Insight Global logo

Remote Senior Engineer, Secure Software Supply Chain

Insight Global

Remote · USJobSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Remote · US
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

We are seeking a Senior Engineer, Secure Software Supply Chain to design, build, and support security capabilities that integrate directly into software development and delivery processes. This hands‑on role will partner with engineering, platform, and security teams to create secure‑by‑default tools, workflows, and automation that improve both software supply chain security and developer experience.

Skills & qualifications

RequiredNice to have

Skills

PythonGoJavaC#TypeScriptJavaScriptCI/CD PipelinesSource ControlArtifact RepositoriesContainer PlatformsDependency and Package ManagementVulnerability and Secrets DetectionSoftware Provenance and SigningPolicy-as-CodeContainer Image SecuritySLSASigstoreCosignIn-TotoOpenSSFBackstageGitHubGitHub ActionsReusable WorkflowsSelf‑Hosted RunnersArtifactoryCloudsmithNexusNpmMavenNuGetPyPIKubernetesOpenShiftAWSAzureHybrid CloudStrong CommunicationCollaborationProblem‑Solving

Qualifications

Bachelor's Degree in Computer Science, Engineering, Cybersecurity or Related Field or Equivalent Experience7+ Years Software Engineering, Platform Engineering, DevSecOps, Application Security Engineering or Related Fields3+ Years Building Developer‑Facing Security Automation, CI/CD Integrations or Secure Software Delivery CapabilitiesExperience Implementing Security Controls Without Negatively Impacting Developer Productivity

Full job description

Job Description

Overview We are seeking a Senior Engineer, Secure Software Supply Chain to design, build, and support security capabilities that integrate directly into software development and delivery processes. This hands-on role will partner with engineering, platform, and security teams to create secure-by-default tools, workflows, and automation that improve both software supply chain security and developer experience.

Key Responsibilities

  • Design, build, test, and support reusable software, services, and integrations that improve software supply chain security.
  • Implement automated security controls across source control, CI/CD pipelines, artifact repositories, container platforms, and release workflows.
  • Develop secure-by-default delivery patterns for software packages, artifacts, and containers.
  • Create self-service tools, APIs, templates, and workflows that reduce developer friction.
  • Partner with application, platform, and security teams to integrate security into existing engineering processes.
  • Drive adoption through documentation, enablement, and continuous improvement.
  • Define and monitor metrics related to adoption, reliability, developer experience, and security outcomes.

Skills and Requirements

Required Qualifications

  • Bachelor's degree in Computer Science, Engineering, Cybersecurity, or related field (or equivalent experience).

  • 7+ years of experience in Software Engineering, Platform Engineering, DevSecOps, Application Security Engineering, or related fields.

  • 3+ years building developer-facing security automation, CI/CD integrations, or secure software delivery capabilities.

  • Experience with multiple software supply chain security domains, including: o Dependency and package management o Artifact repositories and container registries o CI/CD and build security o Vulnerability and secrets detection o Software provenance and signing o Policy-as-code and automated security controls o Container image security

  • Experience implementing security controls without negatively impacting developer productivity.

  • Proficiency in at least one modern programming language such as Python, Go, Java, C#, TypeScript, or JavaScript.

  • Strong understanding of modern software development practices including code reviews, automated testing, deployment pipelines, monitoring, and operational support.

  • Strong communication, collaboration, and problem-solving skills. Preferred Qualifications

  • Experience with software supply chain security frameworks and technologies such as SLSA, Sigstore, Cosign, in-toto, or OpenSSF.

  • Experience building or extending Backstage or similar developer platforms.

  • Experience with GitHub, GitHub Actions, reusable workflows, and self-hosted runners.

  • Experience with Artifactory, Cloudsmith, Nexus, or similar artifact management platforms.

  • Experience supporting package ecosystems including npm, Maven, NuGet, and PyPI.

  • Experience with Kubernetes, OpenShift, container registries, and cloud-native platforms.

  • Experience working within AWS, Azure, or hybrid cloud environments.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.