Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security.
The role covers secure SDLC, pipeline architecture and access, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependencies, secrets, SAST/DAST, containers, IaC, vulnerability governance and regulatory evidence.
The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions and remediation; produce audit-ready findings, release-readiness and residual-risk conclusions; and recommend finding-specific work. CRA, regulated-product and stakeholder-reporting experience is highly preferred.
Key Responsibilities
Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management to support lifecycle security evaluation and compliance traceability.
Review SDLC processes, tooling, and secure development practices
Assess software supply chain security, including SCA, SBOM accuracy/completeness, dependency governance, and third-party risk
Evaluate CI/CD pipeline security, artifact integrity, and secure release controls
Review secrets management across development, build, deployment, and operational environments
Assess logging, auditability, and security event traceability controls
Evaluate vulnerability management, remediation tracking, and patch governance processes
Support lifecycle security assessment, compliance evidence mapping, and traceability
Contribute to assessment reporting, remediation guidance, and release governance reviews
Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, stakeholder-ready executive communication and recommendations for finding-specific follow-up work.
Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls, infrastructure-as-code and pipeline-as-code security, policy-as-code implementation and automated security-gate effectiveness.
Required Skills & Experience
Mandatory:
Strong understanding of DevSecOps and secure software delivery practices
Experience with SBOM frameworks (CycloneDX, SPDX) and SCA tooling
Familiarity with CI/CD security controls and artifact integrity validation
Experience with vulnerability management and dependency governance programs
Understanding of lifecycle security, auditability, and compliance evidence requirements
Experience with secrets management and secure release governance
Build provenance and software-delivery traceability
Artifact signing, verification and tamper testing
Container, registry, build-agent and CI/CD runner security
Infrastructure-as-Code and pipeline-as-code security
Signing-key, certificate and HSM lifecycle controls
SBOM generation and binary-to-SBOM reconciliation
Open-source and third-party dependency governance
EOL/EOS and patch-lifecycle governance
Security exception and release-risk governance
Pipeline policy-as-code and automated security gates
Vulnerability metrics and release-readiness reporting
NIST SSDF and secure software supply-chain practices
Supplier security and software-acquisition assessments
Tools such as Syft, Grype, Trivy, Gitleaks, Dependency-Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins and Azure DevOps
US Citizen or Green Card holder (US Person)
Good to have:
Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments
Experience participating in engagement related to export-controlled environments
Familiarity with SLSA or modern software supply chain security practices
Strong documentation skills
Preferred Certifications
CSSLP, Certified DevSecOps Professional or any other relevant product-security credentials
Years of Required Experience
10+ years in secure CI/CD pipeline setup, governance and controls validation, including setting up, maintaining and validating Secure CI/CD pipelines across different types of technology stacks.
2+ years of hands-on SBOM analysis experience.
Powered by JazzHR
Numbers & Facts
Location
Tewksbury, MA
Skills
Analysis Skillsunmatched
Architectural Analysisunmatched
Computer Securityunmatched
Consultingunmatched
Continuous Deployment/Deliveryunmatched
Continuous Integrationunmatched
DevOpsunmatched
GitHubunmatched
Internet Securityunmatched
Jenkinsunmatched
Machine Toolunmatched
Maintain Complianceunmatched
Metricsunmatched
Microsoft Windows Azureunmatched
Open Sourceunmatched
OpenSSLunmatched
Reconciliationunmatched
Regulationsunmatched
Regulatory Complianceunmatched
Reporting Skillsunmatched
Riskunmatched
Security Analysisunmatched
Security Consultingunmatched
Security Policyunmatched
Security Softwareunmatched
Software Development Lifecycle (SDLC)unmatched
Software Patchesunmatched
Supply Chainunmatched
Testingunmatched
Traceabilityunmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
United States Citizenunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.