DevSecOps Platform Engineer/ SBOM/CBOM Security Automation

Irving, TX, US • Posted 6 hours ago • Updated 6 hours ago
Contract W2
12 Months
No Travel Required
On-site
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🫥 Flibbertigibetting...

Job Details

Skills

  • DevSecOps.

Summary

Role: DevSecOps Platform Engineer/ SBOM/CBOM Security Automation

Location: Location: Irving, TX

Duration: Long term

Mode of Interview: F2F

only on W2

 

 

  • SBOM / CBOM Inventory, Vulnerability Scanning & AI Auto-Remediation
  • We are looking for a hands-on Senior Full Stack + DevSecOps Platform Engineer to help build an internal security automation platform for SBOM/CBOM inventory, vulnerability scanning, and Claude-based auto-remediation.
  • This is not a traditional full-stack developer role. The right candidate should be able to build applications, design CI/CD pipelines, integrate security scanning tools, understand cryptography inventory, and automate remediation safely.

Key Responsibilities

                 Design and build a centralized platform for SBOM and CBOM inventory.

                 Scan applications, repositories, containers, dependencies, certificates, keys, crypto algorithms, TLS configurations, and runtime components.

                 Integrate SBOM/CBOM and vulnerability scanning into Jenkins/GitLab CI/CD pipelines.

                 Identify vulnerable dependencies, CVEs, weak cryptography, expired certificates, insecure TLS versions, hardcoded secrets, and non-compliant libraries.

                 Build automation workflows to support remediation using Claude or similar AI coding agents.

                 Automate safe fixes such as dependency upgrades, base image updates, configuration changes, and pull request creation.

                 Ensure all AI-assisted remediations are validated through build, test, scan, approval, and audit workflows before merge or deployment.

                 Build dashboards and reports for application inventory, vulnerability posture, crypto posture, remediation status, and SLA tracking.

                 Work closely with application, security, DevOps, and platform teams.

Required Skills

                 Strong hands-on experience with Java/Spring Boot.

                 Experience with at least one additional language such as Node.js, Python, or Go.

                 Experience building REST APIs, microservices, batch jobs, and platform integrations.

                 Hands-on experience with Jenkins and/or GitLab CI/CD.

                 Strong understanding of SBOM, dependency scanning, transitive dependencies, CVEs, and container image scanning.

                 Experience with tools such as Syft, Grype, CycloneDX, SPDX, JFrog Xray, Sonatype, Fortify, or Veracode.

                 Good understanding of CBOM and cryptography inventory, including TLS/HTTPS, certificates, keys, cipher suites, encryption algorithms, hashing algorithms, signing algorithms, keystores, truststores, and secrets.

                 Ability to identify weak crypto such as MD5, SHA-1, DES/3DES, RC4, RSA-1024, TLS 1.0/TLS 1.1, and disabled certificate validation.

                 Hands-on AWS experience with services such as Lambda, API Gateway, S3, DynamoDB, IAM, ECS/EKS, CloudWatch, X-Ray, Secrets Manager, and KMS.

                 Experience with observability tools such as Splunk, ELK/Kibana, CloudWatch, and X-Ray.

                 Strong troubleshooting skills across application, pipeline, cloud, and security issues.

                 The candidate should understand how to use Claude or similar AI tools in a controlled engineering workflow

 

Preferred Skills

                 Experience building internal developer platforms or security automation platforms.

                 Experience with vulnerability management and remediation workflows.

                 Experience with policy engines such as OPA or custom rule engines.

                 Knowledge of post-quantum cryptography readiness and crypto-agility.

                 Experience with certificate lifecycle management, secrets management, and cloud security controls.

                 Frontend experience with Angular or React for dashboards and reporting.

Minimum Qualifications

                 8+ years of software engineering experience.

                 3+ years of DevOps, DevSecOps, platform engineering, or security automation experience.

                 Strong Java/Spring Boot background.

                 Hands-on CI/CD and cloud experience.

                 Practical experience with security scanning and vulnerability remediation.

                 Strong communication skills and ability to work across security, platform, DevOps, and application teams.

Ideal Candidate

                 The ideal candidate can code, build pipelines, integrate scanners, understand SBOM/CBOM findings, troubleshoot AWS and production issues, and design safe AI-assisted remediation workflows

 

Email:

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91172920
  • Position Id: 8980628
  • Posted 6 hours ago

Company Info

About 3BEES TECHNOLOGIES INC


Trusted Software Development Company
We transform your business with powerful and customizable digital solutions that meet today's needs and open up opportunities for tomorrow. As India's leading software development outsourcing company, we help your company reach new heights and grow rapidly to maximize profits. We have a team of qualified and experienced IT professionals who can provide the best software solutions for different companies in different industries.

Over the years, we have partnered with thousands of brands, ensuring the success of our brand-oriented software development services. We place emphasis on creating business value for our clients through new ideas along with fast implementation.

Contact the job poster
KP

Karthik Padishala

Recruiter @ 3BEES TECHNOLOGIES INC
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Plano, Texas

21d ago

Easy Apply

Contract

Depends on Experience

Lake Mary, Florida

11d ago

Easy Apply

Contract

Depends on Experience

Search all similar jobs