> Markdown version of [/jobs/ext/1182124-senior-python-engineer-open-source-stewardship](https://www.wearedevelopers.com/jobs/ext/1182124-senior-python-engineer-open-source-stewardship). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Python Engineer - Open Source Stewardship... - **Company:** Insight Global - **Location:** Raleigh, NC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Continuous Integration, Data Governance, Relational Databases, Github, Python (Programming Language), PostgreSQL, Open Source Technology, OpenShift, Red Hat Enterprise Linux, Software Security, Gitlab-ci, Kubernetes, Build Process, Docker - **Published:** July 4, 2026 - **Apply:** https://www.juju.com/job/00000000gdjf0p ## About the Role Advanced (5+ years) knowledge of Python programming language and their ecosystems. * 4+ years experience designing non-trivial algorithms and systems. * 2+ years developing and testing applications using Python programming language and adjacent ecosystem. * Deep understanding of Software Supply Chain Security concepts, including SBOM standards (SPDX, CycloneDX) and vulnerability data formats (CSAF, VEX, OSV). * Intermediate (3+ years) experience with relational databases (e.g., PostgreSQL) for managing vulnerability and component metadata. * Experience with CI/CD pipelines (e.g., Tekton, GitHub Actions, GitLab CI) and integrating security scanning tools into build processes. * Interest in the container ecosystem (Kubernetes, Red Hat OpenShift, Podman). * Good written and verbal communication skills in English, with a strong ability to collaborate in open-source communities ## Description A client of Insight Global is looking for a Senior Software Engineer. In this role, you will work as part of a team responsible for establishing the technical stewardship capabilities required by the EU Cyber Resilience Act (CRA). You will focus on developing the tooling and infrastructure necessary to generate comprehensive Software Bill of Materials (SBOMs) for critical open-source community projects and integrating these manifests into Red Hat's incident response workflows. You will build automated solutions that bridge the gap between upstream project development and downstream security compliance, ensuring rapid detection of vulnerabilities in open-source components. You will collaborate with internal security teams and external open-source communities to align on data standards and "secure by design" principles. Primary Job Responsibilities * Design and develop automated tooling to generate and maintain Software Bill of Materials (SBOMs) for upstream open-source projects in standardized machine-readable formats (e.g., SPDX, CycloneDX). * Integrate SBOM generation into community Continuous Integration (CI) systems to ensure real-time tracking of top-level and transitive dependencies, including the generation of unique component identifiers (CPE, PURL). * Build "Early Warning" workflows by connecting community SBOMs with Red Hat's Product Security Incident Response Team (PSIRT) tooling, enabling the automatic mapping of new vulnerabilities (CVEs) to impacted upstream projects. * Implement machine-readable advisory generation (CSAF VEX) for community projects to support transparency and automated vulnerability handling requirements. * Continuously improve tooling to reduce the average time to patch critical ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [Walking into the era of Supply Chain Risks](https://www.wearedevelopers.com/videos/376-walking-into-the-era-of-supply-chain-risks) ## Related Articles - [The Future of Open Source: A Deep Dive - Scott Chacon at WeAreDevelopers World Congress 2024](https://www.wearedevelopers.com/magazine/471-the-future-of-open-source-a-deep-dive-scott-chacon-at-wearedevelopers-world-congress-2024) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 168: Hacking Postgres, Blocking Meta and Fixing CSS](https://www.wearedevelopers.com/magazine/588-dev-digest-168-hacking-postgres-blocking-meta-and-fixing-css) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)