Senior DevSecOps Engineer

Knoxville

Hybrid$104,000

**Senior DevSecOps Engineer** **Permanent Full-Time Lafayette, LA \| Knoxville, TN \| Birmingham, AL \| Columbia SC** **Position Description** This role focuses on improving **software supply chain security, artifact management, open-source governance, CI/CD security, SBOM generation, artifact signing, and software provenance** across enterprise environments. **Key Responsibilities** * Enhance **artifact management, policy governance, and open-source lifecycle processes** using tools such as **Sonatype Lifecycle (IQ Server), Nexus Repository, or JFrog**. * Build and automate **software approval workflows**, including quarantine and waiver processes. * Develop and maintain **repository proxy strategies** across supported software ecosystems. * Drive **dependency upgrades and vulnerability remediation** initiatives. * Support onboarding of emerging ecosystems, including **AI/ML frameworks**. * Build reporting and metrics for: * Software supply chain health * Policy compliance * Repository utilization * Enable **CI/CD artifact signing and verification**. * Implement **SLSA build provenance and attestations**. * Integrate **SBOM generation** into build and deployment pipelines. * Partner with security and development teams to improve **software supply chain visibility, integrity, and security** across the organization. * Help build secure and trustworthy software delivery pipelines at enterprise scale. **Required Qualifications** * **5+ years** of experience in: * DevSecOps * Platform Engineering * Software Supply Chain Engineering * Hands-on experience with: * **Sonatype Lifecycle / IQ Server** * **Nexus Repository** * Or similar tools such as **JFrog** * Experience building and maintaining automated **Open Source Software evaluation policies and workflows**. * Experience with artifact signing technologies such as: * **Sigstore** * **Cosign** * **GPG** * **Notary** * Experience with: * **SLSA provenance** * **in-toto attestations** * Similar software supply chain frameworks * Experience generating **SBOMs** using: * **CycloneDX** * **SPDX** * **Syft** * Strong **CI/CD** experience, preferably: * **GitLab** * GitHub Actions also acceptable * Strong **AWS** experience with: * **IAM** * **ECS / EKS** * **EC2** * **S3** * **Lambda** * **Step Functions** * **CloudWatch** * Experience integrating **security tooling directly into CI/CD pipelines**. * Strong scripting skills in: * **Python** * **Bash** * **Go** * Experience maintaining **enterprise open-source platforms**. * Familiarity with **OCI registries** and package ecosystems such as: * **Maven** * **npm** * **PyPI** * **NuGet** * Knowledge of: * **NIST SSDF** * **Executive Order 14028** * **Secure by Design principles** **Educational Requirement** **Bachelor's degree** in Computer Science, Information Systems, or a related field. Ref: #404-IT Pittsburgh

System One

System One