Chainguard
Chainguard

Staff Vulnerability Management Engineer

engineeringfull-timeUnited Kingdom - Remote
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

The role in a nutshell

You care deeply about the future of open source software, and have a desire to work across the industry to solve the new problems that frontier models are creating for the industry as a whole. At Chainguard, we are leading the charge into the next chapter of AI supply chain security - you will be at the forefront of that.

This is an individual-contributor Staff role. That means technical leadership, cross-team influence, and owning hard problems.

What you’ll do

Manage our novel vulnerabilities pipeline

  • Own the measurement, disclosure and reporting of our pipeline of thousands of novel vulnerabilities weekly identified by frontier models and other sources
  • Calibrate our response process in response to emerging trends
  • Manage the reporting of newly discovered vulnerabilities to upstream projects and maintainers
  • Run our CNA program to assign new CVEs where necessary
  • Co-ordinate internal and external embargoes, working with customers, internal engineering teams, and external maintainers

Co-ordinate across the industry

  • Work with the Linux Foundation, CISA, and other bodies to co-ordinate actions and responses.
  • Guide and lead industry direction to ensure Chainguard customer needs are best met by emerging standards and norms.
  • Represent Chainguard externally and visibly, to be the face of our industry leading efforts.
  • Work with AI model vendors to guide future evolution of the software supply chain.

What we're looking for

Required

  • 7+ years in software security, open source maintenance, or vulnerability disclosure management.
  • A strong understanding of responsible disclosure.
  • Practical expertise with automating pipelines and processes, to operate at large scale, and to remove the human-in-the-loop.
  • Deep experience with open source communities.
  • Experience in co-ordinating with public sector or industry standards bodies and working groups.

Nice to Have

  • Established thought leadership in the industry relating to vulnerability disclosure management and embargoes.
  • Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems.
  • Experience operating a CNA.
  • Software engineering background in Python, Java, Javascript, Go or similar languages.
  • Background in security research, pen testing or bug bounties.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply
Apply now
Staff Vulnerability Management Engineer at Chainguard — Remote