Senior DevSecOps Engineer

System One

Knoxville (TN)

On-site

USD 140,000 - 180,000

Full time

9 days ago
Application generator

Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Restaurant d'entreprise
Indemnités de stage/alternance

Job summary

System One in Knoxville, TN is seeking a Senior DevSecOps Engineer to strengthen enterprise software supply chain security across multiple locations including Lafayette, LA and Birmingham, AL.

You will drive artifact signing, SBOM generation, and governance, integrate security tooling into CI/CD pipelines, and mentor teams on secure by design practices.

Qualifications

  • 5+ years of experience in DevSecOps, Platform Engineering, and Software Supply Chain Engineering.
  • Hands-on experience with Sonatype Lifecycle / IQ Server, Nexus Repository, or JFrog.
  • Experience building and maintaining automated Open Source Software evaluation policies and workflows.
  • Experience with artifact signing technologies such as Sigstore, Cosign, GPG, Notary.
  • Experience with SLSA provenance and in-toto attestations.
  • Experience generating SBOMs using CycloneDX, SPDX, Syft.
  • Strong CI/CD experience with GitLab; GitHub Actions also acceptable.
  • Strong AWS experience across IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, CloudWatch.
  • Scripting in Python, Bash, and Go.
  • Familiarity with OCI registries and ecosystems like Maven, npm, PyPI, NuGet.
  • Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design principles.

Responsibilities

  • Enhance artifact management, policy governance, and open-source lifecycle processes using Sonatype Lifecycle (IQ Server), Nexus Repository, or JFrog.
  • Build and automate software approval workflows, including quarantine and waiver processes.
  • Develop and maintain repository proxy strategies across supported software ecosystems.
  • Drive dependency upgrades and vulnerability remediation initiatives.
  • Support onboarding of emerging ecosystems, including AI/ML frameworks.
  • Build reporting and metrics for software supply chain health, policy compliance, and repository utilization.
  • Enable CI/CD artifact signing and verification.
  • Implement SLSA build provenance and attestations.
  • Integrate SBOM generation into build and deployment pipelines.
  • Partner with security and development teams to improve software supply chain visibility, integrity, and security.
  • Help build secure and trustworthy software delivery pipelines at enterprise scale.

Skills

DevSecOps
Platform Engineering
Software Supply Chain Engineering
OSS governance
SBOM generation
Open Source evaluation policies
Python
Bash
Go
NIST SSDF
Executive Order 14028
Secure by Design
GitLab CI/CD
GitHub Actions
AWS IAM
AWS ECS/EKS
AWS EC2
AWS S3
AWS Lambda
AWS Step Functions
AWS CloudWatch
Python scripting

Education

Bachelor’s degree in Computer Science, Information Systems, or a related field.

Tools

Sonatype Lifecycle
Nexus Repository
JFrog
Sigstore
Cosign
GPG
Notary
SLSA provenance
in-toto attestations
CycloneDX
SPDX
Syft
GitLab
GitHub Actions
Maven
npm
PyPI
NuGet
OCI registries

Job description

Senior DevSecOps Engineer

Permanent Full-Time
Lafayette, LA | Knoxville, TN | Birmingham, AL | Columbia SC

Position Description

This role focuses on improving software supply chain security, artifact management, open-source governance, CI/CD security, SBOM generation, artifact signing, and software provenance across enterprise environments.

Key Responsibilities
  • Enhance artifact management, policy governance, and open-source lifecycle processes using tools such as Sonatype Lifecycle (IQ Server), Nexus Repository, or JFrog.
  • Build and automate software approval workflows, including quarantine and waiver processes.
  • Develop and maintain repository proxy strategies across supported software ecosystems.
  • Drive dependency upgrades and vulnerability remediation initiatives.
  • Support onboarding of emerging ecosystems, including AI/ML frameworks.
  • Build reporting and metrics for:
    • Software supply chain health
    • Policy compliance
    • Repository utilization
  • Enable CI/CD artifact signing and verification.
  • Implement SLSA build provenance and attestations.
  • Integrate SBOM generation into build and deployment pipelines.
  • Partner with security and development teams to improve software supply chain visibility, integrity, and security across the organization.
  • Help build secure and trustworthy software delivery pipelines at enterprise scale.
Required Qualifications
  • 5+ years of experience in:
    • DevSecOps
    • Platform Engineering
    • Software Supply Chain Engineering
  • Hands‑on experience with:
    • Sonatype Lifecycle / IQ Server
    • Nexus Repository
    • Or similar tools such as JFrog
  • Experience building and maintaining automated Open Source Software evaluation policies and workflows.
  • Experience with artifact signing technologies such as:
    • Sigstore
    • Cosign
    • GPG
    • Notary
  • Experience with:
    • SLSA provenance
    • in‑toto attestations
    • Similar software supply chain frameworks
  • Experience generating SBOMs using:
    • CycloneDX
    • SPDX
    • Syft
  • Strong CI/CD experience, preferably:
    • GitLab
    • GitHub Actions also acceptable
  • Strong AWS experience with:
    • IAM
    • ECS / EKS
    • EC2
    • S3
    • Lambda
    • Step Functions
    • CloudWatch
  • Experience integrating security tooling directly into CI/CD pipelines.
  • Strong scripting skills in:
    • Python
    • Bash
    • Go
  • Experience maintaining enterprise open‑source platforms.
  • Familiarity with OCI registries and package ecosystems such as:
    • Maven
    • npm
    • PyPI
    • NuGet
  • Knowledge of:
    • NIST SSDF
    • Executive Order 14028
    • Secure by Design principles
Educational Requirement

Bachelor’s degree in Computer Science, Information Systems, or a related field.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DevSecOps Engineer
Senior DevSecOps Engineer

System One • Lafayette (LA)

On-site
USD 140,000 - 180,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

System One • Birmingham (AL)

Hybrid
USD 140,000 - 190,000
Senior DevSecOps Engineer - Knoxville, TN
Senior DevSecOps Engineer - Knoxville, TN

System One • Knoxville (TN)

On-site
USD 140,000 - 170,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
DevSecOps & Supply Chain Security Consultant
DevSecOps & Supply Chain Security Consultant

Zappsec Inc. • Tewksbury (MA)

On-site
USD 150,000 - 230,000
DevSecOps & Supply Chain Security Consultant
DevSecOps & Supply Chain Security Consultant

Zappsec • Tewksbury (MA), Northern (KY)

On-site
USD 150,000 - 210,000
Principal DevSecOps Engineer
Principal DevSecOps Engineer

Compunnel, Inc. • Omaha (NE)

On-site
USD 180,000 - 230,000
Senior DevSecOps Engineer: Secure Software Supply Chain
Senior DevSecOps Engineer: Secure Software Supply Chain

System One • Knoxville (TN)

Hybrid
USD 140,000 - 170,000
System Engineer 2
System Engineer 2

Gormat • Corridor North (MD)

On-site
USD 110,000 - 165,000
DevSecOps Platform Engineer
DevSecOps Platform Engineer

SBS Creatix LLC • St. Louis (MO)

Hybrid
USD 140,000 - 190,000