×
Register Here to Apply for Jobs or Post Jobs. X

DevSecOps & Supply Chain Security Consultant Onsite - Boston, MA)

Job in Boston, Suffolk County, Massachusetts, 02298, USA
Listing for: OMG Technology
Full Time position
Listed on 2026-09-12
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 140000 - 190000 USD Yearly USD 140000.00 190000.00 YEAR
Job Description & How to Apply Below

Dev Sec Ops  & Supply Chain Security Consultant - (Onsite - Boston, MA)

We are looking to hire a candidate with the mentioned skill sets and experience for one of our clients,

Job Summary

We are seeking a Dev Sec Ops  & Supply Chain Security Consultant with 10+ years of experience in secure software delivery, CI/CD, and software supply-chain security. The consultant will focus on secure SDLC, CI/CD pipeline architecture and security, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependency and secrets management, SAST/DAST, containers, IaC, vulnerability governance, and regulatory evidence.

The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions, remediation, release readiness, and residual risk and will produce audit-ready findings and stakeholder-ready reporting.

Work Authorization

Must be a US Citizen or Green Card holder (US Person).

Travel

Up to three (3) weeks of travel to the client’s Tewksbury, MA site during the engagement. Travel and accommodation expenses will be arranged and covered. Travel may be a single visit or split across multiple visits based on project requirements.

Key Responsibilities
  • Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management.
  • Review SDLC processes, security tooling, and secure development practices.
  • Assess SCA, SBOM accuracy/completeness, dependency governance, and third-party risk.
  • Evaluate CI/CD pipeline security, artifact integrity, secure release controls, and build provenance.
  • Validate source-to-release traceability, artifact signing and promotion, tamper resistance, SBOM accuracy, security gates, exceptions, and remediation decisions.
  • Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls.
  • Evaluate Infrastructure-as-Code, pipeline-as-code, policy-as-code, and automated security-gate effectiveness.
  • Review secrets management across development, build, deployment, and operational environments.
  • Evaluate vulnerability management, remediation tracking, patch governance, EOL/EOS, and release-risk governance.
  • Assess signing-key, certificate, and HSM lifecycle controls.
  • Validate SBOM generation and binary-to-SBOM reconciliation.
  • Support lifecycle security assessments, compliance evidence mapping, and audit traceability.
  • Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, remediation guidance, and stakeholder-ready executive communication.
  • Recommend finding-specific follow-up work and support release governance reviews.
Required Skills / Experience
  • 10+ years of experience in secure CI/CD pipeline setup, governance, and controls validation across different technology stacks.
  • 2+ years of hands-on SBOM analysis experience.
  • Strong understanding of Dev Sec Ops  and secure software delivery practices.
  • Strong experience with SBOM frameworks:
    CycloneDX, SPDX, VEX/CSAF.
  • Experience with SCA, SAST, DAST, dependency scanning, and secrets scanning.
  • Experience with artifact integrity, artifact signing, verification, tamper testing, and build provenance.
  • Strong knowledge of CI/CD security, secure release governance, and automated security gates.
  • Experience with vulnerability management, remediation governance, dependency governance, and patch lifecycle management.
  • Experience with secrets management and secure release controls.
  • Knowledge of container, registry, build-agent, and CI/CD runner security.
  • Experience with Infrastructure-as-Code and pipeline-as-code security.
  • Knowledge of policy-as-code and security controls validation.
  • Experience with compliance evidence, audit traceability, and regulatory security…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary