- Execute the software supply chain security strategy to expand State Street’s ability to deploy secure-by-default open source artifacts across the enterprise
- Partner with Engineering team leads to create, implement, and apply DevSecOps and AppSec principles and processes
- Assist application teams with onboarding to adopted security tools and technologies
- Work with vendors to troubleshoot platforms and integration-related issues
- Deliver and communicate reporting via dashboards and metrics
- Develop and maintain supply chain security and DevSecOps documentation
- Continuously improve DevSecOps and Software Supply Chain Security processes and tools
- Deliver tasks based on project objectives and technically support projects through completion
Requirements
- Proven expertise in Application Security (AppSec) and software supply chain security implementation/governance
- Hands‑on experience in application security, build and release management, secure software development lifecycle (SSDLC), and automation of security processes within CI/CD pipelines
- Experience configuring and managing artifact caches (e.g. JFrog Artifactory) and enterprise‑scale artifact sources of truth
- Deep familiarity with package ecosystems such as Maven Central and PyPI
- Familiarity with SLSA principles
- Previous experience developing software in Java, .Net, Python, Node.js, or similar technologies
- Experience with Azure and AWS
- Extensive experience developing and managing application and software supply chain security solutions
- Experience managing artifact caches, locking down artifact sourcing, and continuous security assessment
- Current information security certification, including CISSP
- Experience with automation and orchestration tools such as Ansible, Terraform, or Kubernetes is valuable
- Knowledge of Infrastructure as Code (IaC) principles and experience automating deployment and management tasks in a hybrid cloud environment is beneficial
- Proven technical solutioning experience with Agile Development, DevOps, Cloud Engineering, System Hardening, DevSecOps, Cybersecurity, and Cloud Security
- Excellent verbal and written communication skills across internal and external organizations
- Ability to prioritize and manage several projects or priorities simultaneously
- 6+ years of relevant combined experience across development, CI/CD, software supply chain security, and application security
- Experience with application security tooling and its operations with modern CI/CD and DevSecOps best practices
- Experience partnering with the Dev community to influence adoption of application security best practices and tooling
- Security+ or other cybersecurity security certification
- Experience with one or more common programming languages such as Java, .Net, or Python
Core Competencies
Demonstrates expertise in Application Security and Software Supply Chain Security, with a strong focus on implementing DevSecOps principles and managing security tools within CI/CD pipelines. Proven ability to develop secure software solutions and enhance security processes in cloud environments.
Highest-signal resume keywords
- Application Security (AppSec)
- Software Supply Chain Security
- DevSecOps Implementation
- CISSP Certification
- CI/CD Pipeline Automation
ATS Optimization Keywords
Hard Skills
- Secure Software Development Lifecycle (SSDLC)
- Artifact Cache Management
- Java Development
- Python Development
- Azure Cloud
- AWS Cloud
- Infrastructure as Code (IaC)
- Agile Development
- DevOps Practices
- Continuous Security Assessment
Soft Skills
- Excellent Communication Skills
- Project Management
Certifications & Qualifications
- CISSP
- Security+
Industry Keywords
- DevSecOps
- Cybersecurity
- Cloud Security
- SLSA Principles
- Package Ecosystems
Tools & Technologies
- JFrog Artifactory
- Ansible
- Terraform
- Kubernetes
- CI/CD Tools
Software Supply Chain Security Engineer in ma at Unknown Company
This position is listed as full time and hybrid.