Chainguard
Staff Vulnerability Management Engineer
engineeringfull-timeUnited Kingdom - Remote
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more
About the role
The role in a nutshell
You care deeply about the future of open source software, and have a desire to work across the industry to solve the new problems that frontier models are creating for the industry as a whole. At Chainguard, we are leading the charge into the next chapter of AI supply chain security - you will be at the forefront of that.
This is an individual-contributor Staff role. That means technical leadership, cross-team influence, and owning hard problems.
What you’ll do
Manage our novel vulnerabilities pipeline
- Own the measurement, disclosure and reporting of our pipeline of thousands of novel vulnerabilities weekly identified by frontier models and other sources
- Calibrate our response process in response to emerging trends
- Manage the reporting of newly discovered vulnerabilities to upstream projects and maintainers
- Run our CNA program to assign new CVEs where necessary
- Co-ordinate internal and external embargoes, working with customers, internal engineering teams, and external maintainers
Co-ordinate across the industry
- Work with the Linux Foundation, CISA, and other bodies to co-ordinate actions and responses.
- Guide and lead industry direction to ensure Chainguard customer needs are best met by emerging standards and norms.
- Represent Chainguard externally and visibly, to be the face of our industry leading efforts.
- Work with AI model vendors to guide future evolution of the software supply chain.
What we're looking for
Required
- 7+ years in software security, open source maintenance, or vulnerability disclosure management.
- A strong understanding of responsible disclosure.
- Practical expertise with automating pipelines and processes, to operate at large scale, and to remove the human-in-the-loop.
- Deep experience with open source communities.
- Experience in co-ordinating with public sector or industry standards bodies and working groups.
Nice to Have
- Established thought leadership in the industry relating to vulnerability disclosure management and embargoes.
- Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems.
- Experience operating a CNA.
- Software engineering background in Python, Java, Javascript, Go or similar languages.
- Background in security research, pen testing or bug bounties.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply