DevSecOps & Supply Chain Security Consultant - (Onsite - Boston, MA)

Boston, MA, US • Posted 1 day ago • Updated 1 day ago
Contract W2
6 Months
50% Travel Required
On-site
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Supply Chain Management
  • Software Development Methodology
  • Continuous Delivery
  • Employment Authorization
  • Management
  • Mapping
  • Mergers and Acquisitions
  • DevSecOps
  • Auditing
  • Cyber Security
  • DevOps
  • Lifecycle Management
  • OpenSSL
  • Microsoft Azure
  • Regulatory Compliance
  • Jenkins
  • Reporting
  • Testing

Summary

DevSecOps & Supply Chain Security Consultant - (Onsite - Boston, MA)

We are looking to hire a candidate with the mentioned skill sets and experience for one of our clients, 

Job Summary

We are seeking a DevSecOps & Supply Chain Security Consultant with 10+ years of experience in secure software delivery, CI/CD, and software supply-chain security. The consultant will focus on secure SDLC, CI/CD pipeline architecture and security, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependency and secrets management, SAST/DAST, containers, IaC, vulnerability governance, and regulatory evidence.

The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions, remediation, release readiness, and residual risk and will produce audit-ready findings and stakeholder-ready reporting.

Travel: Up to three (3) weeks of travel to the client’s Tewksbury, MA site during the engagement. Travel and accommodation expenses will be arranged and covered. Travel may be a single visit or split across multiple visits based on project requirements.

Key Responsibilities

  • Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management.
  • Review SDLC processes, security tooling, and secure development practices.
  • Assess SCA, SBOM accuracy/completeness, dependency governance, and third-party risk.
  • Evaluate CI/CD pipeline security, artifact integrity, secure release controls, and build provenance.
  • Validate source-to-release traceability, artifact signing and promotion, tamper resistance, SBOM accuracy, security gates, exceptions, and remediation decisions.
  • Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls.
  • Evaluate Infrastructure-as-Code, pipeline-as-code, policy-as-code, and automated security-gate effectiveness.
  • Review secrets management across development, build, deployment, and operational environments.
  • Evaluate vulnerability management, remediation tracking, patch governance, EOL/EOS, and release-risk governance.
  • Assess signing-key, certificate, and HSM lifecycle controls.
  • Validate SBOM generation and binary-to-SBOM reconciliation.
  • Support lifecycle security assessments, compliance evidence mapping, and audit traceability.
  • Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, remediation guidance, and stakeholder-ready executive communication.
  • Recommend finding-specific follow-up work and support release governance reviews.

Required Skills / Experience

  • 10+ years of experience in secure CI/CD pipeline setup, governance, and controls validation across different technology stacks.
  • 2+ years of hands-on SBOM analysis experience.
  • Strong understanding of DevSecOps and secure software delivery practices.
  • Strong experience with SBOM frameworks: CycloneDX, SPDX, VEX/CSAF.
  • Experience with SCA, SAST, DAST, dependency scanning, and secrets scanning.
  • Experience with artifact integrity, artifact signing, verification, tamper testing, and build provenance.
  • Strong knowledge of CI/CD security, secure release governance, and automated security gates.
  • Experience with vulnerability management, remediation governance, dependency governance, and patch lifecycle management.
  • Experience with secrets management and secure release controls.
  • Knowledge of container, registry, build-agent, and CI/CD runner security.
  • Experience with Infrastructure-as-Code and pipeline-as-code security.
  • Knowledge of policy-as-code and security controls validation.
  • Experience with compliance evidence, audit traceability, and regulatory security assessments.
  • Knowledge of NIST SSDF and secure software supply-chain practices.
  • Experience with supplier security and software-acquisition assessments.
  • Hands-on experience with tools such as Syft, Grype, Trivy, Gitleaks, Dependency-Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins, and Azure DevOps.
  • Experience with CRA / regulatory security assessments is highly preferred.
  • Familiarity with SLSA or modern software supply-chain security practices is a plus.
  • Experience with regulated products, export-controlled environments, or compliance-driven cybersecurity assessments is preferred.
  • Strong documentation and stakeholder communication skills.
  • Candidate needs to be . 

Preferred Certifications

  • CSSLP
  • Certified DevSecOps Professional
  • Other relevant product-security credentials.

Location & Travel

  • Location: Boston, MA
  • On-site: Ability to work from the Boston office for 4–6 weeks during the engagement.
  • Travel: Up to 3 weeks at the client’s Tewksbury, MA site during the engagement. Travel and accommodation expenses will be covered. 

Other Job Details:

  • Job Type: C2C or W2.
  • Location:  Boston, MA, USA.
  • Interviews: Video interviews.
  • Docs required: ID proof will be required.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91093052
  • Position Id: 9079757
  • Posted 1 day ago

Company Info

About OMG Technologies

From our humble beginnings as a small IT service provider in 2006, OMG Technologies has grown to become a reliable provider of management and IT consulting services, while still maintaining agility of a small company. With multiple clients in various industries, OMG Technologies continues to grow at a good, steady and consistent pace based on our client focused approach.

Whatever it Takes to deliver value is our CORE approach

Contact the job poster
Sudhasini Swaminathan

Sudhasini Swaminathan

Talent Acquisition Specialist @ OMG Technologies
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs