Назад
Company hidden
1 день назад

Senior DevSecOps Engineer

89 600 - 139 300$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior DevSecOps Engineer (Software Supply Chain/AWS): Enhancing artifact management, software approval workflows, and open-source lifecycle processes with an accent on vulnerability remediation, artifact signing, SLSA provenance, and SBOM integration. Focus on automating CI/CD security controls, building supply-chain health metrics, and improving software integrity across enterprise ecosystems.

Location: Hybrid role in Lafayette, Louisiana, United States

Salary: $89,600–$139,300 per year

Company

hirify.global delivers outsourced services and workforce solutions across North America.

What you will do

  • Enhance artifact management, policy governance, and open-source lifecycle processes with Sonatype Lifecycle and Nexus Repository.
  • Build automated software approval, quarantine, waiver, and repository proxy workflows.
  • Drive dependency upgrades, vulnerability remediation, and onboarding of emerging ecosystems, including AI/ML frameworks.
  • Develop reporting and metrics for software supply-chain health, policy compliance, and repository utilization.
  • Implement artifact signing and verification, SLSA build provenance, attestations, and SBOM generation in CI/CD pipelines.
  • Collaborate with security and development teams to improve software supply-chain visibility and integrity.

Requirements

  • 5+ years of experience in DevSecOps, Platform Engineering, or Software Supply Chain Engineering.
  • Hands-on experience with Sonatype Lifecycle, Nexus Repository, or comparable tools such as JFrog.
  • Experience with automated open-source evaluation policies, artifact signing, SLSA provenance, attestations, and SBOM tools such as CycloneDX, SPDX, or Syft.
  • CI/CD experience with GitLab or GitHub Actions and experience integrating security tooling into pipelines.
  • Strong AWS experience across IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch.
  • Proficiency in Python, Bash, or Go, plus knowledge of OCI registries, package ecosystems, NIST SSDF, Executive Order 14028, and Secure by Design principles. A bachelor's degree in Computer Science, Information Systems, or a related field is required.

Culture & Benefits

  • Direct-hire employment with a hybrid work model.
  • Eligible employees may receive medical, dental, vision, spending account, life insurance, and voluntary plan options.
  • Participation in a 401(k) plan is available to eligible employees.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →