DevSecOps & Supply Chain Security Consultant
Role Summary
-
Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security.
-
The role covers secure SDLC, pipeline architecture and access, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependencies, secrets, SAST/DAST, containers, IaC, vulnerability governance and regulatory evidence.
-
The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions and remediation; produce audit-ready findings, release-readiness and residual-risk conclusions; and recommend finding-specific work. CRA, regulated-product and stakeholder-reporting experience is highly preferred.
Key Responsibilities
-
Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management to support lifecycle security evaluation and compliance traceability.
-
Review SDLC processes, tooling, and secure development practices
-
Assess software supply chain security, including SCA, SBOM accuracy/completeness, dependency governance, and third-party risk
-
Evaluate CI/CD pipeline security, artifact integrity, and secure release controls
-
Review secrets management across development, build, deployment, and operational environments
-
Assess logging, auditability, and security event traceability controls
-
Evaluate vulnerability management, remediation tracking, and patch governance processes
-
Support lifecycle security assessment, compliance evidence mapping, and traceability
-
Contribute to assessment reporting, remediation guidance, and release governance reviews
-
Validate source-to-release traceability, build provenance, tamper resistance, artifact signing and promotion controls, SBOM accuracy, security gates, exceptions, remediation decisions, release-readiness conclusions and residual-risk positions.
-
Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, stakeholder-ready executive communication and recommendations for finding-specific follow-up work.
-
Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls, infrastructure-as-code and pipeline-as-code security, policy-as-code implementation and automated security-gate effectiveness.
Required Skills & Experience
Mandatory:
-
Strong understanding of DevSecOps and secure software delivery practices
-
Experience with SBOM frameworks (CycloneDX, SPDX) and SCA tooling
-
Familiarity with CI/CD security controls and artifact integrity validation
-
Experience with vulnerability management and dependency governance programs
-
Understanding of lifecycle security, auditability, and compliance evidence requirements
-
Experience with secrets management and secure release governance
-
SBOM Analysis (CycloneDX, SPDX, VEX/CSAF)
-
Artifact Integrity
-
SAST, DAST, Dependency & Secrets Scanning
-
Vulnerability Management & Remediation Governance
-
Secrets Management
-
Compliance Evidence & Audit Traceability
-
CRA / Regulatory Security Assessments
-
Syft and related SBOM tools
-
Secure Release Governance & Security Controls Validation
-
Build provenance and software-delivery traceability
-
Artifact signing, verification and tamper testing
-
Container, registry, build-agent and CI/CD runner security
-
Infrastructure-as-Code and pipeline-as-code security
-
Signing-key, certificate and HSM lifecycle controls
-
SBOM generation and binary-to-SBOM reconciliation
-
Open-source and third-party dependency governance
-
EOL/EOS and patch-lifecycle governance
-
Security exception and release-risk governance
-
Pipeline policy-as-code and automated security gates
-
Vulnerability metrics and release-readiness reporting
-
NIST SSDF and secure software supply-chain practices
-
Supplier security and software-acquisition assessments
-
Tools such as Syft, Grype, Trivy, Gitleaks, Dependency-Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins and Azure DevOps
-
US Citizen or Green Card holder (US Person)
Good to have:
-
Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments
-
Experience participating in engagement related to export-controlled environments
-
Familiarity with SLSA or modern software supply chain security practices
-
Strong documentation skills
Preferred Certifications
-
CSSLP, Certified DevSecOps Professional or any other relevant product-security credentials
Years of Required Experience
-
10+ years in secure CI/CD pipeline setup, governance and controls validation, including setting up, maintaining and validating Secure CI/CD pipelines across different types of technology stacks.
-
2+ years of hands-on SBOM analysis experience.
oPM0jGmMGC