Senior DevSecOps Engineer

System One

Birmingham (AL)

Hybrid

USD 140,000 - 190,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

System One is seeking a Senior DevSecOps Engineer to strengthen software supply chain security across enterprise environments in Lafayette, LA; Knoxville, TN; Birmingham, AL; and Columbia, SC.

Key tasks include automating artifact management, signing, SBOMs, and provenance in CI/CD pipelines, plus promoting secure build practices and governance across teams.

Qualifications

  • 5+ years of experience in DevSecOps, Platform Engineering, or Software Supply Chain Engineering.
  • Hands-on experience with Sonatype Lifecycle / IQ Server, Nexus Repository, or JFrog.
  • Experience building automated OSS evaluation policies and workflows.

Responsibilities

  • Enhance artifact management, policy governance, and open-source lifecycle processes.
  • Build and automate software approval workflows, including quarantine and waiver processes.
  • Develop and maintain repository proxy strategies across ecosystems.
  • Drive dependency upgrades and vulnerability remediation.

Skills

DevSecOps
Platform Engineering
Software Supply Chain Engineering
CI/CD security

Education

Bachelor's degree in Computer Science or related field

Tools

Sonatype Lifecycle / IQ Server
Nexus Repository
JFrog
Sigstore
Cosign
GPG
Notary
SLSA provenance
in-toto attestations
CycloneDX
SPDX
Syft
GitLab
GitHub Actions
AWS
IAM
ECS/EKS
EC2
S3
Lambda
Step Functions
CloudWatch

Job description

Senior DevSecOps Engineer

Permanent Full-Time

Lafayette, LA | Knoxville, TN | Birmingham, AL | Columbia SC

Position Description

This role focuses on improving software supply chain security, artifact management, open-source governance, CI/CD security, SBOM generation, artifact signing, and software provenance across enterprise environments.

Key Responsibilities
  • Enhance artifact management, policy governance, and open-source lifecycle processes using tools such as Sonatype Lifecycle (IQ Server), Nexus Repository, or JFrog.
  • Build and automate software approval workflows, including quarantine and waiver processes.
  • Develop and maintain repository proxy strategies across supported software ecosystems.
  • Drive dependency upgrades and vulnerability remediation initiatives.
  • Support onboarding of emerging ecosystems, including AI/ML frameworks.
  • Build reporting and metrics for:
    • Software supply chain health
    • Policy compliance
    • Repository utilization
  • Enable CI/CD artifact signing and verification.
  • Implement SLSA build provenance and attestations.
  • Integrate SBOM generation into build and deployment pipelines.
  • Partner with security and development teams to improve software supply chain visibility, integrity, and security across the organization.
  • Help build secure and trustworthy software delivery pipelines at enterprise scale.
Required Qualifications
  • 5+ years of experience in:
    • DevSecOps
    • Platform Engineering
    • Software Supply Chain Engineering
  • Hands-on experience with:
    • Sonatype Lifecycle / IQ Server
    • Nexus Repository
    • Or similar tools such as JFrog
  • Experience building and maintaining automated Open Source Software evaluation policies and workflows.
  • Experience with artifact signing technologies such as:
    • Sigstore
    • Cosign
    • GPG
    • Notary
  • Experience with:
    • SLSA provenance
    • in-toto attestations
    • Similar software supply chain frameworks
  • Experience generating SBOMs using:
    • CycloneDX
    • SPDX
    • Syft
  • Strong CI/CD experience, preferably:
    • GitLab
    • GitHub Actions also acceptable
  • Strong AWS experience with:
    • IAM
    • ECS / EKS
    • EC2
    • S3
    • Lambda
    • Step Functions
    • CloudWatch
  • Experience integrating security tooling directly into CI/CD pipelines.
  • Strong scripting skills in:
    • Python
    • Bash
    • Go
  • Experience maintaining enterprise open-source platforms.
  • Familiarity with OCI registries and package ecosystems such as:
    • Maven
    • npm
    • PyPI
    • NuGet
  • Knowledge of:
    • NIST SSDF
    • Executive Order 14028
    • Secure by Design principles
Educational Requirement

Bachelor’s degree in Computer Science, Information Systems, or a related field.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DevSecOps Engineer
Senior DevSecOps Engineer

System One • Lafayette (LA)

On-site
USD 140,000 - 180,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

System One • Knoxville (TN)

On-site
USD 140,000 - 180,000
Restaurant d'entreprise
Indemnités de stage/alternance
Senior DevSecOps Engineer - Knoxville, TN
Senior DevSecOps Engineer - Knoxville, TN

System One • Knoxville (TN)

On-site
USD 140,000 - 170,000
Principal DevSecOps Engineer
Principal DevSecOps Engineer

Compunnel, Inc. • Omaha (NE)

On-site
USD 180,000 - 230,000
System Engineer 2
System Engineer 2

Gormat • Maryland

On-site
USD 110,000 - 150,000
DevSecOps & Supply Chain Security Consultant
DevSecOps & Supply Chain Security Consultant

Zappsec Inc. • Tewksbury (MA)

On-site
USD 150,000 - 230,000
System Engineer 2
System Engineer 2

Gormat • Corridor North (MD)

On-site
USD 110,000 - 165,000
DevSecOps & Supply Chain Security Consultant
DevSecOps & Supply Chain Security Consultant

Zappsec • Tewksbury (MA), Northern (KY)

On-site
USD 150,000 - 210,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
Senior DevSecOps Engineer: Secure Software Supply Chain
Senior DevSecOps Engineer: Secure Software Supply Chain

System One • Knoxville (TN)

Hybrid
USD 140,000 - 170,000