Software Supply Chain Security Engineer

Cerebras Systems

$150K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8-10 years of experience in software supply chain and SDLC including secure code management and pipeline hardening
  • Master's in Computer Science or PhD preferred
  • Strong hands-on skills in DevOps and SDLC
  • Experience modernizing legacy build environments is a plus
  • Familiarity with AWS, Jenkins, SLSA, and secure artifact practices
  • Excellent communication skills for non-specialists
  • Knowledge of Agentic workflows and understanding of LLM reasoning cycles

Responsibilities

  • Define security requirements for artifact build pipelines and implement them
  • Collaborate with various teams to identify gaps and deliver security solutions
  • Develop threat models for build and deployment layers
  • Incorporate secure supply chain principles with engineering leads and architects
  • Balance security controls with engineering outcomes to facilitate secure delivery
  • Document security strategies for both technical and non-technical audiences

Benefits

  • Opportunity to influence and mature software security processes
  • Collaborative environment partnering with diverse technical teams
  • Work in a fast-paced, innovative development setting
  • Room for professional growth and involvement in cutting-edge security practices
  • Flexibility to adapt security standards without compromising quality
Full Job Description
Cerebras is seeking a Software Supply Chain Security Engineer to help build a secure foundation for our build and development workflows.

In this role you will be responsible for assessing and hardening every layer of our source to artifact pipeline, from how we store and manage code to what we deploy into our clusters.

The ideal candidate brings a combination of wide breadth of knowledge on a variety of software supply chain topics throughout the whole SDLC process, a pragmatic and results-driven outlook on security, and the flexibility and attention to detail to work in a fast-paced development environment without compromising our security standards.
Responsibilities
  • Define core security requirements for artifact build pipelines including maturing SLSA processes, and see them through from ideation to implementation
  • Partner with platform, infrastructure, networking, and hardware teams to identify supply chain gaps and deliver end-to-end solutions for ensuring confidence in CI/CD artifacts
  • Develop threat models for each layer of the build and deploy stack, outlining trust boundaries and the interplay between first and third-party mechanisms
  • Work with engineering leads and devops architects to build in secure supply chain principles from the beginning
  • Balance engineering outcomes with security controls, enabling the company to deliver securely quickly
  • Document security posture and strategy for technical and nontechnical audiences from both 1p and 3p perspectives
Skills and Qualifications
  • 8-10 years of experience with software supply chain and SDLC topics including secure code management, build pipeline hardening, artifact signing and attestation, and the end-to-end integration thereof.
  • Masters in Computer Science or PhD (preferred)
  • Strong hands-on engineering abilities in devops and SDLC contexts
  • Ability to work in fragmented and legacy build environments, experience with modernizing stacks is a plus
  • Familiarity with AWS, Jenkins, SLSA, and best practices for secure artifact provenance and builds are a plus
  • Strong written communication skills, with the ability to make security concepts approachable for non-specialists.
  • Direct work with Agentic workflows and deep understanding of LLM and reasoning cycles.


Similar Jobs

More Jobs at Cerebras Systems

More Information Technology Jobs

Find similar Software Supply Chain Security Engineer jobs: