Find similar career opportunities
DevSecOps Engineer * Category: Project Management
Main location: United States, Louisiana, Lafayette
Position ID:J0926-1445
Employment Type: Full Time
Position Description: CGI is seeking a DevSecOps Engineer to strengthen our software supply chain security program within a large scale, AWS based financial services environment. In this role, you will help secure the software delivery lifecycle - from open source governance to CI/CD artifact integrity - ensuring that software built and deployed across the organization meets rigorous compliance and security standards.
You'll work hands on with tools like Sonatype Nexus/IQ Server, implement artifact signing and provenance frameworks (SLSA, Sigstore/Cosign), and build automation that supports vulnerability remediation, SBOM generation, and open source policy enforcement. This is a great opportunity for someone who enjoys solving real security problems at scale, working across CI/CD pipelines, cloud infrastructure, and emerging technology ecosystems (including AI/ML tooling).
This position is required in one of the following locations: Lafayette, LA, Knoxville, TN, Birmingham, AL
Your future duties and responsibilities: . Support secure software delivery through enterprise supply chain initiatives
. Manage and enhance artifact repository tooling and open source policy governance
. Build and maintain software approval, quarantine, and lifecycle workflows
. Drive dependency upgrades and vulnerability remediation efforts
. Onboard new/emerging technology ecosystems (including AI/ML frameworks)
. Create dashboards and metrics for supply chain health and compliance
. Implement CI/CD artifact signing, build provenance (SLSA), and SBOM integration
Required qualifications to be successful in this role: . 5+ years working in DevSecOps, Platform Engineering, or Software Supply Chain roles
. Hands on experience with Sonatype Nexus and IQ Server (or similar - jFrog Artifactory is fine too)
. Comfortable building and maintaining automated open source policy workflows
. Experience with artifact signing tools like Sigstore/Cosign, GPG, or Notary
. Familiarity with SLSA provenance and in toto attestations (or similar supply chain security frameworks)
. Know your way around SBOM generation tools - CycloneDX, SPDX, or Syft
. Solid CI/CD background, ideally with GitLab (GitHub Actions also welcome)
. Strong AWS chops - IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, CloudWatch
. Scripting ability in Python, Bash, or Go
. Exposure to OCI registries and package ecosystems like Maven, npm, PyPI, or NuGet
Educational Requirement:
Bachelor's degree in Computer Science, Information Systems, or a related field.
Other Information:
CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set, level, experience, relevant training, and licensure and certifications. To support the ability to reward for merit based performance, CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $89,600.00 $139,300.00.
CGI's benefits are offered to eligible professionals on their first day of employment to include: . Competitive compensation . Comprehensive insurance options . Matching contributions through the 401(k) plan and the share purchase plan . Paid time off for vacation, holidays, and sick time . Paid parental leave .Learning opportunities and tuition assistance . Wellness and Well being programs
Skills: - Amazon Web Services Cloud
- BASH
- DevOps Security
- GitHub
- GitLab
- Python