
Staff Vulnerability Management Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United Kingdom.
• Take charge of the measurement, disclosure, and reporting of a vast pipeline of novel vulnerabilities identified weekly through frontier models and additional sources.
• Adjust the vulnerability response process based on emerging trends.
• Oversee the reporting of newly discovered vulnerabilities to upstream projects and maintainers.
• Administer the CNA program to assign new CVEs when necessary.
• Coordinate internal and external embargoes with customers, internal engineering teams, and external maintainers.
• Collaborate with the Linux Foundation, CISA, and other organizations to synchronize actions and responses.
• Steer industry direction to ensure that Chainguard customer needs are addressed by emerging standards and norms.
• Represent Chainguard externally and prominently as the face of its industry-leading initiatives.
• Partner with AI model vendors to influence the future evolution of the software supply chain.
• Over 7 years of experience in software security, open source maintenance, or vulnerability disclosure management.
• Strong comprehension of responsible disclosure practices.
• Practical experience in automating pipelines and processes at scale while minimizing human intervention.
• Extensive experience with open source communities.
• Background in coordinating with public sector or industry standards bodies and working groups.
• Established thought leadership in vulnerability disclosure management and embargo processes (preferred).
• Familiarity with Chainguard Images or other minimal/hardened container base image ecosystems (preferred).
• Experience operating a CNA (preferred).
• Software engineering background in Python, Java, JavaScript, Go, or similar languages (preferred).
• Experience in security research, penetration testing, or bug bounty programs (preferred).
• Flexible & Remote-First Culture.
• Opportunities for team meetups.
• Bi-annual destination summits.
• Monthly stipend for coworking spaces, phone, and internet expenses.
• Stock options upon hiring and promotion.
• Participation in secondary offerings.
• 10 years to exercise stock options.
• 100% coverage of health, vision, and dental insurance premiums for employees and their dependents.
• Unlimited flexible time off.
• 18 weeks of paid parental leave for birthing parents.
• 12 weeks of paid parental leave for non-birthing parents.
• Option to utilize parental leave all at once or spread it throughout the child's first year.
LiteLLM AI Gateway
Snowflake
RTX
C-MORE
Get handpicked remote jobs straight to your inbox weekly.