Senior Supply Chain Security Engineer
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
TL;DR
Senior Supply Chain Security Engineer ( Hardened Images): Authoring and maintaining security-hardened container image definitions and adapting upstream Helm charts with an accent on tracking OSS releases, handling security constraints, and Kubernetes compatibility. Focus on triaging CVEs, writing Go integration tests, and reviewing PRs to ensure minimal, up-to-date, and safe deployments in regulated environments.
Location: Remote from Canada, England, France, Germany, Italy, Portugal, Spain, or United States
EU Salary Range: β¬83.9K β β¬139.7K β’ Offers Equity; US Salary Range: $154.6K β $250.8K β’ Offers Equity
Company
Globally distributed remote-first team building developer tools including Desktop, Hub, and Scout.
What you will do
- Author and maintain image definition files tracking upstream OSS releases and build steps across dozens of images
- Adapt upstream Helm charts (cert-manager, grafana, mongodb, kyverno, etc.) for DHI images, handling security and Kubernetes concerns
- Track upstream versions, semver patterns, monorepos, and dependency chains
- Write Go-based integration tests validating images and charts in Kubernetes environments
- Triage CVEs and contribute to security hardening decisions
- Review peer PRs for definitions and charts against conventions
Requirements
- 6+ years of backend engineering experience with production-grade systems
- Bachelorβs degree in Computer Science, Engineering, or equivalent practical experience
- Strong familiarity with container and Kubernetes ecosystem (cert-manager, kyverno, grafana, istio)
- Comfort with YAML as primary working medium
- Understanding of container security basics (non-root users, UID/GID, image layers, multi-arch, supply chain)
- Some Go proficiency for reading/writing test code
- Maintainer mindset with GitHub-heavy OSS workflows
Nice to have
- Experience as package maintainer (Linux distro, Homebrew)
- Helm chart authorship or contributions
- Familiarity with supply chain tooling (Sigstore, SBOM, SLSA)
- Experience in regulated or security-conscious environments
Culture & Benefits
- Remote-first culture with offices in Seattle and Paris
- Freedom and flexibility to fit work around life
- Quarterly Whaleness Days plus end-of-year break
- Home office setup and $100 USD/month technology stipend
- 16 weeks paid parental leave (after 6 months), PTO plan, training stipend
- Equity, swag, medical benefits, retirement, and holidays vary by country
- Sponsorship considered case-by-case based on business needs
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β