Staff Vulnerability Management Engineer

Posted 3hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Staff engineer managing AI-discovered vulnerabilities for Chainguard, which builds hardened open-source software. Coordinating disclosures, CVEs, embargoes, and industry-wide supply-chain security efforts.

Responsibilities:

  • Own measurement, disclosure, and reporting of a pipeline of thousands of novel vulnerabilities identified weekly by frontier models and other sources
  • Calibrate the vulnerability response process in response to emerging trends
  • Manage reporting of newly discovered vulnerabilities to upstream projects and maintainers
  • Run the CNA program to assign new CVEs where necessary
  • Coordinate internal and external embargoes with customers, internal engineering teams, and external maintainers
  • Work with the Linux Foundation, CISA, and other bodies to coordinate actions and responses
  • Guide industry direction so Chainguard customer needs are met by emerging standards and norms
  • Represent Chainguard externally and visibly as the face of its industry-leading efforts
  • Work with AI model vendors to guide the future evolution of the software supply chain

Requirements:

  • 7+ years in software security, open source maintenance, or vulnerability disclosure management
  • Strong understanding of responsible disclosure
  • Practical expertise automating pipelines and processes at large scale and removing the human-in-the-loop
  • Deep experience with open source communities
  • Experience coordinating with public sector or industry standards bodies and working groups
  • Established vulnerability disclosure management and embargo thought leadership (nice to have)
  • Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems (nice to have)
  • Experience operating a CNA (nice to have)
  • Software engineering background in Python, Java, Javascript, Go, or similar languages (nice to have)
  • Background in security research, pen testing, or bug bounties (nice to have)

Benefits:

  • Flexible & Remote-First Culture
  • Team meetup opportunities
  • Bi-annual destination summits
  • Monthly stipend for coworking spaces, phone and internet costs
  • Stock options upon hire and promotion
  • Participation in secondary offerings
  • 10 years to exercise stock options
  • 100% covered health, vision and dental insurance premiums for employee and dependents
  • Unlimited flexible time off
  • 18 weeks paid parental leave for birthing parents
  • 12 weeks paid parental leave for non-birthing parents
  • Option to use parental leave all at once or throughout the child's first year