Senior Python Engineer - Open Source Stewardship & Tooling

Insight Global
Raleigh, NC
Job Description A client of Insight Global is looking for a Senior Software Engineer. In this role, you will work as part of a team responsible for establishing the technical stewardship capabilities required by the EU Cyber Resilience Act (CRA). You will focus on developing the tooling and infrastructure necessary to generate comprehensive Software Bill of Materials (SBOMs) for critical open-source community projects and integrating these manifests into Red Hat's incident response workflows. You will build automated solutions that bridge the gap between upstream project development and downstream security compliance, ensuring rapid detection of vulnerabilities in open-source components. You will collaborate with internal security teams and external open-source communities to align on data standards and "secure by design" principles. Primary Job Responsibilities ● Design and develop automated tooling to generate and maintain Software Bill of Materials (SBOMs) for upstream open-source projects in standardized machine-readable formats (e.g., SPDX, CycloneDX). ● Integrate SBOM generation into community Continuous Integration (CI) systems to ensure real-time tracking of top-level and transitive dependencies, including the generation of unique component identifiers (CPE, PURL). ● Build "Early Warning" workflows by connecting community SBOMs with Red Hat's Product Security Incident Response Team (PSIRT) tooling, enabling the automatic mapping of new vulnerabilities (CVEs) to impacted upstream projects. ● Implement machine-readable advisory generation (CSAF VEX) for community projects to support transparency and automated vulnerability handling requirements. ● Continuously improve tooling to reduce the average time to patch critical vulnerabilities in stewarded open-source components. We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to [email protected] learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: Skills and Requirements Advanced (5+ years) knowledge of Python programming language and their ecosystems. ● Deep understanding of Software Supply Chain Security concepts, including SBOM standards (SPDX, CycloneDX) and vulnerability data formats (CSAF, VEX, OSV). ● Intermediate (3+ years) experience with relational databases (e.g., PostgreSQL) for managing vulnerability and component metadata. ● Experience with CI/CD pipelines (e.g., Tekton, GitHub Actions, GitLab CI) and integrating security scanning tools into build processes. ● Interest in the container ecosystem (Kubernetes, Red Hat OpenShift, Podman). ● Good written and verbal communication skills in English, with a strong ability to collaborate in open-source communities
Posted 2025-12-02

Recommended Jobs

Product Specialist Lead

ABB
Pinetops, NC

At ABB, we help industries outrun - leaner and cleaner. Here, progress is an expectation - for you, your team, and the world. As a global market leader, we'll give you what you need to make it happen.…

View Details
Posted 2025-12-13

Java Developer

IMCS Group
Charlotte, NC

Requirements Candidate should have Financial industry exp to be considered for this role •       BPMN OR Sprint Boot •       MQ •       SOAP and REST API Integration •       Core Java …

View Details
Posted 2025-12-11

Mid/Senior Software Developer

Aecom
Raleigh, NC

Company Description Work with Us. Change the World. At AECOM, we're delivering a better world. Whether improving your commute, keeping the lights on, providing access to clean water, or trans…

View Details
Posted 2025-11-25

Contract HHA Position

Guardian Angel Senior Services
Salisbury, NC

&##127970; Guardian Angel Senior Services is hiring for a Contract Position with Beth Israel Lahey Health at Home &##128338; Full-Time – Short Hour Shifts- 13 weeks 5-6 clients per day   What…

View Details
Posted 2025-11-26

Employed Gastroenterology - North of Charlotte, North Carolina - Great system

Enterprise Medical Recruiting
North Carolina

Enterprise Medical Recruiting is assisting a group practice in North Carolina, about 40 minutes north of Charlotte, to recruit a new Gastroenterologist. This is a 4 person group with 4 Advanced Pract…

View Details
Posted 2025-09-29

Sales and Service Specialist (35789)

Hertz
Winston Salem, NC

The Sales and Service Specialist , TNC is an essential member of the Hertz Local Edition team. As a brand ambassador, the Sales and Service Specialist will be facilitating the fastest, easiest,…

View Details
Posted 2025-10-09

Staff Accountant

Insteel Industries
North Carolina

Staff Accountant Position Snapshot Assist the Assistant Controller and the Financial Services Department with accounting, financial reporting, and compliance activities. Essential Duties and…

View Details
Posted 2025-12-05

Principal Member of Technical Staff - OCI Network Operating Systems

Oracle
Raleigh, NC

**Job Description** In this role, you will have ownership and influence over the core architecture and implementation of the Network Operating System, driving critical features and improvements for OC…

View Details
Posted 2025-11-14

FR Y-14A Reporting and Capital Special Projects Manager

Truist
Charlotte, NC

**The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to cre…

View Details
Posted 2025-11-18

Optical Design Engineer

Broadcom
Charlotte, NC

**Please Note:** **1. If you are a first time user, please create your candidate login account before you apply for a job. (Click Sign In Create Account)** **2. If you already have a Candidate Acco…

View Details
Posted 2025-12-02