Software Supply Chain Security Engineer

Jobtailor

Massachusetts

On-site

USD 140,000 - 180,000

Full time

43 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a seasoned DevSecOps professional to lead software supply chain security initiatives across our enterprise. The role involves applying AppSec and DevSecOps principles with engineering leaders, enabling secure-by-default practices, and ensuring secure artifact sourcing and automation.

The ideal candidate brings extensive experience in SSDLC, cloud security (Azure/AWS), and building scalable security tooling within CI/CD pipelines, plus strong communication across technical

Qualifications

  • Proven AppSec and software supply chain governance experience.
  • Hands-on SSDLC and CI/CD security automation.
  • Experience configuring artifact caches and enterprise sources of truth.
  • Familiarity with Maven Central and PyPI ecosystems.
  • Security+ or CISSP certification; strong programming background.

Responsibilities

  • Execute the software supply chain security strategy across the enterprise.
  • Partner with Engineering team leads to apply DevSecOps and AppSec principles.
  • Assist application teams onboarding to security tools.
  • Work with vendors to troubleshoot platforms and integration-related issues.
  • Deliver dashboards and metrics reporting.
  • Develop and maintain supply chain security documentation.
  • Continuously improve DevSecOps processes and tooling.
  • Deliver tasks supporting project objectives to completion.

Skills

AppSec & SBOM governance
CI/CD security automation
DevSecOps
Cloud security
SSDLC
Communication

Education

CISSP
Security+

Tools

JFrog Artifactory
Ansible
Terraform
Kubernetes

Job description

  • Execute the software supply chain security strategy to expand State Street’s ability to deploy secure-by-default open source artifacts across the enterprise
  • Partner with Engineering team leads to create, implement, and apply DevSecOps and AppSec principles and processes
  • Assist application teams with onboarding to adopted security tools and technologies
  • Work with vendors to troubleshoot platforms and integration-related issues
  • Deliver and communicate reporting via dashboards and metrics
  • Develop and maintain supply chain security and DevSecOps documentation
  • Continuously improve DevSecOps and Software Supply Chain Security processes and tools
  • Deliver tasks based on project objectives and technically support projects through completion
Requirements
  • Proven expertise in Application Security (AppSec) and software supply chain security implementation/governance
  • Hands‑on experience in application security, build and release management, secure software development lifecycle (SSDLC), and automation of security processes within CI/CD pipelines
  • Experience configuring and managing artifact caches (e.g. JFrog Artifactory) and enterprise‑scale artifact sources of truth
  • Deep familiarity with package ecosystems such as Maven Central and PyPI
  • Familiarity with SLSA principles
  • Previous experience developing software in Java, .Net, Python, Node.js, or similar technologies
  • Experience with Azure and AWS
  • Extensive experience developing and managing application and software supply chain security solutions
  • Experience managing artifact caches, locking down artifact sourcing, and continuous security assessment
  • Current information security certification, including CISSP
  • Experience with automation and orchestration tools such as Ansible, Terraform, or Kubernetes is valuable
  • Knowledge of Infrastructure as Code (IaC) principles and experience automating deployment and management tasks in a hybrid cloud environment is beneficial
  • Proven technical solutioning experience with Agile Development, DevOps, Cloud Engineering, System Hardening, DevSecOps, Cybersecurity, and Cloud Security
  • Excellent verbal and written communication skills across internal and external organizations
  • Ability to prioritize and manage several projects or priorities simultaneously
  • 6+ years of relevant combined experience across development, CI/CD, software supply chain security, and application security
  • Experience with application security tooling and its operations with modern CI/CD and DevSecOps best practices
  • Experience partnering with the Dev community to influence adoption of application security best practices and tooling
  • Security+ or other cybersecurity security certification
  • Experience with one or more common programming languages such as Java, .Net, or Python
Core Competencies

Demonstrates expertise in Application Security and Software Supply Chain Security, with a strong focus on implementing DevSecOps principles and managing security tools within CI/CD pipelines. Proven ability to develop secure software solutions and enhance security processes in cloud environments.

Highest-signal resume keywords
  • Application Security (AppSec)
  • Software Supply Chain Security
  • DevSecOps Implementation
  • CISSP Certification
  • CI/CD Pipeline Automation
ATS Optimization Keywords
Hard Skills
  • Secure Software Development Lifecycle (SSDLC)
  • Artifact Cache Management
  • Java Development
  • Python Development
  • Azure Cloud
  • AWS Cloud
  • Infrastructure as Code (IaC)
  • Agile Development
  • DevOps Practices
  • Continuous Security Assessment
Soft Skills
  • Excellent Communication Skills
  • Project Management
Certifications & Qualifications
  • CISSP
  • Security+
Industry Keywords
  • DevSecOps
  • Cybersecurity
  • Cloud Security
  • SLSA Principles
  • Package Ecosystems
Tools & Technologies
  • JFrog Artifactory
  • Ansible
  • Terraform
  • Kubernetes
  • CI/CD Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Open Source Software Security Engineer – Software Supply Chain
Open Source Software Security Engineer – Software Supply Chain

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Software Supply Chain Security Engineer
Software Supply Chain Security Engineer

State Street • Austin (TX)

On-site
USD 90,000 - 158,000
401K with company match
Medical, dental, vision coverage
Paid time off
Software Supply Chain Security Engineer
Software Supply Chain Security Engineer

State Street • Atlanta (GA)

On-site
USD 90,000 - 158,000
401K with company match
Health, dental, vision insurance
Paid time off and family leave
+3
Software Supply Chain Security Engineer
Software Supply Chain Security Engineer

State Street • Quincy (MA)

On-site
USD 90,000 - 158,000
401K with company match
Comprehensive medical, dental, vision
Paid time off
+3
Senior DevSecOps Engineer – Software Supply Chain
Senior DevSecOps Engineer – Software Supply Chain

State Street • Austin (TX)

On-site
USD 90,000 - 158,000
401K with company match
Medical, dental, vision coverage
Paid time off
DevSecOps Engineer, Python, CI/CD
DevSecOps Engineer, Python, CI/CD

Jobtailor • Washington

On-site
USD 140,000 - 190,000
DevSecOps Engineer: Software Supply Chain Security
DevSecOps Engineer: Software Supply Chain Security

State Street • Quincy (MA)

On-site
USD 90,000 - 158,000
401K with company match
Comprehensive medical, dental, vision
Paid time off
+3
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
Software Supply Chain Security Specialist
Software Supply Chain Security Specialist

Vanguard • Malvern

On-site
USD 150,000 - 210,000
DevSecOps & Supply Chain Security Consultant
DevSecOps & Supply Chain Security Consultant

Zappsec Inc. • Tewksbury (MA)

On-site
USD 150,000 - 230,000