Senior DevSecOps Engineer(Socket.dev and Chainguard)
REMOTE
6 months
Position Overview
Our client is seeking a Senior DevSecOps Engineer to lead the implementation and adoption of software supply chain security solutions, including and Chainguard. This individual will work closely with application development, platform engineering, cloud operations, and security teams to improve the security posture of the software development lifecycle and container ecosystem.
The ideal candidate will have experience implementing software composition analysis (SCA), dependency security tools, container security platforms, and DevSecOps best practices within enterprise environments. The role will focus on integrating security controls into CI/CD pipelines, securing open-source dependencies, reducing container vulnerabilities, and establishing software supply chain governance.
Key Responsibilities
- Lead deployment and operationalization of across enterprise development environments.
- Implement software dependency security controls and risk management processes.
- Establish governance for open-source software consumption and dependency management.
- Partner with development teams to identify and remediate supply chain risks.
- Support implementation of Software Bill of Materials (SBOM) strategies.
Chainguard Implementation
- Deploy and integrate Chainguard images and related security capabilities into containerized environments.
- Assist with enterprise adoption of secure-by-default container images.
- Support migration from legacy container images to hardened Chainguard images.
- Develop standards and best practices for container image security.
- Establish image governance, lifecycle management, and vulnerability remediation processes.
DevSecOps & CI/CD Integration
- Integrate and Chainguard into CI/CD pipelines and developer workflows.
- Implement automated security checks throughout the software development lifecycle.
- Collaborate with platform engineering teams to improve security automation.
- Enhance release pipelines through automated policy enforcement and compliance controls.
- Support secure software delivery initiatives.
Cloud & Container Security
- Secure Kubernetes and container-based environments.
- Assist with container security architecture and operational best practices.
- Implement image scanning, signing, and provenance validation processes.
- Work with engineering teams to improve cloud-native security controls.
Collaboration & Enablement
- Work closely with application development teams to drive tool adoption.
- Provide technical guidance and knowledge transfer to developers and platform teams.
- Develop documentation, implementation standards, and operational runbooks.
- Support security assessments and compliance initiatives related to software supply chain security.
Required Qualifications
- 5+ years of experience in DevOps, DevSecOps, Application Security, or Cloud Security.
- Experience implementing software supply chain security controls.
- Strong understanding of CI/CD pipelines and secure development practices.
- Experience with GitHub, GitLab, Azure DevOps, or similar platforms.
- Experience working with containerized environments.
- Knowledge of open-source dependency management and vulnerability remediation.
- Strong troubleshooting and communication skills.
Qualifications
- Experience deploying or supporting .
- Experience deploying or supporting Chainguard.
- Kubernetes and container platform experience.
- Experience with:
- GitHub Advanced Security
- Sonatype
- JFrog
- Aqua Security
- Prisma Cloud
- Snyk
- Azure DevOps
- GitLab CI/CD
- GitHub Actions
- OpenShift
- Kubernetes
- Docker
- Experience with:
- Secure SDLC practices
- Software Composition Analysis (SCA)
- Sigstore/Cosign
- Container image signing
- SBOMs
Thanks,
Vinod.