Staff Vulnerability Management Engineer
Posted 3hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Staff engineer managing novel vulnerability disclosure and CVE coordination for Chainguard, which secures open-source software supply chains. Leading industry collaboration on AI-driven software security standards, embargoes, and response processes.
Responsibilities:
- Own measurement, disclosure, and reporting of a pipeline of thousands of novel vulnerabilities identified weekly by frontier models and other sources
- Calibrate the response process in response to emerging trends
- Manage reporting of newly discovered vulnerabilities to upstream projects and maintainers
- Run the CNA program to assign new CVEs where necessary
- Coordinate internal and external embargoes with customers, internal engineering teams, and external maintainers
- Work with the Linux Foundation, CISA, and other bodies to coordinate actions and responses
- Guide industry direction so Chainguard customer needs are met by emerging standards and norms
- Represent Chainguard externally and visibly as the face of its industry-leading efforts
- Work with AI model vendors to guide future evolution of the software supply chain
- Provide technical leadership, cross-team influence, and ownership of complex problems as an individual contributor
Requirements:
- 7+ years in software security, open source maintenance, or vulnerability disclosure management
- Strong understanding of responsible disclosure
- Practical expertise automating pipelines and processes at large scale and removing the human-in-the-loop
- Deep experience with open source communities
- Experience coordinating with public sector or industry standards bodies and working groups
- Established vulnerability disclosure management and embargo thought leadership (nice to have)
- Familiarity with Chainguard Images or minimal/hardened container base image ecosystems (nice to have)
- Experience operating a CNA (nice to have)
- Software engineering background in Python, Java, Javascript, Go, or similar languages (nice to have)
- Background in security research, penetration testing, or bug bounties (nice to have)
Benefits:
- Flexible & Remote-First Culture
- Team meetup opportunities
- Bi-annual destination summits
- Monthly stipend for coworking spaces, phone and internet costs
- Stock options upon hire and promotion
- Participation in secondary offerings
- 10 years to exercise stock options
- 100% covered health, vision and dental insurance premiums for you and your dependents
- Flexible time off
- 18 weeks paid parental leave for birthing parents
- 12 weeks paid parental leave for non-birthing parents
- Option to use parental leave all at once or throughout the child's first year













