← All open roles

H11 Β· Systems software

Build and Software Supply Chain Engineer

Make every delivered component traceable to an intended source and build. You will protect the path from an engineer's change to a user's computer.

Pilot expansionOffice-first9 cities

About the role

You protect the path from an engineer's change to a user's computer, so every delivered component is traceable to an intended source and build. Supply chain is where a lot of otherwise careful security postures quietly fail, and this role exists because we would rather not find that out later.

The work

Build reproducible packaging, dependency inventories, artifact signing, isolated build systems and release provenance. Apply the same discipline to firmware, containers, models and extensions. Design signing-key rotation and recovery from a compromised release credential.

What good looks like

In your first 90 days, produce a signed release with a software bill of materials, verifiable provenance and a tested rollback path.

Evidence we look for

Bring practical build-system and release-security experience. Explain the difference between signing an artifact and proving that it was built from an approved source.

What we need to see

  • Practical build-system and release-security experience in production
  • You can explain the difference between signing an artifact and proving it was built from approved source, and have implemented the second
  • Reproducible or verifiable builds in practice
  • You think about the dependency tree as an attack surface

Nice to have

  • SLSA, in-toto, Sigstore, or equivalent frameworks
  • You have responded to a real supply-chain incident
  • Experience hardening CI/CD itself

The exercise

Design a release response after a dependency is compromised, including how affected users and artifacts are identified.

Where and how we work

In the office together five days a week, in any of these cities. Remote-friendly around your family, arranged one person at a time.