation, and strategic project deliverables.
Requirements
- Bachelor’s degree or equivalent education, training, and work-related experience.
- Minimum 10 years of experience in security engineering or related cybersecurity roles.
- Deep knowledge of cybersecurity principles, theories, and concepts, with extensive experience in software development lifecycle security.
- Expertise in threat modeling, security testing, and penetration testing, plus experience implementing and managing complex information security technologies.
- Preferred experience leading cybersecurity, DevSecOps, application security, or software supply chain security teams, including direct supervision of employees, contractors, and cross-functional resources.
- Preferred advanced cybersecurity certifications such as CISSP, CISM, CEH, or GIAC.
- Experience with security automation, orchestration, advanced threat detection, application security, vulnerability management, secure engineering, or DevSecOps.
- Strong understanding of open source governance, dependency management, SBOM, SCA, secure SDLC, CI/CD pipelines, and software supply chain threats.
- Working knowledge of OWASP, NIST Secure Software Development Framework, SLSA, and related secure development guidance.
- Hands-on experience with CI/CD platforms, source code management, package managers, build systems, artifact repositories, developer workflows, and scripting or automation using Python, PowerShell, Bash, or similar.
- Ability to partner with engineering, platform, cloud, risk, audit, and compliance stakeholders and translate technical risk into executive-ready reporting and remediation plans.
Benefits
- Medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401(k) plan for eligible regular teammates working 20 or more hours per week.
- At least 10 days of vacation, 10 sick days, and paid holidays during the first year, prorated as applicable.
- Depending on the position and division, eligibility may include a defined benefit pension plan, restricted stock units, and/or deferred compensation plan.
- Regular, non-temporary position on the first shift in the United States; English fluency is required.