Quick Overview
Job Description
DevSecOps Engineer
Introduction
This position involves leading the design and enablement of enterprise software supply chain initiatives to support secure software delivery. The DevSecOps Engineer will be responsible for enhancing artifact management, firewall policy governance, and open-source software lifecycle. They will also automate software approval workflows, quarantine waiver processes, and repository utilization.
Responsibilities
Lead design and enablement of enterprise software supply chain initiatives, supporting secure software delivery.
Enhance Sonatype Repository artifact management, IQ firewall policy governance, and open-source software lifecycle.
Define and automate software approval workflows, quarantine waiver, and lifecycle management processes.
Design and enable repository proxy strategies for supported software ecosystems.
Drive dependency upgrades and vulnerability remediation workflows.
Support design and onboarding of emerging ecosystems, including AI/ML frameworks.
Design and enable reporting and metrics for software supply chain health, policy compliance, and repository utilization.
Design and enable CI/CD artifact signing and verification capabilities for software builds.
Design and implement SLSA build provenance and attestations across CI/CD platforms.
Integrate SBOM generation and software metadata into build and deployment pipelines.
Collaborate with security and development teams to improve software supply chain visibility and integrity.
Required Technical Skills
9+ years of DevSecOps, Platform Engineering, or Software Supply Chain Engineering experience.
Hands-on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository (or comparable tooling, e.g., jFrog)
Experience creating and maintaining automated Open Source Software Evaluation policies and workflows.
Experience implementing artifact signing technologies (Sigstore/Cosign, GPG, Notary, etc.).
Experience with SLSA provenance, in-toto attestations, or similar frameworks.
Experience with SBOM generation (CycloneDX, SPDX, Syft).
CI/CD experience with GitLab preferred (or comparable tooling, e.g. GitHub Actions)
Strong AWS experience (IAM, ECS/EKS, EC2, S3, Lambda, Step Function, CloudWatch).
Experience integrating security tooling into CI/CD pipelines.
Strong scripting skills (Python, Bash, or Go).
Experience designing and maintaining enterprise Open Source platforms.
Familiarity with OCI registries and package ecosystems (Maven, npm, PyPI, NuGet).
Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design initiatives.
Similar jobs
- AL
Azure DevOps Build Engineer
NewArthur Lawrence
Bowmansdale, PA🇺🇸HybridYesterdayAngularAzure.NETTechnology - SC
Observability Engineer
NewSN Cloud Solutions
Phoenix, AZ🇺🇸HybridYesterdayEngineering - ST
Certified Cloud Engineer - Hybrid Cloud / AWS / Azure / DevOps - Madison, WI
NewShiro Technologies
Madison, WI🇺🇸HybridYesterdayAWSEncryptionAzure+2Technology - SP
SharePoint Online & Power Platform Engineer
NewStellar Professionals LLC
Blythewood, SC🇺🇸On-siteYesterdayPowerShellTechnology - UP
Software Engineer, Site Reliability
NewUpstart
United States🇺🇸$142k - $196.6k/yrRemoteYesterdayAWSDatadogJavaScript+3Technology - HA
Senior Specialist, Systems Engineering - Database DevOps
NewHarris Corporation
Greenville, TX🇺🇸On-siteYesterdayDockerMongoDBMySQL+13Technology