O

DevSecOps & Supply Chain Security Consultant - (Onsite - Boston, MA)

Job Description - DevSecOps & Supply Chain Security Consultant - (Onsite - Boston, MA)

DevSecOps & Supply Chain Security Consultant - (Onsite - Boston, MA)

We are looking to hire a candidate with the mentioned skill sets and experience for one of our clients, 


Job Summary


We are seeking a DevSecOps & Supply Chain Security Consultant with 10+ years of experience in secure software delivery, CI/CD, and software supply-chain security. The consultant will focus on secure SDLC, CI/CD pipeline architecture and security, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependency and secrets management, SAST/DAST, containers, IaC, vulnerability governance, and regulatory evidence.


The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions, remediation, release readiness, and residual risk and will produce audit-ready findings and stakeholder-ready reporting.


Work Authorization: Must be a US Citizen or Green Card holder (US Person).


Travel: Up to three (3) weeks of travel to the client’s Tewksbury, MA site during the engagement. Travel and accommodation expenses will be arranged and covered. Travel may be a single visit or split across multiple visits based on project requirements.


Key Responsibilities



  • Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management.

  • Review SDLC processes, security tooling, and secure development practices.

  • Assess SCA, SBOM accuracy/completeness, dependency governance, and third-party risk.

  • Evaluate CI/CD pipeline security, artifact integrity, secure release controls, and build provenance.

  • Validate source-to-release traceability, artifact signing and promotion, tamper resistance, SBOM accuracy, security gates, exceptions, and remediation decisions.

  • Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls.

  • Evaluate Infrastructure-as-Code, pipeline-as-code, policy-as-code, and automated security-gate effectiveness.

  • Review secrets management across development, build, deployment, and operational environments.

  • Evaluate vulnerability management, remediation tracking, patch governance, EOL/EOS, and release-risk governance.

  • Assess signing-key, certificate, and HSM lifecycle controls.

  • Validate SBOM generation and binary-to-SBOM reconciliation.

  • Support lifecycle security assessments, compliance evidence mapping, and audit traceability.

  • Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, remediation guidance, and stakeholder-ready executive communication.

  • Recommend finding-specific follow-up work and support release governance reviews.



Required Skills / Experience



  • 10+ years of experience in secure CI/CD pipeline setup, governance, and controls validation across different technology stacks.

  • 2+ years of hands-on SBOM analysis experience.

  • Strong understanding of DevSecOps and secure software delivery practices.

  • Strong experience with SBOM frameworks: CycloneDX, SPDX, VEX/CSAF.

  • Experience with SCA, SAST, DAST, dependency scanning, and secrets scanning.

  • Experience with artifact integrity, artifact signing, verification, tamper testing, and build provenance.

  • Strong knowledge of CI/CD security, secure release governance, and automated security gates.

  • Experience with vulnerability management, remediation governance, dependency governance, and patch lifecycle management.

  • Experience with secrets management and secure release controls.

  • Knowledge of container, registry, build-agent, and CI/CD runner security.

  • Experience with Infrastructure-as-Code and pipeline-as-code security.

  • Knowledge of policy-as-code and security controls validation.

  • Experience with compliance evidence, audit traceability, and regulatory security assessments.

  • Knowledge of NIST SSDF and secure software supply-chain practices.

  • Experience with supplier security and software-acquisition assessments.

  • Hands-on experience with tools such as Syft, Grype, Trivy, Gitleaks, Dependency-Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins, and Azure DevOps.

  • Experience with CRA / regulatory security assessments is highly preferred.

  • Familiarity with SLSA or modern software supply-chain security practices is a plus.

  • Experience with regulated products, export-controlled environments, or compliance-driven cybersecurity assessments is preferred.

  • Strong documentation and stakeholder communication skills.

  • Candidate needs to be US Citizen or Green Card holder. 



Preferred Certifications



  • CSSLP

  • Certified DevSecOps Professional

  • Other relevant product-security credentials.



Location & Travel



  • Location: Boston, MA

  • On-site: Ability to work from the Boston office for 4–6 weeks during the engagement.

  • Travel: Up to 3 weeks at the client’s Tewksbury, MA site during the engagement. Travel and accommodation expenses will be covered. 



Other Job Details:




  • Job Type: C2C or W2.

  • Location:  Boston, MA, USA.

  • Interviews: Video interviews.

  • Docs required: ID proof will be required.

Original job DevSecOps & Supply Chain Security Consultant - (Onsite - Boston, MA) posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Similar DevSecOps & Supply Chain Security Consultant Jobs in the US

GrabJobs is the no1 job portal in the US, connecting you to thousands of jobs fast! Find the best jobs in the US, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.