Skip to content

This job closed

It is no longer accepting applications. You can still read what the job asked for.

Principal Software Engineer

Sets technical direction for a secure libraries platform that builds, verifies, and serves open-source packages across multiple ecosystems. The role requires principal-level infrastructure experience, strong Go proficiency, and a track record of automating CI/CD and vulnerability-remediation workflows.

About the job

Responsibilities

  • Define the architecture for scaling the Libraries Platform across language ecosystems, including .NET, Go, and Rust.
  • Generalize package indexing, build orchestration, and metadata services while preserving clean ecosystem-specific extension points.
  • Automate CVE remediation from detection through patching, rebuilding, verification, release, SBOM and provenance regeneration, policy verification, and rollout.
  • Establish direction for agentic and AI-driven security patch generation, including validation, regression testing, provenance, and human checkpoints.
  • Set platform-wide technical direction across package indexes, build and packaging pipelines, registry mirrors, and orchestration tooling.
  • Make build-versus-buy and sequencing decisions for new ecosystem support.
  • Partner with Ecosystem, Platform, Delivery, Sustaining, and Security teams on roadmap and risk alignment.
  • Mentor Staff and Senior Engineers, lead design reviews, and write technical documentation and RFCs.
  • Define SLOs, lead incident response, and conduct postmortems for consequential platform failures.
  • Troubleshoot toolchain, compiler, and dependency-resolution issues involving NuGet, Go modules, Cargo, and related systems.

Requirements

  • 12+ years designing, building, and operating infrastructure for language ecosystems or developer platforms.
  • Principal-level experience setting technical direction across multiple teams.
  • Experience onboarding or significantly extending platform support for a language ecosystem or packaging model.
  • Strong proficiency in Go.
  • Experience automating manual remediation workflows with appropriate human checkpoints.
  • Deep experience with CI/CD, agentic pipelines, cloud-native infrastructure, and infrastructure as code.
  • Experience with Docker/OCI, Kubernetes, Terraform, and pipeline tooling such as GitHub Actions, Argo, or Tekton.
  • Ability to diagnose toolchain, compiler, and packaging failures across multiple ecosystems and create systemic prevention.
  • Excellent written communication in remote, distributed environments.

Nice to Have

  • Software supply chain security experience, including SLSA, SBOMs, Sigstore, provenance, attestations, and secure-by-default packaging.
  • Experience with Linux distributions, packaging, and reproducible build systems, including Alpine, Wolfi, Debian, Bazel, CMake, or Ninja.
  • Familiarity with AI/ML packaging and infrastructure, including PyTorch and TensorFlow, in cloud and Kubernetes environments.
  • Experience leading major improvements in automation maturity.

Compensation and Benefits

  • Base salary: $229,000–$258,000 USD.
  • Flexible, remote-first culture with team meetups, biannual destination summits, and a monthly coworking, phone, and internet stipend.
  • Stock options upon hire and promotion, participation in secondary offerings, and a 10-year exercise window.
  • 100% covered health, vision, and dental insurance.

Skills

Go, Docker, Oci, Kubernetes, Terraform, GitHub Actions, Argo, Tekton, Nuget, Go Modules, Cargo, Slsa, Sbom, Sigstore