Engineer II, Software Assurance, Product Security at Jobgether
$100,000–$145,000from the description
Jul 20, 2026
—
Jul 22, 2026
What this job asks for AI summary
A software security engineering role focused on protecting software supply chains, open-source ecosystems, and code-hosting platforms. Day-to-day work involves securing source code repositories, assessing third-party and open-source dependency risks, building security automation and tooling, and partnering with engineering teams to embed secure development practices across the organization. Suits engineers with hands-on experience in GitHub administration, scripting, and software composition analysis.
Mid level · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 13,900 people nationally plausibly meet what this posting asks for (information security analysts). range 8,400–20,900
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The role is titled 'Engineer II' — a numeric level explicitly signaling Mid-level — and the requirements (no stated years minimum, hands-on implementation scope within a team) are consistent with that band.
SOC classification is a genuine toss-up: the role is security-focused (15-1212) but involves substantial automation/tooling development and scripting (15-1252). 15-1212 was chosen because the primary framing is security assessment, risk mitigation, and security controls rather than general software product delivery.
Scripting languages (Python, Golang, Shell, JavaScript) are listed as interchangeable options under a single requirement; Python is used as the primary name with the others as alternatives.
GitLab and Bitbucket are listed under 'Familiarity with source control platforms such as…' — a softer framing than the firm GitHub requirement — so they are marked preferred.
Artifactory and S3 are listed together as artifact storage options; Artifactory is used as the primary name with S3 as an alternative.
AI/AI technologies appears in the requirements section but is framed as 'experience leveraging AI technologies' without naming a specific tool or platform, making it a soft gate; it is marked preferred.
No overall years-of-experience minimum is stated in the posting.
The posting is listed via Jobgether on behalf of an unnamed partner company; the actual employer is not disclosed.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.