Security Engineer
Open Home Foundation
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role Overview
Join the Home Assistant team as a Security Engineer. You will improve the project’s security posture by owning the process for handling security issues, hardening CI/CD and release workflows, strengthening software supply chain defenses, and coordinating external security assessments.
Responsibilities
- Security issue intake & coordination
- Triaging reports via established channels (including GitHub Security Advisories and the security contact process)
- Reproducing issues, coordinating fixes with maintainers
- Ensuring responsible disclosure practices
- Remediation & communication
- Tracking SLAs, updating reporters and internal stakeholders
- Coordinating releases and backports when needed
- Harden CI/CD and release workflows
- Improve build pipeline security, secrets management, artifact integrity, and access controls
- Reduce exposure to supply chain attacks
- Strengthen supply chain security
- Improve dependency and artifact verification, provenance, signing, and monitoring
- Harden how third-party code and integrations enter the ecosystem
- Preventive security practices
- Introduce and continuously improve security testing/scanning in engineering workflows
- Apply SAST/DAST (where appropriate), dependency/artifact scanning, and CI/workflow static analysis
- Coordinate external security work
- Scope/manage third-party audits, pentests, and targeted reviews
- Ensure findings are effectively remediated
- Security processes & community collaboration
- Maintain clear, repeatable, community-friendly security documentation (runbooks for incident response and disclosure)
- Support maintainers/contributors with security guidance; review security-relevant PRs
- Help raise security awareness across the project
Requirements
- Experience: 5+ years preferred, or 3+ years with strong demonstrated ownership in vulnerability management and CI/CD / supply-chain security
- Experience triaging/coordinating vulnerability reports (e.g., CVEs, responsible disclosure workflows) and driving remediation across stakeholders
- Strong understanding of software supply chain security (dependencies, build systems, artifacts, signing/provenance, CI/CD hardening)
- Experience securing CI/CD pipelines (e.g., GitHub Actions), including secrets management, permissions, token scopes, and isolation
- Practical secure development practices, including risk assessments and security reviews
- Ability to work independently with strong problem-solving and attention to detail
- Extensive proficiency with Git/GitHub workflows
- Fluent English (written and verbal)
- EU residency and eligibility to work in Europe
Nice to Have
- Experience with Python ecosystems and packaging (pip, PyPI), dependency management, and security tooling
- Familiarity with SBOMs, SLSA, signing/attestations (e.g., Sigstore/cosign), and reproducible builds
- Incident response and post-incident reviews
- Prior contributions to Home Assistant or other open-source projects
- Experience with IoT/smart home threat models
- Experience improving security testing and integrating checks into developer workflows
- Passion for Home Assistant/open-source community-driven development
About Open Home Foundation
Open Home Foundation is an open-source organization associated with the Home Assistant project, providing home automation software and ecosystem contributions. The role focuses on improving security across the Home Assistant codebase, build/release pipelines, dependencies, and community disclosure processes.
Scraped 4/16/2026