Software Engineer, DevSecOps
$150,000–$187,000 year
On-siteLos Angeles, California, United States
Job Summary
Build and maintain CI/CD pipelines across languages and functions, primarily in GitHub Actions, while optimizing containerized build and test workflows. Own the secure container supply chain by hardening base images, managing trusted registries, and integrating image scanning into every build. Automate SBOM generation and vulnerability scanning across artifacts, delivering results in a clear, actionable format. Own code-signing infrastructure and verification workflows to guarantee software authenticity and integrity. Partner with software engineers to triage application security vulnerabilities and champion secure coding practices. Work with embedded, ground, and infrastructure teams to embed security principles directly into pipelines. This role requires U.S. Person status for access to export-controlled data and 4+ years of DevOps experience.
Required Qualifications
- U.S. Person status
- 4+ years of hands-on experience in DevOps, platform / DevSecOps, or cloud infrastructure roles
- Bachelor's degree in Computer Science, Electrical Engineering, or equivalent experience
- Strong proficiency building and maintaining CI/CD pipelines in GitHub Actions
- Hands-on experience with Docker and container development — building, hardening, and optimizing images
- Experience with secure container, SBOM, and scanning tools (e.g., Chainguard, JFrog Xray, Binarly)
- Experience with artifact management (JFrog Artifactory)
Desired Qualifications
- Experience with container orchestration (Kubernetes)
- Working knowledge of Linux and system administration
- Experience with cloud infrastructure (AWS preferred), networking, and services
- Familiarity with static analysis tooling (Black Duck, Klocwork)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.