"Alerted.org

Job Title, Industry, Employer
City & State or Zip Code
20 mi
  • 0 mi
  • 5 mi
  • 10 mi
  • 20 mi
  • 50 mi
  • 100 mi
Advanced Search

Advanced Search

Cancel
Remove
+ Add search criteria
City & State or Zip Code
20 mi
  • 0 mi
  • 5 mi
  • 10 mi
  • 20 mi
  • 50 mi
  • 100 mi
Related to

  • Senior Python Engineer - Open Source Stewardship…

    Insight Global (Raleigh, NC)



    Apply Now

    Job Description

    A client of Insight Global is looking for a Senior Software Engineer. In this role, you will work as part of a team responsible for establishing the technical

     

    stewardship capabilities required by the EU Cyber Resilience Act (CRA).

     

    You will focus on developing the tooling and infrastructure necessary to generate comprehensive Software Bill of Materials (SBOMs) for critical open-source community

     

    projects and integrating these manifests into Red Hat’s incident response workflows.

     

    You will build automated solutions that bridge the gap between upstream project development and downstream security compliance, ensuring rapid detection of

     

    vulnerabilities in open-source components. You will collaborate with internal security teams and external open-source communities to align on data standards and "secure by design" principles.

    Primary Job Responsibilities

    • Design and develop automated tooling to generate and maintain Software Bill

    of Materials (SBOMs) for upstream open-source projects in standardized

    machine-readable formats (e.g., SPDX, CycloneDX).

     

    • Integrate SBOM generation into community Continuous Integration (CI)

     

    systems to ensure real-time tracking of top-level and transitive dependencies,

     

    including the generation of unique component identifiers (CPE, PURL).

     

    • Build "Early Warning" workflows by connecting community SBOMs with Red

     

    Hat's Product Security Incident Response Team (PSIRT) tooling, enabling the

     

    automatic mapping of new vulnerabilities (CVEs) to impacted upstream projects.

     

    • Implement machine-readable advisory generation (CSAF VEX) for

     

    community projects to support transparency and automated vulnerability

     

    handling requirements.

     

    • Continuously improve tooling to reduce the average time to patch critical

     

    vulnerabilities in stewarded open-source components.

     

    We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to [email protected] learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

     

    Skills and Requirements

     

    Advanced (5+ years) knowledge of Python programming language and their

     

    ecosystems.

     

    • Deep understanding of Software Supply Chain Security concepts, including

     

    SBOM standards (SPDX, CycloneDX) and vulnerability data formats (CSAF,

     

    VEX, OSV).

     

    • Intermediate (3+ years) experience with relational databases (e.g., PostgreSQL)

     

    for managing vulnerability and component metadata.

     

    • Experience with CI/CD pipelines (e.g., Tekton, GitHub Actions, GitLab CI) and

     

    integrating security scanning tools into build processes.

     

    • Interest in the container ecosystem (Kubernetes, Red Hat OpenShift, Podman).

    • Good written and verbal communication skills in English, with a strong ability to

     

    collaborate in open-source communities

     


    Apply Now



Recent Searches

  • Material Management Supervisor Full (United States)
  • Merchandise Sales Manager Arena (Washington)
  • rn vascular surgery office (United States)
  • Per Diem Surgical Outcomes (New York)
[X] Clear History

Recent Jobs

  • Senior Python Engineer - Open Source Stewardship & Tooling
    Insight Global (Raleigh, NC)
  • Certified Personal Trainer
    Anytime Fitness (Goshen, IN)
  • Nurse Practitioner - GYN Oncology - .6 FTE
    PeaceHealth (Bellingham, WA)
  • Automotive Detailer - Car Washer - Eldon - Temp
    Enterprise Mobility (Eldon, MO)
[X] Clear History

Account Login

Cancel
 
Forgot your password?

Not a member? Sign up

Sign Up

Cancel
 

Already have an account? Log in
Forgot your password?

Forgot your password?

Cancel
 
Enter the email associated with your account.

Already have an account? Sign in
Not a member? Sign up

© 2025 Alerted.org