Назад
Company hidden
1 день назад

Senior DevSecOps Engineer (AWS)

89 600 - 139 300$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior DevSecOps Engineer (AWS/software supply chain security): Enhancing artifact management, approval workflows, vulnerability remediation, and CI/CD security controls with an accent on SBOM generation, artifact signing, SLSA provenance, and repository governance. Focus on building secure software supply chain automation, integrating AWS security tooling, and improving visibility and integrity across development pipelines.

Location: Hybrid in Lafayette, Louisiana; Knoxville, Tennessee; Birmingham, Alabama; or Columbia, South Carolina

Salary: $89,600–$139,300 per year

Company

hirify.global delivers outsourced services and workforce solutions across North America.

What you will do

  • Enhance artifact management, policy governance, and open-source lifecycle processes using Sonatype and Nexus Repository.
  • Build automated software approval, quarantine, waiver, and repository proxy workflows.
  • Drive dependency upgrades, vulnerability remediation, and security-tool integration across CI/CD pipelines.
  • Support AI/ML ecosystem onboarding and create reporting for software supply chain health, policy compliance, and repository utilization.
  • Enable artifact signing and verification, implement SLSA provenance and attestations, and integrate SBOM generation into build and deployment pipelines.
  • Collaborate with security and development teams to improve software supply chain visibility and integrity.

Requirements

  • 5+ years of experience in DevSecOps, platform engineering, or software supply chain engineering.
  • Hands-on experience with Sonatype Lifecycle, Nexus Repository, or comparable platforms such as JFrog.
  • Experience with open-source evaluation policies, artifact signing, SLSA or similar frameworks, and SBOM tools such as CycloneDX, SPDX, or Syft.
  • CI/CD experience with GitLab or GitHub Actions and strong AWS experience across IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch.
  • Strong scripting skills in Python, Bash, or Go, plus familiarity with OCI registries and Maven, npm, PyPI, or NuGet ecosystems.
  • Bachelor’s degree in Computer Science, Information Systems, or a related field; knowledge of NIST SSDF, Executive Order 14028, and Secure by Design principles.

Culture & Benefits

  • Direct-hire position with a hybrid work model and a 40-hour work week.
  • Eligible employees may receive medical, dental, vision, spending account, life insurance, and voluntary plan coverage.
  • Participation in a 401(k) plan is available to eligible employees.
  • Equal opportunity employment practices.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →