
DevSecOps & Supply Chain Security Consultant - (Onsite - Boston, MA)
- DevSecOps
- CI/CD
- Secrets Management
- SAST
- DAST
- IaC
- Vulnerability Management
- Grype
- Trivy
- cosign
- Sigstore
- GitHub Actions
- GitLab CI
- Jenkins
- Azure DevOps
- CSSLP
DevSecOps & Supply Chain Security Consultant- (Onsite - Boston, MA)
We are looking to hire a candidate with the mentioned skill sets and experience for one of our clients,Â
Job Summary
We are seeking aDevSecOps & Supply Chain Security Consultant with10+ years of experience in secure software delivery, CI/CD, and software supply-chain security. The consultant will focus on secure SDLC, CI/CD pipeline architecture and security, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependency and secrets management, SAST/DAST, containers, IaC, vulnerability governance, and regulatory evidence.
The consultant will validatesource-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions, remediation, release readiness, and residual risk and will produce audit-ready findings and stakeholder-ready reporting.
Work Authorization: Must be aUS Citizen or Green Card holder (US Person).
Travel: Up tothree (3) weeks of travel to the client’sTewksbury, MA site during the engagement. Travel and accommodation expenses will be arranged and covered. Travel may be a single visit or split across multiple visits based on project requirements.
Key Responsibilities
- Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management.
- Review SDLC processes, security tooling, and secure development practices.
- Assess SCA, SBOM accuracy/completeness, dependency governance, and third-party risk.
- Evaluate CI/CD pipeline security, artifact integrity, secure release controls, and build provenance.
- Validate source-to-release traceability, artifact signing and promotion, tamper resistance, SBOM accuracy, security gates, exceptions, and remediation decisions.
- Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls.
- Evaluate Infrastructure-as-Code, pipeline-as-code, policy-as-code, and automated security-gate effectiveness.
- Review secrets management across development, build, deployment, and operational environments.
- Evaluate vulnerability management, remediation tracking, patch governance, EOL/EOS, and release-risk governance.
- Assess signing-key, certificate, and HSM lifecycle controls.
- Validate SBOM generation and binary-to-SBOM reconciliation.
- Support lifecycle security assessments, compliance evidence mapping, and audit traceability.
- Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, remediation guidance, and stakeholder-ready executive communication.
- Recommend finding-specific follow-up work and support release governance reviews.
Required Skills / Experience
- 10+ years of experience in secure CI/CD pipeline setup, governance, and controls validation across different technology stacks.
- 2+ years of hands-on SBOM analysis experience.
- Strong understanding ofDevSecOps and secure software delivery practices.
- Strong experience withSBOM frameworks: CycloneDX, SPDX, VEX/CSAF.
- Experience withSCA, SAST, DAST, dependency scanning, and secrets scanning.
- Experience withartifact integrity, artifact signing, verification, tamper testing, and build provenance.
- Strong knowledge ofCI/CD security, secure release governance, and automated security gates.
- Experience withvulnerability management, remediation governance, dependency governance, and patch lifecycle management.
- Experience withsecrets management and secure release controls.
- Knowledge ofcontainer, registry, build-agent, and CI/CD runner security.
- Experience withInfrastructure-as-Code and pipeline-as-code security.
- Knowledge ofpolicy-as-code and security controls validation.
- Experience withcompliance evidence, audit traceability, and regulatory security assessments.
- Knowledge ofNIST SSDF and secure software supply-chain practices.
- Experience withsupplier security and software-acquisition assessments.
- Hands-on experience with tools such asSyft, Grype, Trivy, Gitleaks, Dependency-Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins, and Azure DevOps.
- Experience withCRA / regulatory security assessments is highly preferred.
- Familiarity withSLSA or modern software supply-chain security practices is a plus.
- Experience withregulated products, export-controlled environments, or compliance-driven cybersecurity assessments is preferred.
- Strong documentation and stakeholder communication skills.
- Candidate needs to be US Citizen or Green Card holder.Â
Preferred Certifications
- CSSLP
- Certified DevSecOps Professional
- Other relevant product-security credentials.
Location & Travel
- Location: Boston, MA
- On-site: Ability to work from the Boston office for4–6 weeks during the engagement.
- Travel: Up to3 weeks at the client’s Tewksbury, MA site during the engagement. Travel and accommodation expenses will be covered.Â
Other Job Details:
- Job Type:Â C2C or W2.
- Location:Â Â Boston, MA, USA.
- Interviews:Â Video interviews.
- Docs required:Â ID proof will be required.
DevSecOps & Supply Chain Security Consultant - (Onsite - Boston, MA) · OMG Technology