Senior Principal Product Manager - Trusted Software Supply Chain (Konflux)

Red Hat
Boston / Raleigh2026-03-25Full time

About the job

Red Hat is looking for a Senior Principal Product Manager to lead the vision and strategy for Konflux, our next-generation internal build system. Konflux is the engine behind Red Hat’s business, responsible for building, securing, and releasing the enterprise-grade open source products that power the world’s most critical infrastructure. In this role, you will be at the heart of the Trusted Software Supply Chain. You will not only manage an internal product but also act as a technical leader and advocate, helping our customers understand how to replicate Red Hat’s 'Software Factory' model using our commercial products. As we enter the age of AI-driven development, you will lead the charge in integrating agentic AI to modernize our build systems, ensuring unparalleled speed, efficiency, and security.

Responsibilities

Product Vision & Strategy: Define and drive the roadmap for Konflux, ensuring it remains the gold standard for building secure software

AI Modernization: Lead strategic initiatives to incorporate agentic AI and machine learning into the build pipeline to automate security triage, optimize resource allocation, and enhance supply chain integrity

Security Architecture Leadership: Serve as a subject matter expert on secure software factory concepts, aligning Konflux with industry standards like the CNCF Secure Software Factory framework, OpenSSF, and SLSA

Cross-Functional Influence: Collaborate with engineering leads and various product teams across Red Hat to align internal build capabilities with external product requirements, creating 'win-win' scenarios for the entire product portfolio

High-Visibility Advocacy: Interface directly with Red Hat’s security leadership and C-suite; represent Red Hat at major industry conferences (KubeCon, Open Source Summit, etc.) and in customer briefings.

Customer Consulting: Partner with customers to showcase the 'Art of the Possible,' helping them build their own trusted software factories based on Red Hat's internal best practices

Qualifications

Minimum

Security Expertise: Deep understanding of the security space, specifically around Supply Chain Levels for Software Artifacts (SLSA), Software Bill of Materials (SBOMs), and the CNCF Secure Software Factory Whitepaper

Orchestration & CI/CD: Tekton, ArgoCD, and Kubernetes

Supply Chain Security: Cosign and GUAC (Graph for Understanding Artifact Composition)

Platforms: Linux, Linux containers (Podman/Docker), and OCI standards

Security Architecture: Proven experience designing or managing complex security architectures for enterprise-scale systems

Preferred

Product Management: Prior experience in product management highly preferred, with track record of managing technical products through their entire