Senior Backend Engineer
You will design and implement secure backend features for a software supply chain security add-on. You will build package policy evaluation, artifact signing and verification, provenance attestation APIs, and malicious package detection integrations. You will create backend and GraphQL configuration interfaces, integrate with security policy frameworks, maintain RSpec and integration tests, review merge requests with a security-first mindset, and collaborate on architecture and cross-functional product delivery in an all-remote, asynchronous environment.
Responsibilities
- Design and implement backend features for policy enforcement, artifact signing and verification, provenance attestation APIs, and malicious package detection integrations.
- Build and improve the package policy evaluation engine, including rule compilation, request matching, enforcement decisions, and performance-sensitive execution paths.
- Develop artifact signing and verification workflows using Sigstore, Cosign, signing key lifecycle management, keyless signing with OpenID Connect, and policy-based promotion gates.
- Create and evolve backend APIs and GraphQL configuration interfaces for enterprise security teams.
- Integrate add-on capabilities with the existing security policy framework, including policy inheritance and policy-as-code support through YAML.
- Collaborate with adjacent teams to incorporate malicious package intelligence into the add-on.
- Write and maintain RSpec and integration test coverage and improve test reliability.
- Review merge requests with a security-first mindset and implement solutions in partnership with the Staff Backend Engineer.
Requirements
- Proven backend engineering experience with production Ruby on Rails expertise.
- Working knowledge of Go or the willingness and ability to learn it quickly.
- API design experience with REST, GraphQL, and internal service boundaries.
- PostgreSQL knowledge, including schema design, query optimization, and indexing strategies.
- Experience with Redis for caching and distributed coordination patterns.
- Security-aware engineering judgment concerning trust boundaries, input validation, and failure modes.
- Familiarity with software supply chain security concepts such as SLSA, SBOM, artifact signing, or security scanning.
- Interest in rules engines, package ecosystems, cryptographic signing, DevSecOps product development, or related policy, registry, and platform problems.
Benefits
- Health, financial, and well-being benefits.
- Flexible Paid Time Off.
- Team Member Resource Groups.
- Equity compensation and Employee Stock Purchase Plan.
- Growth and Development Fund.
- Parental Leave.
