Source Job

Canada Israel Netherlands UK US Unlimited PTO

  • Lead the end-to-end software supply chain security architecture for GitLab’s CI/CD platform.
  • Drive cross-team technical strategy and decisions across our Software Supply Chain Security (SSCS) stage teams.
  • Teach, mentor, and coach Staff Engineers and individual contributors.

DevSecOps Go Rust Kubernetes

20 jobs similar to Principal Engineer, Software Supply Chain Security

Jobs ranked by similarity.

Global

  • Design and implement resiliency across our cloud platform and CI/CD pipelines.
  • Embed “security as code” and help lead incident response for high-severity outages.
  • Partner with engineering teams to enable safe, fast delivery at scale.

Alpaca is a US-headquartered self-clearing broker-dealer and brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more. Our global team of 230+ members spans the USA, Canada, Japan, and beyond, fostering a vibrant community.

Europe US

  • Own and operate n8n’s vulnerability intake and triage process, including the [email protected] inbox
  • Define and maintain security policies, standards, and public-facing disclosure documentation
  • Embed security into the software development lifecycle through threat modeling, design reviews, and pragmatic guardrails

n8n is the open workflow orchestration platform built for the new era of AI. They give technical teams the freedom of code with the speed of no-code, so they can automate faster, smarter, and without limits. Since their founding in 2019, they’ve grown into a diverse team of over 160.

US

  • Design and manage infrastructure-as-code with Terraform and GitOps.
  • Build and maintain secure CI/CD pipelines with integrated security automation.
  • Deploy and operate Kubernetes/K3s clusters in AWS GovCloud (IL5/IL6).

Rackner is a cloud-native software consultancy delivering solutions for startups, enterprises, and the public sector. They enable digital transformation through DevSecOps, AI/ML, and cloud-first innovation, solving high-impact problems and delivering secure, scalable solutions for the Department of Defense and federal health programs.

$136,595–$189,000/yr
US Unlimited PTO

  • Define and drive the strategic roadmap for proactive security vulnerability analysis.
  • Establish the technical vision and program for integrating robust security controls at every stage of the SDLC.
  • Lead collaborative and cross-functional threat modeling initiatives for core systems, new features, and evolving services.

Modern Health is a mental health benefits platform for employers, offering access to resources for emotional, professional, social, financial, and physical well-being. They are a fully remote workforce known for their culture centered around empathy and accountability, with a drive to win.

US

  • Design and implement the next generation of our Continuous Integration and Continuous Delivery (CI/CD) pipelines, focusing on security, speed, and reliability.
  • Maintain and optimize the health of our monorepo, ensuring scalable dependency management and fast incremental builds.
  • Work with GCP to architect secure, scalable runtime environments.

Anchorage Digital is building the world’s most advanced digital asset platform for institutions to participate in crypto. As a diverse team of more than 600 members, they are united in one common goal: building the future of finance by providing the foundation upon which value moves safely in the new global economy.

$170,000–$190,000/yr
US Unlimited PTO 13w maternity 9w paternity

  • Engineer and deploy clever controls so security incidents stay rare.
  • Lead incident response efforts and security tool deployments.
  • Embrace AI and automation to protect the enterprise at machine speed.

Chainguard provides a secure foundation for software development and deployment. By providing guarded open source software, built from source and updated continuously, Chainguard helps organizations eliminate threats in their software supply chains. They value customer obsession, prioritize intentional action, and trust each other.

$171,400–$367,200/yr
US Unlimited PTO

  • Own and drive the architectural direction for critical infrastructure platforms that support GitLab at global scale.
  • Lead the design and evolution of large platforms and distributed systems that are scalable, resilient, secure, and cost-efficient.
  • Serve as the technical authority on complex initiatives, guiding decisions that impact multiple teams and product areas.

GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world.

Europe

  • Embed security into CI/CD pipelines.
  • Automate vulnerability management and remediation.
  • Harden cloud and Kubernetes environments.

Jobgether connects job seekers with partner companies using an AI-powered matching process. They ensure applications are reviewed quickly and fairly and are committed to an inclusive, diverse, and supportive work environment.

$200,000–$250,000/yr
US

  • Partner with Product teams to ensure that products are designed, built, and operated securely.
  • Conduct threat modeling activities with Product teams to ensure product threats are understood, documented, and mitigated.
  • Review and analyze product source code to identify security vulnerabilities and providing recommendations for secure implementation.

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. Affirm is a remote-first company and offers competitive benefits anchored to their core value of people come first.

US Unlimited PTO

  • Lead development/implementation of cluster & application lifecycles, ensuring security & efficiency.
  • Collaborate with clients, guiding in design/execution of containerized and boundary solutions.
  • Take a leading role in the construction of CI/CD pipelines, driving efficient software updates.

