Source description
About the role
Define and drive the technical direction for software supply chain protection capabilities that detect and prevent threats before they reach developer projects or production environments. Design, build, and operate large-scale distributed systems that analyze open-source packages, code behavior, provenance, and trust signals across ecosystems in real time. Develop new security primitives for package risk assessment, malicious dependency detection, typosquatting prevention, provenance validation, and AI-assisted threat detection. Provide hands-on technical leadership across architecture, design reviews, API/data contracts, prototypes, and implementation to de-risk complex systems and accelerate delivery. Drive engineering excellence through reliable, scalable, secure, and observable services, with strong focus on quality, performance, and operational readiness. Embody our Culture and Values Bachelor's Degree in Computer Science or related technical field AND 6+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C#, Java, JavaScript, or Python OR equivalent experience. These requirements include, but are not limited to the following specialized security screenings: Bachelor's Degree in Computer Science or related technical field AND 8+ years technical engineering experience with coding in languages including, but not limited to, C, C++, C, Java, JavaScript, Rust, Go, or Python - OR Master's Degree in Computer Science or related technical field AND 6+ years technical engineering experience OR equivalent experience 6+ years of experience designing, building, and shipping production backend services, platforms, or data pipelines. Hands-on experience with software supply chain security and open-source package ecosystems (e.g., npm, PyPI, NuGet, Maven, Cargo), including dependency, vulnerability, or malware analysis. Experience with program analysis techniques — static and dynamic analysis, sandboxing/detonation, deobfuscation, or behavioral analysis — to determine what code actually does. Experience building and operating large-scale scanning, detection, or data-processing pipelines in the cloud (Azure preferred). Familiarity with supply chain integrity frameworks and standards such as SBOM, SLSA, provenance, and artifact signing (e.g., Sigstore). Demonstrated security background — threat detection, malware/vulnerability research, EDR/antivirus, or other security-sensitive software. Experience integrating with developer tools
More at Microsoft