Job Title: DevSecOps Engineer
Duration: Full Time / Permanent Position
Location: Lafayette, LA, Knoxville, TN, Birmingham, AL
Work Mode: 5 Days OnsiteSystemone is seeking a DevSecOps Engineer to strengthen our software supply chain security program within a large scale, AWS based financial services environment. In this role, you will help secure the software delivery lifecycle - from open source governance to CI/CD artifact integrity - ensuring that software built and deployed across the organization meets rigorous compliance and security standards.
You'll work hands on with tools like Sonatype Nexus/IQ Server, implement artifact signing and provenance frameworks (SLSA, Sigstore/Cosign), and build automation that supports vulnerability remediation, SBOM generation, and open source policy enforcement. This is a great opportunity for someone who enjoys solving real security problems at scale, working across CI/CD pipelines, cloud infrastructure, and emerging technology ecosystems (including AI/ML tooling).
Your future duties and responsibilities- Support secure software delivery through enterprise supply chain initiatives
- Manage and enhance artifact repository tooling and open source policy governance
- Build and maintain software approval, quarantine, and lifecycle workflows
- Drive dependency upgrades and vulnerability remediation efforts
- Onboard new/emerging technology ecosystems (including AI/ML frameworks)
- Create dashboards and metrics for supply chain health and compliance
- Implement CI/CD artifact signing, build provenance (SLSA), and SBOM integration
Required qualifications to be successful in this role - 5+ years working in DevSecOps, Platform Engineering, or Software Supply Chain roles
- Hands on experience with Sonatype Nexus and IQ Server (or similar - jFrog Artifactory is fine too)
- Comfortable building and maintaining automated open source policy workflows
- Experience with artifact signing tools like Sigstore/Cosign, GPG, or Notary
- Familiarity with SLSA provenance and in toto attestations (or similar supply chain security frameworks)
- Know your way around SBOM generation tools - CycloneDX, SPDX, or Syft
- Solid CI/CD background, ideally with GitLab (GitHub Actions also welcome)
- Strong AWS chops - IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, CloudWatch
- Scripting ability in Python, Bash, or Go
- Exposure to OCI registries and package ecosystems like Maven, npm, PyPI, or NuGet
Educational Requirement:Bachelor's degree in Computer Science, Information Systems, or a related field.
Ref: #404-IT Pittsburgh