Raft is a customer-obsessed non-traditional small business with a purposeful focus on Distributed Data Systems, Platforms at Scale, and Complex Application Development. Their range of clients includes innovative federal and public agencies leveraging design thinking, cutting-edge tech stack, and cloud-native ecosystem.

$138,600–$297,000/yr
Canada US Unlimited PTO

  • Lead technical discovery, architecture design, demos, and end-to-end evaluations.
  • Drive AI-focused solution strategy as the team’s AI subject matter expert.
  • Own the technical strategy and influence Customer Success Plans for assigned accounts.

GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. They aim to enable everyone to contribute to and co-create the software that powers our world.

$115,600–$160,000/yr
US

  • Own the configuration, tuning, and management of our SIEM solution.
  • Perform architecture reviews, code reviews, and infrastructure configuration reviews.
  • Maintain and optimize a vulnerability management CI/CD pipeline within our container/application delivery infrastructure.

Engine is transforming business travel into something personalized, rewarding, and simple. More than 20,000 companies already rely on Engine to support over 1 million travelers and billions in annual bookings each year.

India

  • Design, implement, and operate automated patch pipelines for Linux/Windows across GCE and GKE nodes.
  • Proactively monitor security dashboards, logs, and alerts for threats, anomalies, and suspicious activity.
  • Support the vulnerability management program by triaging, prioritizing, and coordinating the remediation of infrastructure-related vulnerabilities.

Turing, based in San Francisco, is a research accelerator for frontier AI labs and a partner for enterprises deploying advanced AI systems. They accelerate research with data, talent, and training, and build intelligence systems, with a leadership team from top tech companies.

US Unlimited PTO

  • Architect and implement secure AWS configurations.
  • Embed security into CI/CD pipelines and repos using policy-as-code tools.
  • Conduct threat modeling sessions and risk‑driven design reviews early in development.

OnePay is an all-in-one financial platform driven by a simple mission: better money makes life better. They are backed by Walmart and Ribbit Capital, and deeply embedded with the distribution of the world’s largest omnichannel retailer.

$184,000–$252,000/yr
US

  • Lead secure design reviews and threat modeling for AI-driven products.
  • Build and maintain security automation and governance frameworks.
  • Drive software supply chain security and vulnerability reduction.

AlphaSense empowers companies to make smarter decisions by providing market intelligence and search functionality driven by AI. With over 2,000 employees globally and offices in multiple countries, they foster a collaborative and innovative environment.

$131,600–$282,000/yr
US Unlimited PTO

  • Hire, lead, and support a high-performing Infrastructure Platforms team.
  • Connect business goals and customer needs with sound engineering.
  • Guide the security, reliability, performance, and scalability of core platform components.

GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Their mission is to enable everyone to contribute to and co-create the software that powers our world.

$100,649–$174,459/yr

  • Design and implement security solutions across enterprise platforms and cloud environments.
  • Perform threat modeling and security risk assessments for new features and platforms.
  • Partner with product teams to embed security requirements early in the SDLC.

Experian is a global data and technology company, powering opportunities for people and businesses around the world. As a FTSE 100 Index company listed on the London Stock Exchange, they have a team of 22,500 people across 32 countries and are committed to investing in their people.

US

  • Own developer operations and platform reliability across Introzy’s product stack.
  • Lead how we run infrastructure on Render, design and evolve our observability and alerting, shape our CI/CD and release practices.
  • Continuously improve internal developer experience so the engineering team can ship quickly and safely.

Introzy is a multi-app platform designed to unify networking, workflow, and productivity. As a subsidiary of Sanguine Technology Solutions, they are an early-stage company moving fast to deliver value, with a lean engineering team and a culture that embraces AI.

US Europe

  • Analyze and assess security issues via design reviews, code audits, and penetration tests.
  • Design and build security tools, and develop mitigations and hardening strategies.
  • Review and develop secure operational practices, and provide security guidance for engineers.

Aptos Labs is building a people-first blockchain that aims to provide universal and fair access to decentralized assets in a safe and scalable way. Founded by original creators/maintainers of the Diem blockchain, they value diversity and are an Equal Opportunity Employer.

Europe Unlimited PTO 18w maternity 12w paternity

  • Lead technical implementations and drive adoption of Chainguard images.
  • Partner with the account team to understand customer vision and pain points.
  • Maintain account level architecture and share best practices and lessons learned.

Chainguard is the secure foundation for software development and deployment. By providing guarded open source software, built from source and updated continuously, they help organizations eliminate threats in their software supply chains. The company values its customers, encourages action, embraces humor, and trusts its team members.