attestation payloads from CI/CD systems, public registries, signed bundles, and customer-uploaded artifacts across a wide range of formats (SLSA, in-toto, SBOM attestations, Sigstore bundles etc).Store: Own the storage architecture for signed provenance metadata. Validate: Build the validation engine that verifies cryptographic integrity and evaluates attestation … their output. Cryptographic Foundations: Comfortable with signing and verification: key material, ECDSA/RSA, certificate chains, OIDC-based keyless signing flows, and transparency logs. SBOM Formats: Familiarity with CycloneDX and SPDX, and how they are packaged as attestation artifacts. Backend & Platform EngineeringExperience: 5+ years of production backend engineering, with real ...