Principal Software Engineer (Supply Chain Security)
Full description
Principal Software Engineer, Supply Chain Security
Artifact Provenance - SLSA - SBOMs - Cryptography - Greenfield Platform Engineering
Join a fast-growing, developer-first technology company building critical infrastructure for modern software delivery.
You will help create the next generation of software supply chain trust systems, giving organisations verifiable traceability from source code to built artifact and every downstream environment in which it is used.
The Role
As a Principal Software Engineer within the Supply Chain Trust team, you will design and build systems that capture, validate, store, and expose software build provenance.
This goes beyond identifying where an artifact came from. Customers need to understand how it was built, what went into it, whether its provenance can be trusted, and where it was used across pipelines and deployments.
You will take substantial ownership of this greenfield capability, influencing its architecture, technical direction, engineering standards, and evolution into a secure product used by enterprise customers.
This is a product engineering role for someone with deep backend, platform, or security experience. It is not a pure DevOps or SRE position.
What You Will Be Doing
Designing and shipping provenance ingestion services for CI/CD systems, artifact registries, signed bundles, and customer-uploaded artifacts.Processing provenance and attestation formats including SLSA, in-toto, SBOM attestations, and Sigstore bundles.Designing storage models for signed metadata, artifact graphs, build relationships, and downstream usage.Building validation engines that verify cryptographic integrity and evaluate attestations against customer trust policies.Developing reliable APIs that make provenance data queryable, auditable, and useful.Solving high-volume ingestion, storage, performance, and schema-evolution challenges.Working with product, customer success, and engineering to turn enterprise security requirements into valuable product capabilities.Setting a high standard for security, correctness, observability, and technical decision-making.Mentoring engineers through design discussions, documentation, code reviews, and open collaboration.
What You Need To Succeed
Strong knowledge of artifact management, software supply chains, provenance, or build security.Practical familiarity with SLSA, in-toto, Sigstore, DSSE, SBOMs, SPDX, or CycloneDX.An understanding of signing and verification, key material, ECDSA or RSA, certificate chains, keyless signing, and transparency logs.At least five years of production backend engineering experience.Evidence that you have built and owned complex product capabilities, rather than working exclusively in DevOps or SRE.Experience designing scalable ingestion pipelines for varied, high-volume, schema-evolving data.Strong data-modelling skills, particularly for metadata, graphs, and queryable relationships.Experience building and versioning APIs for enterprise customers or third-party integrations.Familiarity with multi-tenant SaaS systems, including isolation, access control, and auditability.Strong communication skills and the judgement to balance thoughtful architecture with iterative delivery.
Python is the preferred backend language, with AWS and Terraform used across the platform. However, deep supply chain security expertise is more important than an exact technology match.
The Opportunity
You will work on a technically demanding problem at the centre of how software is built, secured, and delivered.
The role offers significant greenfield ownership, direct influence over a critical product capability, and the opportunity to help define how organisations establish trust across increasingly complex software supply chains.
The package includes equity, flexible UK working, comprehensive health and wellbeing benefits, generous annual leave, and dedicated support for professional development.
Applicants must be based in the UK and have the right to work independently without sponsorship.
Next Steps
If you have built secure backend products and understand provenance, SBOMs, SLSA, attestations, or artifact traceability, send your CV or get in touch in confidence to discuss the role.