Supply Chain Security Lead
Core
Lead the software supply chain security strategy to secure open source artifacts and enforce security governance across the enterprise build and release lifecycle.
Role type
Senior IC supply chain security lead (DevSecOps)
Builds
Secure-by-default open source artifacts and enterprise CI/CD pipelines
Domain
Financial services / Software Supply Chain Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
software supply chain security, artifact cache management, SBOM governance, code provenance, policy-as-code, CI/CD automation, SLSA principles, cloud security (Azure/AWS), application security tooling
Preferred skills
Java, .Net, Python, Node.js, Ansible, Terraform, Kubernetes, Infrastructure as Code, Agile/DevOps
Technologies
JFrog Artifactory, Maven Central, PyPI, Azure, AWS, Ansible, Terraform, Kubernetes
Responsibilities
Build and execute software supply chain security strategy; Lead and grow the Software Supply Chain Security team; Partner with Engineering leads to implement DevSecOps and AppSec principles; Establish governance for SBOM, artifact integrity, and code provenance; Deliver security reporting via dashboards and metrics; Develop and maintain security documentation; Continuously improve DevSecOps processes and tools.
Seniority
Senior, hands-on IC with team leadership