Software Supply Chain Security Engineer

Cerebras
Sunnyvale
Workplace: HybridFull timeFunction: CybersecurityEducation: mastersSkills: ["Pragmatic","Results-driven","Attention to detail","Strong written communication","Flexible in fast-paced environments"]

Assess and harden the full software supply chain, from storing and managing source code to deploying CI/CD artifacts into clusters. Define security requirements for artifact build pipelines, mature SLSA processes, and identify supply chain gaps across platform, infrastructure, networking, and hardware teams. Create threat models across build and deploy layers, embed security principles with devops and engineering leads, and communicate security posture to technical and nontechnical audiences.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cerebras
Cerebras
1 day ago

Software Supply Chain Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Assess and harden the full software supply chain, from storing and managing source code to deploying CI/CD artifacts into clusters. Define security requirements for artifact build pipelines, mature SLSA processes, and identify supply chain gaps across platform, infrastructure, networking, and hardware teams. Create threat models across build and deploy layers, embed security principles with devops and engineering leads, and communicate security posture to technical and nontechnical audiences.
Location: Sunnyvale
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Define core security requirements for artifact build pipelines, including maturing SLSA processes, from ideation through implementation.
  • •Partner with platform, infrastructure, networking, and hardware teams to identify supply chain gaps and deliver end-to-end CI/CD artifact confidence solutions.
  • •Develop threat models for each build/deploy layer, outlining trust boundaries and first- vs third-party mechanisms.
  • •Work with engineering leads and devops architects to bake secure supply chain principles into the build and deployment stack.
  • •Balance security controls with engineering outcomes and document security posture and strategy for technical and nontechnical audiences.

Key Requirements

  • •8-10 years of experience in software supply chain and SDLC, including secure code management and build pipeline hardening.
  • •Experience with artifact signing, attestation, and end-to-end integration across the SDLC.
  • •Strong hands-on engineering abilities in DevOps and SDLC contexts.
  • •Ability to work in fragmented and legacy build environments, including modernizing stacks (plus).
  • •Master’s in Computer Science or PhD (preferred).
Experience:Software supply chainSDLCCI/CDDevOpsLLM/agentic workflows
Education:Master's
Skills:PragmaticResults-drivenAttention to detailStrong written communicationFlexible in fast-paced environments
Tech Stack:AWSJenkinsSLSACI/CDDevOpsLLMAgentic workflows

Company Brief

Cerebras
Designs and builds wafer-scale AI accelerators and systems for large-scale deep learning workloads, delivering specialized hardware and software to accelerate model training and inference for enterprises and research institutions.
Industry: Hardware Devices
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: Sunnyvale, United States
Founded: 2016
WebsiteLinkedIn