DevSecOps Consultant

Amtex Systems Inc — United States · Posted ~23 hours ago

Mid Full-time

Skills

DevSecOps Software Supply Chain Security Open-Source Software Lifecycle CI/CD SBOM SLSA Vulnerability Remediation Dependency Management Repository Artifact Management AI/ML Frameworks Vulnerability Management Repository Management

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

We are an enterprise technology firm leading critical software supply chain security initiatives. We seek a consultant to design and enable secure software delivery, govern repository artifact policies, automate security approval workflows, and implement build provenance and dependency management standards across modern software ecosystems.

Highlights

Enterprise-level leadership of software supply chain security initiatives, automation of approval workflows and vulnerability remediation, CI/CD artifact signing and SLSA provenance implementation, and strong compliance reporting metrics.

Description

Title: DevSecOps Location: Atlanta, GA Duration: Full Time Responsibilities Lead design and enablement of enterprise software supply chain initiatives, supporting secure software delivery.Enhance Sonatype Repository artifact management, IQ firewall policy governance, and open-source software lifecycle.Define and automate software approval workflows, quarantine waiver, and lifecycle management processes.Design and enable repository proxy strategies for supported software ecosystems.Drive dependency upgrades and vulnerability remediation workflows.Support design and onboarding of emerging ecosystems, including AI/ML frameworks.Design and enable reporting and metrics for software supply chain health, policy compliance, and repository utilization.Design and enable CI/CD artifact signing and verification capabilities for software builds.Design and implement SLSA build provenance and attestations across CI/CD platforms.Integrate SBOM generation and software metadata into build and deployment pipelines.Collaborate with security and development teams to improve software supply chain visibility and integrity. Required Technical Skills 9+ years of DevSecOps, Platform Engineering, or Software Supply Chain Engineering experience.Hands-on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository (or comparable tooling, e.g., jFrog)Experience creating and maintaining automated Open Source Software Evaluation policies and workflows.Experience implementing artifact signing technologies (Sigstore/Cosign, GPG, Notary, etc.).Experience with SLSA provenance, in-toto attestations, or similar frameworks.Experience with SBOM generation (CycloneDX, SPDX, Syft).CI/CD experience with GitLab preferred (or comparable tooling, e.g. GitHub Actions)Strong AWS experience (IAM, ECS/EKS, EC2, S3, Lambda, Step Function, CloudWatch).Experience integrating security tooling into CI/CD pipelines.Strong scripting skills (Python, Bash, or Go).Experience designing and maintaining enterprise Open Source platforms.Familiarity with OCI registries and package ecosystems (Maven, npm, PyPI, NuGet).Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design initiatives.