Senior DevSecOps Engineer *

CGI

• $89K — $139K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in DevSecOps, Platform Engineering, or Software Supply Chain Engineering
  • Hands-on experience with Sonatype Lifecycle and Nexus Repository
  • Experience with automated Open Source Software evaluation workflows
  • Familiarity with artifact signing technologies
  • Experience with SLSA provenance or similar frameworks
  • Background generating SBOMs using relevant standards
  • CI/CD experience, preferably with GitLab or GitHub Actions
  • Strong AWS skills across multiple services
  • Solid scripting ability in Python, Bash, or Go

Responsibilities

  • Enhance artifact management and policy governance processes
  • Build and automate software approval workflows
  • Drive dependency upgrades and vulnerability remediation efforts
  • Support onboarding of emerging AI/ML ecosystems
  • Build reporting and metrics for software supply chain health
  • Enable CI/CD artifact signing and verification
  • Integrate SBOM generation into build and deployment pipelines

Benefits

  • Competitive compensation
  • Comprehensive insurance options
  • 401(k) plan with matching contributions
  • Paid time off and parental leave
  • Learning opportunities and tuition assistance
  • Wellness and well-being programs
Full Job Description
Find similar career opportunities

Senior DevSecOps Engineer *

Category: Software Development/ Engineering

Main location: United States, Louisiana, Lafayette

Position ID:J0926-1443

Employment Type: Full Time

Position Description:

CGI is seeking a Supply Chain Engineer to lead and enable enterprise initiatives that strengthen secure software delivery.

This position is required in one of the following locations: Lafayette, LA, Knoxville, TN, Birmingham, AL

Your future duties and responsibilities:

In this role, you'll enhance artifact management, policy governance, and open source lifecycle processes using tools like Sonatype and Nexus Repository. You'll build and automate software approval workflows, quarantine/waiver processes, and repository proxy strategies across supported ecosystems.

You'll drive dependency upgrades and vulnerability remediation efforts, support onboarding of emerging ecosystems including AI/ML frameworks, and build reporting and metrics to track software supply chain health, policy compliance, and repository utilization. This role also involves enabling CI/CD artifact signing and verification, implementing SLSA build provenance and attestations, and integrating SBOM generation into build and deployment pipelines.

You'll work closely with security and development teams to improve software supply chain visibility and integrity across the organization. This is a great opportunity for someone passionate about DevSecOps and building secure, trustworthy software delivery pipelines at scale.

Required qualifications to be successful in this role:

. 5+ years in DevSecOps, Platform Engineering, or Software Supply Chain Engineering
. Hands on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository, or similar tools like jFrog
. Experience building and maintaining automated Open Source Software evaluation policies and workflows
. Familiarity with artifact signing technologies such as Sigstore/Cosign, GPG, or Notary
. Experience with SLSA provenance, in toto attestations, or similar frameworks
. Background generating SBOMs using CycloneDX, SPDX, or Syft
. CI/CD experience, ideally with GitLab (GitHub Actions also welcome)
. Strong AWS skills across IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch
. Experience integrating security tooling directly into CI/CD pipelines
. Solid scripting ability in Python, Bash, or Go
. Experience maintaining enterprise open source platforms
. Familiarity with OCI registries and package ecosystems (Maven, npm, PyPI, NuGet)
. Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design principles

Educational Requirement:
Bachelor's degree in Computer Science, Information Systems, or a related field.

Other Information:
CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set, level, experience, relevant training, and licensure and certifications. To support the ability to reward for merit based performance, CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $89,600.00 $139,300.00.
CGI's benefits are offered to eligible professionals on their first day of employment to include: . Competitive compensation . Comprehensive insurance options . Matching contributions through the 401(k) plan and the share purchase plan . Paid time off for vacation, holidays, and sick time . Paid parental leave .Learning opportunities and tuition assistance . Wellness and Well being programs

Skills:
  • Amazon Web Services Cloud
  • DevOps Security
  • GitLab
  • Python
  • BASH


Similar Jobs

More Jobs at CGI

More Information Technology Jobs

Find similar Senior DevSecOps Engineer * jobs: