Haystack
← Back to Jobs
Engineering
SO

Senior DevSecOps Engineer - Knoxville, TN

System OneKnoxville, TN🇺🇸United StatesPosted Sep 29, 2026

Why This Role Stands Out

This hybrid role offers a fantastic opportunity to shape the future of software supply chain security within a reputable company, with significant potential for skill development in cutting-edge DevSecOps practices. You'll thrive here if you're a seasoned engineer passionate about automation, security, and collaborative problem-solving, eager to contribute to critical infrastructure. Apply now to join a dynamic team and make a tangible impact.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Knoxville, TN, United States
Posted
1 week ago

Job Description

Job Title: Senior DevSecOps Engineer
Locations: Lafayette, LA | Knoxville, TN | Birmingham, AL | Columbia, SC
Type: Direct Hire
Work Model: Hybrid 
Hours: 40.0

Responsibilities

  • Enhance artifact management, policy governance, and open source lifecycle processes using tools like Sonatype and Nexus Repository.
  • Build and automate software approval workflows, quarantine/waiver processes, and repository proxy strategies across supported ecosystems.
  • Drive dependency upgrades and vulnerability remediation efforts.
  • Support onboarding of emerging ecosystems including AI/ML frameworks.
  • Build reporting and metrics to track software supply chain health, policy compliance, and repository utilization.
  • Enable CI/CD artifact signing and verification.
  • Implement SLSA build provenance and attestations.
  • Integrate SBOM generation into build and deployment pipelines.
  • Work closely with security and development teams to improve software supply chain visibility and integrity.
Requirements
  • 5+ years in DevSecOps, Platform Engineering, or Software Supply Chain Engineering.
  • Hands on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository, or similar tools like jFrog.
  • Experience building and maintaining automated Open Source Software evaluation policies and workflows.
  • Familiarity with artifact signing technologies such as Sigstore/Cosign, GPG, or Notary.
  • Experience with SLSA provenance, in toto attestations, or similar frameworks.
  • Background generating SBOMs using CycloneDX, SPDX, or Syft.
  • CI/CD experience, ideally with GitLab (GitHub Actions also welcome).
  • Strong AWS skills across IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch.
  • Experience integrating security tooling directly into CI/CD pipelines.
  • Solid scripting ability in Python, Bash, or Go.
  • Experience maintaining enterprise open source platforms.
  • Familiarity with OCI registries and package ecosystems (Maven, npm, PyPI, NuGet).
  • Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design principles.
  • Educational Requirement: Bachelor's degree in Computer Science, Information Systems, or a related field.

System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

#M-
#LI-


Ref: #404-IT Pittsburgh

Similar jobs