By contacting us you agree with the storage and handling of your data by this website.
About Triam Security:
Triam Security is revolutionizing software supply chain security through our advanced
vulnerability database platform and CleanStart product line. We provide hardened,
vulnerability-free container images with built-in security, compliance, and performance
benefits. Our mission is to transform container security by eliminating pre-existing
vulnerabilities and providing full visibility and control over the software supply chain.
Role Overview:
As a Senior DevSecOps Engineer on our Design team, you will lead the architecture and
design of new hardened container images for our CleanStart product line. You will establish
secure-by-design principles, create reproducible image specifications, and collaborate
with cross-functional teams to ensure our container images meet the highest security
standards while maintaining compatibility and performance. Your expertise will drive
innovation in our container image portfolio and set the foundation for vulnerability-free
deployments.
Key Responsibilities:
- Lead the architectural design of new hardened container images with zero
vulnerabilities
- Develop declarative specifications and build definitions for container images
- Establish security standards and guidelines for container image creation
- Design minimized base images that reduce attack surface while maintaining
functionality
- Create reproducible build processes for container images
- Collaborate with security researchers to address vulnerabilities at the design
phase
- Design image verification and validation methodologies
- Mentor junior engineers and provide technical leadership
- Contribute to the evolution of image design best practices and standards
- Collaborate with Build teams to ensure designs are implementable and maintainable
Required Qualifications:
- 5+ years of experience in DevOps, infrastructure as code, or security engineering
- Strong understanding of container technologies and image creation (Docker,
Buildah, etc.)
- Experience with declarative configuration and infrastructure as code
- Deep knowledge of Linux systems and package management
- Understanding of security principles and vulnerability management
- Proficiency in scripting languages (Bash, Python, Go, etc.)
- Experience with CI/CD pipelines and automation
- Strong problem-solving and architectural thinking skills
- Excellent communication and collaboration abilities
Preferred Qualifications:
- Experience with container image hardening or minimization techniques
- Knowledge of software supply chain security concepts and frameworks
- Familiarity with SLSA, SBOM, or in-toto attestation
- Experience with multiple container base images and distributions
- Background in security engineering or secure development
- Contributions to open-source projects related to containers or security
- Experience with Google Cloud Platform or other cloud environments
- Understanding of compliance frameworks (FIPS, NIST, etc.)