





Strong brand, remote/hybrid role, mid-level generalist title, and metro location increase applicant competition.
Specialized software supply-chain security and DevSecOps focus reduces cross-industry portability of experience.
Explicit 6+ years in Golang, specific security toolchain and cloud/infra requirements create strict screening filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Design and develop Software Supply Chain Security capabilities including SBOM generation, artifact signing, provenance tracking, and secure build/release workflows.
Develop secure DevSecOps frameworks, libraries, CI templates, and IDE plugins to improve product teams' security adoption.
Lead automation and policy-driven controls for trusted software deployments and contribute to a centralized product security application for team self-service.
6+ years experience as software developer with Golang (backend) and JavaScript (VueJS frontend).
Proficient in developing robust, scalable REST APIs; exposure to GraphQL is a plus.
Experience building secure CI/CD pipelines using GitHub Actions and infrastructure as code with Terraform.
Working knowledge of AWS services (IAM, SQS, S3, Lambdas, DynamoDB, RDS, EKS, EC2) and familiarity with software supply chain security concepts (SBOMs, artifact signing, provenance).
Experienced in security engineering domains such as application security, DevSecOps, platform or product security automation.
Proven ability to design and implement secure-by-default development and deployment workflows integrating supply chain security standards (SLSA, Sigstore, SPDX, in-toto).
Capable of autonomous programming across backend and frontend stacks and advising on security best practices to management and cross-functional teams.