Full Stack + DevSecOps Platform Engineer
Listed on 2026-05-30
-
IT/Tech
Cybersecurity, Data Security
Job Title: Senior Full Stack + Dev Sec Ops Platform Engineer
Tax Term: W2/1099 Only
Location: Atlanta – Onsite
Employment Type: Contract
Job Descrpition:SBOM / CBOM Inventory, Vulnerability Scanning & AI Auto-Remediation Platform
We are looking for a hands‑on Senior Full Stack + Dev Sec Ops Platform Engineer to design and build an internal security automation platform focused on SBOM/CBOM inventory, vulnerability scanning, and AI‑assisted auto‑remediation using Claude.
This is not a traditional full‑stack developer role. The ideal candidate should have strong expertise across application development, CI/CD, cloud engineering, security scanning, cryptography inventory, and remediation automation.
Key ResponsibilitiesDesign and build a centralized platform for SBOM and CBOM inventory.
Scan applications, repositories, containers, dependencies, certificates, keys, crypto algorithms, TLS/HTTPS configurations, secrets, and runtime components.
Build and integrate Jenkins/Git Lab CI/CD pipelines for:
SBOM scanning
CBOM scanning
Vulnerability scanning
Container scanning
Code scanning
Crypto policy scans
Identify:
Vulnerable dependencies
CVEs
Weak cryptography
Expired certificates
Insecure TLS versions
Hardcoded secrets
Non‑compliant libraries
Build dashboards and reporting for:
Application inventory
Vulnerability posture
Crypto posture
Remediation status
SLA tracking
Integrate security tools such as:
Syft
Grype
CycloneDX
JFrog Xray
Sonatype
Checkmarx
Fortify
Veracode
Similar enterprise security tools
Build AI‑assisted remediation workflows using Claude or similar AI coding agents.
Automate safe fixes including:
Dependency upgrades
Base image updates
Configuration changes
Pull request creation
Ensure all remediations pass through:
Build validation
Testing
Security scans
Approval workflows
Audit checks
Rollback mechanisms
before merge or deployment.
Collaborate closely with Application, Security, Dev Ops, and Platform Engineering teams.
Strong hands‑on backend development experience with Java/Spring Boot
.Experience with at least one additional programming language:
Node.js
Python
Go
Experience building:
REST APIs
Microservices
Batch jobs
Platform integrations
Hands‑on experience with:
Jenkins
Git Lab CI/CD
Strong understanding of:
SBOM
Dependency scanning
Transitive dependencies
CVEs
Container image scanning
Good understanding of CBOM and crypto inventory, including:
TLS/HTTPS
Certificates
Keys
Cipher suites
Encryption algorithms
Hashing algorithms
Signing algorithms
Keystores / Truststores
Secrets management
Ability to identify weak cryptography such as:
MD5
SHA-1
DES / 3
DESRC4
RSA-1024
TLS 1.0 / TLS 1.1
Disabled certificate validation
Hands‑on AWS experience with services such as:
Lambda
API Gateway
S3
DynamoDB
IAM
ECS / EKS
Cloud Watch
X-Ray
Secrets Manager
KMS
Experience with monitoring and troubleshooting tools such as:
Splunk
ELK / Kibana
Cloud Watch
X‑Ray
Strong troubleshooting skills across:
Applications
Pipelines
Cloud infrastructure
Security issues
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).