remote

Salary
$100,000–$145,000from the description
Posted
Jul 20, 2026
Location
Last confirmed open
Jul 22, 2026

What this job asks for AI summary

A software security engineering role focused on protecting software supply chains, open-source ecosystems, and code-hosting platforms. Day-to-day work involves securing source code repositories, assessing third-party and open-source dependency risks, building security automation and tooling, and partnering with engineering teams to embed secure development practices across the organization. Suits engineers with hands-on experience in GitHub administration, scripting, and software composition analysis.

Mid level · Remote · Full-time

Must have (6)
GitHubGitHub ActionsPython, Go, Shell Scripting or JavaScriptLinuxsoftware composition analysis (SCA)Artifactory or AWS
Nice to have (2)
GitLab or BitbucketAI

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 13,900 people nationally plausibly meet what this posting asks for (information security analysts). range 8,400–20,900

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Linux65%Python62%GitHub Actions40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The role is titled 'Engineer II' — a numeric level explicitly signaling Mid-level — and the requirements (no stated years minimum, hands-on implementation scope within a team) are consistent with that band.

SOC classification is a genuine toss-up: the role is security-focused (15-1212) but involves substantial automation/tooling development and scripting (15-1252). 15-1212 was chosen because the primary framing is security assessment, risk mitigation, and security controls rather than general software product delivery.

Scripting languages (Python, Golang, Shell, JavaScript) are listed as interchangeable options under a single requirement; Python is used as the primary name with the others as alternatives.

GitLab and Bitbucket are listed under 'Familiarity with source control platforms such as…' — a softer framing than the firm GitHub requirement — so they are marked preferred.

Artifactory and S3 are listed together as artifact storage options; Artifactory is used as the primary name with S3 as an alternative.

AI/AI technologies appears in the requirements section but is framed as 'experience leveraging AI technologies' without naming a specific tool or platform, making it a soft gate; it is marked preferred.

No overall years-of-experience minimum is stated in the posting.

The posting is listed via Jobgether on behalf of an unnamed partner company; the actual employer is not disclosed.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