HEXAWARE

DevOps Track Sr.Engineer

United States · Posted today

Opens fa-etqo-saasfaprod1.fa.ocs.oraclecloud.com

Get a version of your resume written for this job.

Salary
Not listed
Job type
Not specified
Work mode
Not specified
Source
Oracle (employer's hiring system)

Skills mentioned

Supply Chain, CI/CD, DevOps, Python, Bash, AWS, GitHub Actions, GitLab

About the role

Role: DevSecOps Engineer

Location: Atlanta, GA

Hire Type: Direct Hire

Position Type: Full Time

Responsibilities

Lead the design and enablement of enterprise software supply chain initiatives to support secure software delivery. 

Enhance Sonatype Repository artifact management, IQ firewall policy governance, and open-source software lifecycle processes. 

Define and automate software approval workflows, quarantine waiver processes, and lifecycle management practices. 

Design and enable repository proxy strategies across supported software ecosystems. 

Drive dependency upgrade initiatives and vulnerability remediation workflows. 

Support the design and onboarding of emerging ecosystems, including AI/ML frameworks. 

Design and implement reporting and metrics capabilities to measure software supply chain health, policy compliance, and repository utilization. 

Design and enable CI/CD artifact signing and verification capabilities for software builds. 

Design and implement SLSA build provenance and attestation frameworks across CI/CD platforms. 

Integrate SBOM generation and software metadata into build and deployment pipelines. 

Collaborate closely with security and development teams to enhance software supply chain visibility, integrity, and compliance.

Required Technical Skills

Minimum 9+ years of experience in DevSecOps, Platform Engineering, or Software Supply Chain Engineering. 

Hands-on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository (or comparable tooling, e.g., jFrog). 

Proven experience creating and maintaining automated Open-Source Software Evaluation policies and workflows. 

Experience implementing artifact signing technologies such as Sigstore/Cosign, GPG, Notary, or similar solutions. 

Strong understanding of SLSA provenance, in-toto attestations, or comparable software supply chain security frameworks. 

Experience with SBOM generation tools and standards, including CycloneDX, SPDX, and Syft. 

CI/CD experience with GitLab preferred, or comparable platforms such as GitHub Actions. 

Strong AWS experience across IAM, ECS/EKS, EC2, S3, Lambda, Step Function, and CloudWatch. 

Experience integrating security tools and controls into CI/CD pipelines. 

Strong scripting and automation skills using Python, Bash, or Go. 

Experience designing, implementing, and maintaining enterprise Open-Source platforms. 

Familiarity with OCI registries and package ecosystems, including Maven, npm, PyPI, and NuGet. 

Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design initiatives.

Job ID or-fa-etqo-saasfaprod1-fa-ocs-oraclecloud-com-cx-1-689748 · Original posting ↗

Visa sponsorship history

  • 268 H-1B petitions approved for HEXAWARE TECHNOLOGIES INC in fiscal year 2023 (USCIS).

From public government data. It shows this employer has sponsored workers before, not that this job offers sponsorship: check the job ad or ask the employer. More visa-friendly jobs