Назад
Company hidden
11 часов назад

Senior DevSecOps Engineer

89 600 - 139 300$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior DevSecOps Engineer (AWS/Software Supply Chain): Building secure software delivery pipelines, artifact management workflows, and open source governance processes with an accent on vulnerability remediation, CI/CD integration, and supply chain integrity. Focus on implementing SLSA provenance, artifact signing, SBOM generation, and policy compliance across enterprise ecosystems.

Location: 5 days onsite in Lafayette, Louisiana; Knoxville, Tennessee; or Birmingham, Alabama

Salary: $89,600–$139,300 per year

Company

hirify.global delivers outsourced services and workforce solutions across North America.

What you will do

  • Enhance artifact management, policy governance, and open source lifecycle processes using Sonatype Lifecycle and Nexus Repository.
  • Build automated software approval, quarantine, waiver, and repository proxy workflows.
  • Drive dependency upgrades, vulnerability remediation, and onboarding of emerging ecosystems including AI/ML frameworks.
  • Develop reporting and metrics for software supply chain health, policy compliance, and repository utilization.
  • Implement artifact signing and verification, SLSA provenance and attestations, and SBOM generation in CI/CD pipelines.
  • Collaborate with security and development teams to improve software supply chain visibility and integrity.

Requirements

  • 5+ years of experience in DevSecOps, platform engineering, or software supply chain engineering.
  • Hands-on experience with Sonatype Lifecycle, Nexus Repository, or comparable tools such as JFrog.
  • Experience creating automated open source evaluation policies and workflows.
  • Familiarity with Sigstore/Cosign, GPG, Notary, SLSA, in-toto attestations, and SBOM tools such as CycloneDX, SPDX, or Syft.
  • Experience with CI/CD, security tooling integration, OCI registries, and package ecosystems including Maven, npm, PyPI, and NuGet.
  • Strong AWS skills, scripting ability in Python, Bash, or Go, and knowledge of NIST SSDF, Executive Order 14028, and Secure by Design principles. A bachelor's degree in a related field is required.

Culture & Benefits

  • Direct-hire, full-time permanent position.
  • Medical, dental, vision, spending account, life insurance, and voluntary plan options for eligible employees.
  • Participation in a 401(k) plan.
  • Equal opportunity employment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →