Назад
Company hidden
3 дня назад

Senior DevSecOps Engineer (AWS)

89 600 - 139 300$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior DevSecOps Engineer (AWS/software supply chain security): Building secure enterprise software delivery pipelines with an accent on artifact management, CI/CD security, SBOM generation, artifact signing, and software provenance. Focus on automating approval workflows, implementing SLSA attestations, integrating security tooling, and improving dependency and vulnerability management at scale.

Location: Hybrid, with work locations in Lafayette, Louisiana; Knoxville, Tennessee; Birmingham, Alabama; or Columbia, South Carolina

Salary: $89,600–$139,300 per year

Company

hirify.global delivers outsourced services and workforce solutions across North America.

What you will do

  • Improve software supply chain security, artifact management, open-source governance, and CI/CD security across enterprise environments.
  • Build automated software approval, quarantine, waiver, repository proxy, and open-source lifecycle workflows.
  • Drive dependency upgrades, vulnerability remediation, and onboarding of emerging ecosystems including AI/ML frameworks.
  • Build reporting and metrics for supply chain health, policy compliance, and repository utilization.
  • Enable CI/CD artifact signing and verification, SLSA build provenance, attestations, and SBOM generation.
  • Partner with security and development teams to improve software supply chain visibility, integrity, and security.

Requirements

  • 5+ years of experience in DevSecOps, platform engineering, or software supply chain engineering.
  • Hands-on experience with Sonatype Lifecycle/IQ Server, Nexus Repository, JFrog, or similar tools.
  • Experience with open-source evaluation policies, artifact signing, SLSA provenance, in-toto attestations, and SBOM tools such as CycloneDX, SPDX, or Syft.
  • Strong CI/CD experience and experience integrating security tooling directly into pipelines.
  • Strong AWS experience with IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch.
  • Strong scripting skills in Python, Bash, and Go; familiarity with OCI registries, Maven, npm, PyPI, NuGet, NIST SSDF, Executive Order 14028, and Secure by Design principles.

Culture & Benefits

  • Direct-hire permanent full-time employment.
  • Medical, dental, vision, spending account, life insurance, and voluntary benefit options for eligible employees.
  • Participation in a 401(k) plan.
  • Work in partnership with security and development teams across enterprise environments.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →