DevSecOps & Supply Chain Security Consultant

Zappsec Inc.

Tewksbury (MA)

On-site

USD 150,000 - 230,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Zappsec Inc. is seeking a DevSecOps & Supply Chain Security Consultant to advise on secure SDLC, SBOM governance, pipeline controls and release governance.

The role demands extensive experience with SBOM frameworks, SCA tooling, and audit-ready reporting to support regulatory compliance and risk reduction. The consultant will validate traceability, build provenance, artifact signing and tamper resistance across CI/CD and IaC environments, delivering actionable remediation guidance and executive

Qualifications

  • Strong DevSecOps and secure software delivery practices.
  • Experience with SBOM frameworks (CycloneDX, SPDX) and SCA tooling.
  • Familiarity with CI/CD security controls and artifact integrity validation.
  • Experience with vulnerability management and dependency governance programs.
  • Understanding of lifecycle security, auditability, and compliance evidence requirements.
  • Experience with secrets management and secure release governance.
  • SBOM analysis (CycloneDX, SPDX, VEX/CSAF).
  • Artifact signing, verification and tamper testing.
  • Container, registry, build-agent and CI/CD runner security.
  • Infrastructure-as-Code and pipeline-as-code security; policy-as-code.

Responsibilities

  • Assess software supply chain security, SDLC maturity, SBOM governance and CI/CD controls.
  • Review SDLC processes, tooling, and secure development practices.
  • Assess software supply chain security, including SCA, SBOM accuracy and governance.
  • Evaluate CI/CD pipeline security, artifact integrity and secure release controls.
  • Review secrets management across development, build, deployment and operations.
  • Assess logging, auditability and security event traceability controls.
  • Evaluate vulnerability management, remediation tracking and patch governance.
  • Support lifecycle security assessment, evidence mapping and traceability.
  • Contribute to assessment reporting and remediation guidance.
  • Produce audit-ready findings and executive-ready recommendations.

Skills

DevSecOps
Secure software delivery
SBOM frameworks
SCA tooling
CI/CD security
Vulnerability management
Secrets management
Compliance evidence
CRA/regulatory assessments
SBOM analysis (CycloneDX, SPDX)
Artifact signing & tamper testing
Audit trail & governance
Security gates & release governance

Tools

Syft
Grype
Trivy
Gitleaks
Dependency-Track
OpenSSL
Cosign
Sigstore
GitHub Actions
GitLab CI
Jenkins
Azure DevOps

Job description

DevSecOps & Supply Chain Security Consultant
Role Summary
  • Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security.
  • The role covers secure SDLC, pipeline architecture and access, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependencies, secrets, SAST/DAST, containers, IaC, vulnerability governance and regulatory evidence.
  • The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions and remediation; produce audit-ready findings, release-readiness and residual-risk conclusions; and recommend finding-specific work. CRA, regulated-product and stakeholder-reporting experience is highly preferred.
Key Responsibilities
  • Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management to support lifecycle security evaluation and compliance traceability.
  • Review SDLC processes, tooling, and secure development practices
  • Assess software supply chain security, including SCA, SBOM accuracy/completeness, dependency governance, and third-party risk
  • Evaluate CI/CD pipeline security, artifact integrity, and secure release controls
  • Review secrets management across development, build, deployment, and operational environments
  • Assess logging, auditability, and security event traceability controls
  • Evaluate vulnerability management, remediation tracking, and patch governance processes
  • Support lifecycle security assessment, compliance evidence mapping, and traceability
  • Contribute to assessment reporting, remediation guidance, and release governance reviews
  • Validate source-to-release traceability, build provenance, tamper resistance, artifact signing and promotion controls, SBOM accuracy, security gates, exceptions, remediation decisions, release-readiness conclusions and residual-risk positions.
  • Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, stakeholder-ready executive communication and recommendations for finding-specific follow-up work.
  • Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls, infrastructure-as-code and pipeline-as-code security, policy-as-code implementation and automated security-gate effectiveness.
Required Skills & Experience
Mandatory:
  • Strong understanding of DevSecOps and secure software delivery practices
  • Experience with SBOM frameworks (CycloneDX, SPDX) and SCA tooling
  • Familiarity with CI/CD security controls and artifact integrity validation
  • Experience with vulnerability management and dependency governance programs
  • Understanding of lifecycle security, auditability, and compliance evidence requirements
  • Experience with secrets management and secure release governance
  • SBOM Analysis (CycloneDX, SPDX, VEX/CSAF)
  • Artifact Integrity
  • SAST, DAST, Dependency & Secrets Scanning
  • Vulnerability Management & Remediation Governance
  • Secrets Management
  • Compliance Evidence & Audit Traceability
  • CRA / Regulatory Security Assessments
  • Syft and related SBOM tools
  • Secure Release Governance & Security Controls Validation
  • Build provenance and software-delivery traceability
  • Artifact signing, verification and tamper testing
  • Container, registry, build-agent and CI/CD runner security
  • Infrastructure-as-Code and pipeline-as-code security
  • Signing-key, certificate and HSM lifecycle controls
  • SBOM generation and binary-to-SBOM reconciliation
  • Open-source and third-party dependency governance
  • EOL/EOS and patch-lifecycle governance
  • Security exception and release-risk governance
  • Pipeline policy-as-code and automated security gates
  • Vulnerability metrics and release-readiness reporting
  • NIST SSDF and secure software supply-chain practices
  • Supplier security and software-acquisition assessments
  • Tools such as Syft, Grype, Trivy, Gitleaks, Dependency-Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins and Azure DevOps
  • US Citizen or Green Card holder (US Person)
Good to have:
  • Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments
  • Experience participating in engagement related to export-controlled environments
  • Familiarity with SLSA or modern software supply chain security practices
  • Strong documentation skills
Preferred Certifications
  • CSSLP, Certified DevSecOps Professional or any other relevant product-security credentials
Years of Required Experience
  • 10+ years in secure CI/CD pipeline setup, governance and controls validation, including setting up, maintaining and validating Secure CI/CD pipelines across different types of technology stacks.
  • 2+ years of hands-on SBOM analysis experience.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
Software Supply Chain Security Specialist
Software Supply Chain Security Specialist

Vanguard • Malvern

On-site
USD 150,000 - 210,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
Open Source Software Security Engineer – Software Supply Chain
Open Source Software Security Engineer – Software Supply Chain

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Software Supply Chain Security Engineer
Software Supply Chain Security Engineer

Jobtailor • Massachusetts

On-site
USD 140,000 - 180,000
Sr. IT Application Solutions Architect/ Sr DevSecOps Engineer
Sr. IT Application Solutions Architect/ Sr DevSecOps Engineer

Govserviceshub • Washington

Hybrid
USD 120,000 - 160,000
Sr. IT Application Solutions Architect/ Sr DevSecOps Engineer
Sr. IT Application Solutions Architect/ Sr DevSecOps Engineer

Govserviceshub • Washington

On-site
USD 140,000 - 180,000
Senior DevSecOps Lead: Secure Cloud CI/CD & Automation
Senior DevSecOps Lead: Secure Cloud CI/CD & Automation

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
DevSecOps Lead/Architect
DevSecOps Lead/Architect

UsefulBI • Alameda (CA)

Hybrid
USD 180,000 - 240,000
Onsite work 4 days/week
Exposure to regulatory compliance
Security Development Engineering
Security Development Engineering

FSR, LLC. • Herndon (VA)

Hybrid
USD 90,000 - 130,000