Open Source Software Security Engineer - Software Supply Chain

Truist Financial
Charlotte, Richmond, Atlanta, Raleigh
Workplace: OnsiteFull timeUSD 105,000 - 130,000 annuallyFunction: CybersecurityExperience: 5+ yearsEducation: bachelorsSkills: ["Threat modeling","Risk reporting","Developer enablement","Cross-functional partnership","Executive-ready communication"]

Own the practical execution of open source software security across governance, engineering workflows, tooling, automation, and risk reduction. Define and operate enterprise standards and preventative controls to ensure OSS components and software supply chain artifacts are approved, monitored, remediated, and safely integrated. Partner with CI/CD, DevSecOps, application security, platform, and risk teams to implement automated security gates, dependency/provenance protections, and threat-response capabilities.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Truist Financial
Truist Financial
1 week ago

Open Source Software Security Engineer - Software Supply Chain

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Own the practical execution of open source software security across governance, engineering workflows, tooling, automation, and risk reduction. Define and operate enterprise standards and preventative controls to ensure OSS components and software supply chain artifacts are approved, monitored, remediated, and safely integrated. Partner with CI/CD, DevSecOps, application security, platform, and risk teams to implement automated security gates, dependency/provenance protections, and threat-response capabilities.
Location: Charlotte, Richmond, Atlanta, Raleigh
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Define governance, standards, and preventative controls for approved open source usage, dependency hygiene, SBOM generation, secure package sourcing, and software supply chain risk management.
  • •Establish OSS lifecycle management processes including intake, approval, tracking, vulnerability remediation, end-of-life retirement, and exception governance.
  • •Design and implement CI/CD preventative controls such as automated security gates for dependency scanning, license checks, artifact validation, provenance controls, and policy-based blocking.
  • •Reduce supply chain threats by managing risks for vulnerable dependencies, malicious packages, dependency confusion/typosquatting, compromised maintainers, insecure build artifacts, and unauthorized package sources.
  • •Develop tooling and reporting capabilities (e.g., software composition analysis, SBOM, vulnerability management, risk metrics) and provide developer enablement via guidance and playbooks.

Pay and Benefits

Salary: USD 105,000 - 130,000 annually
Perks:Health InsuranceDentalVisionLife InsuranceDisability Insurance401kPaid Leave

Key Requirements

  • •Bachelor’s degree or equivalent education, training, and work-related experience.
  • •Minimum of 5 years of experience in security engineering or related cybersecurity roles.
  • •Advanced knowledge of cybersecurity principles and software development lifecycle security practices.
  • •Advanced knowledge of threat modeling, security testing, and penetration testing.
  • •Proven experience implementing and managing complex information security technologies.
Experience:5+ yearsOpen sourceSoftware supply chainDevSecOpsCybersecurity
Education:Bachelor's
Skills:Threat modelingRisk reportingDeveloper enablementCross-functional partnershipExecutive-ready communication
Certifications:CISSPCISMCEHGIAC
Languages:English
Tech Stack:SBOMCI/CDDevSecOpsOWASPNIST Secure Software Development Framework (SSDF)SLSASCAPythonPowerShellBashArtifact signingProvenanceDependency scanningVulnerability managementPackage managersBuild systemsArtifact repositories

Company Brief

Truist Financial
Provides consumer and commercial banking, wealth management, insurance, lending, and payments services through a large U.S. financial services platform formed by the merger of BB&T and SunTrust.
Industry: Banking
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Charlotte, United States
Founded: 2019
WebsiteLinkedIn