Security Engineer, Detection
Sparrowhawk watches build pipelines for supply-chain compromise. You would write and maintain the detection rules, which we publish openly, and build the corpus we test them against.
Half the job is adversarial: constructing the attack so we can prove the rule catches it. The other half is keeping the false-positive rate low enough that people leave the tool switched on.
Python and Rust, with a lot of reading of other people's build systems.
About Sparrowhawk Security
Supply-chain security tooling for build pipelines. We publish our detection rules openly and are funded by enterprise support rather than by hoarding signatures.