Software Supply Chain Security Engineer (AI & Data Systems) Job at Oteemo Inc., San Antonio, TX

VTdFVUVXVGZaNzRrRjlzTTNXcDFoSjNtTmc9PQ==
  • Oteemo Inc.
  • San Antonio, TX

Job Description

We are looking for a senior engineer who can apply AI, data analysis, and automation to secure the software supply chain. This is not a “train a model” research role — it’s a practical, hands-on position where you’ll use LLMs, analytics, and automation to detect risks, prioritize fixes, and harden systems ranging from container images to package dependencies. You will turn messy vulnerability and SBOM data into clear, actionable security improvements.

Responsibilities:

  • Develop and automate SBOM workflows using open-source and commercial tools (e.g., Syft, Grype, CycloneDX, Dependency-Track).
  • Design and integrate LLM-driven solutions for vulnerability detection, CVE classification, and intelligent remediation recommendations.
  • Build automated pipelines for continuous ingestion, enrichment, and correlation of CVE and NVD data with internal dependency graphs.
  • Implement AI-assisted triage and prioritization logic for vulnerabilities based on context (CVSS, exploitability, package exposure, and runtime telemetry).
  • Integrate vulnerability scanning results into CI/CD pipelines and security dashboards (e.g., GitHub Actions, Jenkins, GitLab CI, Jira, ServiceNow).
  • Collaborate with security and development teams to automate root cause analysis and recommend mitigation paths using LLMs or knowledge graph–based systems.
  • Develop data pipelines and APIs to connect SBOM data, CVE feeds, and vulnerability databases for real-time updates.
  • Apply AI/ML techniques to prioritize vulnerabilities, suggest fixes, and detect high-risk patterns across large dependency sets.
  • Automate ingestion and normalization of advisories, scanner output, and vendor data for security decision-making.
  • Experiment with LLMs to reduce manual triage, generate draft remediation guidance, and summarize vendor notices.
  • Provide data-driven recommendations for securing containers, AMIs, ISOs, packages, and third-party dependencies.
  • Develop dashboards and metrics (e.g., risk scores, patch coverage, remediation timelines) for engineering and leadership.
  • Document workflows and enable other teams to use AI/automation in supply chain security.
  • Research and evaluate emerging AI and automation frameworks for software supply chain and vulnerability management.

Qualifications:

  • DOD Clearance Eligibility.
  • 5+ years of experience in DevSecOps, cybersecurity engineering, or infrastructure automation.
  • Solid understanding of software supply chain security concepts (containers, packages, SBOMs, vulnerability management).
  • Hands-on experience with SBOM and vulnerability tooling (Syft, Grype, Trivy, Anchore, Dependency-Track, Clair, etc.).
  • Strong knowledge of CVE/NVD, CVSS scoring, CWE classification, and vulnerability lifecycle.
  • Experience building automation pipelines with Python, Go, or similar languages.
  • Familiarity with LLM APIs and frameworks (OpenAI, LangChain, Hugging Face, or similar).
  • Experience integrating AI-driven insights into security workflows or ticketing systems.
  • Solid understanding of container security, dependency management, and CI/CD environments.
  • Experience deploying LLMs or fine-tuning domain-specific models for cybersecurity applications.
  • Background in knowledge graph engineering or semantic enrichment of CVE and SBOM data.
  • Familiarity with Kubernetes, Terraform, and cloud-native security frameworks (AWS, Azure, GCP).
  • Contributions to open-source security automation or SBOM projects.
  • Strong written and verbal communication skills, with the ability to translate technical details into actionable insights.

Nice to Have:

  • Active Secret or Top Secret Clearance.

Job Tags

Similar Jobs

Blizzard Entertainment

Storyboard Artist - Temp (SFD / Cinematics) Job at Blizzard Entertainment

 ...Team Name: Creative Development Job Title: Storyboard Artist Temp (SFD / Cinematics) Requisition ID: R026498 Job Description: Blizzard Entertainment is looking to hire a Storyboard Artist to join our ranks! Our ideal candidate would be an outstanding... 

Addison Group

Recruiter Job at Addison Group

 ...recruiting plans Partner with hiring managers to determine staffing needs and timelines Create and maintain job descriptions...  ...implement college recruiting initiatives Utilize social media and online channels for sourcing Post job openings across appropriate... 

UHP

Assistant Performance Coach Job at UHP

 ...UHP Assistant Performance Coach Location: UHP, 25200 Ranch Rd, Gentry, AR 72734 Job Type: Full-time, in-person Salary Range: $40,000 $50,000 annually Reports To: Director of Performance Position Overview UHP is seeking a motivated, mission-driven... 

MalaceHR

Maintenance Electrician (FLEX2) Job at MalaceHR

Malace|HR is seeking a Maintenance Electrician for a direct-hire/full time opportunity in a 24/7 logistics facility. Must hold an active...  ...appearance. Performs other operational tasks as assigned. Travel as required to support network needs. Minimum... 

Automoves

Technical SEO & WordPress Specialist Job at Automoves

 .... Open or enclosed car shipping is available depending on your needs and budget. The Role The Role Were looking for a Technical SEO & WordPress Specialist to own the technical health, implementation, and ongoing performance of the Automoves website. Youll...