Full-Time

Senior Software Engineer

London

Posted on 9/18/2024

Stacklok

Stacklok

11-50 employees

Enhances software supply chain security tools

Cybersecurity

Senior

London, UK

Requires on-site work in London for 3 days per week.

Category
Backend Engineering
Security Engineering
Software Engineering
Required Skills
Git
Docker
Go
Linux/Unix
Requirements
  • Experience in the software industry
  • Strong understanding of Go language
  • Proficient with Docker, Linux, and Git
  • Interest in or understanding of cyber security and secure coding concepts
  • Proven record of technical accomplishments directly contributing to measurable and impactful business outcomes
  • Deep understanding of Go programming language and backend development principles
  • Strong proficiency in software development and experience with open-source projects
  • Experience with secure coding practices and frameworks (e.g. OWASP, SSDF)
  • In-depth knowledge of software supply chain security
  • Proficiency in modern software development methodologies, particularly in CI/CD processes
  • Excellent written and verbal communication skills
Responsibilities
  • Develop and maintain high-quality software.
  • Participate in the design and implementation of new features and functionalities.
  • Collaborate with cross-functional teams to understand requirements and propose effective solutions.
  • Troubleshoot and resolve software-related issues.
  • Improve system-level security, apply best practices in all work done.
  • Regularly participate in code review to maintain our code quality and learn new things from peers.
  • Contribute to our continuous improvement and growth by sharing knowledge and providing feedback to the team.

Stacklok focuses on improving software supply chain security by helping developers and open-source communities ensure their software and dependencies are secure. Its main product, Trusty, features an "Activity Scoring" system called the Trusty Score, which analyzes public GitHub data to assess the trustworthiness of software repositories. Trusty also verifies the authenticity of software packages using Sigstore and employs generative AI to recommend safer package alternatives. By offering Trusty as a free service through a web app and Visual Studio Code extension, Stacklok aims to build trust within the developer community.

Company Stage

Series A

Total Funding

$17M

Headquarters

Seattle, Washington

Founded

2023

Growth & Insights
Headcount

6 month growth

35%

1 year growth

90%

2 year growth

1800%
Simplify Jobs

Simplify's Take

What believers are saying

  • Increased Sigstore adoption boosts Trusty's credibility and potential user base.
  • Generative AI trends align with Trusty's package recommendation feature, enhancing its relevance.
  • Growing open-source security focus creates demand for Stacklok's Trusty solutions.

What critics are saying

  • New CNCF members may increase competition in cloud-native and open-source sectors.
  • Reliance on generative AI could lead to security risks if models are outdated.
  • Free Trusty model may limit revenue unless premium features are adopted.

What makes Stacklok unique

  • Stacklok's Trusty uses Sigstore for package provenance, ensuring software authenticity.
  • Trusty Score benchmarks GitHub repository activity, aiding in assessing software trustworthiness.
  • Generative AI in Trusty suggests safer package alternatives, enhancing security choices.

Help us improve and share your feedback! Did you find this helpful?

INACTIVE