Job Title: DevSecOps Engineer
Location: Lafayette, LA
Type: Direct Hire
Work Model: Hybrid - onsite and remote
Hours: 40.0
Security Clearance: Not specified in the provided details
Responsibilities
- Support secure software delivery through enterprise supply chain initiatives
- Manage and enhance artifact repository tooling and open source policy governance
- Build and maintain software approval, quarantine, and lifecycle workflows
- Drive dependency upgrades and vulnerability remediation efforts
- Onboard new/emerging technology ecosystems (including AI/ML frameworks)
- Create dashboards and metrics for supply chain health and compliance
- Implement CI/CD artifact signing, build provenance (SLSA), and SBOM integration
Requirements
- 5+ years working in DevSecOps, Platform Engineering, or Software Supply Chain roles
- Hands on experience with Sonatype Nexus and IQ Server (or similar - jFrog Artifactory is fine too)
- Comfortable building and maintaining automated open source policy workflows
- Experience with artifact signing tools like Sigstore/Cosign, GPG, or Notary
- Familiarity with SLSA provenance and in toto attestations (or similar supply chain security frameworks)
- Know your way around SBOM generation tools - CycloneDX, SPDX, or Syft
- Solid CI/CD background, ideally with GitLab (GitHub Actions also welcome)
- Strong AWS chops - IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, CloudWatch
- Scripting ability in Python, Bash, or Go
- Exposure to OCI registries and package ecosystems like Maven, npm, PyPI, or NuGet
- Bachelor's degree in Computer Science, Information Systems, or a related field
System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
#M-
#LI-
Ref: #404-IT Pittsburgh