🤫husshhussh
🤫husshhusshOnePuppy
Systems software · H11

Build and Software Supply Chain Engineer

Make every delivered component traceable to an intended source and build. You will protect the path from an engineer's change to a user's computer.

See what is open todayAll roles

Not open yet: Pilot expansion

This work starts when that stage arrives, so there is no application to submit today and we will not pretend otherwise. What is written below is what the role is for and what would make somebody right for it, published early on purpose so you can decide whether it is worth watching.

The work

What this person actually does

Build reproducible packaging, dependency inventories, artifact signing, isolated build systems and release provenance. Apply the same discipline to firmware, containers, models and extensions. Design signing-key rotation and recovery from a compromised release credential.

The milestone

What it looks like when it is working

In your first 90 days, produce a signed release with a software bill of materials, verifiable provenance and a tested rollback path.

Evidence

What would show us you can do it

Bring practical build-system and release-security experience. Explain the difference between signing an artifact and proving that it was built from an approved source.

Evidence, not credentials. We are describing work you can point at, in whatever form it exists.

The exercise

How we would look at it together

Design a release response after a dependency is compromised, including how affected users and artifacts are identified.

← All 72 roles in the catalog