By contacting us you agree with the storage and handling of your data by this website.
About Triam Security:
Triam Security is revolutionizing software supply chain security through our advanced
vulnerability database platform and CleanStart product line. We provide hardened,
vulnerability-free container images with built-in security, compliance, and performance
benefits. Our mission is to transform container security by eliminating pre-existing
vulnerabilities and providing full visibility and control over the software supply chain.
Role Overview:
As a Senior Container Security & Quality Assurance Engineer, you will lead our efforts in
ensuring the security and quality of our hardened container images. You will develop and
implement testing strategies, automate quality assurance processes, and collaborate with
engineering teams to maintain our zero-vulnerability standard. Your expertise will be crucial
in verifying the security posture, compliance, and performance of our CleanStart image
portfolio.
Key Responsibilities:
- Design and implement comprehensive QA strategies for container image testing
- Develop automated testing frameworks for security validation, compliance
verification, and performance testing
- Lead the evaluation of container images for security vulnerabilities and quality
issues
- Create and maintain test infrastructure for continuous validation of container
images
- Establish quality metrics and benchmarks for hardened container images
- Collaborate with engineering teams to resolve security and quality issues
- Review and approve container images for production release
- Develop and document QA processes and best practices
- Mentor junior QA engineers and provide technical guidance
Required Qualifications:
- 5+ years of experience in software quality assurance or security testing
- Strong knowledge of container technologies (Docker, Kubernetes, etc.)
- Experience with automated testing frameworks and CI/CD pipelines
- Proficiency in scripting languages (Python, Bash, etc.)
- Understanding of Linux systems and container security concepts
- Experience with vulnerability scanning tools (Trivy, Grype, Snyk, etc.)
- Strong problem-solving skills and attention to detail
- Excellent communication and collaboration abilities
Preferred Qualifications:
- Experience with supply chain security or secure image building
- Knowledge of compliance frameworks (SLSA, NIST, FedRAMP)
- Familiarity with SBOM generation and validation
- Experience with container image hardening techniques
- Background in security engineering or secure development
- Knowledge of in-toto or other attestation frameworks
- Experience with Google Cloud Platform or other cloud environments