Назад
Company hidden
9 дней назад

Software Supply Chain Security Engineer (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Software Supply Chain Security Engineer (AI): Building a secure foundation for source-to-artifact pipelines, from code management through deployment into clusters, with an accent on build pipeline hardening, artifact provenance, and SLSA processes. Focus on threat modeling trust boundaries, securing CI/CD artifacts across fragmented environments, and integrating supply chain controls with fast engineering delivery.

Location: Sunnyvale, California, United States; hybrid

Company

hirify.global builds AI accelerator hardware and computing platforms designed to deliver high-speed model training and inference.

What you will do

  • Define and implement security requirements for artifact build pipelines, including maturing SLSA processes.
  • Partner with platform, infrastructure, networking, and hardware teams to identify supply chain gaps and secure CI/CD artifacts end to end.
  • Develop threat models for each layer of the build and deployment stack, including trust boundaries and first- and third-party mechanisms.
  • Work with engineering leads and DevOps architects to integrate secure supply chain principles from the beginning.
  • Balance security controls with engineering outcomes to support fast and secure delivery.
  • Document security posture and strategy for technical and nontechnical audiences.

Requirements

  • 8–10 years of experience with software supply chain and SDLC security, including secure code management, build pipeline hardening, artifact signing, attestation, and end-to-end integration.
  • Strong hands-on engineering experience in DevOps and SDLC environments.
  • Ability to work with fragmented and legacy build environments.
  • Strong written communication skills and the ability to explain security concepts to non-specialists.
  • Direct experience with agentic workflows and a deep understanding of LLM and reasoning cycles.
  • A master’s degree in Computer Science or a PhD is preferred.

Nice to have

  • Experience modernizing legacy technology stacks.
  • Familiarity with AWS, Jenkins, SLSA, and secure artifact provenance and build practices.

Culture & Benefits

  • Work on an AI platform designed beyond the constraints of GPUs.
  • Opportunity to publish and open-source AI research.
  • Work with a high-performance AI supercomputer platform.
  • Startup vitality combined with business stability.
  • Non-corporate culture focused on individual perspectives, learning, growth, and support.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →