Unknown Company

Software Supply Chain Security Engineer

ma • Posted Yesterday
Hybrid Full Time IT & Technology

  • Execute the software supply chain security strategy to expand State Street’s ability to deploy secure-by-default open source artifacts across the enterprise
  • Partner with Engineering team leads to create, implement, and apply DevSecOps and AppSec principles and processes
  • Assist application teams with onboarding to adopted security tools and technologies
  • Work with vendors to troubleshoot platforms and integration-related issues
  • Deliver and communicate reporting via dashboards and metrics
  • Develop and maintain supply chain security and DevSecOps documentation
  • Continuously improve DevSecOps and Software Supply Chain Security processes and tools
  • Deliver tasks based on project objectives and technically support projects through completion

Requirements

  • Proven expertise in Application Security (AppSec) and software supply chain security implementation/governance
  • Hands‑on experience in application security, build and release management, secure software development lifecycle (SSDLC), and automation of security processes within CI/CD pipelines
  • Experience configuring and managing artifact caches (e.g. JFrog Artifactory) and enterprise‑scale artifact sources of truth
  • Deep familiarity with package ecosystems such as Maven Central and PyPI
  • Familiarity with SLSA principles
  • Previous experience developing software in Java, .Net, Python, Node.js, or similar technologies
  • Experience with Azure and AWS
  • Extensive experience developing and managing application and software supply chain security solutions
  • Experience managing artifact caches, locking down artifact sourcing, and continuous security assessment
  • Current information security certification, including CISSP
  • Experience with automation and orchestration tools such as Ansible, Terraform, or Kubernetes is valuable
  • Knowledge of Infrastructure as Code (IaC) principles and experience automating deployment and management tasks in a hybrid cloud environment is beneficial
  • Proven technical solutioning experience with Agile Development, DevOps, Cloud Engineering, System Hardening, DevSecOps, Cybersecurity, and Cloud Security
  • Excellent verbal and written communication skills across internal and external organizations
  • Ability to prioritize and manage several projects or priorities simultaneously
  • 6+ years of relevant combined experience across development, CI/CD, software supply chain security, and application security
  • Experience with application security tooling and its operations with modern CI/CD and DevSecOps best practices
  • Experience partnering with the Dev community to influence adoption of application security best practices and tooling
  • Security+ or other cybersecurity security certification
  • Experience with one or more common programming languages such as Java, .Net, or Python

Core Competencies

Demonstrates expertise in Application Security and Software Supply Chain Security, with a strong focus on implementing DevSecOps principles and managing security tools within CI/CD pipelines. Proven ability to develop secure software solutions and enhance security processes in cloud environments.

Highest-signal resume keywords

  • Application Security (AppSec)
  • Software Supply Chain Security
  • DevSecOps Implementation
  • CISSP Certification
  • CI/CD Pipeline Automation

ATS Optimization Keywords

Hard Skills

  • Secure Software Development Lifecycle (SSDLC)
  • Artifact Cache Management
  • Java Development
  • Python Development
  • Azure Cloud
  • AWS Cloud
  • Infrastructure as Code (IaC)
  • Agile Development
  • DevOps Practices
  • Continuous Security Assessment

Soft Skills

  • Excellent Communication Skills
  • Project Management

Certifications & Qualifications

  • CISSP
  • Security+

Industry Keywords

  • DevSecOps
  • Cybersecurity
  • Cloud Security
  • SLSA Principles
  • Package Ecosystems

Tools & Technologies

  • JFrog Artifactory
  • Ansible
  • Terraform
  • Kubernetes
  • CI/CD Tools

#J-18808-Ljbffr

Software Supply Chain Security Engineer in ma at Unknown Company

This position is listed as full time and hybrid.

Back to Job Search