Staff Vulnerability Management Engineer

Chainguard
United Kingdom
Workplace: RemoteFull timeFunction: Data Analytics & Business IntelligenceExperience: 7+ yearsSkills: ["Technical leadership","Cross-team influence","Responsible disclosure"]

Lead Chainguard’s vulnerability management efforts for open source security in the AI supply chain. You’ll manage a vulnerabilities pipeline driven by frontier models, measure and report newly discovered issues, coordinate responsible disclosure and embargoes with upstream maintainers, and run a CNA program to assign CVEs. You’ll also collaborate across the industry, partnering with standards bodies and AI model vendors to shape emerging security norms.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Chainguard
Chainguard
9 hours ago

Staff Vulnerability Management Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 8 hours agoStatus: Live

Job Summary

Lead Chainguard’s vulnerability management efforts for open source security in the AI supply chain. You’ll manage a vulnerabilities pipeline driven by frontier models, measure and report newly discovered issues, coordinate responsible disclosure and embargoes with upstream maintainers, and run a CNA program to assign CVEs. You’ll also collaborate across the industry, partnering with standards bodies and AI model vendors to shape emerging security norms.
Location: United Kingdom
Workplace: Remote
Employment Type: Full time
Job Function: Data Analytics & Business Intelligence
Seniority: Mid level

Key Responsibilities

  • •Manage the vulnerabilities pipeline and weekly reporting for novel vulnerabilities identified by frontier models and other sources.
  • •Own measurement, disclosure, and reporting processes for newly discovered vulnerabilities.
  • •Calibrate response processes to emerging trends and coordinate reporting to upstream projects and maintainers.
  • •Run the CNA program to assign new CVEs where necessary and coordinate internal/external embargoes.
  • •Coordinate across the industry, working with organizations such as the Linux Foundation and CISA, and represent Chainguard externally.

Pay and Benefits

Perks:Remote WorkHealth InsuranceVisionDentalEquityParental LeavePaid Leave

Key Requirements

  • •7+ years in software security, open source maintenance, or vulnerability disclosure management.
  • •Strong understanding of responsible disclosure.
  • •Practical expertise automating vulnerability pipelines and processes at large scale, reducing human-in-the-loop work.
  • •Deep experience with open source communities.
  • •Experience coordinating with public sector or industry standards bodies and working groups.
Experience:7+ yearsOpen sourceVulnerability disclosureSoftware security
Skills:Technical leadershipCross-team influenceResponsible disclosure
Languages:English
Tech Stack:CVECNAPythonJavaJavaScriptGoLinux FoundationCISA

Company Brief

Chainguard
Builds software supply chain security solutions for containerized and Kubernetes-native environments, offering tools for secure builds, attestations, vulnerability scanning, and policy enforcement to help organizations deploy trustworthy software at scale.
Industry: Cybersecurity
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Funding: Series C
Headquarters: Seattle, United States
Founded: 2020
WebsiteLinkedIn