DevSecOps Engineer *

CGI

• $89K — $139K *
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in DevSecOps, Platform Engineering, or Software Supply Chain roles
  • Hands-on experience with Sonatype Nexus and IQ Server (or similar tools like jFrog Artifactory)
  • Proficient in automated open source policy workflows
  • Experience with artifact signing tools (Sigstore/Cosign, GPG, Notary)
  • Familiarity with supply chain security frameworks (e.g., SLSA provenance, in toto attestations)
  • Knowledge of SBOM generation tools (CycloneDX, SPDX, Syft)
  • Solid background in CI/CD with GitLab or GitHub Actions
  • Strong AWS experience (IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, CloudWatch)
  • Scripting capabilities in Python, Bash, or Go

Responsibilities

  • Support secure software delivery via enterprise supply chain initiatives
  • Manage and enhance artifact repository tooling and open source policy governance
  • Build and maintain software approval, quarantine, and lifecycle workflows
  • Drive dependency upgrades and vulnerability remediation efforts
  • Onboard new/emerging technology ecosystems, including AI/ML frameworks
  • Create dashboards and metrics for supply chain health and compliance
  • Implement CI/CD artifact signing and SBOM integration

Benefits

  • Competitive compensation
  • Comprehensive insurance options
  • 401(k) matching contributions and share purchase plan
  • Paid time off for vacation, holidays, and sick leave
  • Paid parental leave
  • Learning and tuition assistance programs
  • Wellness and well-being programs
Full Job Description
Find similar career opportunities

DevSecOps Engineer *

Category: Project Management

Main location: United States, Louisiana, Lafayette

Position ID:J0926-1445

Employment Type: Full Time

Position Description:

CGI is seeking a DevSecOps Engineer to strengthen our software supply chain security program within a large scale, AWS based financial services environment. In this role, you will help secure the software delivery lifecycle - from open source governance to CI/CD artifact integrity - ensuring that software built and deployed across the organization meets rigorous compliance and security standards.

You'll work hands on with tools like Sonatype Nexus/IQ Server, implement artifact signing and provenance frameworks (SLSA, Sigstore/Cosign), and build automation that supports vulnerability remediation, SBOM generation, and open source policy enforcement. This is a great opportunity for someone who enjoys solving real security problems at scale, working across CI/CD pipelines, cloud infrastructure, and emerging technology ecosystems (including AI/ML tooling).

This position is required in one of the following locations: Lafayette, LA, Knoxville, TN, Birmingham, AL

Your future duties and responsibilities:

. Support secure software delivery through enterprise supply chain initiatives
. Manage and enhance artifact repository tooling and open source policy governance
. Build and maintain software approval, quarantine, and lifecycle workflows
. Drive dependency upgrades and vulnerability remediation efforts
. Onboard new/emerging technology ecosystems (including AI/ML frameworks)
. Create dashboards and metrics for supply chain health and compliance
. Implement CI/CD artifact signing, build provenance (SLSA), and SBOM integration

Required qualifications to be successful in this role:

. 5+ years working in DevSecOps, Platform Engineering, or Software Supply Chain roles
. Hands on experience with Sonatype Nexus and IQ Server (or similar - jFrog Artifactory is fine too)
. Comfortable building and maintaining automated open source policy workflows
. Experience with artifact signing tools like Sigstore/Cosign, GPG, or Notary
. Familiarity with SLSA provenance and in toto attestations (or similar supply chain security frameworks)
. Know your way around SBOM generation tools - CycloneDX, SPDX, or Syft
. Solid CI/CD background, ideally with GitLab (GitHub Actions also welcome)
. Strong AWS chops - IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, CloudWatch
. Scripting ability in Python, Bash, or Go
. Exposure to OCI registries and package ecosystems like Maven, npm, PyPI, or NuGet

Educational Requirement:
Bachelor's degree in Computer Science, Information Systems, or a related field.

Other Information:
CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set, level, experience, relevant training, and licensure and certifications. To support the ability to reward for merit based performance, CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $89,600.00 $139,300.00.
CGI's benefits are offered to eligible professionals on their first day of employment to include: . Competitive compensation . Comprehensive insurance options . Matching contributions through the 401(k) plan and the share purchase plan . Paid time off for vacation, holidays, and sick time . Paid parental leave .Learning opportunities and tuition assistance . Wellness and Well being programs

Skills:
  • Amazon Web Services Cloud
  • BASH
  • DevOps Security
  • GitHub
  • GitLab
  • Python


Similar Jobs

More Jobs at CGI

More Finance & Insurance Jobs

Find similar DevSecOps Engineer * jobs: