Staff Vulnerability Management Engineer
Core
Manage the pipeline for thousands of novel vulnerabilities weekly identified by frontier AI models, handling measurement, disclosure, reporting, and coordination with upstream projects and industry bodies.
Role type
Staff Vulnerability Management Engineer (Individual Contributor)
Builds
Secure open source software supply chain and hardened container base images
Domain
Cybersecurity, Open Source, AI Supply Chain Security
Deliverable
production ML models | dashboards & analysis | client delivery
Required skills
Vulnerability disclosure management, responsible disclosure, pipeline automation at scale, open source community coordination, public sector/standards body coordination, CVE assignment (CNA)
Preferred skills
Thought leadership in vulnerability disclosure, minimal/hardened container ecosystems, CNA operation, security research/pen testing/bug bounties, Python/Java/JavaScript/Go
Technologies
Python, Java, JavaScript, Go
Responsibilities
Manage the novel vulnerabilities pipeline; Calibrate response processes for emerging trends; Report vulnerabilities to upstream projects and maintainers; Run the CNA program to assign new CVEs; Coordinate internal and external embargoes; Work with Linux Foundation, CISA, and other bodies; Represent Chainguard externally; Work with AI model vendors to guide software supply chain evolution
Seniority
Staff, technical leadership & cross-team influence