xelys jobs xelys jobs

Security Engineer

Open Home Foundation

seniorpermanentsecuritybackend Italy 106 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Security EngineeringVulnerability ManagementSupply Chain SecurityCI/CDGitHub ActionsGitHub Security AdvisoriesSoftware Supply ChainSASTDASTSBOMs

About the role

Role Overview

Join the Home Assistant team as a Security Engineer. You will improve the project’s security posture by owning the process for handling security issues, hardening CI/CD and release workflows, strengthening software supply chain defenses, and coordinating external security assessments.

Responsibilities

  • Security issue intake & coordination
    • Triaging reports via established channels (including GitHub Security Advisories and the security contact process)
    • Reproducing issues, coordinating fixes with maintainers
    • Ensuring responsible disclosure practices
  • Remediation & communication
    • Tracking SLAs, updating reporters and internal stakeholders
    • Coordinating releases and backports when needed
  • Harden CI/CD and release workflows
    • Improve build pipeline security, secrets management, artifact integrity, and access controls
    • Reduce exposure to supply chain attacks
  • Strengthen supply chain security
    • Improve dependency and artifact verification, provenance, signing, and monitoring
    • Harden how third-party code and integrations enter the ecosystem
  • Preventive security practices
    • Introduce and continuously improve security testing/scanning in engineering workflows
    • Apply SAST/DAST (where appropriate), dependency/artifact scanning, and CI/workflow static analysis
  • Coordinate external security work
    • Scope/manage third-party audits, pentests, and targeted reviews
    • Ensure findings are effectively remediated
  • Security processes & community collaboration
    • Maintain clear, repeatable, community-friendly security documentation (runbooks for incident response and disclosure)
    • Support maintainers/contributors with security guidance; review security-relevant PRs
    • Help raise security awareness across the project

Requirements

  • Experience: 5+ years preferred, or 3+ years with strong demonstrated ownership in vulnerability management and CI/CD / supply-chain security
  • Experience triaging/coordinating vulnerability reports (e.g., CVEs, responsible disclosure workflows) and driving remediation across stakeholders
  • Strong understanding of software supply chain security (dependencies, build systems, artifacts, signing/provenance, CI/CD hardening)
  • Experience securing CI/CD pipelines (e.g., GitHub Actions), including secrets management, permissions, token scopes, and isolation
  • Practical secure development practices, including risk assessments and security reviews
  • Ability to work independently with strong problem-solving and attention to detail
  • Extensive proficiency with Git/GitHub workflows
  • Fluent English (written and verbal)
  • EU residency and eligibility to work in Europe

Nice to Have

  • Experience with Python ecosystems and packaging (pip, PyPI), dependency management, and security tooling
  • Familiarity with SBOMs, SLSA, signing/attestations (e.g., Sigstore/cosign), and reproducible builds
  • Incident response and post-incident reviews
  • Prior contributions to Home Assistant or other open-source projects
  • Experience with IoT/smart home threat models
  • Experience improving security testing and integrating checks into developer workflows
  • Passion for Home Assistant/open-source community-driven development

About Open Home Foundation

Open Home Foundation is an open-source organization associated with the Home Assistant project, providing home automation software and ecosystem contributions. The role focuses on improving security across the Home Assistant codebase, build/release pipelines, dependencies, and community disclosure processes.

Scraped 4/16/2026