Why This Role Stands Out
This remote role offers significant career growth by placing you at the forefront of software supply chain security, leveraging cutting-edge tools like Socket.dev and Chainguard. You'll thrive here if you're a mid-senior DevSecOps professional eager to enhance security postures across development and operations. Apply now to make a substantial impact in this dynamic field.
Quick Overview
Job Description
Job Title: Senior DevSecOps Engineer with (Socket.dev & Chainguard)
Location: Remote
Duration: Long term
Responsibilities
Senior DevSecOps Engineer
Software Supply Chain Security (Socket.dev & Chainguard)
Position Overview
Client is seeking a Senior DevSecOps Engineer to lead the implementation and adoption of software supply chain security solutions, including Socket.dev and Chainguard. This individual will work closely with application development, platform engineering, cloud operations, and security teams to improve the security posture of the software development lifecycle and container ecosystem.
The ideal candidate will have experience implementing software composition analysis (SCA), dependency security tools, container security platforms, and DevSecOps best practices within enterprise environments. The role will focus on integrating security controls into CI/CD pipelines, securing open-source dependencies, reducing container vulnerabilities, and establishing software supply chain governance.
Key Responsibilities
Software Supply Chain Security
· Lead deployment and operationalization of Socket.dev across enterprise development environments.
· Implement software dependency security controls and risk management processes.
· Establish governance for open-source software consumption and dependency management.
· Partner with development teams to identify and remediate supply chain risks.
· Support implementation of Software Bill of Materials (SBOM) strategies. Chainguard Implementation
· Deploy and integrate Chainguard images and related security capabilities into containerized environments.
· Assist with enterprise adoption of secure-by-default container images.
· Support migration from legacy container images to hardened Chainguard images.
· Develop standards and best practices for container image security.
· Establish image governance, lifecycle management, and vulnerability remediation processes.
DevSecOps & CI/CD Integration
· Integrate Socket.dev and Chainguard into CI/CD pipelines and developer workflows.
· Implement automated security checks throughout the software development lifecycle.
· Collaborate with platform engineering teams to improve security automation.
· Enhance release pipelines through automated policy enforcement and compliance controls.
· Support secure software delivery initiatives. Cloud & Container Security
· Secure Kubernetes and container-based environments.
· Assist with container security architecture and operational best practices.
· Implement image scanning, signing, and provenance validation processes.
· Work with engineering teams to improve cloud-native security controls. Collaboration & Enablement
· Work closely with application development teams to drive tool adoption.
· Provide technical guidance and knowledge transfer to developers and platform teams.
· Develop documentation, implementation standards, and operational runbooks.
· Support security assessments and compliance initiatives related to software supply chain security. Required
Qualifications
· 5+ years of experience in DevOps, DevSecOps, Application Security, or Cloud Security.
· Experience implementing software supply chain security controls.
· Strong understanding of CI/CD pipelines and secure development practices.
· Experience with GitHub, GitLab, Azure DevOps, or similar platforms.
· Experience working with containerized environments.
· Knowledge of open-source dependency management and vulnerability remediation.
· Strong troubleshooting and communication skills. Qualifications
· Experience deploying or supporting Socket.dev.
· Experience deploying or supporting Chainguard.
· Kubernetes and container platform experience.
Experience with:
· GitHub Advanced Security
· Sonatype
· JFrog
· Aqua Security
· Prisma Cloud
· Snyk
· Azure DevOps
· GitLab CI/CD
· GitHub Actions
· OpenShift
· Kubernetes
· Docker
· Experience with:
· Secure SDLC practices
· Software Composition Analysis (SCA)
· Sigstore/Cosign
· Container image signing
· SBOMs
Similar jobs
- M6
SIGINT Analyst
NewMorgan 6
Tampa, Florida🇺🇸$65k - $98k/yrOn-site50 minutes agoAgileCompensation & Benefits - M6
SIGINT Analyst - $65000 - $98000 Yearly Salary
NewMorgan 6
Tampa, Florida🇺🇸$65k - $98k/yrOn-site50 minutes agoAgileCompensation & Benefits - CL
MRO Specialist:
NewCloudious
Houston, TX🇺🇸HybridYesterdayAssemblyMicrosoft OfficeReconciliation - IU
CA Gen Modernization Lead
NewiTech US, Inc.
United States🇺🇸RemoteYesterdayCOBOL - AS
MDM Lead
NewApex Systems
Quincy, MA🇺🇸HybridYesterdayERPProcurementSAP+2 - AS
D&A RTE
NewApex Systems
Houston, TX🇺🇸On-siteYesterdaySAFeScrumAgile+4 - ST
EPIC Population Health (Healthy Planet) Analyst - Remote
NewSR Talent Solution Inc
United States🇺🇸RemoteYesterday - 4C
Database Architect
New4 Consulting Inc
United States🇺🇸HybridYesterdayOracleSQLSnowflake+4 - KT
E-Learning Specialist
NewKforce Technology Staffing
Charlotte, NC🇺🇸HybridYesterdayArticulateE-LearningInstructional Design+5 - KY
Senior Regulatory Affairs Specialist - On W2
NewKyyba Inc
Santa Clara, CA🇺🇸HybridYesterdayComplianceRegulatory ComplianceStakeholder Management - KT
People Services Associate
NewKforce Technology Staffing
Santa Monica, CA🇺🇸HybridYesterdayBackground ChecksComplianceContinuous Improvement+5 - MI
Head of Data and AI Platforms
NewMedline Industries, LP
Northbrook, IL🇺🇸$203k - $305k/yrHybridYesterdayMLOpsMachine LearningAzure+6