VI

DevSecOps Engineer / 10+yrs/ Relocation / All Visas are Accepted

Moves you to
United States
Support
Relocation support
Posted
Is this job info correct?
Show job description

All Visas are Accepted for this role

Job Title :- DevSecOps Engineer / 10+yrs / Relocation will work

Location :- Atlanta GA ( 5 Days per Week Onsite )

Employment Type :-Full Time


Job Description :-

We are looking for a senior DevSecOps Engineer with strong expertise in Software Supply Chain Security, DevSecOps, and Platform Engineering. This role will focus on securing the software development lifecycle, enhancing artifact management, implementing supply chain security controls, and enabling secure CI/CD practices across the enterprise.

Key Responsibilities

  • Lead enterprise software supply chain security initiatives and support secure software delivery practices.
  • Manage and enhance Sonatype Nexus Repository and IQ Server policies for artifact governance and open-source software compliance.
  • Design and automate software approval workflows, quarantine processes, waivers, and lifecycle management.
  • Implement repository proxy strategies across various software ecosystems.
  • Drive dependency management, vulnerability remediation, and secure package consumption.
  • Support onboarding of emerging technologies and ecosystems, including AI/ML frameworks.
  • Develop dashboards and metrics for repository usage, policy compliance, and software supply chain health.
  • Implement artifact signing and verification using technologies such as Cosign, Sigstore, GPG, or Notary.
  • Design and implement SLSA provenance, build attestations, and secure build frameworks.
  • Integrate SBOM generation and software metadata into CI/CD pipelines.
  • Partner with development and security teams to improve software integrity, visibility, and compliance.


Required Skills & Experience

  • 9+ years of experience in DevSecOps
  • Strong hands-on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository (or equivalent tools such as JFrog Artifactory).
  • Experience implementing Open Source Software (OSS) governance policies and automated approval workflows.
  • Expertise in artifact signing technologies (Sigstore/Cosign, GPG, Notary).
  • Experience with SLSA, in-toto attestations, and software supply chain security frameworks.
  • Hands-on experience with SBOM tools and standards (CycloneDX, SPDX, Syft).
  • Strong CI/CD experience using GitLab, GitHub Actions, or similar platforms.
  • Deep AWS expertise including IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch.
  • Experience integrating security tools into CI/CD pipelines.
  • Strong scripting and automation skills in Python, Bash, or Go.
  • Knowledge of OCI registries and package ecosystems including Maven, npm, PyPI, and NuGet.
  • Familiarity with NIST SSDF, Executive Order 14028, and Secure-by-Design principles.


Similar jobs

Apply on LinkedIn