This job closed
It is no longer accepting applications. You can still read what the job asked for.
Principal Software Engineer
Sets technical direction for a secure libraries platform that builds, verifies, and serves open-source packages across multiple ecosystems. The role requires principal-level infrastructure experience, strong Go proficiency, and a track record of automating CI/CD and vulnerability-remediation workflows.
About the job
Responsibilities
- Define the architecture for scaling the Libraries Platform across language ecosystems, including .NET, Go, and Rust.
- Generalize package indexing, build orchestration, and metadata services while preserving clean ecosystem-specific extension points.
- Automate CVE remediation from detection through patching, rebuilding, verification, release, SBOM and provenance regeneration, policy verification, and rollout.
- Establish direction for agentic and AI-driven security patch generation, including validation, regression testing, provenance, and human checkpoints.
- Set platform-wide technical direction across package indexes, build and packaging pipelines, registry mirrors, and orchestration tooling.
- Make build-versus-buy and sequencing decisions for new ecosystem support.
- Partner with Ecosystem, Platform, Delivery, Sustaining, and Security teams on roadmap and risk alignment.
- Mentor Staff and Senior Engineers, lead design reviews, and write technical documentation and RFCs.
- Define SLOs, lead incident response, and conduct postmortems for consequential platform failures.
- Troubleshoot toolchain, compiler, and dependency-resolution issues involving NuGet, Go modules, Cargo, and related systems.
Requirements
- 12+ years designing, building, and operating infrastructure for language ecosystems or developer platforms.
- Principal-level experience setting technical direction across multiple teams.
- Experience onboarding or significantly extending platform support for a language ecosystem or packaging model.
- Strong proficiency in Go.
- Experience automating manual remediation workflows with appropriate human checkpoints.
- Deep experience with CI/CD, agentic pipelines, cloud-native infrastructure, and infrastructure as code.
- Experience with Docker/OCI, Kubernetes, Terraform, and pipeline tooling such as GitHub Actions, Argo, or Tekton.
- Ability to diagnose toolchain, compiler, and packaging failures across multiple ecosystems and create systemic prevention.
- Excellent written communication in remote, distributed environments.
Nice to Have
- Software supply chain security experience, including SLSA, SBOMs, Sigstore, provenance, attestations, and secure-by-default packaging.
- Experience with Linux distributions, packaging, and reproducible build systems, including Alpine, Wolfi, Debian, Bazel, CMake, or Ninja.
- Familiarity with AI/ML packaging and infrastructure, including PyTorch and TensorFlow, in cloud and Kubernetes environments.
- Experience leading major improvements in automation maturity.
Compensation and Benefits
- Base salary: $229,000–$258,000 USD.
- Flexible, remote-first culture with team meetups, biannual destination summits, and a monthly coworking, phone, and internet stipend.
- Stock options upon hire and promotion, participation in secondary offerings, and a 10-year exercise window.
- 100% covered health, vision, and dental insurance.
Skills
Go, Docker, Oci, Kubernetes, Terraform, GitHub Actions, Argo, Tekton, Nuget, Go Modules, Cargo, Slsa, Sbom, Sigstore