Senior Python Engineer - Open Source Stewardship...

Insight Global
Raleigh, NC, United States
2 months ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Continuous Integration Data Governance Relational Databases Github Python (Programming Language) PostgreSQL Open Source Technology OpenShift Red Hat Enterprise Linux Software Security Gitlab-ci Kubernetes
+2 more
Build Process Docker

Job description

A client of Insight Global is looking for a Senior Software Engineer. In this role, you will work as part of a team responsible for establishing the technical

stewardship capabilities required by the EU Cyber Resilience Act (CRA).

You will focus on developing the tooling and infrastructure necessary to generate comprehensive Software Bill of Materials (SBOMs) for critical open-source community

projects and integrating these manifests into Red Hat’s incident response workflows.

You will build automated solutions that bridge the gap between upstream project development and downstream security compliance, ensuring rapid detection of

vulnerabilities in open-source components. You will collaborate with internal security teams and external open-source communities to align on data standards and “secure by design” principles.

Primary Job Responsibilities

  • Design and develop automated tooling to generate and maintain Software Bill

of Materials (SBOMs) for upstream open-source projects in standardized

machine-readable formats (e.g., SPDX, CycloneDX).

  • Integrate SBOM generation into community Continuous Integration (CI)

systems to ensure real-time tracking of top-level and transitive dependencies,

including the generation of unique component identifiers (CPE, PURL).

  • Build “Early Warning” workflows by connecting community SBOMs with Red

Hat’s Product Security Incident Response Team (PSIRT) tooling, enabling the

automatic mapping of new vulnerabilities (CVEs) to impacted upstream projects.

  • Implement machine-readable advisory generation (CSAF VEX) for

community projects to support transparency and automated vulnerability

handling requirements.

  • Continuously improve tooling to reduce the average time to patch critical

Requirements

Advanced (5+ years) knowledge of Python programming language and their

ecosystems.

  • 4+ years experience designing non-trivial algorithms and systems.

  • 2+ years developing and testing applications using Python programming language and adjacent ecosystem.

  • Deep understanding of Software Supply Chain Security concepts, including

SBOM standards (SPDX, CycloneDX) and vulnerability data formats (CSAF,

VEX, OSV).

  • Intermediate (3+ years) experience with relational databases (e.g., PostgreSQL)

for managing vulnerability and component metadata.

  • Experience with CI/CD pipelines (e.g., Tekton, GitHub Actions, GitLab CI) and

integrating security scanning tools into build processes.

  • Interest in the container ecosystem (Kubernetes, Red Hat OpenShift, Podman).

  • Good written and verbal communication skills in English, with a strong ability to

collaborate in open-source communities

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:01 min

Bridging the gap between software development and security

Vandana Verma ¡ LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters ¡ World Congress 2023

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz ¡ World Congress 2025

4:47 min

Exploring OpenShift and Red Hat Developer Sandbox resources

Markus Eisele Markus Eisele ¡ World Congress 2024

1:32 min

Embracing open source engineering in a digital bank

Ferd Scheepers ¡ World Congress 2022

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle ¡ Coffee With Developers

Videos

See all

Related articles

See all