Senior DevSecOps Engineer - Knoxville, TN

System One Holdings, LLC

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in DevSecOps, Platform Engineering, or Software Supply Chain Engineering.
  • Hands-on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository, or similar tools like jFrog.
  • Experience building and maintaining automated Open Source Software evaluation policies and workflows.
  • Familiarity with artifact signing technologies such as Sigstore/Cosign, GPG, or Notary.
  • Experience with SLSA provenance, in toto attestations, or similar frameworks.
  • Background generating SBOMs using CycloneDX, SPDX, or Syft.
  • Strong AWS skills across IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch.

Responsibilities

  • Enhance artifact management, policy governance, and open source lifecycle processes using tools like Sonatype and Nexus Repository.
  • Build and automate software approval workflows, quarantine/waiver processes, and repository proxy strategies across supported ecosystems.
  • Drive dependency upgrades and vulnerability remediation efforts.
  • Support onboarding of emerging ecosystems including AI/ML frameworks.
  • Build reporting and metrics to track software supply chain health, policy compliance, and repository utilization.
  • Enable CI/CD artifact signing and verification.
  • Implement SLSA build provenance and attestations.

Benefits

  • Hybrid work model offering flexibility.
  • Opportunity to work with cutting-edge technologies in AI/ML.
  • Engagement with security and development teams to enhance software supply chain integrity.
  • Direct hire position providing job stability.
Full Job Description
Job Title: Senior DevSecOps Engineer
Locations: Lafayette, LA | Knoxville, TN | Birmingham, AL | Columbia, SC
Type: Direct Hire

Work Model: Hybrid
Hours: 40.0

Responsibilities

  • Enhance artifact management, policy governance, and open source lifecycle processes using tools like Sonatype and Nexus Repository.
  • Build and automate software approval workflows, quarantine/waiver processes, and repository proxy strategies across supported ecosystems.
  • Drive dependency upgrades and vulnerability remediation efforts.
  • Support onboarding of emerging ecosystems including AI/ML frameworks.
  • Build reporting and metrics to track software supply chain health, policy compliance, and repository utilization.
  • Enable CI/CD artifact signing and verification.
  • Implement SLSA build provenance and attestations.
  • Integrate SBOM generation into build and deployment pipelines.
  • Work closely with security and development teams to improve software supply chain visibility and integrity.

Requirements
  • 5+ years in DevSecOps, Platform Engineering, or Software Supply Chain Engineering.
  • Hands on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository, or similar tools like jFrog.
  • Experience building and maintaining automated Open Source Software evaluation policies and workflows.
  • Familiarity with artifact signing technologies such as Sigstore/Cosign, GPG, or Notary.
  • Experience with SLSA provenance, in toto attestations, or similar frameworks.
  • Background generating SBOMs using CycloneDX, SPDX, or Syft.
  • CI/CD experience, ideally with GitLab (GitHub Actions also welcome).
  • Strong AWS skills across IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch.
  • Experience integrating security tooling directly into CI/CD pipelines.
  • Solid scripting ability in Python, Bash, or Go.
  • Experience maintaining enterprise open source platforms.
  • Familiarity with OCI registries and package ecosystems (Maven, npm, PyPI, NuGet).
  • Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design principles.
  • Educational Requirement: Bachelor's degree in Computer Science, Information Systems, or a related field.

Similar Jobs

More Jobs at System One Holdings, LLC

More Information Technology Jobs

Find similar Senior DevSecOps Engineer - Knoxville, TN jobs: