DevSecOps Engineer

Reston, VA, US • Posted 1 day ago • Updated 1 day ago
Full Time
No Travel Required
On-site
120000 - 130000/yr
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • DevSecOps
  • Platform Engineering
  • Nexus Repository
  • GitLab
  • Scripting

Summary

DevSecOps Engineer

Introduction

This position involves leading the design and enablement of enterprise software supply chain initiatives to support secure software delivery. The DevSecOps Engineer will be responsible for enhancing artifact management, firewall policy governance, and open-source software lifecycle. They will also automate software approval workflows, quarantine waiver processes, and repository utilization.

Responsibilities

Lead design and enablement of enterprise software supply chain initiatives, supporting secure software delivery.
Enhance Sonatype Repository artifact management, IQ firewall policy governance, and open-source software lifecycle.
Define and automate software approval workflows, quarantine waiver, and lifecycle management processes.
Design and enable repository proxy strategies for supported software ecosystems.
Drive dependency upgrades and vulnerability remediation workflows.
Support design and onboarding of emerging ecosystems, including AI/ML frameworks.
Design and enable reporting and metrics for software supply chain health, policy compliance, and repository utilization.
Design and enable CI/CD artifact signing and verification capabilities for software builds.
Design and implement SLSA build provenance and attestations across CI/CD platforms.
Integrate SBOM generation and software metadata into build and deployment pipelines.
Collaborate with security and development teams to improve software supply chain visibility and integrity.

Required Technical Skills

9+ years of DevSecOps, Platform Engineering, or Software Supply Chain Engineering experience.
Hands-on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository (or comparable tooling, e.g., jFrog)
Experience creating and maintaining automated Open Source Software Evaluation policies and workflows.
Experience implementing artifact signing technologies (Sigstore/Cosign, GPG, Notary, etc.).
Experience with SLSA provenance, in-toto attestations, or similar frameworks.
Experience with SBOM generation (CycloneDX, SPDX, Syft).
CI/CD experience with GitLab preferred (or comparable tooling, e.g. GitHub Actions)
Strong AWS experience (IAM, ECS/EKS, EC2, S3, Lambda, Step Function, CloudWatch).
Experience integrating security tooling into CI/CD pipelines.
Strong scripting skills (Python, Bash, or Go).
Experience designing and maintaining enterprise Open Source platforms.
Familiarity with OCI registries and package ecosystems (Maven, npm, PyPI, NuGet).
Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design initiatives.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: hexaware
  • Position Id: FMEGS0924
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Ashburn, Virginia

•

Today

Full-time

Arlington, Virginia

•

Today

Full-time

USD 155,000.00 - 185,000.00 per year

Reston, Virginia

•

Today

Easy Apply

Full-time

Hybrid in Washington, District of Columbia

•

2d ago

Easy Apply

Full-time

120,000 - 140,000

Search all similar jobs