nineDots.io
Principal Software Engineer (Supply Chain Security)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Principal Software Engineer, Supply Chain Security
Artifact Provenance - SLSA - SBOMs - Cryptography - Greenfield Platform Engineering
Join a fast-growing, developer-first technology company building critical infrastructure for modern software delivery.
You will help create the next generation of software supply chain trust systems, giving organisations verifiable traceability from source code to built artifact and every downstream environment in which it is used.
The Role
As a Principal Software Engineer within the Supply Chain Trust team, you will design and build systems that capture, validate, store, and expose software build provenance.
This goes beyond identifying where an artifact came from. Customers need to understand how it was built, what went into it, whether its provenance can be trusted, and where it was used across pipelines and deployments.
You will take substantial ownership of this greenfield capability, influencing its architecture, technical direction, engineering standards, and evolution into a secure product used by enterprise customers.
This is a product engineering role for someone with deep backend, platform, or security experience. It is not a pure DevOps or SRE position.
What You Will Be Doing
- Designing and shipping provenance ingestion services for CI/CD systems, artifact registries, signed bundles, and customer-uploaded artifacts.
- Processing provenance and attestation formats including SLSA, in-toto, SBOM attestations, and Sigstore bundles.
- Designing storage models for signed metadata, artifact graphs, build relationships, and downstream usage.
- Building validation engines that verify cryptographic integrity and evaluate attestations against customer trust policies.
- Developing reliable APIs that make provenance data queryable, auditable, and useful.
- Solving high-volume ingestion, storage, performance, and schema-evolution challenges.
- Working with product, customer success, and engineering to turn enterprise security requirements into valuable product capabilities.
- Setting a high standard for security, correctness, observability, and technical decision-making.
- Mentoring engineers through design discussions, documentation, code reviews, and open collaboration.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What You Need To Succeed
- Strong knowledge of artifact management, software supply chains, provenance, or build security.
- Practical familiarity with SLSA, in-toto, Sigstore, DSSE, SBOMs, SPDX, or CycloneDX.
- An understanding of signing and verification, key material, ECDSA or RSA, certificate chains, keyless signing, and transparency logs.
- At least five years of production backend engineering experience.
- Evidence that you have built and owned complex product capabilities, rather than working exclusively in DevOps or SRE.
- Experience designing scalable ingestion pipelines for varied, high-volume, schema-evolving data.
- Strong data-modelling skills, particularly for metadata, graphs, and queryable relationships.
- Experience building and versioning APIs for enterprise customers or third-party integrations.
- Familiarity with multi-tenant SaaS systems, including isolation, access control, and auditability.
- Strong communication skills and the judgement to balance thoughtful architecture with iterative delivery.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Python is the preferred backend language, with AWS and Terraform used across the platform. However, deep supply chain security expertise is more important than an exact technology match.
The Opportunity
You will work on a technically demanding problem at the centre of how software is built, secured, and delivered.
The role offers significant greenfield ownership, direct influence over a critical product capability, and the opportunity to help define how organisations establish trust across increasingly complex software supply chains.
The package includes equity, flexible UK working, comprehensive health and wellbeing benefits, generous annual leave, and dedicated support for professional development.
Applicants must be based in the UK and have the right to work independently without sponsorship.
Next Steps
If you have built secure backend products and understand provenance, SBOMs, SLSA, attestations, or artifact traceability, send your CV or get in touch in confidence to discuss the role.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location