Staff Vulnerability Management Engineer
Chainguard · United States - Remote
About this role
## Chainguard — Staff Vulnerability Management Engineer ### The role in a nutshell You care deeply about the future of open source software and want to solve the new problems created by frontier models. At Chainguard, you’ll help lead the next chapter of AI supply chain security—working as an individual contributor with technical leadership, cross-team influence, and ownership of hard problems. ### What you’ll do - **Manage our novel vulnerabilities pipeline** - Own the measurement, disclosure, and reporting of a pipeline of **thousands of novel vulnerabilities weekly**, identified by frontier models and other sources - Calibrate our response process as emerging trends evolve - Manage reporting of newly discovered vulnerabilities to upstream projects and maintainers - Run our **CNA program** to assign new CVEs where necessary - Coordinate internal and external embargoes with customers, internal engineering teams, and external maintainers - **Coordinate across the industry** - Work with the **Linux Foundation**, **CISA**, and other bodies to coordinate actions and responses - Guide and lead industry direction to ensure Chainguard customer needs are met by emerging standards and norms - Represent Chainguard externally and visibly as a face of industry-leading efforts - Work with AI model vendors to guide the future evolution of the software supply chain ### What we’re looking for **Required** - **7+ years** in software security, open source maintenance, or vulnerability disclosure management - Strong understanding of **responsible disclosure** - Practical expertise automating pipelines and processes to operate at large scale and reduce human-in-the-loop - Deep experience with **open source communities** - Experience coordinating with public sector or industry standards bodies and working groups **Nice to Have** - Established thought leadership in vulnerability disclosure management and embargoes - Familiarity with **Chainguard Images** or other minimal/hardened container base image ecosystems - Experience operating a **CNA** - Software engineering background in **Python, Java, JavaScript, Go**, or similar languages - Background in security research, pen testing, or bug bounties ### Base salary range **$170,000 — $231,000 USD** ### About us We live and breathe our company values: - **Customer obsessed** - **Bias for intentional action** (prioritize, plan, try things, fail fast) - **Serious work, not serious selves** - **Trust each other and assume good intentions** (transparent decisions) **Benefits include:** - **Flexible, remote-first culture** (remote work + team meetup opportunities, destination summits, coworking/phone/internet stipend) - **Equity approach:** stock options upon hire and promotion; secondary offerings; **10 years** to exercise options - **100% covered health insurance** (health, vision, dental premiums for you and dependents) - **∞ Flexible Time Off** - **18 weeks paid parental leave** (birthing parents) and **12 weeks** (non-birthing parents) If your experience is close but doesn’t fulfill all requirements, please apply. Chainguard is an equal opportunity employer.
Listing freshness
CronJobs last confirmed this listing 3h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.