Senior Linux Distribution Engineer – Software Supply Chain Security
Posted 9hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Linux Distribution Engineer responsible for securing Linux package ecosystems and container images. Building, maintaining, and validating software delivery at scale with close collaboration across teams.
Responsibilities:
- Own end-to-end vulnerability remediation across Linux package ecosystems and container images.
- Analyze CVEs affecting OS packages, runtimes, libraries, and transitive dependencies across multiple Linux distributions.
- Validate upstream fixes, evaluate patch applicability, and determine appropriate remediation strategies.
- Rebuild, backport, patch, curate, sign, and publish packages across multiple Linux distribution branches.
- Maintain and manage trusted package repositories across diverse Linux ecosystems.
- Resolve complex dependency, compatibility, and ABI issues across distributions and package versions.
- Ensure package and image updates do not break customer environments, builds, or runtime compatibility.
- Design and scale automated pipelines for package rebuilding, validation, remediation, signing, publishing, and image generation.
- Integrate package validation, repository management, and remediation workflows into pipelines.
- Generate and maintain SBOMs, package metadata, provenance data, and trusted software artifacts.
- Improve image performance, package footprint, startup efficiency, and operational reliability.
- Research emerging threats and best practices in Linux distributions, containers, Kubernetes, and software supply chain security.
Requirements:
- 5+ years of experience in Linux systems engineering, Linux distribution engineering, platform engineering, DevSecOps, release engineering, or SRE.
- Deep expertise in Linux distributions and package ecosystems.
- Strong experience with Linux package build systems and tooling including rpmbuild, dpkg-buildpackage, APKBUILD/abuild, and associated repository and release tooling.
- Strong hands-on experience with Linux package managers including dpkg/apt, rpm/yum/dnf, apk, and associated repository tooling.
- Proven experience rebuilding, patching, backporting, maintaining, or publishing Linux packages across distribution versions.
- Strong understanding of package repositories, dependency resolution, ABI compatibility, package signing, and release workflows.
- Experience identifying and remediating vulnerabilities within Linux packages and containerized environments.
- Deep understanding of container internals, Linux, namespaces, and runtime behavior.
- Strong scripting or programming skills in Bash, C/C++, Python, Go, and other languages.
- Experience building CI/CD automation for package validation, remediation, release, and repository management workflows.
- Familiarity with software supply chain security concepts including SBOMs, provenance, signing, and artifact trust.
- Strong troubleshooting skills across Linux systems, package ecosystems, dependency graphs, and build pipelines.
Benefits:
- healthcare
- PTO
- equity participation
















