DevSecOps & Supply Chain Security Consultant - (Onsite - Boston, MA)

OMG Technology

Boston (MA)

On-site

USD 140,000 - 190,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

OMG Technology invites a seasoned DevSecOps & Supply Chain Security Consultant for onsite engagement in Boston, MA. You will lead secure software delivery practices, strengthen CI/CD pipelines, and ensure SBOM accuracy across the release lifecycle.

You will validate traceability, tamper resistance, and governance controls, producing audit-ready findings and executive-level reporting for the client. Travel to the Tewksbury, MA site may be required when needed for engagement milestones.

Qualifications

  • 10+ years of experience in secure CI/CD pipeline setup and controls validation.
  • Hands-on SBOM analysis experience (2+ years).
  • Familiarity with NIST SSDF and secure software supply-chain practices.

Responsibilities

  • Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls.
  • Review SDLC processes, security tooling, and secure development practices.
  • Evaluate CI/CD pipeline security, artifact integrity, and build provenance.
  • Validate SBOM generation, signing, and reconciliation.
  • Produce audit-ready findings and stakeholder-ready reporting.

Skills

CI/CD security
SBOM analysis
SCA/SAST/DAST
Vulnerability governance
Regulatory security

Tools

Syft
Grype
Trivy
Gitleaks
Dependency-Track
Cosign
Sigstore
GitHub Actions
GitLab CI
Jenkins
Azure DevOps

Job description

DevSecOps & Supply Chain Security Consultant - (Onsite - Boston, MA)

We are looking to hire a candidate with the mentioned skill sets and experience for one of our clients,

Job Summary

We are seeking a DevSecOps & Supply Chain Security Consultant with 10+ years of experience in secure software delivery, CI/CD, and software supply-chain security. The consultant will focus on secure SDLC, CI/CD pipeline architecture and security, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependency and secrets management, SAST/DAST, containers, IaC, vulnerability governance, and regulatory evidence.

The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions, remediation, release readiness, and residual risk and will produce audit-ready findings and stakeholder-ready reporting.

Work Authorization

Must be a US Citizen or Green Card holder (US Person).

Travel

Up to three (3) weeks of travel to the client’s Tewksbury, MA site during the engagement. Travel and accommodation expenses will be arranged and covered. Travel may be a single visit or split across multiple visits based on project requirements.

Key Responsibilities
  • Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management.
  • Review SDLC processes, security tooling, and secure development practices.
  • Assess SCA, SBOM accuracy/completeness, dependency governance, and third-party risk.
  • Evaluate CI/CD pipeline security, artifact integrity, secure release controls, and build provenance.
  • Validate source-to-release traceability, artifact signing and promotion, tamper resistance, SBOM accuracy, security gates, exceptions, and remediation decisions.
  • Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls.
  • Evaluate Infrastructure-as-Code, pipeline-as-code, policy-as-code, and automated security-gate effectiveness.
  • Review secrets management across development, build, deployment, and operational environments.
  • Evaluate vulnerability management, remediation tracking, patch governance, EOL/EOS, and release-risk governance.
  • Assess signing-key, certificate, and HSM lifecycle controls.
  • Validate SBOM generation and binary-to-SBOM reconciliation.
  • Support lifecycle security assessments, compliance evidence mapping, and audit traceability.
  • Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, remediation guidance, and stakeholder-ready executive communication.
  • Recommend finding-specific follow-up work and support release governance reviews.
Required Skills / Experience
  • 10+ years of experience in secure CI/CD pipeline setup, governance, and controls validation across different technology stacks.
  • 2+ years of hands-on SBOM analysis experience.
  • Strong understanding of DevSecOps and secure software delivery practices.
  • Strong experience with SBOM frameworks: CycloneDX, SPDX, VEX/CSAF.
  • Experience with SCA, SAST, DAST, dependency scanning, and secrets scanning.
  • Experience with artifact integrity, artifact signing, verification, tamper testing, and build provenance.
  • Strong knowledge of CI/CD security, secure release governance, and automated security gates.
  • Experience with vulnerability management, remediation governance, dependency governance, and patch lifecycle management.
  • Experience with secrets management and secure release controls.
  • Knowledge of container, registry, build-agent, and CI/CD runner security.
  • Experience with Infrastructure-as-Code and pipeline-as-code security.
  • Knowledge of policy-as-code and security controls validation.
  • Experience with compliance evidence, audit traceability, and regulatory security assessments.
  • Knowledge of NIST SSDF and secure software supply-chain practices.
  • Experience with supplier security and software-acquisition assessments.
  • Hands‑on experience with tools such as Syft, Grype, Trivy, Gitleaks, Dependency‑Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins, and Azure DevOps.
  • Experience with CRA / regulatory security assessments is highly preferred.
  • Familiarity with SLSA or modern software supply-chain security practices is a plus.
  • Experience with regulated products, export‑controlled environments, or compliance‑driven cybersecurity assessments is preferred.
  • Strong documentation and stakeholder communication skills.
  • Candidate needs to be US Citizen or Green Card holder.
Preferred Certifications
  • CSSLP
  • Certified DevSecOps Professional
  • Other relevant product-security credentials.
Location & Travel
  • Location: Boston, MA
  • On‑site: Ability to work from the Boston office for 4-6 weeks during the engagement.
  • Travel: Up to 3 weeks at the client’s Tewksbury, MA site during the engagement. Travel and accommodation expenses will be covered.
Other Job Details:
  • Job Type: C2C or W2.
  • Location: Boston, MA, USA.
  • Interviews: Video interviews.
  • Docs required: ID proof will be required.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps & Supply Chain Security Consultant - Onsite - Boston, MA - omgtech
DevSecOps & Supply Chain Security Consultant - Onsite - Boston, MA - omgtech

OpenTalent • Boston (MA)

On-site
USD 160,000 - 210,000
DevSecOps & Supply Chain Security Consultant - Onsite - Boston, MA - OMG Technology
DevSecOps & Supply Chain Security Consultant - Onsite - Boston, MA - OMG Technology

OpenTalent • Boston (MA)

On-site
USD 140,000 - 190,000
DevSecOps & Supply Chain Security Consultant
DevSecOps & Supply Chain Security Consultant

Rivago Infotech Inc • Tewksbury (MA)

Hybrid
USD 120,000 - 160,000
DevSecOps & Supply Chain Security Consultant
DevSecOps & Supply Chain Security Consultant

Zappsec • Tewksbury (MA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Senior DevSecOps & Supply-Chain Security Architect
Senior DevSecOps & Supply-Chain Security Architect

OpenTalent • Boston (MA)

On-site
USD 160,000 - 210,000
Senior DevSecOps & Supply Chain Security Strategist
Senior DevSecOps & Supply Chain Security Strategist

OpenTalent • Boston (MA)

On-site
USD 140,000 - 190,000
Senior DevSecOps & Supply-Chain Security Architect
Senior DevSecOps & Supply-Chain Security Architect

OMG Technology • Boston (MA)

On-site
USD 140,000 - 190,000
Senior DevSecOps & Supply Chain Security Consultant
Senior DevSecOps & Supply Chain Security Consultant

OpenTalent • Tewksbury (MA)

On-site
USD 140,000 - 200,000
DevSecOps & Supply Chain Security Consultant - Zappsec
DevSecOps & Supply Chain Security Consultant - Zappsec

OpenTalent • Tewksbury (MA)

On-site
USD 140,000 - 200,000
Software Supply Chain Security Engineer
Software Supply Chain Security Engineer

Jobtailor • Massachusetts

On-site
USD 140,000 - 180,000