Haystack
← Back to Jobs
Engineering
HT

DevSecOps Engineer

Hexaware Technologies, IncReston, VA🇺🇸United StatesPosted Sep 24, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Reston, VA, United States
Posted
Yesterday

Job Description

DevSecOps Engineer

Introduction

This position involves leading the design and enablement of enterprise software supply chain initiatives to support secure software delivery. The DevSecOps Engineer will be responsible for enhancing artifact management, firewall policy governance, and open-source software lifecycle. They will also automate software approval workflows, quarantine waiver processes, and repository utilization.

Responsibilities

Lead design and enablement of enterprise software supply chain initiatives, supporting secure software delivery.
Enhance Sonatype Repository artifact management, IQ firewall policy governance, and open-source software lifecycle.
Define and automate software approval workflows, quarantine waiver, and lifecycle management processes.
Design and enable repository proxy strategies for supported software ecosystems.
Drive dependency upgrades and vulnerability remediation workflows.
Support design and onboarding of emerging ecosystems, including AI/ML frameworks.
Design and enable reporting and metrics for software supply chain health, policy compliance, and repository utilization.
Design and enable CI/CD artifact signing and verification capabilities for software builds.
Design and implement SLSA build provenance and attestations across CI/CD platforms.
Integrate SBOM generation and software metadata into build and deployment pipelines.
Collaborate with security and development teams to improve software supply chain visibility and integrity.

Required Technical Skills

9+ years of DevSecOps, Platform Engineering, or Software Supply Chain Engineering experience.
Hands-on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository (or comparable tooling, e.g., jFrog)
Experience creating and maintaining automated Open Source Software Evaluation policies and workflows.
Experience implementing artifact signing technologies (Sigstore/Cosign, GPG, Notary, etc.).
Experience with SLSA provenance, in-toto attestations, or similar frameworks.
Experience with SBOM generation (CycloneDX, SPDX, Syft).
CI/CD experience with GitLab preferred (or comparable tooling, e.g. GitHub Actions)
Strong AWS experience (IAM, ECS/EKS, EC2, S3, Lambda, Step Function, CloudWatch).
Experience integrating security tooling into CI/CD pipelines.
Strong scripting skills (Python, Bash, or Go).
Experience designing and maintaining enterprise Open Source platforms.
Familiarity with OCI registries and package ecosystems (Maven, npm, PyPI, NuGet).
Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design initiatives.

Similar jobs