Please Accept our Privacy Policy
Job Title: DevSecOps Engineer Duration: Full Time / Permanent Position Location: Lafayette, LA, Knoxville, TN, Birmingham, AL Work Mode: 5 Days Onsite
Systemone is seeking a DevSecOps Engineer to strengthen our software supply chain security program within a large scale, AWS based financial services environment. In this role, you will help secure the software delivery lifecycle from open source governance to CI/CD artifact integrity ensuring that software built and deployed across the organization meets rigorous compliance and security standards.
You'll work hands on with tools like Sonatype Nexus/IQ Server, implement artifact signing and provenance frameworks (SLSA, Sigstore/Cosign), and build automation that supports vulnerability remediation, SBOM generation, and open source policy enforcement. This is a great opportunity for someone who enjoys solving real security problems at scale, working across CI/CD pipelines, cloud infrastructure, and emerging technology ecosystems (including AI/ML tooling).
Your future duties and responsibilities
Support secure software delivery through enterprise supply chain initiatives
Manage and enhance artifact repository tooling and open source policy governance
Build and maintain software approval, quarantine, and lifecycle workflows
Drive dependency upgrades and vulnerability remediation efforts
Onboard new/emerging technology ecosystems (including AI/ML frameworks)
Create dashboards and metrics for supply chain health and compliance
Implement CI/CD artifact signing, build provenance (SLSA), and SBOM integration
Required qualifications to be successful in this role
5+ years working in DevSecOps, Platform Engineering, or Software Supply Chain roles
Hands on experience with Sonatype Nexus and IQ Server (or similar jFrog Artifactory is fine too)
Comfortable building and maintaining automated open source policy workflows
Experience with artifact signing tools like Sigstore/Cosign, GPG, or Notary
Familiarity with SLSA provenance and in toto attestations (or similar supply chain security frameworks)
Know your way around SBOM generation tools CycloneDX, SPDX, or Syft
Solid CI/CD background, ideally with GitLab (GitHub Actions also welcome)
Strong AWS chops IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, CloudWatch
Scripting ability in Python, Bash, or Go
Exposure to OCI registries and package ecosystems like Maven, npm, PyPI, or NuGet
Educational Requirement:
Bachelor's degree in Computer Science, Information Systems, or a related field.
Ref: #404-IT Pittsburgh