Senior DevSecOps Engineer

System One Holdings, LLC

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in DevSecOps, Platform Engineering, or Software Supply Chain Engineering
  • Hands-on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository, or similar tools
  • Experience building and maintaining automated Open Source Software evaluation policies and workflows
  • Familiarity with artifact signing technologies such as Sigstore/Cosign, GPG, or Notary
  • Experience with SLSA provenance or similar frameworks
  • Background generating SBOMs using CycloneDX, SPDX, or Syft
  • Strong AWS skills across various services
  • Experience integrating security tooling directly into CI/CD pipelines
  • Solid scripting ability in Python, Bash, or Go
  • Experience maintaining enterprise open source platforms
  • Familiarity with OCI registries and package ecosystems
  • Knowledge of NIST SSDF and Secure by Design principles

Responsibilities

  • Enhance artifact management, policy governance, and open source lifecycle processes
  • Build and automate software approval workflows and quarantine/waiver processes
  • Drive dependency upgrades and vulnerability remediation efforts
  • Support onboarding of emerging ecosystems like AI/ML frameworks
  • Build reporting and metrics for software supply chain health and policy compliance
  • Enable CI/CD artifact signing and verification
  • Improve software supply chain visibility and integrity across the organization

Benefits

  • Full-time permanent position
  • Onsite work mode, promoting collaboration and team cohesion
  • Opportunity to work with cutting-edge tools and technologies in the DevSecOps space
  • Engage in a role that merges security with development for impactful outcomes
  • Contribute to a secure, trustworthy software delivery pipeline at scale
Full Job Description
Job Title: Senior DevSecOps Engineer
Duration: Full Time / Permanent Position
Location:
Lafayette, LA, Knoxville, TN, Birmingham, AL
Work Mode: 5 Days Onsite

Your future duties and responsibilities
In this role, you'll enhance artifact management, policy governance, and open source lifecycle processes using tools like Sonatype and Nexus Repository. You'll build and automate software approval workflows, quarantine/waiver processes, and repository proxy strategies across supported ecosystems.

You'll drive dependency upgrades and vulnerability remediation efforts, support onboarding of emerging ecosystems including AI/ML frameworks, and build reporting and metrics to track software supply chain health, policy compliance, and repository utilization. This role also involves enabling CI/CD artifact signing and verification, implementing SLSA build provenance and attestations, and integrating SBOM generation into build and deployment pipelines.

You'll work closely with security and development teams to improve software supply chain visibility and integrity across the organization. This is a great opportunity for someone passionate about DevSecOps and building secure, trustworthy software delivery pipelines at scale.

Required qualifications to be successful in this role

  • 5+ years in DevSecOps, Platform Engineering, or Software Supply Chain Engineering
  • Hands on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository, or similar tools like jFrog
  • Experience building and maintaining automated Open Source Software evaluation policies and workflows
  • Familiarity with artifact signing technologies such as Sigstore/Cosign, GPG, or Notary
  • Experience with SLSA provenance, in toto attestations, or similar frameworks
  • Background generating SBOMs using CycloneDX, SPDX, or Syft
  • CI/CD experience, ideally with GitLab (GitHub Actions also welcome)
  • Strong AWS skills across IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch
  • Experience integrating security tooling directly into CI/CD pipelines
  • Solid scripting ability in Python, Bash, or Go
  • Experience maintaining enterprise open source platforms
  • Familiarity with OCI registries and package ecosystems (Maven, npm, PyPI, NuGet)
  • Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design principles


Educational Requirement:
Bachelor's degree in Computer Science, Information Systems, or a related field.?

Ref: #404-IT Pittsburgh

Similar Jobs

More Jobs at System One Holdings, LLC

  • Senior Budget Analyst
    $110K — $130K *
    Fort George G Meade, MD 20755 (Anne Arundel County)
    Aerospace & Defense
    In-Person
  • Senior DevSecOps Engineer
    $110K — $130K *
    Lafayette, LA 70506 (Lafayette County)
    Information Technology
    In-Person
  • Site Contracts Administrator
    $80K — $95K *
    Shreveport, LA 71106 (Caddo County)
    Real Estate & Construction
    In-Person
  • Senior CyberArk PAM Engineer
    $110K — $130K *
    Columbia, SC 29223 (Richland County)
    Enterprise Technology
    In-Person
  • BIM Manager
    $110K — $130K *
    Sugar Land, TX 77479 (Fort Bend County)
    Real Estate & Construction
    In-Person

More Information Technology Jobs

Find similar Senior DevSecOps Engineer jobs: