Quick Overview
Seniority
Mid Senior
Work mode
On Site
Location
Tewksbury, MA, United States
Posted
Yesterday
Job Description
Role: DevSecOps & Supply Chain Security Consultant
Work Location: Tewksbury, MA 01876 (100% Onsite)
Role Summary
Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management to support lifecycle security evaluation and compliance traceability.
Key Responsibilities
- Review SDLC processes, tooling, and secure development practices
- Assess software supply chain security, including SCA, SBOM accuracy/completeness, dependency governance, and third-party risk
- Evaluate CI/CD pipeline security, artifact integrity, and secure release controls
- Review secrets management across development, build, deployment, and operational environments
- Assess logging, auditability, and security event traceability controls
- Evaluate vulnerability management, remediation tracking, and patch governance processes
- Support lifecycle security assessment, compliance evidence mapping, and traceability
- Contribute to assessment reporting, remediation guidance, and release governance reviews
Required Skills & Experience
Mandatory:
- Strong understanding of DevSecOps and secure software delivery practices
- Experience with SBOM frameworks (CycloneDX, SPDX) and SCA tooling
- Familiarity with CI/CD security controls and artifact integrity validation
- Experience with vulnerability management and dependency governance programs
- Understanding of lifecycle security, auditability, and compliance evidence requirements
- Experience with secrets management and secure release governance
Good to have:
- Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments
- Experience participating in engagement related to export-controlled environments
- Strong documentation skills
Preferred Certifications
- Kubernetes / Cloud Security certifications preferred
- DevSecOps or secure software supply chain experience preferred
- Familiarity with SLSA or modern software supply chain security practices
- Clearance / Compliance Requirements
Years of Required Experience
- 7-10 years in setting up, maintaining and controls validation of Secure. CI/CD pipelines across different type of tech stack.
- 2+ Years experience with SBOM analysis
Similar jobs
- GD
Supply Chain Specialist
NewGDH
New Albany, OH🇺🇸$20 - $30/hrOn-siteYesterdayInventory ManagementProcurementSupply Chain Management+1Logistics - TT
Supply Chain Manager
NewTAT Technologies Ltd
Greensboro, North Carolina🇺🇸On-site8 hours ago401kERPCompliance+4Logistics - PI
Director of Supply Chain
NewPrince Industries LLC
Carol Stream, Illinois🇺🇸On-site3 hours agoERPContinuous ImprovementInventory Management+1Logistics - DO
Maintenance Technician - Food Supply Chain
Domino's
Eagan, MN🇺🇸On-site1 week agoLogistics - HP
D365 SCM Consultant (Supply Chain Management Consultant)
NewHR Pundits
Durham, NC🇺🇸On-siteYesterdayInventory ManagementProcurementSupply Chain Management+2Logistics - DE
Supply Chain Specialist I
Dev
Augusta, Arkansas🇺🇸On-site2 years agoConcreteInventory ManagementLogistics