Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details
Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Zappsec Inc.

DevSecOps & Supply Chain Security Consultant

Career Insights for Supply Chain Specialist (General)

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Massachusetts data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Supply Chain Specialist coordinates shipments and works to improve supply chain processes at a company or organization. Procures materials and manages order prices and quantities; receives shipments and organizes inventories; forecasts demand, responds to changes in demand, and resolves supply chain issues.

$102,619 / year median in Massachusetts

+15% projected growth

Explore Career

Job Description

DevSecOps & Supply Chain Security Consultant Zappsec Inc. Tewksbury, MA Job Details Full-time 1 day ago Qualifications Security Authorization Containerization systems DevSecOps Practices Test scanning software Verification (System development task) Tooling Infrastructure as Code (IaC) Compliance audits & assessments Digital signature usage Metrics Reporting NIST standards IT control testing Software development Vulnerability management Reporting on compliance risks Regulatory compliance analysis DevOps automation Key management Web Application Security Testing Information security auditing Supplier risk evaluation Vuls Full Job Description DevSecOps & Supply Chain Security Consultant Role Summary Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security. The role covers secure SDLC, pipeline architecture and access, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependencies, secrets, SAST/DAST, containers, IaC, vulnerability governance and regulatory evidence. The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions and remediation; produce audit-ready findings, release-readiness and residual-risk conclusions; and recommend finding-specific work. CRA, regulated-product and stakeholder-reporting experience is highly preferred. Key Responsibilities Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management to support lifecycle security evaluation and compliance traceability. Review SDLC processes, tooling, and secure development practices Assess software supply chain security, including
SCA, SBOM
accuracy/completeness, dependency governance, and third-party risk Evaluate CI/CD pipeline security, artifact integrity, and secure release controls Review secrets management across development, build, deployment, and operational environments Assess logging, auditability, and security event traceability controls Evaluate vulnerability management, remediation tracking, and patch governance processes Support lifecycle security assessment, compliance evidence mapping, and traceability Contribute to assessment reporting, remediation guidance, and release governance reviews Validate source-to-release traceability, build provenance, tamper resistance, artifact signing and promotion controls, SBOM accuracy, security gates, exceptions, remediation decisions, release-readiness conclusions and residual-risk positions. Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, stakeholder-ready executive communication and recommendations for finding-specific follow-up work. Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls, infrastructure-as-code and pipeline-as-code security, policy-as-code implementation and automated security-gate effectiveness.
Required Skills & Experience Mandatory:
Strong understanding of DevSecOps and secure software delivery practices Experience with SBOM frameworks (Cyclone
DX, SPDX
) and SCA tooling Familiarity with CI/CD security controls and artifact integrity validation Experience with vulnerability management and dependency governance programs Understanding of lifecycle security, auditability, and compliance evidence requirements Experience with secrets management and secure release governance SBOM Analysis (Cyclone
DX, SPDX, VEX/CSAF
) Artifact Integrity SAST, DAST, Dependency & Secrets Scanning Vulnerability Management & Remediation Governance Secrets Management Compliance Evidence & Audit Traceability CRA / Regulatory Security Assessments Syft and related SBOM tools Secure Release Governance & Security Controls Validation Build provenance and software-delivery traceability Artifact signing, verification and tamper testing Container, registry, build-agent and CI/CD runner security Infrastructure-as-Code and pipeline-as-code security Signing-key, certificate and HSM lifecycle controls SBOM generation and binary-to-SBOM reconciliation Open-source and third-party dependency governance EOL/EOS and patch-lifecycle governance Security exception and release-risk governance Pipeline policy-as-code and automated security gates Vulnerability metrics and release-readiness reporting NIST SSDF and secure software supply-chain practices Supplier security and software-acquisition assessments Tools such as Syft, Grype, Trivy, Gitleaks, Dependency-Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins and Azure DevOps US Citizen or Green Card holder (US Person) Good to have: Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments Experience participating in engagement related to export-controlled environments Familiarity with SLSA or modern software supply chain security practices Strong documentation skills Preferred Certifications CSSLP, Certified DevSecOps Professional or any other relevant product-security credentials Years of Required Experience 10+ years in secure CI/CD pipeline setup, governance and controls validation, including setting up, maintaining and validating Secure CI/CD pipelines across different types of technology stacks. 2+ years of hands-on SBOM analysis experience. oPM0jGmMGC