Open Source Software Senior Security Engineer - Software Supply Chain

Truist Financial
Charlotte, North Carolina, Richmond, Raleigh, Atlanta
Workplace: OnsiteFull timeUSD 140,000 - 180,000 annuallyFunction: CybersecurityExperience: 7+ yearsEducation: bachelorsSkills: ["Partnering with stakeholders","Translating risk","Risk reporting","Developer enablement"]

Own practical open source software security across governance, engineering workflows, tooling, automation, and risk reduction. Define and operate enterprise standards and preventative controls for secure-by-default OSS lifecycles, including CI/CD security gates, dependency and provenance safeguards, artifact/build validation, and threat detection. Partner with CI/CD, DevSecOps, application security, engineering, platform, and risk teams to ensure components and pipelines are approved, monitored, remediated, and safely integrated.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Truist Financial
Truist Financial
1 week ago

Open Source Software Senior Security Engineer - Software Supply Chain

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Own practical open source software security across governance, engineering workflows, tooling, automation, and risk reduction. Define and operate enterprise standards and preventative controls for secure-by-default OSS lifecycles, including CI/CD security gates, dependency and provenance safeguards, artifact/build validation, and threat detection. Partner with CI/CD, DevSecOps, application security, engineering, platform, and risk teams to ensure components and pipelines are approved, monitored, remediated, and safely integrated.
Location: Charlotte, North Carolina, Richmond, Raleigh, Atlanta
Workplace: Onsite
Employment Type: Full time · Permanent
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Define policies, standards, and control requirements for approved open source usage, dependency hygiene, SBOM generation, and software supply chain risk management.
  • •Establish OSS intake, approval, tracking, version management, vulnerability remediation, and exception governance across the component lifecycle.
  • •Design and implement automated CI/CD preventative controls for curated OSS usage, dependency scanning, license checks, artifact validation, provenance controls, and policy-based blocking.
  • •Reduce supply chain risks from vulnerable dependencies, malicious packages, dependency confusion, compromised maintainers, insecure build artifacts, and unauthorized package sources.
  • •Establish capabilities to detect and respond to OSS supply chain threats and build tooling/automation to support SBOM, software composition analysis, repository integration, vulnerability management, and developer enablement.

Pay and Benefits

Salary: USD 140,000 - 180,000 annually
Perks:Health InsuranceDentalVisionLife InsuranceDisability401kPaid LeavePaid HolidaysPaid Sick

Key Requirements

  • •Bachelor’s degree or equivalent education, training, and work-related experience.
  • •Minimum of 7 years of experience in security engineering or related cybersecurity roles.
  • •Deep specialized knowledge of cybersecurity principles, concepts, threat modeling, security testing, and penetration testing.
  • •Proven experience applying software development lifecycle security practices.
  • •Experience implementing and managing complex information security technologies.
Experience:7+ yearsOpen sourceSoftware supply chain securityDevSecOpsApplication securityVulnerability managementSecure SDLC
Education:Bachelor's
Skills:Partnering with stakeholdersTranslating riskRisk reportingDeveloper enablement
Certifications:CISSPCISMCEHGIAC
Languages:English
Tech Stack:CI/CDDevSecOpsSBOMSCASLSAOWASPNIST SSDFArtifact signingProvenanceDependency scanningLicense checksSoftware composition analysisPackage repositoryVulnerability managementThreat modelingPenetration testingSBOM generationBashPythonPowerShell

Company Brief

Truist Financial
Provides consumer and commercial banking, wealth management, insurance, lending, and payments services through a large U.S. financial services platform formed by the merger of BB&T and SunTrust.
Industry: Banking
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Charlotte, United States
Founded: 2019
WebsiteLinkedIn