The Linux Foundation is a 501(c)(6) non-profit that provides a neutral, trusted hub for developers and organizations to code, manage, and scale open technology projects and ecosystems.
The Open Source Security Foundation (OpenSSF) is a cross-industry organization at the Linux Foundation that brings together the industry's most important open source security initiatives and the individuals and companies that support them. The OpenSSF is committed to collaboration and working both upstream and with existing communities to advance open source security for all.
The OSS-SIRT Director is the senior program leader responsible for standing up, governing, and operating the OpenSSF's OSS-SIRT and OSS-VulnDB capability. This role combines program leadership, policy stewardship, ecosystem coordination, and incident-response governance, serving as the public and internal face of the program.
The Director ensures the program delivers trusted, neutral, high-quality vulnerability coordination aligned with OSV, CVE/CNA practices, CRA expectations, and OpenSSF's upstream-first principles.
Own the OSS-VulnDB + OSS-SIRT roadmap, milestones, and delivery across transitions from MVP to public beta to steady state
Establish and operate OSS-SIRT governance, policies, disclosure timelines, and escalation paths
Serve as primary liaison to:
CVE Program / CNAs
OSV and federated VulnDB operators
Regulators and public-sector stakeholders (e.g., CRA-aligned reporting pathways)
Define and enforce data quality, curation, and dispute-resolution policies
Lead incident coordination for complex, multi-party vulnerabilities affecting critical OSS
Oversee program KPIs, risk management, reporting, and budget execution
Partner with OpenSSF working groups on standards alignment (OSV, VEX, SBOM, CWE)
Support funding sustainability efforts (founding partners, grants, member engagement)
Travel: Up to 20%
10+ years in security program management, PSIRT/SIRT leadership, or large-scale security operations
Direct experience with coordinated vulnerability disclosure (CVD)
Familiarity with CVE, CNA operations, OSV, NVD, and vulnerability lifecycles
Proven ability to operate in multi-stakeholder, neutral governance environments
Strong policy, communication, and executive-level briefing skills
Open source foundation or standards-body leadership
Exposure to global regulatory frameworks (CRA, NIS2, SSDF, etc.)
Incident leadership for ecosystem-wide vulnerabilities (e.g., Log4Shell-class events)
OSS-SIRT operational within 90 days
MVP VulnDB + workflows live within 6 months
Measurable reduction in time-to-publication and data-quality gaps
Successful onboarding of initial ecosystems and partners
Salary: $185,000 – $210,000 USD
All your information will be kept confidential according to EEO guidelines.
...What Pharmacy Services & Delivery contributes to Cardinal Health Pharmacy Services & Delivery is responsible for the prompt and accurate delivery... ...work experience, preferred Must hold a valid driver's license and have a good driving record Minimum of 18...
...culture of excellence - that's Penn State Health. But what makes our healthcare award-winning? That's all you. This job posting is a general... ...orders that prohibit or outlaw discrimination. Position Unit Desk Clerk Surgical Telemetry - 6 Main Location US:PA: Camp...
...believe everyone deserves the opportunity to have a job they love, work in a great environment, grow their career & enjoy a positive... ...a customer service and sales focused environment. Utilize computers to determine product inventory levels and product arrival dates...
...and manages organizational performance to achieve on-time delivery, quality and cost performance, and contract fulfillment for all purchased products and services, Small Business and Strategic Savings targets. Manages Supplier Performance and develops and implements...
...shift: First work hours: 7 AM - 3:30 PM education: No Degree Required Responsibilities Fill Customer orders accurately... ...Years of experience: 0 years Experience level: Entry Level Randstad is a world leader in matching great people...